FreeFixer v0.54 log
http://www.freefixer.com/
Operating system: Windows XP Service Pack 3
Log dated 2010-03-30 01:29
UserInits (1 whitelisted)
D:\WINDOWS\system32\msedyu32.exe
Winlogon Notify
!SASWinLogon - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!SASWinLogon'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
crypt32chain - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\crypt32chain'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
cryptnet - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\cryptnet'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
cscdll - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\cscdll'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
dimsntfy - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\dimsntfy'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
ScCertProp - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\ScCertProp'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
Schedule - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\Schedule'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
sclgntfy - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\sclgntfy'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
SensLogn - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\SensLogn'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
termsrv - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\termsrv'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
wlballoon - (no file specified)
Error when opening a registry key, access is denied. Key:
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\wlballoon'.
System error message: Ăśberlappender E/A-Vorgang wird verarbeitet.
Error code: 997.
Browser Helper Objects (3 whitelisted)
{02478D38-C3F9-4efb-9B51-7695ECA05670}, , (no file specified)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}, AVG Safe Search, D:\Programme
\AVG\AVG8\avgssie.dll (file is missing)
{724d43a9-0d85-11d4-9908-00400523e39a}, , D:\Programme\Siber Systems
\AI RoboForm\roboform.dll
Internet Explorer toolbars (2 whitelisted)
HKLM\..\Toolbar\{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm - D:
\Programme\Siber Systems\AI RoboForm\roboform.dll
HKCU\..\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - -
(no file specified)
HKCU\..\Toolbar\WebBrowser\{EF99BD32-C1FB-11D2-892F-0090271D4F88} - -
(no file specified)
Basic Internet Explorer settings
HKCU\..\Desktop\General, Wallpaper = D:\Dokumente und Einstellungen
\Dennis\Lokale Einstellungen\Anwendungsdaten\Microsoft\Wallpaper1.bmp
Registry Startups (1 whitelisted)
HKLM\..\Run, NvCplDaemon = RUNDLL32.EXE D:\WINDOWS
\system32\NvCpl.dll,NvStartup
HKCU\..\Run, PeerGuardian = D:\Programme\PeerGuardian2\pg2.exe
Autostart shortcuts
syspck32.exe, , D:\Dokumente und Einstellungen\Dennis\StartmenĂĽ
\Programme\Autostart\syspck32.exe
Processes (19 whitelisted)
D:\WINDOWS\system32\nvsvc32.exe
D:\Programme\PeerGuardian2\pg2.exe
D:\Programme\Winamp\winamp.exe
F:\Temp\FreeFixer\freefixer.exe
D:\Programme\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
Services (38 whitelisted)
nvsvc, NVIDIA Display Driver Service, d:\windows\system32\nvsvc32.exe
Svchost.exe Modules (207 whitelisted)
d:\programme\hp\digital imaging\bin\hpqddsvc.dll
d:\programme\hp\digital imaging\bin\hpqddcmn.dll
d:\programme\hp\digital imaging\bin\hpqcxs08.dll
d:\windows\system32\hpzinw12.dll
d:\windows\system32\hpzipm12.dll
Explorer.exe Modules (135 whitelisted)
D:\Programme\SUPERAntiSpyware\SASSEH.DLL
D:\Programme\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
D:\Programme\WinRAR\rarext.dll
D:\WINDOWS\system32\dfshim.dll
D:\WINDOWS\system32\mscoree.dll
D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Shfusion.dll
D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Fusion.dll
D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\culture.dll
D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ShFusRes.dll
D:\Programme\Siber Systems\AI RoboForm\roboform.dll
D:\WINDOWS\system32\nvcpl.dll
D:\Programme\SUPERAntiSpyware\SASCTXMN.DLL
D:\Programme\Zoto Uploader\zshell.dll
D:\WINDOWS\system32\l3codeca.acm
D:\Programme\Gemeinsame Dateien\Ahead\Lib\AdvrCntr.dll
D:\Programme\Real Alternative\RealMediaSplitter.ax
D:\Programme\Gemeinsame Dateien\Ahead\DSFilter\NeVideo.ax
Drivers (32 whitelisted)
CDRPDACC, CD-ROM Productions Device Access, d:\programme\cd-rom
productions\shared\cdrpdacc.sys
Firefox Extensions
NoDoFollow, D:\Dokumente und Einstellungen\Dennis\Anwendungsdaten
\Mozilla\Firefox\Profiles\q9w830qj.default\extensions\
{c2b1f3ae-5cd5-49b7-8a0c-2c3bcbbbb294}\install.rdf
SearchStatus, D:\Dokumente und Einstellungen\Dennis\Anwendungsdaten
\Mozilla\Firefox\Profiles\q9w830qj.default\extensions\
{d57c9ff1-6389-48fc-b770-f78bd89b6e8a}\install.rdf
Recently created/modified files (27 whitelisted)
2 hours, f:\Temp\Spyware Doctor\BDT\DbgHelp.dll
2 hours, f:\Temp\Spyware Doctor\TFEngine\ATL80.dll
2 hours, f:\Temp\Spyware Doctor\TFEngine\msvcm80.dll
The following errors occurred during the scan:
Problems opening folder 'c:\Dokumente und Einstellungen\All Users
\Anwendungsdaten\Symantec\SRTSP\Quarantine' to enumerate files.
