Oooookayyy... Hmm well first off I'd like to correct the virus part in my last post because while I was writing that I had only had the FIRST notification from Norton and when I pressed Ok it notified of several other viruses too that it removed (didn't write them down cause there were pretty much of them and I guess you don't need all the info about this part
)... Hmm well when I rebooted my system (had downloaded some Windows updates) Trojan Hunter notified me about this Adware thingy in my memory again and when I tried to clean it again my toolbar (isn't that thing down there called toolbar in english
?) disappeared completely and had to reboot once again and now I've done the Findit log:
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: F:\Find It NT-2K-XP
------- System Files in System32 Directory -------
Aseman C nimi on 53_11_02
Aseman sarjanumero on A8FF-B7A1
Kansio C:\WINDOWS\System32
12.01.2005 22:30 <KANSIO> dllcache
12.01.2005 22:28 224˙981 azao01j3e.dll
12.01.2005 22:24 223˙193 dn6o01j3e.dll
12.01.2005 17:11 224˙304 enjml1111.dll
20.06.2004 14:48 32 {BC5E3058-FA03-4016-8E86-09FCC25D59A5}.dat
20.06.2004 14:19 32 {4EAE1052-0ECC-4621-993B-B7657AD2BB15}.dat
18.11.2003 02:36 <KANSIO> Microsoft
5 tiedosto(a) 672˙542 tavua
2 kansio(ta) 17˙320˙296˙448 tavua vapaana
------- Hidden Files in System32 Directory -------
Aseman C nimi on 53_11_02
Aseman sarjanumero on A8FF-B7A1
Kansio C:\WINDOWS\System32
12.01.2005 22:30 <KANSIO> dllcache
20.06.2004 14:48 32 {BC5E3058-FA03-4016-8E86-09FCC25D59A5}.dat
20.06.2004 14:19 32 {4EAE1052-0ECC-4621-993B-B7657AD2BB15}.dat
20.06.2004 12:36 488 WindowsLogon.manifest
20.06.2004 12:36 488 logonui.exe.manifest
20.06.2004 12:34 749 sapi.cpl.manifest
20.06.2004 12:34 749 nwc.cpl.manifest
20.06.2004 12:34 749 ncpa.cpl.manifest
20.06.2004 12:34 749 wuaucpl.cpl.manifest
20.06.2004 12:34 749 cdplayer.exe.manifest
26.09.2003 09:11 2˙045 whlpda32e.dll
10 tiedosto(a) 6˙830 tavua
1 kansio(ta) 17˙320˙292˙352 tavua vapaana
------------ Files Named "Guard" ---------------
Aseman C nimi on 53_11_02
Aseman sarjanumero on A8FF-B7A1
Kansio C:\WINDOWS\System32
12.01.2005 22:29 224˙304 guard.tmp
12.01.2005 17:28 223˙193 guard.tmp.tcf
2 tiedosto(a) 447˙497 tavua
0 kansio(ta) 17˙320˙292˙352 tavua vapaana
------ Temp Files in System32 Directory ------
Aseman C nimi on 53_11_02
Aseman sarjanumero on A8FF-B7A1
Kansio C:\WINDOWS\System32
12.01.2005 22:29 224˙304 guard.tmp
1 tiedosto(a) 224˙304 tavua
0 kansio(ta) 17˙320˙292˙352 tavua vapaana
------------------ User Agent ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F1814209-FA6B-46CD-9712-629E61D05042}"=""
------------- Keys Under Notify -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\enjml1111.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
------------- Locate.com Results -------------
C:\WINDOWS\SYSTEM32\
azao01~1.dll Wed 12 Jan 2005 22.28.16 ..S.R 224 981 219,71 K
dn6o01~1.dll Wed 12 Jan 2005 22.24.04 ..S.R 223 193 217,96 K
enjml1~1.dll Wed 12 Jan 2005 17.11.04 ..S.R 224 304 219,05 K
3 items found: 3 files, 0 directories.
Total of file sizes: 672 478 bytes 656,71 K
-------- Strings.exe Qoologic Results --------
--------- Strings.exe Aspack Results ---------
-------------- HKLM Run Key ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"Advanced Tools Check"="C:\\PROGRA~1\\NORTON~1\\AdvTools\\ADVCHK.EXE"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
"Lexmark 3100 Series"="\"C:\\Program Files\\Lexmark 3100 Series\\lxbrbmgr.exe\""
"LXBRKsk"="C:\\PROGRA~1\\LEXMAR~1\\LXBRKsk.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"StarSkin"="C:\\PROGRAM FILES\\ROCKET DIVISION SOFTWARE\\STARSKIN\\STARSKIN.EXE -H"
"SoundMan"="SOUNDMAN.EXE"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"WinampAgent"="F:\\Winamp\\winampa.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"gcasServ"="\"C:\\Program Files\\GIANT Company Software\\GIANT AntiSpyware\\gcasServ.exe\""
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.1\\THGuard.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"