Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
I downloaded and installed a program called PortFlash, and somewhere along the
way I must have picked up a Trojan virus. That was fixed.
After installation, however, there were also popups, adwares, hijackers. I used several programs to detect and get rid of them. Some of the files that the programs was unable to erase or had erased but were there again after reboot, I erased manually in safe mode.
I still have popups (example: popuppers advertisement window64) and files running that have weird names.
Also, nothing works when I log-on to Windows for the first time. I can't open a file or a program without making it "freeze", and the web browser won't work. Only after I log-off (and this takes a long time) and log-on again will everything work. Last time I rebooted the computer rearranged my icons by itself!
Logfile of HijackThis v1.99.1
Scan saved at 오전 3:15:40, on 2005-02-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Any of the following you did not set as trusted sites.
O15 - Trusted Zone: http://*.sbs.co.kr
O15 - Trusted Zone: http://*.shinhan.com
O15 - Trusted Zone: http://*.shinhancard.com
O15 - Trusted Zone: http://*.buddybuddy.co.kr (HKLM)
O15 - Trusted Zone: http://www.lgqls.co.kr (HKLM)
ALL 016 entries. Good ones will be re-installed as you need them.
O23 - Service: bfjhwoliaxrj (kjsxlgqo6) - Unknown owner - C:\WINDOWS\system32\bczhrhpy6.exe (file missing)
Right click My Computer and choose properties. On system restore tab, check the box to turn off. OK out.
Go to start>run and type msconfig, hit enter. On the boot.ini tab, check the box next to /safeboot and OK. Yes to restart. This will restart your computer in safe mode. Logon to your user account.
Now in safe mode, you will need to show hidden files and folders, as well as system files and extensions for known file types.
Delete all files/folders in bold.
Open C:\Temp if present, select all and delete.
Open C:\Windows\Temp, select all and delete.
Open C:\Windows\Prefetch, select all and delete.
Open C:\Documents and Settings\username\Local Settings\temp, select all and delete. Do this for all usernames.
Open the control panel, then internet options and delete the temporary internet files, checking the box for offline content. Close Internet Options.
Open My Computer, right click Local disk C: and choose properties, then disk cleanup. Check all boxes except compress old files and click OK.
Uncheck the /safeboot box in msconfig and ok to reboot.
Scan your PC with RAV. If any files are infected, click the report button then copy and paste it here.
Found
============================
Viruses found: 1
Suspicious files: 1
Disinfected files: 0
Mail files: 69
This is the new hijackthis log, I've never heard of http://www.lgqls.co.kr
and I checked it last time but it's still there after reboot.
Logfile of HijackThis v1.99.1
Scan saved at 오후 10:29:16, on 2005-02-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Delete the HyperLinker3.exe file from C:\Windows\Sysstem32
Fix this entry with HJT.
O23 - Service: bfjhwoliaxrj (kjsxlgqo6) - Unknown owner - C:\WINDOWS\system32\bczhrhpy6.exe (file missing)
Close all IE windows and open Internet options in the control panel. Click the security tab, then highlight Trusted Sites and click the Sites button. Remove the www.lgqls.co.kr entry. Close and reboot. Scan again and let me know if those two entries are still present.
Copy the text in the quote box below to notepad, then save it to the desktop as Export.bat Make sure to change the file type to All files. Now double click it to run. It will open a text file named Drivers.txt. Save it and post the contents.
Quote:
cd "%windir%\system32\drivers\users"
dir /s /a >Drivers.txt
Start notepad Drivers.txt
echo %systemroot%
cls
Under Trusted Sites the www.lgqls.co.kr entry doesn't exist, there are just three entries instead of four. They are still there after reboot.
Here is the Drivers.txt.
C 드라이브의 볼륨에는 이름이 없습니다.
볼륨 일련 번호: F897-471A
C:\Documents and Settings\JW\바탕 화면 디렉터리
2005-02-19 오전 08:48 <DIR> .
2005-02-19 오전 08:48 <DIR> ..