FindFirstFile failed. System error message: Access denied Error code:
5.
Problems opening folder 'c:\Dokumente und Einstellungen\All Users
\Anwendungsdaten\Symantec\SRTSP\SrtETmp' to enumerate files.
FindFirstFile failed. System error message: Access denied Error code:
5.
End of FreeFixer log
I read on the major geeks forum that this is related to the combofix
program. So I guess I dont have to worry about it? Odd though,
combofix is not installed anymore...
syspck32.exe and msedyu32.exe sure sounds like malware. You did the
right thing to delete them. It should not be a problem that msedyu32.exe
appears in FreeFixer's scan result or in msconfig, as long as the file
has been deleted from the machine. If you like, you can tidy up the scan
result by checking the msedyu32.exe userinit item for removal.
I'm not sure about D:\DOKUME~1\Dennis\LOKALE~1\Temp\catchme.sys. Please
upload it to virustotal.com and include the link to the scan result in
your reply.
Seems FreeFixer is unable to scan the Winlogon Notify packages installed
on your system. I'm not sure why. Please scan your computer with GMER.
Does it find any rootkit activity?
/Roger
--
You received this message because you are subscribed to the Google
Groups "FreeFixer User Forum" group. To post to this group, send email
to freefix...@googlegroups.com. To unsubscribe from this group,
send email to freefixer-for...@googlegroups.com.
For more options, visit this group at
http://groups.google.com/group/freefixer-forum?hl=en.
---- System - GMER 1.0.15 ----
SSDT \??\D:\WINDOWS\system32\Drivers\regguard.sys (Registry
Guard - registry keys protection driver for Windows NT/2000/XP/2003/
Vista/Windows7/Greatis Software) ZwDeleteKey [0xF7C16DA0]
SSDT \??\D:\WINDOWS\system32\Drivers\regguard.sys (Registry
Guard - registry keys protection driver for Windows NT/2000/XP/2003/
Vista/Windows7/Greatis Software) ZwDeleteValueKey [0xF7C16FC0]
SSDT \??\D:\WINDOWS\system32\Drivers\regguard.sys (Registry
Guard - registry keys protection driver for Windows NT/2000/XP/2003/
Vista/Windows7/Greatis Software) ZwOpenKey [0xF7C16C70]
SSDT \??\D:\WINDOWS\system32\Drivers\regguard.sys (Registry
Guard - registry keys protection driver for Windows NT/2000/XP/2003/
Vista/Windows7/Greatis Software) ZwQueryValueKey [0xF7C170E0]
---- Kernel code sections - GMER 1.0.15 ----
.text D:\WINDOWS\system32\DRIVERS
\nv4_mini.sys
section is writeable [0xF6ED1380, 0x3DF545, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
SetScrollInfo
7E369056 7 Bytes JMP 01D7A68D D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
GetScrollInfo
7E37DFE2 7 Bytes JMP 01D7A615 D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
ShowScrollBar
7E37F2F2 5 Bytes JMP 01D7A711 D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
GetScrollPos
7E37F704 5 Bytes JMP 01D7A63D D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
SetScrollPos
7E37F750 5 Bytes JMP 01D7A6B8 D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
GetScrollRange
7E37F787 5 Bytes JMP 01D7A662 D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
SetScrollRange
7E37F99B 5 Bytes JMP 01D7A6E3 D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\Programme\Winamp\winamp.exe[2068] USER32.dll!
