Fixwareout Last edited 2/11/2007
Post this report in the forums please
...
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="csiao.exe"
»»»»» System restarted
»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "pgtshlld" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "nidnsdr" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "djkse" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23rtcdaol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "6" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23rtcdool" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "8" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "9" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "10" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "11" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "12" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "13" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "14" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "15" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "16" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "17" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "18" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23naelch" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "20" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "21" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "22" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "24" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "25" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "26" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "27" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "28" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "1dedoc" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "llams_ogol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "repiwh" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "domdnb" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "orcimlh" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23tsniow" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "35" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "36" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "37" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "38" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "39" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "40" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "41" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "42" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "43" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "44" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "45" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "46" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "47" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "48" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "49" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "50" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "51" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "52" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "53" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "54" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "55" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "56" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "57" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "58" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "59" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "60" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "61" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "62" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "63" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "64" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "65" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "66" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "67" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "68" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "69" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "70" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "71" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "72" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "73" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "74" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "75" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "76" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "77" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "78" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "79" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "80" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "81" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "82" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "83" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "84" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "85" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "86" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "87" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "88" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "89" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "90" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "91" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "92" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "93" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "94" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "95" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "96" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "97" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "98" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "99" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "100" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "101" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "102" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "103" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "104" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "105" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "106" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "107" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "108" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "109" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "110" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "111" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "xedocne" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "gib_ogol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "repiwoh" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "23plhps" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "mgcppp" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "tesvaf" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "golmedi" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "32refaselif" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "120" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "121" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "122" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "123" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "124" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "125" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "126" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "127" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "128" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "129" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "130" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "131" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "132" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "133" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "134" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "135" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "136" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "rjhmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "137" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "138" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "139" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "140" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "141" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "142" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "143" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "144" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "145" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "pgtshlld" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "nidnsdr" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "ytpme" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "23lserspg" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "ifpnxesm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "23rtcdaol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "ibpnxesm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "23rtcdool" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "gib_ogol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "23naelch" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "lserspg" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1dedoc" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "llams_ogol" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "repiwh" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "domdnb" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "orcimlh" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "putesprpgd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "23tsniow" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "xedocne" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "repiwoh" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "llun" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "23plhps" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "mgcppp" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "tesvaf" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "golmedi" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "32refaselif" Deleted
....
»»»»» Misc files.
C:\Documents and Settings\mina\Application Data\uns.tmp Deleted
C:\WINDOWS\BALLOON.WAV Deleted
C:\WINDOWS\System32\close.bmp Deleted
C:\WINDOWS\System32\dating.bmp Deleted
C:\WINDOWS\System32\gambling.bmp Deleted
C:\WINDOWS\System32\idesk.conf Deleted
C:\WINDOWS\System32\insurance.bmp Deleted
C:\WINDOWS\System32\pharmacy.bmp Deleted
C:\WINDOWS\System32\spyware.bmp Deleted
C:\WINDOWS\System32\WOINST32.EXE Deleted
C:\WINDOWS\System32\xxx.bmp Deleted
....
»»»»» Checking for older varients.
....
Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.
Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or
http://virusscan.jotti.org/
»»»»» Other
»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"Motive SmartBridge"="C:\\PROGRA~1\\NUMERI~1\\MONASS~1\\SMARTB~1\\MotiveSB.exe"
"EPSON Stylus C64 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC2.EXE /P23 \"EPSON Stylus C64 Series\" /O6 \"USB002\" /M \"Stylus C64\""
"StatusCheck"="AppMasterCenter.exe"
"powerdll"="10010.exe"
"APVXDWIN"="\"C:\\Program Files\\Panda Software\\Panda Antivirus Titanium\\APVXDWIN.EXE\" /s"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
02/04/2007 00h04