2005-02-19 오전 08:49 0 Drivers.txt
2005-02-19 오전 08:48 113 Export.bat
2005-02-19 오전 08:40 4,099 for me.txt
2005-02-16 오전 11:06 218,112 HijackThis.exe
2005-02-19 오전 08:48 <DIR> new
2005-02-10 오후 04:17 65,024 Thumbs.db
2004-12-11 오후 04:21 592 ? .lnk
2005-02-17 오후 11:45 776 .lnk
2005-02-18 오전 01:28 2,307 .lnk
2005-02-16 오후 11:43 638 .lnk
2005-02-17 오후 11:45 <DIR> 사용하지 않는 바탕 화면 바로 가기
9개 파일 291,661 바이트
C:\Documents and Settings\JW\바탕 화면\new 디렉터리
2005-02-19 오전 08:48 <DIR> .
2005-02-19 오전 08:48 <DIR> ..
2005-02-16 오전 01:03 90,545 16294609.jpg
2005-02-02 오전 08:56 5,662 al.txt
2005-02-18 오전 12:51 1,216 dothis.txt
2005-02-18 오전 12:57 38,911 dothis2.txt
2005-02-18 오전 12:45 38 erase.txt
2005-02-18 오전 02:25 503,919 error.jpg
2005-02-15 오후 02:37 49,664 February 13.doc
2005-02-19 오전 08:29 4,059 for me.txt
2005-02-19 오전 08:34 5,988 hijackthis.log
2005-02-18 오후 02:51 1,843 my situation.txt
2005-01-16 오후 04:08 819 order.txt
2005-02-18 오후 02:22 1,204 popuppers.txt
2005-02-18 오후 02:59 23,989 popuppersremove.txt
2005-02-17 오전 01:04 134 port.txt
2005-02-18 오전 01:29 71,168 Printable Version of Topic.doc
2005-02-09 오후 10:37 113,436 pyramid.jpg
2005-01-16 오후 04:12 1,372 rock countdown.txt
2005-02-19 오전 08:48 18,944 Thumbs.db
2005-02-14 오후 11:29 159 uconn ice cream flavor.txt
2005-02-18 오후 02:47 2,208 viewremove.txt
20개 파일 935,278 바이트
C:\Documents and Settings\JW\바탕 화면\사용하지 않는 바탕 화면 바로 가기 디렉터리
2005-02-17 오후 11:45 <DIR> .
2005-02-17 오후 11:45 <DIR> ..
2004-06-17 오전 12:59 882 Acrobat Reader 5.0.lnk
2004-12-24 오후 12:47 1,740 Adobe Reader 6.0.lnk
2004-09-21 오후 04:46 685 DAEMON Tools.lnk
2004-10-23 오후 08:18 2,105 Hangul 2002.lnk
2004-09-13 오후 04:35 713 HP Deskjet 3840 Series 사용 설명서.lnk
2004-09-13 오후 04:35 828 HP 사진 인쇄.lnk
2004-06-17 오전 12:59 1,684 Java Web Start.lnk
2004-10-31 오전 09:42 <DIR> Microsoft Outlook.{00020D75-0000-0000-C000-000000000046}
2004-11-19 오후 02:49 1,766 NBA LIVE 2005.lnk
2004-06-17 오전 01:08 1,684 PowerDVD.lnk
2004-09-12 오후 05:30 803 RealPlayer.lnk
2005-01-08 오후 01:23 679 SBC Yahoo! DSL.lnk
2004-06-17 오전 01:00 1,680 매직인터넷 자이젠.lnk
2005-02-17 오후 01:03 814 조인스랜드 뉴스알리미.lnk
13개 파일 16,063 바이트
C:\Documents and Settings\JW\바탕 화면\사용하지 않는 바탕 화면 바로 가기\Microsoft Outlook.{00020D75-0000-0000-C000-000000000046} 디렉터리
2004-10-31 오전 09:42 <DIR> .
2004-10-31 오전 09:42 <DIR> ..
