This is the second log report. When I moved the file my norton picked it up and stated that it was automaticly deleted. But you never know if it didnt just move some where else. But so far the computer is running fine and the about:blank hasn't showed it's ugly face yet. Thanks again for all your help.
Fri 10 Sep 04 14:23:30
»»»»»»»»»»»»»»»»»»***LOG2!(*updated *9/1*)***»»»»»»»»»»»»»»»»
*System:
Microsoft Windows XP Home Edition 5.1 Service Pack 2 (Build 2600)
*IE version:
6.0.2900.2180 SP2
The type of the file system is NTFS.
___________________________________________
!!Restoring backups!!
The operation completed successfully
The operation completed successfully
14:23:22.43 Fri 09/10/2004
___________________________________________
*Local time:
Friday, September 10, 2004 (9/10/2004)
2:23 PM, Central Standard Time
*Uptime:
14:23:32 up 0 days, 0:18:18
*path:
C:\FINDnFIX
Running in WORKSTATION MODE.
SystemDrive is C:
SystemRoot is C:\WINDOWS
Logon Domain is HP-MAIN
Administrator's Name is Owner
Computer Name is HP-MAIN
LOGON SERVER is \\HP-MAIN
------------------------------------------
This log will confirm if the file was successfully moved, and/or
the right file was selected...
Scanning for file(s) in System32...
»»»»»»» (1) »»»»»»»
»»»»»»» (2) »»»»»»»
»»»»»»» (3) »»»»»»»
No matches found.
Unknown/hidden files...
No matches found.
»»»»»»» (4) »»»»»»»
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
»»»»»(5)»»»»»
»»»»»(6)»»»»»
»»»»»»» Search by size And Date...
*List of files specs according to size:
*Note: Not all files listed here are infected!
____________________________________________________________________________
Path: C:\WINDOWS\SYSTEM32 Including: *.DLL
234. Dpwsockx Dll 57,344 . . . . A 8-04-04 2:56 am
684. Msasn1 Dll 57,344 . . . . A 8-04-04 2:56 am
206. Dmloader Dll 35,840 . . . . A 8-04-04 2:56 am
398. Imgutil Dll 35,840 . . . . A 8-04-04 2:56 am
1258. Umandlg Dll 35,840 . . . . A 8-04-04 2:56 am
230. Dpvacm Dll 21,504 . . . . A 8-04-04 2:56 am
278. Feclient Dll 21,504 . . . . A 8-04-04 2:56 am
____________________________________________________________________________
C:\WINDOWS\SYSTEM32\
dpwsockx.dll Wed Aug 4 2004 2:56:42a A.... 57,344 56.00 K
msasn1.dll Wed Aug 4 2004 2:56:42a A.... 57,344 56.00 K
2 items found: 2 files, 0 directories.
Total of file sizes: 114,688 bytes 112.00 K
C:\WINDOWS\SYSTEM32\
dmloader.dll Wed Aug 4 2004 2:56:42a A.... 35,840 35.00 K
imgutil.dll Wed Aug 4 2004 2:56:42a A.... 35,840 35.00 K
umandlg.dll Wed Aug 4 2004 2:56:46a A.... 35,840 35.00 K
3 items found: 3 files, 0 directories.
Total of file sizes: 107,520 bytes 105.00 K
C:\WINDOWS\SYSTEM32\
dpvacm.dll Wed Aug 4 2004 2:56:42a A.... 21,504 21.00 K
feclient.dll Wed Aug 4 2004 2:56:42a A.... 21,504 21.00 K
2 items found: 2 files, 0 directories.
Total of file sizes: 43,008 bytes 42.00 K
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\DPWSOCKX.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\MSASN1.DLL
SNiF 1.34 statistics
Matching files : 2 Amount in bytes : 114688
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\DMLOADER.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\IMGUTIL.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\UMANDLG.DLL
SNiF 1.34 statistics
Matching files : 3 Amount in bytes : 107520
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINDOWS\SYSTEM32\DPVACM.DLL
Sniffed -> C:\WINDOWS\SYSTEM32\FECLIENT.DLL
SNiF 1.34 statistics
Matching files : 2 Amount in bytes : 43008
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
BHO search and other files...
No matches found.
"C:\WINDOWS\system32\"
rtipxmib.dll Aug 4 2004 31744 "rtipxmib.dll"
1 item found: 1 file, 0 directories.
Total of file sizes: 31,744 bytes 31.00 K
No matches found.
--*sp.html in temp folder was NOT FOUND!--
*Filter keys search...
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html' (2)
--(*text/html Subkey was NOT FOUND!)--
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain' (2)
--(*text/plain Subkey was NOT FOUND!)--
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»*»»» Scanning for moved file... »»»*»»»
No matches found.
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.*
fgrep: no files found for C:\FINDNFIX\JUNKXXX\*.*
Analyzer v1.36 by Boogie Copyright (C) 1997 ESP Team
Files: C:\FINDNFIX\JUNKXXX\*.*
Ä
Ä
Volume: HP_PAVILION * DDIR * 2:28 pm | Fri, 9-10-04
Ser #: 7888-AAB4 DOS Ver. 5.00 0% Used space
Path: C:\FINDNFIX\JUNKXXX All files selected
No files found.
