|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
#1
|
|||
|
|||
|
been hijacked... too many errors and popups
i am having the same problems as stupidads,(popups like crazy,that stupid shopnav keeps coming up whenever i search for something in msn) i made the mistake in removing Search Assistant 180 when it asked me to uninstall, do i need this program??..also i can't get to my email through my msn email account, it says i have no messages and i have to go through hotmail to view my email. and last when i log on to msn error reports pop up..please help here is my log
Logfile of HijackThis v1.98.0 Scan saved at 1:19:54 AM, on 7/6/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Nhksrv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\WINDOWS\DELLMMKB.EXE C:\PROGRA~1\NORTON~1\navapw32.exe C:\WINDOWS\System32\qttask.exe C:\WINDOWS\System32\wjview.exe C:\WINDOWS\System32\dcomx.exe C:\documents and settings\rachelle\local settings\temp\VWnlT.exe C:\WINDOWS\System32\P2P Networking\P2P Networking.exe C:\Program Files\FinePixViewer\QuickDCF.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\Program Files\Netropa\OSD.exe C:\Program Files\MSN\MSNCoreFiles\msn.exe C:\Program Files\MSN\MSNIA\msniasvc.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\MSN\MSNCoreFiles\dw15.exe C:\WINDOWS\System32\dwwin.exe C:\Program Files\Microsoft Bootvis\BootVis.exe C:\Program Files\hijackkthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nkvd.us (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://nkvd.us (obfuscated) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nkvd.us (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\rachelle\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://nkvd.us (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nkvd.us (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://nkvd.us (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank F0 - system.ini: Shell= F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL O2 - BHO: SuperBar - {136A9D1D-1F4B-43D4-8359-6F2382449255} - C:\Program Files\SuperBar\SuperBar.Dll O2 - BHO: SNHlprObj Class - {14b3d246-6274-40b5-8d50-6c2ade2ab29b} - C:\Program Files\Srng\SNHelper.dll O2 - BHO: (no name) - {97E9BE63-D47F-4643-9089-75B599545AEF} - C:\WINDOWS\System32\gpddmaa.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll O2 - BHO: OsbornTech Popup Blocker - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - C:\WINDOWS\System32\mshelper.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: SuperBar - {5D9960CE-BD39-4C4F-AC67-79669D19B5FB} - C:\Program Files\SuperBar\SuperBar.Dll O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\en-us\msntb.dll O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [EbatesMoeMoneyMaker] wjview /cp "C:\Program Files\EbatesMoeMoneyMaker\System\Code" Main lp: "C:\Program Files\EbatesMoeMoneyMaker"O4 - HKLM\..\Run: [system] dcomx.exe O4 - HKLM\..\Run: [BMWERJT] C:\WINDOWS\BMWERJT.exe O4 - HKLM\..\Run: [SpyBlocs] C:\Program Files\SpyBlocs\SpyBlocs.exe O4 - HKLM\..\Run: [VWnlT] C:\documents and settings\rachelle\local settings\temp\VWnlT.exe O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART O4 - HKLM\..\RunServices: [system] dcomx.exe O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe O4 - Global Startup: LimeWire 3.8.7.lnk = C:\Program Files\LimeWire\3.8.7\LimeWire.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\Office\OSA9.EXE O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O8 - Extra context menu item: Ebates - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - (no file) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra button: Ebates - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm (file missing) (HKCU) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O13 - DefaultPrefix: http://%6E%6B%76%64%2E%75%73/ O13 - WWW Prefix: http://%6E%6B%76%64%2E%75%73/ O13 - Home Prefix: http://%6E%6B%76%64%2E%75%73/ O13 - Mosaic Prefix: http://%6E%6B%76%64%2E%75%73/ O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) - http://imgfarm.com/images/nocache/f...etup1.0.0.5.cab O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/02cca90f69ab67...etzip/RdxIE.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/2726bb7f6fe2f0...ip/RdxIE601.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://jdl.sun.com/update/1.4.2/jin...indows-i586.cab O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://www.gleim.com/data/tpdemodeploy/eqe.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{30FF3174-7263-4B12-8EA9-56B02E75617A}: NameServer = 209.244.0.3 209.244.0.4 O17 - HKLM\System\CS1\Services\Tcpip\..\{30FF3174-7263-4B12-8EA9-56B02E75617A}: NameServer = 209.244.0.3 209.244.0.4 O18 - Filter: text/html - {7C72D745-CF37-43E3-8F47-1AFB9A86F01C} - C:\WINDOWS\System32\gpddmaa.dll O18 - Filter: text/plain - {7C72D745-CF37-43E3-8F47-1AFB9A86F01C} - C:\WINDOWS\System32\gpddmaa.dll thank you |
