Thank you for your help to this point!
When I re-booted, my Norton Internet Security program (which I had disabled before rebooting) was enabled upon re-start.
After moving the MSINI.dll file to the C:\Findnfix\junkxxx folder, I went into the junkxxx folder by mistake. I was reading a hard-copy print out of your last post, and I opened the wrong folder. Upon doing this, Norton Internet Security box popped up with a box that said
"A virus was detected on your computer (MSINI.dll) and deleted". I hope this didn't screw up the fix.
After that occurred, I ran RESTORE.bat from the FINDnFIX folder as instructed. Here's the log:
Mon 03 Jan 05 13:57:55
»»»»»»»»»»»»»»»»»»***LOG2!(*updated *9/1*)***»»»»»»»»»»»»»»»»
*System:
Microsoft Windows XP Home Edition 5.1 Service Pack 2 (Build 2600)
*IE version:
6.0.2900.2180 SP2
The type of the file system is NTFS.
___________________________________________
!!Restoring backups!!
The operation completed successfully
The operation completed successfully
13:57:53.54 Mon 01/03/2005
___________________________________________
*Local time:
Monday, January 03, 2005 (1/3/2005)
1:57 PM, Central Standard Time
*Uptime:
13:57:56 up 0 days, 0:06:28
*path:
C:\FINDnFIX
Running in WORKSTATION MODE.
SystemDrive is C:
SystemRoot is C:\WINNT
Logon Domain is S1100375735
Administrator's Name is Owner
Computer Name is S1100375735
LOGON SERVER is \\S1100375735
——————————————
This log will confirm if the file was successfully moved, and/or
the right file was selected…
Scanning for file(s) in System32…
»»»»»»» (1) »»»»»»»
»»»»»»» (2) »»»»»»»
»»»»»»» (3) »»»»»»»
No matches found.
Unknown/hidden files…
No matches found.
»»»»»»» (4) »»»»»»»
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
»»»»»(5)»»»»»
»»»»»(6)»»»»»
»»»»»»» Search by size And Date…
*List of files specs according to size:
*Note: Not all files listed here are infected!
____________________________________________________________________________
Path: C:\WINNT\SYSTEM32 Including: *.DLL
220. Dpwsockx Dll 57,344 . . . . A 8-04-04 1:56 am
637. Msasn1 Dll 57,344 . . . . A 8-04-04 1:56 am
192. Dmloader Dll 35,840 . . . . A 8-04-04 1:56 am
360. Imgutil Dll 35,840 . . . . A 8-04-04 1:56 am
1104. Umandlg Dll 35,840 . . . . A 8-04-04 1:56 am
216. Dpvacm Dll 21,504 . . . . A 8-04-04 1:56 am
264. Feclient Dll 21,504 . . . . A 8-04-04 1:56 am
293. Hidserv Dll 21,504 . . . . A 8-04-04 1:56 am
____________________________________________________________________________
C:\WINNT\SYSTEM32\
dpwsockx.dll Wed Aug 4 2004 1:56:42a A…. 57,344 56.00 K
msasn1.dll Wed Aug 4 2004 1:56:42a A…. 57,344 56.00 K
2 items found: 2 files, 0 directories.
Total of file sizes: 114,688 bytes 112.00 K
C:\WINNT\SYSTEM32\
dmloader.dll Wed Aug 4 2004 1:56:42a A…. 35,840 35.00 K
imgutil.dll Wed Aug 4 2004 1:56:42a A…. 35,840 35.00 K
umandlg.dll Wed Aug 4 2004 1:56:46a A…. 35,840 35.00 K
3 items found: 3 files, 0 directories.
Total of file sizes: 107,520 bytes 105.00 K
C:\WINNT\SYSTEM32\
dpvacm.dll Wed Aug 4 2004 1:56:42a A…. 21,504 21.00 K
feclient.dll Wed Aug 4 2004 1:56:42a A…. 21,504 21.00 K
hidserv.dll Wed Aug 4 2004 1:56:42a A…. 21,504 21.00 K
3 items found: 3 files, 0 directories.
Total of file sizes: 64,512 bytes 63.00 K
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
Sniffed -> C:\WINNT\SYSTEM32\DPVACM.DLL
Sniffed -> C:\WINNT\SYSTEM32\FECLIENT.DLL
Sniffed -> C:\WINNT\SYSTEM32\HIDSERV.DLL
SNiF 1.34 statistics
Matching files : 3 Amount in bytes : 64512
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.DLL
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
BHO search and other files…
**File C:\WINNT\SYSTEM32\AAIMK.DLL
00005E50: 2D 26 14 E7 0F 64 8A 00 . 00 00 00 00 C0 82 05 B3 -&.ç.dŠ. ….À‚.³
**File C:\WINNT\SYSTEM32\BELCCHL.DLL
00005E50: 2D 26 14 E7 0F 64 8A 00 . 00 00 00 00 C0 82 05 B3 -&.ç.dŠ. ….À‚.³
**File C:\WINNT\SYSTEM32\NIEPBKE.DLL
00005E50: 2D 26 14 E7 0F 64 8A 00 . 00 00 00 00 C0 82 05 B3 -&.ç.dŠ. ….À‚.³
No matches found.
No matches found.
No matches found.
–*sp.html in temp folder was NOT FOUND!–
*Filter keys search…
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html' (2)
–(*text/html Subkey was NOT FOUND!)–
REGDMP: Unable to open key 'HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain' (2)
–(*text/plain Subkey was NOT FOUND!)–
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»*»»» Scanning for moved file… »»»*»»»
No matches found.
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.