No. of files: 0 | List size: 0
Disk size: 976.5 M | Actual spc: 0
Bytes free: 976.5 M | Conserved space: 0
File not found - C:\FINDnFIX\junkxxx\*.*
CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.
MD5 Message Digest Algorithm by RSA Data Security, Inc.
File name Size Date Time MD5 Hash
________________________________________________________________________
CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk
C:\FINDNFIX\JUNKXXX
No files found
#######################################################
*Known files are...
--------------------
File: ((56k; (57,344 bytes)
CRC-32 : D5C9FB2E
MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249
--------------------
File: ((35k; (35,840 bytes)
CRC-32 : 33081C8B
MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE
--------------------
File: ((21k; (21,504 bytes)
CRC-32 : 2258F59E
MD5 : EFEE2CB3 B342A351 51802356 9637F8E6
#######################################################
»»Permissions:
ERROR: There are no more files. Directory "C:\FINDnFIX\junkxxx\."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000003 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000002 tc-- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000009 --o- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000002 tc-- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000009 --o- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000013 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000013 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000010 t--- 001F01FF ---- DSPO rw+x HP-MAIN\Owner
Allow 0000001B -co- 10000000 ---A ---- ---- \CREATOR OWNER
Allow 00000013 tco- 001200A9 ---- -S-- r--x BUILTIN\Users
Allow 00000012 tc-- 00000004 ---- ---- --+- BUILTIN\Users
Allow 00000012 tc-- 00000002 ---- ---- -w-- BUILTIN\Users
Owner: HP-MAIN\Owner
Primary Group: HP-MAIN\None
Directory "C:\FINDnFIX\junkxxx\.."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000003 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000000 t--- 001F01FF ---- DSPO rw+x HP-MAIN\Owner
Allow 0000000B -co- 10000000 ---A ---- ---- \CREATOR OWNER
Allow 00000003 tco- 001200A9 ---- -S-- r--x BUILTIN\Users
Allow 00000002 tc-- 00000004 ---- ---- --+- BUILTIN\Users
Allow 00000002 tc-- 00000002 ---- ---- -w-- BUILTIN\Users
Owner: HP-MAIN\Owner
Primary Group: HP-MAIN\None
»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)
Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450
»»Checking for AppInit_DLLs (empty) value...
________________________________
!"AppInit_DLLs"=""!
Value Matches
________________________________
»»Comparing *saved* key with *original*...
REGDIFF 2.1 - Freeware written by Gerson Kurz ( http://www.p-nand-q.com )
Comparing File #1 (Keys1\winkey.reg) with File #2 (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows).
Value "AppInit_DLLs" in key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" has different lengths (31 vs 1)
»»Dumping Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs =
»»Security settings for 'Windows' key:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software ( http://www.heysoft.de )
This program is Freeware, use it on your own risk!
Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM
00001150: vk UDeviceNotSelecte
00001190:dTimeout 1 5 ( h vk ' zGDIProce
000011D0:ssHandleQuota" 9 0 =t vk Spooler2
00001210: y e s _ vk 5swapdisk h
00001250: X vk . TransmissionRetryTimeout vk
00001290: ' USERProcessHandleQuota h X
000012D0: vk UAppInit_DLLsecte
00001310:
00001350:
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
---------- NEWWIN.TXT
ÀUAppInit_DLLsecte
--------------
--------------
$0117F: UDeviceNotSelectedTimeout
$011C7: zGDIProcessHandleQuota
$01270: TransmissionRetryTimeout
$012A0: USERProcessHandleQuota
$012EF: UAppInit_DLLsecte
--------------
--------------
msacm.msg723
--------------
--------------
d.... 0 Sep 10 9:56 .
d.... 0 Sep 10 9:56 ..
2 files found occupying -1024 bytes
===============================================================================
0 bytes 0 cps
Files: 0 Records: 0 Matches: 0 Elapsed Time: 00:00:00.01
VDIR v1.00
Path: C:\FINDNFIX\JUNKXXX\*.*
---------------------------------------+---------------------------------------
. 09-10-:4 09:56|.. 09-10-:4 09:56
---------------------------------------+---------------------------------------
2 files totaling 0 bytes consuming 0 bytes of disk space.
17299968 bytes available on Drive C: Volume label: HP_PAVILION
...File dump...
Detecting...
C:\FINDnFIX\junkxxx
Finished Detecting...
=========================================
0 C:\FINDnFIX\junkxxx (DIR Total)
Owner No. Files Total Size
=========================================
________________________________________________________________________________
***THE FIX IS NOT COMPATIBLE WITH EARLIER;UNPATCHED VERSIONS OF WIN2K'(SP3 and BELLOW)'
AND/OR LAX OF SECURITY UPDATES AND SERVICE PACKS FOR ALL PLATFORMS!
MINIMAL REQUIREMENTS INCLUDE:
_________XP HOME/PRO; SP1; IE6/SP1
_________2K/SP4; IE6/SP1
________________________________________________________________________________
»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»
Fri 10 Sep 04 14:28:39
-----END-----