|
#2
|
|||
|
|||
|
Please do the following:
Download the program FindNFix from the following location: http://freeatlast100.100free.com/ Once at that page, download FindNFix. Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window. On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt. Copy the contents of that file into a reply to this post. |
|
#3
|
|||
|
|||
|
first half
Microsoft Windows XP [Version 5.1.2600]
IE build and last SP(s) 6.0.2800.1106 SP1-Q822925-Q330994-Q828750-Q824145-Q832894-Q837009-Q831167-Q823353 The type of the file system is NTFS. C: is not dirty. Sat 07/24/2004 0:03am up 0 days, 0:36 ***LOG!*** Scanning for file(s)... ********* (*1*) ......... Locked or 'Suspect' file(s) found... C:\WINDOWS\System32\WDMA.DLL +++ File read error \\?\C:\WINDOWS\System32\WDMA.DLL +++ File read error (*2*) ........ **File C:\FINDnFIX\LIST.TXT WDMA.DLL Can't Open! (*3*) ........ C:\WINDOWS\SYSTEM32\ wdma.dll Thu Jun 24 2004 11:53:56a A...R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K C:\WINDOWS\SYSTEM32\ wdma.dll Thu Jun 24 2004 11:53:56a A...R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K unknown/hidden files... No matches found. (*4*) ......... Sniffing.......... Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMA.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMA.DLL (*5*) **File C:\WINDOWS\SYSTEM32\DLLXXX.TXT Access denied ..................... WDMA.DLL .....57344 24.06.2004 ********* Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512...) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 Dumping Values........ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM Member of...: (Admin logon required!) User is a member of group RACHELLESD\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group \LOCAL. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. Service search different variant) '"Network Security Service","__NS_Service_3"...[SC] GetServiceKeyName FAILED 1060: The specified service does not exist as an installed service. [SC] GetServiceDisplayName FAILED 1060: The specified service does not exist as an installed service. Notepad check.... No matches found. No matches found. No matches found. Dir 'junkxxx' was created with the following permissions... (FAT32=NA) Directory "C:\junkxxx" Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000009 --o- 101F01FF ---A DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000002 tc-- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000009 --o- 101F01FF ---A DSPO rw+x BUILTIN\Administrators |
|
#4
|
|||
|
|||
|
2nd half , thank you for your time!!
Allow 00000002 tc-- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000010 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators Allow 00000010 t--- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000010 t--- 001F01FF ---- DSPO rw+x RACHELLESD\rachelle Allow 0000001B -co- 10000000 ---A ---- ---- \CREATOR OWNER Allow 00000010 t--- 001200A9 ---- -S-- r--x BUILTIN\Users Allow 0000001B -co- A0000000 R-X- ---- ---- BUILTIN\Users Allow 00000012 tc-- 00000004 ---- ---- --+- BUILTIN\Users Allow 00000012 tc-- 00000002 ---- ---- -w-- BUILTIN\Users Owner: RACHELLESD\rachelle Primary Group: RACHELLESD\None Backups created... 0:05am up 0 days, 0:38 Sat 07/24/2004 A C:\FINDnFIX\winBack.hiv --a-- - - - - - 8,192 07-06-2004 winback.hiv A C:\FINDnFIX\keys1\winkey.reg --a-- - - - - - 287 07-06-2004 winkey.reg Performing string scan.... 00001150: vk : f AppInit_DLLs G 00001190: C : \ W I N D O W S \ S y s t e m 3 2 \ w d m a . d l l 000011D0: h vk UDeviceNotSelectedTimeout 1 5 00001210: P 9 0 vk ' zGDIProcessHandle 00001250:Quota" vk x Spooler2 y e s _ h 00001290: ( X vk 5swapdisk vk 000012D0: . TransmissionRetryTimeout h ( X 00001310: vk ' M USERProcessHandleQuotaB 00001350: 00001390: 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: ---------- WIN.TXT fAppInit_DLLs֍GC -------------- -------------- C:\WINDOWS\System32\wdma.dll yes REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 **File C:\FINDnFIX\WIN.TXT regf |
|
#5
|
|||
|
|||
|
Delete the entire c:\findnfix directory as it is way too old now.
