scan result from dllfix
--------------------------------------------------------
CWSDLL/Searchx Appinit Fix By Shadowwar
Version 2.01 053104
Please Do not mirror Without Permission!
I can be contacted at spywaresubmit at aol.com
wo 02-06-2004
20:19
Backing up Registry Hive
De bewerking is voltooid
Deleting Windows Key
De bewerking is voltooid
Adding Test Windows Key
De bewerking is voltooid
Restoring temp Values Key
De bewerking is voltooid
Deleting Bad Appinit Value
De bewerking is voltooid
Backup of Modified Hiv
De bewerking is voltooid
Deleting test Windows key
De bewerking is voltooid
Deleting Filter text
Running from C:\dllfix
Scanning For main hijacker.
Scanning for Hidden Dll in system32 1st pass
File was not found on first Pass.
Scanning for Hidden Dll in system32 2nd pass
A file could not be found.
Here is a directory listing to post.
---------- DIR.TXT
12-05-2004 22:20 17.187 mtjpgh.dll
12-05-2004 22:20 144 mtjpgb.dll
11-05-2004 03:54 2 nthst32.dll
11-05-2004 03:54 766 xcwer32.dll
11-05-2004 03:54 766 icnfe.dll
11-05-2004 03:54 766 icqrt.dll
11-05-2004 03:54 766 icvbr.dll
11-05-2004 03:54 766 wecxg32.dll
11-05-2004 03:54 766 sdfup.dll
11-05-2004 03:54 766 cidft.dll
11-05-2004 03:54 766 cidpoq32.dll
11-05-2004 03:54 766 gupd.dll
11-05-2004 03:54 766 zxmsn.dll
09-04-2004 21:28 43.520 CmdLineExt03.dll
06-04-2004 22:28 131.072 x3zsmaf3jv.dll
23-03-2004 22:52 126.976 ev25bbgpi9.dll
05-03-2004 00:04 135.168 RTCRES.dll
03-03-2004 10:29 172.032 nvrsesm.dll
03-03-2004 10:29 163.840 nvrsde.dll
03-03-2004 10:29 4.256.896 nv4_disp.dll
03-03-2004 10:29 163.840 nvwrsko.dll
03-03-2004 10:29 31.744 nvcodins.dll
03-03-2004 10:29 237.568 nvwrseng.dll
03-03-2004 10:29 36.864 nvwddi.dll
03-03-2004 10:29 147.456 nvrseng.dll
03-03-2004 10:29 278.528 nvwrses.dll
03-03-2004 10:29 159.744 nvrsnl.dll
03-03-2004 10:29 270.336 nvwrsesm.dll
03-03-2004 10:29 143.360 nvrsfi.dll
03-03-2004 10:29 163.840 nvrses.dll
03-03-2004 10:29 262.144 nvwrsnl.dll
03-03-2004 10:29 245.760 nvwrsda.dll
03-03-2004 10:29 31.744 nvcod.dll
03-03-2004 10:29 147.456 nvrsno.dll
03-03-2004 10:29 278.528 nvwrsel.dll
03-03-2004 10:29 176.128 nvwrsja.dll
03-03-2004 10:29 1.617.920 nvwdmcpl.dll
03-03-2004 10:29 249.856 nvwrsno.dll
03-03-2004 10:29 172.032 nvrsja.dll
03-03-2004 10:29 151.552 nvrsda.dll
03-03-2004 10:29 233.472 nvwrscs.dll
03-03-2004 10:29 46.080 nvmctray.dll
03-03-2004 10:29 2.904.064 nvcpl.dll
03-03-2004 10:29 241.664 nvnt4cpl.dll
03-03-2004 10:29 147.456 nvrssv.dll
03-03-2004 10:29 131.072 nvinstnt.dll
03-03-2004 10:29 147.456 nvrspl.dll
03-03-2004 10:29 249.856 nvwrsfi.dll
03-03-2004 10:29 249.856 nvwrssl.dll
03-03-2004 10:29 4.841.472 nvoglnt.dll
03-03-2004 10:29 167.936 nvrsfr.dll
03-03-2004 10:29 245.760 nvwrspl.dll
03-03-2004 10:29 163.840 nvrsel.dll
03-03-2004 10:29 155.648 nvrspt.dll
03-03-2004 10:29 270.336 nvwrsfr.dll
03-03-2004 10:29 196.608 nvrshe.dll
03-03-2004 10:29 229.376 nvwrshe.dll
03-03-2004 10:29 151.552 nvrshu.dll
03-03-2004 10:29 262.144 nvwrshu.dll
03-03-2004 10:29 143.360 nvrscs.dll
03-03-2004 10:29 167.936 nvrsit.dll