EnableScrollBar
7E3B8005 7 Bytes JMP 01D7A5ED D:\Programme\Winamp\Plugins
\gen_jumpex.dll
.text D:\WINDOWS\explorer.exe[3072] ntdll.dll!
NtQueryDirectoryFile +
6
7C91D756 4 Bytes [90, 61, D0, 00] {NOP ; POPA ; ROL BYTE [EAX], 0x1}
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat
\Fat
fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@ Microsoft-Datentr?
gerkontingent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@NoBackgroundPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@DllName dskquota.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
@ Internet Explorer-
Zonenzuordnung
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
@DllName iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
@ProcessGroupPolicy
ProcessGroupPolicyForZoneMap
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
@RequiresSucessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@ProcessGroupPolicy
SceProcessSecurityPolicyGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@GenerateGroupPolicy SceGenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@ExtensionRsopPlanningDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@ProcessGroupPolicyEx
SceProcessSecurityPolicyGPOEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@ExtensionDebugLevel 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@ Security
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@EnableAsynchronousProcessing 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
@MaxNoGPOListChangesInterval 960
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@ProcessGroupPolicyEx ProcessGroupPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@DllName iedkcs32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@ Internet Explorer-
Branding
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
@NoMachinePolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
@ProcessGroupPolicy
SceProcessEFSRecoveryGPO
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
@DllName scecli.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
@ EFS recovery
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@ 802.3 Group Policy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@DisplayName @dot3gpclnt.dll,-100
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@ProcessGroupPolicyEx ProcessLANPolicyEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@GenerateGroupPolicy GenerateLANPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@DllName dot3gpclnt.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
@NoGPOListChanges 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@ Microsoft Offline Files
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@DllName %SystemRoot%
\System32\cscui.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@EnableAsynchronousProcessing 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@NoGPOListChanges 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@NoMachinePolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@NoSlowLink 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@NoUserPolicy 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@PerUserLocalSettings 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@ProcessGroupPolicy ProcessGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
@RequiresSuccessfulRegistry 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@ Softwareinstallation
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@DllName appmgmts.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@ProcessGroupPolicyEx
ProcessGroupPolicyObjectsEx
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@GenerateGroupPolicy GenerateGroupPolicy
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@NoBackgroundPolicy 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@RequiresSucessfulRegistry 0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@NoSlowLink 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@PerUserLocalSettings 1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
@EventSources (Application
Management,Application)?(MsiInstaller,Application)?
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@DllName
D:\Programme\SUPERAntiSpyware\SASWINLO.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@Logon
SABWINLOLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@Logoff
SABWINLOLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@Startup
SABWINLOStartup
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@Shutdown
SABWINLOShutdown
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@Asynchronous
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify\!
SASWinLogon@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\crypt32chain@Asynchronous
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\crypt32chain@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\crypt32chain@DllName
crypt32.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\crypt32chain@Logoff
ChainWlxLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cryptnet@Asynchronous
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cryptnet@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cryptnet@DllName
cryptnet.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cryptnet@Logoff
CryptnetWlxLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@DLLName
cscdll.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@Logon
WinlogonLogonEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@Logoff
WinlogonLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@ScreenSaver
WinlogonScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@Startup
WinlogonStartupEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@Shutdown
WinlogonShutdownEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@StartShell
WinlogonStartShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\cscdll@Asynchronous
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Asynchronous
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@DllName
%SystemRoot%\System32\dimsntfy.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Startup
WlDimsStartup
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Shutdown
WlDimsShutdown
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Logon
WlDimsLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Logoff
WlDimsLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@StartShell
WlDimsStartShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Lock
WlDimsLock
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\dimsntfy@Unlock
WlDimsUnlock
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@DLLName
wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Logon
SCardStartCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Logoff
SCardStopCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Lock
SCardSuspendCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Unlock
SCardResumeCertProp