THen foillow these steps to get a newer version: Please do the following: Download the program FindNFix from the following location: http://www10.brinkster.com/expl0iter/freeatlast/FNF/ Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window. On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt. Copy the contents of that file into a reply to this post. |
|
#6
|
|||
|
|||
|
here is the updated version of findnfix log....thanks again for your time
Wed 04 Aug 04 20:06:40
*** www10.brinkster.com/expl0iter/freeatlast/FNF/ *** Microsoft Windows XP Home Edition 5.1 Service Pack 1 (Build 2600) Microsoft Windows XP [Version 5.1.2600] IE version: 6.0.2800.1106 SP1-Q822925-Q330994-Q828750-Q824145-Q832894-Q837009-Q823353-Q867801 The type of the file system is NTFS. Wednesday, August 04, 2004 (8/4/2004) 8:06 PM, Pacific Daylight Time 8:06pm up 0 days, 0:15 Member of...: ("ADMIN" logon + group match required!) !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Group BUILTIN\Administrators matches list. Group BUILTIN\Users matches list. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! User is a member of group RACHELLESD\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group \LOCAL. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. *** Note! *** The list will produce a small database of files that will match certain criteria. Ex: read only files, s/h files, last modified date. size, etc. The filters provided and registry scan should match the corresponding file(s) listed. Unless the file match the entire criteria, it should not be pointed to remove without attempting to confirm it's nature! At times there could be several (legit) files flagged, and/or duplicate culprit file(s)! If in doubt, always search the file(s) and properties according to criteria! The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder ***LOG!***(*updated 8/05) **Use at your own risk!** Scanning for file(s)... ********* (*1*) ......... Locked or 'Suspect' file(s) found... C:\WINDOWS\SYSTEM32\WDMA.DLL +++ File read error \\?\C:\WINDOWS\System32\WDMA.DLL +++ File read error (*2*) ........ WDMA.DLL Can't Open! (*3*) ........ C:\WINDOWS\SYSTEM32\ wdma.dll Thu Jun 24 2004 11:53:56a A...R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K unknown/hidden files... No matches found. (*4*) ......... Sniffing.......... Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMA.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL (*5*) Access denied ..................... WDMA.DLL .....57344 24.06.2004 (*6*) fgrep: can't open input C:\WINDOWS\SYSTEM32\WDMA.DLL ********* Search by size... C:\WINDOWS\SYSTEM32\ wdma.dll Thu Jun 24 2004 11:53:56a A...R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMA.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL ********* BHO search... **File C:\WINDOWS\SYSTEM32\AMCICGA.DLL 00001FF0: 25 25 25 30 32 78 00 00 . 00 00 00 00 C0 82 05 B3 %%%02x.. ..... fgrep: can't open input C:\WINDOWS\SYSTEM32\WDMA.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. |
|
#7
|
|||
|
|||
|
2nd half
Sniffed -> C:\WINDOWS\SYSTEM32\AMCICGA.DLL
SNiF 1.34 statistics Matching files : 1 Amount in bytes : 30720 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL ********* Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512...) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 Dumping Values........ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM Performing string scan.... 00001150: ; Yu vk UDeviceNotSelecte 00001190:dTimeout 1 5 P h vk ' zGDIProce 000011D0:ssHandleQuota" 9 0 vk Spooler2 00001210: y e s _ vk 5swapdisk h 00001250: X vk . TransmissionRetryTimeout vk 00001290: ' M USERProcessHandleQuotaB h X 000012D0: vk : f AppInit_DLLs G C : \ W I N 00001310 O W S \ S y s t e m 3 2 \ w d m a . d l l SVW e 1 00001350:] E U V E P d % (SVW e + ] 00001390: U j 5 1 5 1 d Pd % QQ %T2 Y e E 000013D0: , %\2 9 * z 00001410: P P Ph P %p2 j X % 00001450: % 1 9 u % 2 E P ~ E P ~ 00001490: n5 ^ P ] ] ] ] } ~ S u SSP T 000014D0: " C5 5 9 u % 2 } e M u Yd 00001510: _^[ % 1 % P ~ %`2 ) 00001550: } ] u j 1 Y % 2 V 00001590: / u ~ s M E P F<P E P 000015D0: O UT]j h 1 h + d 5 XPd % ] 9] ---------- WIN.TXT fAppInit_DLLs֍GC -------------- -------------- $0117F: UDeviceNotSelectedTimeout $011C7: zGDIProcessHandleQuota $01270: TransmissionRetryTimeout $012A0: USERProcessHandleQuotaB $012F0: AppInit_DLLs -------------- -------------- C:\WINDOWS\System32\wdma.dll -------------- -------------- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 A handle was successfully obtained for the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key. This key has 0 subkeys. The AppInitDLLs value exists and reports as 58 bytes, including the 2 for string termination. [AppInitDLLs] Ansi string : "C:\WINDOWS\System32\wdma.dll" 0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O. 0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e. 0020 6d 00 33 00 32 00 5c 00 77 00 64 00 6d 00 61 00 | m.3.2.\.w.d.m.a. 0030 2e 00 64 00 6c 00 6c 00 00 00 | ..d.l.l... ----------------------- Backups list... 8:10pm up 0 days, 0:19 Wed 04 Aug 04 20:10:48 C:\FINDNFIX\ keyback.hiv Wed Aug 4 2004 8:06:40p A.... 8,192 8.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 8,192 bytes 8.00 K C:\FINDNFIX\KEYS1\ winkey.reg Tue Jul 6 2004 12:06:28p A.... 287 0.28 K 1 item found: 1 file, 0 directories. Total of file sizes: 287 bytes 0.28 K *Temp backups... "C:\Documents and Settings\rachelle\Local Settings\Temp\Backs2\" keyback2.hi_ Aug 4 2004 8192 "keyback2.hi_" winkey2.re_ Jul 6 2004 287 "winkey2.re_" 2 items found: 2 files, 0 directories. Total of file sizes: 8,479 bytes 8.28 K C:\FINDNFIX\ JUNKXXX Wed Aug 4 2004 8:06:40p .D... <Dir> 1 item found: 0 files, 1 directory. -----END------ Wed 04 Aug 04 20:10:50 |
|
#8
|
|||
|
|||
|
Once again delete the entire c:\findnfix directory as it is too old now. This stuff changes pretty quick so it is important you reply as soon as possible.