03-03-2004 10:29 1.335.296 nview.dll
03-03-2004 10:29 233.472 nvwrsar.dll
03-03-2004 10:29 270.336 nvwrspt.dll
03-03-2004 10:29 200.704 nvrsar.dll
03-03-2004 10:29 159.744 nvrsptb.dll
03-03-2004 10:29 139.264 nvwrszht.dll
03-03-2004 10:29 1.019.904 nvwimg.dll
03-03-2004 10:29 172.032 nvrsko.dll
03-03-2004 10:29 245.760 nvwrssv.dll
03-03-2004 10:29 151.552 nvrstr.dll
03-03-2004 10:29 249.856 nvwrstr.dll
03-03-2004 10:29 147.456 nvrszhc.dll
03-03-2004 10:29 266.240 nvwrsptb.dll
03-03-2004 10:29 135.168 nvwrszhc.dll
03-03-2004 10:29 77.824 nvrszht.dll
03-03-2004 10:29 155.648 nvrssl.dll
03-03-2004 10:29 454.656 nvshell.dll
03-03-2004 10:29 245.760 nvwrssk.dll
03-03-2004 10:29 155.648 nvrsru.dll
03-03-2004 10:29 253.952 nvwrsde.dll
03-03-2004 10:29 262.144 nvwrsru.dll
03-03-2004 10:29 147.456 nvrssk.dll
03-03-2004 10:29 270.336 nvwrsit.dll
13-02-2004 18:42 2.272 w95inf16.dll
13-02-2004 18:42 4.608 w95inf32.dll
12-02-2004 14:44 352.256 eSellerateEngine.dll
Adding Back Windows Key
De bewerking is voltooid
Restoring Registry Hive
De bewerking is voltooid
Restoring Cleaned Appinit Value
De bewerking is voltooid
-----------------------------------------------------------------------------------------------
hijackthis scan result
-----------------------------------------------------------------------------------------------
Logfile of HijackThis v1.97.7
Scan saved at 20:31:33, on 2-6-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\LVComS.exe
D:\Downloads\Applications\spybot updates\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\searchpage.html#1525
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html#1525
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = c:\searchpage.html#1525
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\searchpage.html#1525
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINDOWS\System32\acgipd.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = c:\searchpage.html#1525
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = c:\searchpage.html#1525
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = c:\searchpage.html#1525
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = c:\searchpage.html#1525
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html#1525
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = c:\searchpage.html#1525
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {82895596-C2D9-4767-8840-2D23CDF07CA9} - (no file)
O2 - BHO: (no name) - {AD79D9C9-5AFD-403A-B008-EE5CDB243C1F} - (no file)
O2 - BHO: (no name) - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WCPC] C:\WINDOWS\System32\wintsvcc.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Real.com (HKLM)
O13 - DefaultPrefix: c:\searchpage.html?page=
O13 - WWW Prefix: c:\searchpage.html?page=
O13 - Home Prefix: c:\searchpage.html?page=
O13 - Mosaic Prefix: c:\searchpage.html?page=
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) -
http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/...7862.2038657407O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cab