The Fixwareout worked great. I am unsure of the results though. Your assistance is appreciated.


Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B67CBF7075D7-1AEA-2864-F0E5-DF7DE243{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\jxjmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\1trap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\2trap
...

Microsoft (R) Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmjxj.exe"=-
...

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF
YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

Searching by size/names...


Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at
Virustotal
C:\WINNT\SYSTEM32\CSTQV.EXE 51,804 2006-10-07

C:\WINNT\SYSTEM32\DMJXJ.EXE 60,977 2003-06-19

Other suspects.
Directory of C:\WINNT\system32

Misc files.

Checking for older varients covered by the Rem3
tool.