THen foillow these steps to get a newer version: Please do the following: Download the program FindNFix from the following location: http://www10.brinkster.com/expl0iter/freeatlast/FNF/ Once it is downloaded, double-click on the file to run it. Follow the prompts to install the program. Once it is installed a window will open up showing the installation directory and a bunch of files in the right section of the window. On the right portion of the window look for the file called !LOG!.bat and double-click on it. It will scan through your computer for a while, so be patient. When it is completed it will automatically open a notepad window called Log.txt. Copy the contents of that file into a reply to this post. |
|
#9
|
|||
|
|||
|
sorry about that i hope this is more recent
Thu 05 Aug 04 13:04:53
*** www10.brinkster.com/expl0iter/freeatlast/FNF/ *** Microsoft Windows XP Home Edition 5.1 Service Pack 1 (Build 2600) Microsoft Windows XP [Version 5.1.2600] IE version: 6.0.2800.1106 SP1-Q822925-Q330994-Q828750-Q824145-Q832894-Q837009-Q823353-Q867801 The type of the file system is NTFS. Thursday, August 05, 2004 (8/5/2004) 1:04 PM, Pacific Daylight Time 1:04pm up 0 days, 0:21 Member of...: ("ADMIN" logon + group match required!) !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! Group BUILTIN\Administrators matches list. Group BUILTIN\Users matches list. !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! User is a member of group RACHELLESD\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group \LOCAL. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. *** Note! *** The list will produce a small database of files that will match certain criteria. Ex: read only files, s/h files, last modified date. size, etc. The filters provided and registry scan should match the corresponding file(s) listed. Unless the file match the entire criteria, it should not be pointed to remove without attempting to confirm it's nature! At times there could be several (legit) files flagged, and/or duplicate culprit file(s)! If in doubt, always search the file(s) and properties according to criteria! The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder ***LOG!***(*updated 8/05) **Use at your own risk!** Scanning for file(s)... ********* (*1*) ......... Locked or 'Suspect' file(s) found... C:\WINDOWS\SYSTEM32\WDMA.DLL +++ File read error \\?\C:\WINDOWS\System32\WDMA.DLL +++ File read error (*2*) ........ WDMA.DLL Can't Open! (*3*) ........ C:\WINDOWS\SYSTEM32\ wdma.dll Thu Jun 24 2004 11:53:56a A...R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K unknown/hidden files... No matches found. (*4*) ......... Sniffing.......... Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMA.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL (*5*) Access denied ..................... WDMA.DLL .....57344 24.06.2004 (*6*) fgrep: can't open input C:\WINDOWS\SYSTEM32\WDMA.DLL ********* Search by size... C:\WINDOWS\SYSTEM32\ wdma.dll Thu Jun 24 2004 11:53:56a A...R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMA.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL ********* BHO search... **File C:\WINDOWS\SYSTEM32\AMCICGA.DLL 00001FF0: 25 25 25 30 32 78 00 00 . 00 00 00 00 C0 82 05 B3 %%%02x.. ..... fgrep: can't open input C:\WINDOWS\SYSTEM32\WDMA.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\AMCICGA.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 30720 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL ********* Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512...) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 Dumping Values........ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 |
|
#10
|
|||
|
|||
|
2nd half
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM Performing string scan |