0개 파일 0 바이트
전체 파일:
42개 파일 1,243,002 바이트
11개 디렉터리 2,898,051,072 바이트 남음
2005-02-19 오후 04:01 <DIR> .
2005-02-19 오후 04:01 <DIR> ..
2004-08-04 오전 01:10 53,248 1394bus.sys
2004-08-04 오전 02:36 186,240 acpi.sys
2003-04-09 오전 07:00 11,648 acpiec.sys
2004-08-04 오전 02:53 4,255 adv01nt5.dll
2004-08-04 오전 02:53 3,967 adv02nt5.dll
2004-08-04 오전 02:53 3,615 adv05nt5.dll
2004-08-04 오전 02:53 3,647 adv07nt5.dll
2004-08-04 오전 02:53 3,135 adv08nt5.dll
2004-08-04 오전 02:53 3,711 adv09nt5.dll
2004-08-04 오전 02:53 3,775 adv11nt5.dll
2004-08-04 오전 12:39 142,464 aec.sys
2004-08-04 오전 01:14 138,496 afd.sys
2004-08-04 오전 01:07 42,368 agp440.sys
2004-08-04 오전 01:07 44,928 agpcpq.sys
2003-06-10 오전 06:37 1,164,576 AGRSM.sys
2004-08-18 오후 02:21 43,904 ahnflt2k.sys
2004-08-18 오후 02:22 45,320 ahnfltnt.sys
2003-02-28 오전 10:11 13,568 ahnrec2k.sys
2003-02-28 오전 10:12 13,480 ahnrecnt.sys
2004-08-04 오전 01:07 42,752 alim1541.sys
2004-08-04 오전 01:07 43,008 amdagp.sys
2004-08-04 오전 02:36 40,064 amdk6.sys
2004-08-04 오전 02:36 40,448 amdk7.sys
2004-08-04 오전 12:58 60,800 arp1394.sys
2004-08-04 오전 01:05 14,336 asyncmac.sys
2004-08-04 오전 12:59 95,360 atapi.sys
2004-08-04 오전 12:29 56,623 ati1btxx.sys
2004-08-04 오전 12:29 11,615 ati1mdxx.sys
2004-08-04 오전 12:29 12,047 ati1pdxx.sys
2004-08-04 오전 12:29 30,671 ati1raxx.sys
2004-08-04 오전 12:29 63,663 ati1rvxx.sys
2004-08-04 오전 12:29 26,367 ati1snxx.sys
2004-08-04 오전 12:29 21,343 ati1ttxx.sys
2004-08-04 오전 12:29 36,463 ati1tuxx.sys
2004-08-04 오전 12:29 29,455 ati1xbxx.sys
2004-08-04 오전 12:29 34,735 ati1xsxx.sys
2004-08-04 오전 12:29 327,040 ati2mtaa.sys
2003-06-10 오전 06:37 631,936 ati2mtag.sys
2004-08-04 오전 12:29 57,856 atinbtxx.sys
2004-08-04 오전 12:29 13,824 atinmdxx.sys
2004-08-04 오전 12:29 14,336 atinpdxx.sys
2004-08-04 오전 12:29 52,224 atinraxx.sys
2004-08-04 오전 12:29 104,960 atinrvxx.sys
2004-08-04 오전 12:29 28,672 atinsnxx.sys
2004-08-04 오전 12:29 13,824 atinttxx.sys
2004-08-04 오전 12:29 73,216 atintuxx.sys
2004-08-04 오전 12:29 31,744 atinxbxx.sys
2004-08-04 오전 12:29 63,488 atinxsxx.sys
2004-07-17 오후 01:36 64,352 ativmc20.cod
2003-09-08 오전 02:02 5,786 ATKACPI.sys
2004-08-04 오전 12:58 59,904 atmarpc.sys
2003-04-09 오전 07:00 31,360 atmepvc.sys
2004-08-04 오전 12:58 55,936 atmlane.sys
2003-04-09 오전 07:00 352,256 atmuni.sys
2004-08-04 오전 02:53 21,183 atv01nt5.dll