SNiF 1.34 statistics
Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0
Masks sniffed for: *.*
fgrep: no files found for C:\FINDNFIX\JUNKXXX\*.*
Analyzer v1.36 by Boogie Copyright © 1997 ESP Team
Files: C:\FINDNFIX\JUNKXXX\*.*
Ä
Ä
Volume: None * DDIR * 1:59 pm | Mon, 1-03-05
Ser #: DC06-894C DOS Ver. 5.00 0% Used space
Path: C:\FINDNFIX\JUNKXXX All files selected
No files found.
No. of files: 0 | List size: 0
Disk size: 976.5 M | Actual spc: 0
Bytes free: 976.5 M | Conserved space: 0
File not found - C:\FINDnFIX\junkxxx\*.*
CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.
MD5 Message Digest Algorithm by RSA Data Security, Inc.
File name Size Date Time MD5 Hash
________________________________________________________________________
CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk
C:\FINDNFIX\JUNKXXX
No files found
#######################################################
*Known files are…
——————–
File: ((56k; (57,344 bytes)
CRC-32 : D5C9FB2E
MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249
——————–
File: ((35k; (35,840 bytes)
CRC-32 : 33081C8B
MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE
——————–
File: ((21k; (21,504 bytes)
CRC-32 : 2258F59E
MD5 : EFEE2CB3 B342A351 51802356 9637F8E6
#######################################################
»»Permissions:
ERROR: There are no more files.
Directory "C:\FINDnFIX\junkxxx\."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000002 tc– 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000009 –o- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000002 tc– 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000009 –o- 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000010 t— 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 0000001B -co- 10000000 —A —- —- BUILTIN\Administrators
Allow 00000010 t— 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 0000001B -co- 10000000 —A —- —- NT AUTHORITY\SYSTEM
Allow 00000010 t— 001F01FF —- DSPO rw+x S1100375735\Owner
Allow 0000001B -co- 10000000 —A —- —- \CREATOR OWNER
Allow 00000010 t— 001200A9 —- -S– r–x BUILTIN\Users
Allow 0000001B -co- A0000000 R-X- —- —- BUILTIN\Users
Allow 00000012 tc– 00000004 —- —- –+- BUILTIN\Users
Allow 00000012 tc– 00000002 —- —- -w– BUILTIN\Users
Owner: S1100375735\Owner
Primary Group: S1100375735\None
Directory "C:\FINDnFIX\junkxxx\.."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000010 t— 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 0000001B -co- 10000000 —A —- —- BUILTIN\Administrators
Allow 00000010 t— 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 0000001B -co- 10000000 —A —- —- NT AUTHORITY\SYSTEM
Allow 00000010 t— 001F01FF —- DSPO rw+x S1100375735\Owner
Allow 0000001B -co- 10000000 —A —- —- \CREATOR OWNER
Allow 00000010 t— 001200A9 —- -S– r–x BUILTIN\Users
Allow 0000001B -co- A0000000 R-X- —- —- BUILTIN\Users
Allow 00000012 tc– 00000004 —- —- –+- BUILTIN\Users
Allow 00000012 tc– 00000002 —- —- -w– BUILTIN\Users
Owner: S1100375735\Owner
Primary Group: S1100375735\None
»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512…)
Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450
»»Checking for AppInit_DLLs (empty) value…
________________________________
!"AppInit_DLLs"=""!
Value Matches
________________________________
»»Comparing *saved* key with *original*…
REGDIFF 2.1 - Freeware written by Gerson Kurz (http://www.p-nand-q.com)
Comparing File #1 (Keys1\winkey.reg) with File #2 (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows).
No differences found.
»»Dumping Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs =
»»Security settings for 'Windows' key:
RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (
http://www.heysoft.de)
This program is Freeware, use it on your own risk!
Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER
Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM
00001150: vk UDeviceNotSelecte
00001190:dTimeout 1 5 x h vk ' zGDIProce
000011D0:ssHandleQuota" 9 0 =t vk Spooler2
00001210: y e s _ vk 5swapdisk h
00001250: X vk . TransmissionRetryTimeout vk
00001290: ' % USERProcessHandleQuota h X
000012D0: vk f AppInit_DLLs G
00001310:
00001350:
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
———- NEWWIN.TXT
fùAppInit_DLLsÖæG
————–
————–
$0117F: UDeviceNotSelectedTimeout
$011C7: zGDIProcessHandleQuota
$01270: TransmissionRetryTimeout
$012A0: USERProcessHandleQuota
$012F0: AppInit_DLLs
————–
————–
No strings found.
————–
————–
d…. 0 Jan 3 12:46 .
d…. 0 Jan 3 12:46 ..
2 files found occupying -1024 bytes
===============================================================================
0 bytes 0 cps
Files: 0 Records: 0 Matches: 0 Elapsed Time: 00:00:00.06
VDIR v1.00
Path: C:\FINDNFIX\JUNKXXX\*.*
—————————————+—————————————
. 01-03-:5 12:46|.. 01-03-:5 12:46
—————————————+—————————————
2 files totaling 0 bytes consuming 0 bytes of disk space.
17299968 bytes available on Drive C: No volume label
…File dump…
Detecting…
C:\FINDnFIX\junkxxx
Finished Detecting…
=========================================
0 C:\FINDnFIX\junkxxx (DIR Total)
Owner No. Files Total Size
=========================================
________________________________________________________________________________
***THE FIX IS NOT COMPATIBLE WITH EARLIER;UNPATCHED VERSIONS OF WIN2K'(SP3 and BELLOW)'
AND/OR LAX OF SECURITY UPDATES AND SERVICE PACKS FOR ALL PLATFORMS!
MINIMAL REQUIREMENTS INCLUDE:
_________XP HOME/PRO; SP1; IE6/SP1
_________2K/SP4; IE6/SP1
________________________________________________________________________________
»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»
Mon 03 Jan 05 13:59:35
—–END—–