Fixwareout
Fixwareout Last edited 4/5/2007
Post this report in the forums please
...
サササササPrerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdpht.exe"
サササササ System restarted
サササササ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
サササササ Misc files.
....
サササササ Checking for older varients.
....
Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.
Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or
http://virusscan.jotti.org/
サササササ Other
サササササ Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="\"G:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="G:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="G:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"NvCplDaemon"="RUNDLL32.EXE G:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE G:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SoundMAXPnP"="G:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SoundMAX"="\"G:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"ccApp"="\"G:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"URLLSTCK.exe"="G:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"
"MessengerPlus3"="\"G:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
"Symantec NetDriver Monitor"="G:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"DAEMON Tools"="\"G:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"WinampAgent"="G:\\Program Files\\Winamp\\winampa.exe"
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="G:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"Run StartupMonitor"="StartupMonitor.exe"
"NeroFilterCheck"="G:\\WINDOWS\\system32\\NeroCheck.exe"
"StormCodec_Helper"="\"G:\\Program Files\\Ringz Studio\\Storm Codec\\StormSet.exe\" /S /opti"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="G:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"G:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"msnmsgr"="\"G:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"swg"="G:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it
サササササ End report サササササ
AVG:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:45:39 AM 8/04/2007
+ Scan result:
G:\bob\My Documents\Nb_ff8.exe -> Dropper.Small : Cleaned.
G:\bob\My Documents\ff8pced.zip/Nb_ff8.exe -> Dropper.Small : Cleaned.
G:\bob\My Documents\miltosraynor-ff8.zip/FF8 by Miltos Raynor.exe -> Dropper.Small : Cleaned.
C:\Yet to be sorted\external\Folders2\Downloads\Activity Monitor 3.5 + Crack.rar/swatcher.EXE -> Not-A-Virus.Monitor.Win32.ActivityMonitor.35 : Cleaned.
C:\Yet to be sorted\external\New Folder (2)\zips\Activity_Monitor_v3.5 + crack.zip/swatcher.EXE -> Not-A-Virus.Monitor.Win32.ActivityMonitor.35 : Cleaned.
C:\Yet to be sorted\external\New Folder (2)\zips\Activity_Monitor_v3.5 crack.zip/swatcher.EXE -> Not-A-Virus.Monitor.Win32.ActivityMonitor.35 : Cleaned.
C:\Yet to be sorted\external\New Folder (2)\zips\family.key.logger.2.50.full.incl.keygen-tsrh.zip/familykeylogger.zip/FamilyKeyLogger-setup.exe -> Not-A-Virus.Monitor.Win32.FamilyKeyLogger.230 : Cleaned.
G:\bob\My Documents\keylogger-download.zip/HomeKeyLogger-setup.exe -> Not-A-Virus.Monitor.Win32.HomeKeyLogger.162 : Cleaned.
C:\My Music\Music Albums\ユナノリコュネォシッMP3\ユナノリコュ-ナキネュ\ウャシカエ惕柀晴ソ・ルーイネォ.zip/³¬¼¶´úÀíÈí¼þ¿ìËÙ°²È«/¶¯Ì¬ÍøÈí¼þ/¶¯ÍøÍ¨/dynapass1.5.exe -> Not-A-Virus.NetTool.Win32.UltraScape.15 : Cleaned.
E:\My Music\Music Albums\ユナノリコュネォシッMP3\ユナノリコュ-ナキネュ\ウャシカエ惕柀晴ソ・ルーイネォ.zip/³¬¼¶´úÀíÈí¼þ¿ìËÙ°²È«/¶¯Ì¬ÍøÈí¼þ/¶¯ÍøÍ¨/dynapass1.5.exe -> Not-A-Virus.NetTool.Win32.UltraScape.15 : Cleaned.
G:\bob\Cookies\bob@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
G:\bob\Cookies\bob@ads18.bpath[2].txt -> TrackingCookie.Bpath : Cleaned.
G:\bob\Cookies\bob@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
G:\bob\Cookies\bob@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
G:\bob\Cookies\bob@com[2].txt -> TrackingCookie.Com : Cleaned.
G:\bob\Cookies\bob@com[3].txt -> TrackingCookie.Com : Cleaned.
G:\bob\Cookies\bob@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
G:\bob\Cookies\bob@www.gamershell[1].txt -> TrackingCookie.Gamershell : Cleaned.
G:\bob\Cookies\bob@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
G:\bob\Cookies\bob@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
G:\bob\Cookies\bob@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
G:\bob\Cookies\bob@www.sidefind[2].txt -> TrackingCookie.Sidefind : Cleaned.
G:\bob\Cookies\bob@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
G:\System Volume Information\_restore{09288CCE-FFF3-4B83-BE51-73EBD0867D7F}\RP109\A0023370.exe -> Trojan.DNSChanger.ik : Cleaned.
C:\Yet to be sorted\external\Folders2\Downloads\Website.Extractor.9.03.Cracked-iNFECTED-Pleasuredome101.rar/Website.Extractor.9.03.Cracked-iNFECTED-Pleasuredome101\patch_webextra.exe -> Trojan.Proxcrak.A : Cleaned.
C:\Yet to be sorted\external\Folders2\Downloads\Website.Extractor.9.03.Cracked-iNFECTED-Pleasuredome101\patch_webextra.exe -> Trojan.Proxcrak.A : Cleaned.
G:\Old Program Files\WebSite eXtractor2\patch_webextra.exe -> Trojan.Proxcrak.A : Cleaned.
::Report end