2004-08-04 오전 02:53 11,359 atv02nt5.dll
2004-08-04 오전 02:53 25,471 atv04nt5.dll
2004-08-04 오전 02:53 14,143 atv06nt5.dll
2004-08-04 오전 02:53 17,279 atv10nt5.dll
2001-08-16 오후 11:59 3,072 audstub.sys
2001-08-27 오전 01:04 16,128 battc.sys
2004-08-04 오전 01:10 11,776 bdasup.sys
2003-04-09 오전 07:00 4,224 beep.sys
2004-08-04 오전 12:59 71,552 bridge.sys
2004-08-04 오전 01:10 17,024 bthenum.sys
2004-08-04 오전 01:10 38,016 bthmodem.sys
2004-08-04 오전 12:58 100,992 bthpan.sys
2004-08-04 오전 02:39 272,512 bthport.sys
2004-08-04 오전 01:10 35,456 bthprint.sys
2004-08-04 오전 01:10 18,944 bthusb.sys
2003-04-09 오전 07:00 13,952 cbidf2k.sys
2004-08-04 오전 01:10 17,024 ccdecode.sys
2003-04-09 오전 07:00 18,688 cdaudio.sys
2004-08-04 오전 01:14 63,744 cdfs.sys
2004-08-04 오전 12:59 49,536 cdrom.sys
2005-01-01 오전 07:27 7,604 CDSpace.cfg
2004-08-04 오전 02:53 15,423 ch7xxnt5.dll
2003-04-09 오전 07:00 262,528 cinemst2.sys
2004-08-04 오전 01:14 49,664 classpnp.sys
2004-08-04 오전 01:07 14,080 cmbatt.sys
2001-08-16 오후 11:58 9,344 compbatt.sys
2003-04-09 오전 07:00 11,776 cpqdap01.sys
2004-08-04 오전 02:42 39,552 crusoe.sys
2004-07-18 오전 12:55 129,045 cxthsfs2.cty
2004-08-22 오후 03:31 155,136 d347bus.sys
2004-08-22 오후 03:31 5,248 d347prt.sys
2005-02-16 오후 07:52 7,359 dgtsys.sys
2004-06-17 오전 09:15 <DIR> disdn
2004-08-04 오전 12:59 36,352 disk.sys
2004-08-04 오전 12:59 14,208 diskdump.sys
2004-08-04 오전 02:44 799,488 dmboot.sys
2004-08-04 오전 02:44 152,448 dmio.sys
2003-04-09 오전 07:00 5,888 dmload.sys
2004-08-04 오전 01:07 52,864 dmusic.sys
2005-02-19 오후 04:01 0 Drivers.txt
2004-08-04 오전 01:07 60,288 drmk.sys
2004-08-04 오전 01:07 2,944 drmkaud.sys
2003-04-09 오전 07:00 10,496 dxapi.sys
2004-08-04 오전 01:00 71,040 dxg.sys
2003-04-09 오전 07:00 3,328 dxgthk.sys
2001-08-16 오후 11:46 6,400 enum1394.sys
2005-02-17 오후 11:56 <DIR> etc
2004-08-04 오전 01:14 143,360 fastfat.sys
2004-08-04 오전 12:59 27,392 fdc.sys
2003-04-09 오전 07:00 34,944 fips.sys
2004-08-04 오전 12:59 20,480 flpydisk.sys
2004-08-04 오전 01:01 124,800 fltmgr.sys
2003-04-09 오전 07:00 12,160 fsvga.sys
2003-04-09 오전 07:00 7,936 fs_rec.sys
2003-04-09 오전 07:00 125,056 ftdisk.sys
2004-08-04 오전 01:07 46,464 gagp30kx.sys
2003-04-09 오전 07:00 3,440,660 gm.dls
2003-04-09 오전 07:00 646 gmreadme.txt
2002-11-17 오후 06:20 30,976 gv3.sys
2004-08-04 오전 02:39 25,344 hidbth.sys
2004-08-04 오전 01:08 36,224 hidclass.sys
