DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________C:\WINNTOLD\SYSTEM32\o048la~1.dll Wed Dec 29 2004 2:10:48p ..S.R 222,920 217.70 K
C:\WINNTOLD\SYSTEM32\uyimdmat.dll Wed Dec 29 2004 10:22:16p ..S.R 225,348 220.07 K
C:\WINNTOLD\SYSTEM32\irlsl5~1.dll Wed Dec 15 2004 7:36:10p ..S.R 223,745 218.50 K
C:\WINNTOLD\SYSTEM32\jtjm07~1.dll Wed Dec 22 2004 9:32:06a ..S.R 225,980 220.68 K
C:\WINNTOLD\SYSTEM32\j8j60i~1.dll Mon Dec 20 2004 5:05:10p ..S.R 225,980 220.68 K
C:\WINNTOLD\SYSTEM32\hr8405~1.dll Wed Dec 22 2004 10:07:34a ..S.R 222,450 217.23 K
C:\WINNTOLD\SYSTEM32\ir2sl5~1.dll Thu Dec 23 2004 6:05:54p ..S.R 226,008 220.71 K
C:\WINNTOLD\SYSTEM32\r6r60g~1.dll Tue Dec 28 2004 4:09:02p ..S.R 224,283 219.02 K
C:\WINNTOLD\SYSTEM32\n44s0e~1.dll Wed Dec 29 2004 2:28:18p ..S.R 225,103 219.82 K
C:\WINNTOLD\SYSTEM32\j0j6la~1.dll Wed Dec 22 2004 9:41:58a ..S.R 225,980 220.68 K
C:\WINNTOLD\SYSTEM32\ir6ql5~1.dll Tue Dec 28 2004 4:41:16p ..S.R 224,701 219.43 K
C:\WINNTOLD\SYSTEM32\lvpq09~1.dll Tue Dec 28 2004 6:36:14p ..S.R 225,600 220.31 K
C:\WINNTOLD\SYSTEM32\c2000c~1.dll Wed Dec 22 2004 10:29:36a ..S.R 225,982 220.68 K
C:\WINNTOLD\SYSTEM32\k4jsle~1.dll Tue Dec 14 2004 9:36:48p ..S.R 223,745 218.50 K
C:\WINNTOLD\SYSTEM32\l4n4le~1.dll Tue Dec 14 2004 5:31:56p ..S.R 224,826 219.55 K
C:\WINNTOLD\SYSTEM32\fp2m03~1.dll Tue Dec 28 2004 7:22:46p ..S.R 225,035 219.76 K
C:\WINNTOLD\SYSTEM32\jtno07~1.dll Thu Dec 9 2004 8:10:58p ..S.R 223,589 218.35 K
C:\WINNTOLD\SYSTEM32\m0jula~1.dll Fri Dec 17 2004 5:45:14p ..S.R 225,655 220.36 K
C:\WINNTOLD\SYSTEM32\ir44l5~1.dll Wed Dec 29 2004 4:21:28p ..S.R 225,348 220.07 K
C:\WINNTOLD\SYSTEM32\irr8l5~1.dll Wed Dec 15 2004 6:29:18p ..S.R 223,745 218.50 K
C:\WINNTOLD\SYSTEM32\j4p0le~1.dll Wed Dec 15 2004 7:51:26a ..S.R 223,745 218.50 K
C:\WINNTOLD\SYSTEM32\dn6001~1.dll Mon Dec 20 2004 11:04:44a ..S.R 225,414 220.13 K
C:\WINNTOLD\SYSTEM32\jt6m07~1.dll Sat Dec 18 2004 7:42:42p ..S.R 224,295 219.04 K
C:\WINNTOLD\SYSTEM32\enrul1~1.dll Wed Dec 29 2004 10:06:54p ..S.R 223,203 217.97 K
C:\WINNTOLD\SYSTEM32\p46s0e~1.dll Tue Dec 28 2004 6:49:04p ..S.R 225,676 220.39 K
C:\WINNTOLD\SYSTEM32\k826li~1.dll Mon Dec 20 2004 12:38:14p ..S.R 223,022 217.79 K
C:\WINNTOLD\SYSTEM32\lvr209~1.dll Mon Dec 20 2004 1:07:14p ..S.R 226,279 220.97 K
C:\WINNTOLD\SYSTEM32\en88l1~1.dll Thu Dec 23 2004 8:47:22a ..S.R 225,980 220.68 K
C:\WINNTOLD\SYSTEM32\f6l02g~1.dll Tue Dec 28 2004 7:03:28p ..S.R 223,226 217.99 K
C:\WINNTOLD\SYSTEM32\l4r0le~1.dll Tue Dec 28 2004 7:36:08p ..S.R 226,006 220.71 K
C:\WINNTOLD\SYSTEM32\r48s0e~1.dll Wed Dec 29 2004 3:34:08p ..S.R 225,143 219.86 K
C:\WINNTOLD\SYSTEM32\m8ls0i~1.dll Wed Dec 29 2004 9:49:46p ..S.R 226,086 220.79 K
C:\WINNTOLD\SYSTEM32\o0pqla~1.dll Wed Dec 29 2004 9:58:06p ..S.R 222,993 217.77 K
C:\WINNTOLD\SYSTEM32\m082la~1.dll Wed Dec 29 2004 10:22:14p ..S.R 222,848 217.63 K