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Enabled
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Impersonate
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\ScCertProp@Asynchronous
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\Schedule@Asynchronous
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\Schedule@DllName
wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\Schedule@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\Schedule@StartShell
SchedStartShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\Schedule@Logoff
SchedEventLogOff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\sclgntfy@Logoff
WLEventLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\sclgntfy@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\sclgntfy@Asynchronous
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\sclgntfy@DllName
sclgntfy.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@DLLName
WlNotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Lock
SensLockEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Logon
SensLogonEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Logoff
SensLogoffEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Safe
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@MaxWait
600
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@StartScreenSaver
SensStartScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@StopScreenSaver
SensStopScreenSaverEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Startup
SensStartupEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Shutdown
SensShutdownEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@StartShell
SensStartShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@PostShell
SensPostShellEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Disconnect
SensDisconnectEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Reconnect
SensReconnectEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Unlock
SensUnlockEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Impersonate
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\SensLogn@Asynchronous
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Asynchronous
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@DllName
wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Impersonate
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Logoff
TSEventLogoff
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Logon
TSEventLogon
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@PostShell
TSEventPostShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Shutdown
TSEventShutdown
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@StartShell
TSEventStartShell
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Startup
TSEventStartup
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@MaxWait
600
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Reconnect
TSEventReconnect
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\termsrv@Disconnect
TSEventDisconnect
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\wlballoon@DLLName
wlnotify.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\wlballoon@Logon
RegisterTicketExpiredNotificationEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\wlballoon@Logoff
UnregisterTicketExpiredNotificationEvent
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\wlballoon@Impersonate
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\Notify
\wlballoon@Asynchronous
1
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@Hilfeassistent
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@TsInternetUser
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@SQLAgentCmdExec
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@NetShowServices
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@HelpAssistant
0
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@IWAM_
65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@IUSR_
65536
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
\Winlogon\SpecialAccounts
\UserList@VUSR_
65536
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{33F87792-B1F5-3AE6-0EE6-
CE658B478259}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{47D9FB2A-2B30-85E1-F322-
DEAF4E40E071}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{47D9FB2A-2B30-85E1-F322-DEAF4E40E071}
@abooppijfmedgddomodkallkhbndphhbpi 0x70 0x61 0x61 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{47D9FB2A-2B30-85E1-F322-DEAF4E40E071}
@malokpgjibdfgokbndmipojdla 0x6F 0x61 0x6F 0x6D ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{50F48DBB-21EA-CEFD-
F978-1E43976C7B96}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{78A5CA21-B976-E898-A01C-
AC4E7DEC27A6}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{78A5CA21-B976-E898-A01C-AC4E7DEC27A6}
@iambacjnfdocjkmdcg 0x6A 0x61 0x6A 0x6D ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
Extensions\Approved\{78A5CA21-B976-E898-A01C-AC4E7DEC27A6}
@hagbkdnkidolclnj 0x6A 0x61 0x6A 0x6D ...
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
\4345\Shell@WinPos1152x864(1).left
-11
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
\4345\Shell@WinPos1152x864(1).top
5
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
\4345\Shell@WinPos1152x864(1).right
1016
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags
\4345\Shell@WinPos1152x864(1).bottom
807
---- Disk sectors - GMER 1.0.15 ----
Disk \Device
\Harddisk0\DR0
sector 01: copy of MBR
---------------------
How does this look to you? Just now I twice had trouble starting up
winamp. Each time it would freeze up explorer.exe and even though it
didn’t successfully start up it would still be running in the
background (as you can see in the log). Previously, at the time of the
infection, this behaviour already occurred with winamp and also VLC
player. Explorer.exe itself has been working pretty smoothly again
though and from what I know everything should be fine. Maybe not?
Anything you can see in the log? Thanks.
p.s.: Ok, this is weird - I canceled winamp.exe in the taskmanager now
and after a while winamp started up on the screen, with my last
playlist showing. ?
I think the GMER log is clean. I was worried that the there was a
rootkit preventing FreeFixer from reading some of the registry data and
resulting in the "access is denied" error messages. But after looking at
the GMER log I see that you have the regguard.sys registry protection
driver installed, which I think may be causing the error messages, so
it's probably nothing to worry about.
Unfortunately I don't know how to solve winamp issue.
/Roger
-----Original Message-----
From: freefix...@googlegroups.com
[mailto:freefix...@googlegroups.com] On Behalf Of dennistielmann
Sent: den 6 april 2010 00:23
To: FreeFixer User Forum
Subject: Re: syspck32.exe & msedyu32.exe?
---------------------
--