2004-08-04 오전 01:08 15,104 hidir.sys
2004-08-04 오전 01:08 24,960 hidparse.sys
2004-08-04 오전 12:41 220,032 hsfbs2s2.sys
2004-08-04 오전 12:41 685,056 hsfcxts2.sys
2004-08-04 오전 12:41 1,041,536 hsfdpsp2.sys
2004-08-04 오전 01:00 263,040 http.sys
2004-08-04 오전 02:40 49,152 i8042prt.sys
2004-03-29 오후 05:28 14,531 Ifp1000.sys
2004-03-29 오후 05:28 14,531 ifp300.sys
2004-03-29 오후 05:28 14,531 Ifp500.sys
2004-03-29 오후 05:28 14,531 Ifp700.sys
2004-03-29 오후 05:28 14,531 Ifp800.sys
2004-03-29 오후 05:28 14,531 Ifp900.sys
2004-03-29 오후 05:28 14,531 ifpusb.sys
2003-03-29 오후 03:45 89,184 imagedrv.sys
2004-08-04 오전 01:00 41,856 imapi.sys
2004-08-04 오전 02:42 5,504 intelide.sys
2004-08-04 오전 02:42 39,168 intelppm.sys
2004-08-04 오전 01:00 29,056 ip6fw.sys
2003-04-09 오전 07:00 32,896 ipfltdrv.sys
2004-08-04 오전 01:04 20,992 ipinip.sys
2004-09-29 오후 05:28 134,912 ipnat.sys
2004-08-04 오전 01:14 74,752 ipsec.sys
2003-07-14 오후 02:30 95,884 ipvnmon.sys
2004-08-04 오전 01:08 40,832 irbus.sys
2004-08-04 오전 01:00 11,264 irenum.sys
2001-08-27 오전 01:04 35,840 isapnp.sys
2001-08-17 오전 12:55 6,144 kbd101a.dll
2004-08-04 오전 02:44 23,808 kbdclass.sys
2001-08-17 오전 08:36 8,192 kbdkor.dll
2004-08-04 오전 01:07 171,776 kmixer.sys
2004-08-04 오전 01:15 140,928 ks.sys
2004-08-04 오전 12:59 92,032 ksecdd.sys
2001-12-10 오후 11:21 20,551 LIKECDN2.sys
2003-07-09 오후 03:22 20,780 MagerKey.sys
2003-04-09 오전 07:00 7,680 mcd.sys
2004-04-13 오후 07:20 15,781 mdc8021x.sys
2004-08-04 오전 12:41 11,868 mdmxsdk.sys
2004-08-04 오전 01:07 63,744 mf.sys
2003-04-09 오전 07:00 4,224 mnmdd.sys
2004-08-04 오전 02:36 29,824 modem.sys
2004-08-04 오전 02:37 22,272 mouclass.sys
2004-08-04 오전 12:58 42,240 mountmgr.sys
2004-08-04 오전 01:10 15,360 mpe.sys
2004-08-04 오전 12:58 72,960 mqac.sys
2004-08-04 오전 01:00 181,248 mrxdav.sys
2005-01-18 오후 11:26 451,584 mrxsmb.sys
2004-08-04 오전 01:09 51,328 msdv.sys
2004-08-04 오전 01:00 19,072 msfs.sys
2004-08-04 오전 01:04 35,072 msgpc.sys
2004-08-04 오전 12:58 7,552 mskssrv.sys
2004-08-04 오전 12:58 5,376 mspclock.sys
2004-08-04 오전 12:58 4,992 mspqm.sys
2003-07-14 오후 02:30 158,496 msscript.ocx
2004-08-04 오전 01:07 15,488 mssmbios.sys
2004-08-04 오전 12:58 5,504 mstee.sys
2004-08-04 오전 12:41 126,686 mtlmnt5.sys
2004-08-04 오전 12:41 1,309,184 mtlstrm.sys
2004-08-04 오전 12:29 452,736 mtxparhm.sys