________________________________________________1,026 items found: 1,026 files (34 H/S), 0 directories.
Total of file sizes: 187,348,969 bytes 178.67 MAdministrator Account = True
--------------------End log---------------------
Log for VX2.BetterInternet File Finder
Files Found---
Guardian Key--- is called:
User Agent String---
{2BE5D559-30E5-41F7-8335-5D07419E1634}"Silent Runners.vbs", revision 28, launched at: 22:17
Output limited to non-default values, except where indicated by "{++}"
Operating System: Windows 2000Startup items buried in registry:HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SpySweeper" = ""C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0" ["Webroot Software, Inc."]HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"MSConfig" = "C:\WINNTOLD\msconfig.exe /auto" [MS]
"Synchronization Manager" = "mobsync.exe /logon" [MS]
"TrojanScanner" = "C:\Program Files\Trojan Remover\Trjscan.exe" ["Simply Super Software"]
"Narrator" = "C:\WINNTOLD\system32\viyrrv.exe" [null data]HKLM\Software\Microsoft\Active Setup\Installed Components\
"9c5f97f3-d620-4ecb-88f2-d6772da2e0df(Default)" = ""
\StubPath = "C:\WINNTOLD\system32\lzpwwl.exe" [null data]HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> CLSID InProcServer32 resolves to: "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> CLSID InProcServer32 resolves to: "C:\WINNTOLD\System32\hticons.dll" ["Hilgraeve, Inc."]
"{813790D8-68CD-4318-9F5C-1847AD1AB483}" = ""
-> CLSID InProcServer32 resolves to: "C:\WINNTOLD\system32\guard.tmp" [file not found]
"{FA050674-5655-4D8C-A785-EA25A159DEDB}" = ""
-> CLSID InProcServer32 resolves to: "C:\WINNTOLD\system32\su3res.dll" [null data]
"{F82121F6-B27E-4B55-BF51-41C1B5B3F8EF}" = ""
-> CLSID InProcServer32 resolves to: "C:\WINNTOLD\system32\guard.tmp" [file not found]
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}" = "SpySubtract Shell Extension"
-> CLSID InProcServer32 resolves to: "c:\Program Files\interMute\SpySubtract\sshook.dll" ["InterMute, Inc."]
"{52B87208-9CCF-42C9-B88E-069281105805}" = "Trojan Remover Shell Extension"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\TROJAN~1\Trshlex.dll" ["Simply Super Software"]
"{1BDD258C-7D21-48F0-A4B6-A0AC476250F7}" = ""
-> CLSID InProcServer32 resolves to: "C:\WINNTOLD\system32\pjrfos.dll" [null data]
"{9159CE34-BF49-40D8-AA6D-E116642E9D8C}" = ""
-> CLSID InProcServer32 resolves to: "C:\WINNTOLD\system32\CFMCAT.DLL" [null data]HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! "Applets\DLLName" = "C:\WINNTOLD\system32\ir44l5hq1.dll" [null data]Enabled Scheduled Tasks:"avg" -> launches: "C:\Documents and Settings\JBaker\Desktop\avg.doc" [file not found]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
"Norton AntiVirus - Scan my computer - Thom" -> launches: "C:\PROGRA~1\NORTON~1\Navw32.exe /task:"C:\Documents and Settings\All Users.WINNTOLD\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]Running Services (Display Name, Service Name, Path {Service DLL}):----------
This report excludes default entries except where indicated.
To see everywhere the script checks and everything it finds,
launch it from a command prompt or a shortcut with the -all parameter.----------
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
"Asynchronous"=dword:00000000
"DllName"="C:\WINNTOLD\system32\ir44l5hq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
Here it is... Thanks again