2004-08-04 오전 01:15 107,904 mup.sys
2004-08-04 오전 01:04 12,672 mutohpen.sys
2004-03-29 오후 05:28 14,531 N10.SYS
2004-08-04 오전 01:10 85,376 nabtsfec.sys
2001-12-08 오전 01:00 183,872 NAVAP.SYS
2004-08-04 오전 01:14 182,912 ndis.sys
2004-08-04 오전 01:10 10,880 ndisip.sys
2003-04-09 오전 07:00 9,600 ndistapi.sys
2004-08-04 오전 01:03 12,928 ndisuio.sys
2004-08-04 오전 01:14 91,776 ndiswan.sys
2003-04-09 오전 07:00 38,016 ndproxy.sys
2004-08-04 오전 01:03 34,560 netbios.sys
2004-08-04 오전 01:14 162,816 netbt.sys
2004-06-27 오전 02:55 22,912 NetkFlt.sys
2002-04-15 오후 08:11 67,866 netwlan5.img
2004-08-04 오전 12:58 61,824 nic1394.sys
2003-04-09 오전 07:00 12,032 nikedrv.sys
2004-08-04 오전 12:59 40,320 nmnt.sys
2004-08-04 오전 01:00 30,848 npfs.sys
2004-08-04 오전 01:15 574,592 ntfs.sys
2004-08-04 오전 12:41 180,360 ntmtlfax.sys
2003-04-09 오전 07:00 2,944 null.sys
2004-08-04 오전 12:29 1,897,408 nv4_mini.sys
2003-04-09 오전 07:00 12,416 nwlnkflt.sys
2003-04-09 오전 07:00 32,512 nwlnkfwd.sys
2004-08-04 오전 01:03 88,448 nwlnkipx.sys
2003-04-09 오전 07:00 63,232 nwlnknb.sys
2003-04-09 오전 07:00 55,936 nwlnkspx.sys
2004-08-04 오전 01:02 163,584 nwrdr.sys
2004-08-04 오전 01:10 61,056 ohci1394.sys
2003-04-09 오전 07:00 3,456 oprghdlr.sys
2004-08-04 오전 02:36 45,568 p3.sys
2004-08-04 오전 02:36 79,488 parport.sys
2003-04-09 오전 07:00 18,688 partmgr.sys
2003-04-09 오전 07:00 6,784 parvdm.sys
2004-08-04 오전 02:36 66,688 pci.sys
2001-08-27 오전 01:19 3,328 pciide.sys
2004-08-04 오전 12:59 25,088 pciidex.sys
2004-08-04 오전 02:36 119,168 pcmcia.sys
2004-08-04 오전 01:15 145,792 portcls.sys
2004-08-04 오전 02:38 38,400 processr.sys
2004-08-04 오전 01:04 69,120 psched.sys
2003-04-09 오전 07:00 17,792 ptilink.sys
2003-10-28 오전 05:02 20,016 pxhelp20.sys
2002-06-12 오후 09:37 45,568 R8139n51.sys
2003-04-09 오전 07:00 8,832 rasacd.sys
2004-08-04 오전 01:14 51,328 rasl2tp.sys
2004-08-04 오전 01:05 41,472 raspppoe.sys
2004-08-04 오전 01:14 48,384 raspptp.sys
2003-04-09 오전 07:00 16,512 raspti.sys
2003-04-09 오전 07:00 34,432 rawwan.sys
2004-10-27 오후 08:13 174,592 rdbss.sys
2003-04-09 오전 07:00 4,224 rdpcdd.sys
2004-08-04 오전 01:01 196,864 rdpdr.sys
2004-08-04 오전 02:54 139,400 rdpwd.sys
2004-08-04 오전 12:41 13,776 recagent.sys
2004-08-04 오전 02:39 55,552 redbook.sys
2004-08-04 오전 01:10 59,648 rfcomm.sys
2003-04-09 오전 07:00 12,032 rio8drv.sys
2003-04-09 오전 07:00 12,032 riodrv.sys
2003-04-09 오전 07:00 200,064 RMCast.sys
2002-12-24 오전 05:52 59,520 Rmedia.sys
2004-08-04 오전 01:04 30,080 rndismp.sys
2004-08-04 오전 01:04 30,080 rndismpx.sys
2003-04-09 오전 07:00 5,888 rootmdm.sys
2004-08-04 오전 12:31 20,992 rtl8139.sys
2004-08-04 오전 12:29 166,912 s3gnbm.sys
2004-08-04 오전 12:59 96,256 scsiport.sys
2005-02-14 오전 11:38 7,168 scsk4.sys
2005-02-14 오전 11:38 19,760 scskusbf.sys
2005-02-14 오전 11:38 84,556 scskusbs.sys
2004-08-04 오전 01:07 67,584 sdbus.sys
2004-10-15 오후 10:29 12,400 secdrv.sys
2003-07-09 오후 03:22 21,990 SecurKey.sys
2004-08-04 오전 12:59 15,488 serenum.sys
2004-08-04 오전 02:41 61,568 serial.sys
2004-08-04 오전 12:59 11,136 sffdisk.sys
2004-08-04 오전 12:59 10,240 sffp_sd.sys
2004-08-04 오전 12:59 11,392 sfloppy.sys
2004-08-04 오전 02:53 3,901 siint5.dll
2004-08-04 오전 01:07 41,088 sisagp.sys
2004-08-04 오전 01:10 11,136 slip.sys
2004-08-04 오전 12:41 129,535 slnt7554.sys
2004-08-04 오전 12:41 404,990 slntamr.sys
2004-08-04 오전 12:41 95,424 slnthal.sys
2004-08-04 오전 12:41 13,240 slwdmsup.sys
2004-08-04 오전 01:07 6,016 smbali.sys
2003-04-09 오전 07:00 14,592 smclib.sys
2004-08-04 오전 01:09 25,472 sonydcam.sys
2004-08-04 오전 01:07 6,400 splitter.sys
2004-08-04 오전 02:39 73,344 sr.sys
2004-08-04 오전 01:14 336,256 srv.sys
2003-05-16 오전 08:16 220,048 STAC97.sys
2004-08-04 오전 01:08 48,640 stream.sys
2004-08-04 오전 01:10 15,360 streamip.sys
2004-08-04 오전 12:58 4,352 swenum.sys
2001-08-17 오전 12:00 54,272 swmidi.sys
2005-01-21 오후 10:31 11,544 symdns.sys
2002-03-06 오후 07:25 58,224 SYMEVENT.SYS
2005-01-21 오후 10:31 172,216 symfw.sys
2005-01-21 오후 10:31 35,000 symids.sys
2004-06-29 오전 02:13 170,208 SymIDSCo.sys
2005-01-21 오후 10:31 46,808 symndis.sys
2005-01-21 오후 09:31 20 SymRedir.cat
2005-01-21 오후 09:31 1,133 SymRedir.inf
2005-01-21 오후 10:31 26,424 symredrv.sys
2005-01-21 오후 10:31 267,384 symtdi.sys
2003-06-16 오후 08:40 264,528 SynTP.sys
2004-08-04 오전 01:15 60,800 sysaudio.sys
2004-08-04 오전 12:59 14,976 tape.sys
2004-08-04 오전 01:14 359,040 tcpip.sys
2004-08-04 오전 01:07 223,616 tcpip6.sys
2004-08-04 오전 01:07 18,560 tdi.sys
2004-08-04 오전 02:54 12,040 tdpipe.sys
2004-08-04 오전 02:54 21,896 tdtcp.sys
2004-08-04 오전 02:54 40,840 termdd.sys
2003-04-09 오전 07:00 51,712 tosdvd.sys
2003-04-09 오전 07:00 21,376 tsbvcap.sys
2004-08-04 오전 01:03 12,416 tunmp.sys
2004-08-04 오전 01:07 44,672 uagp35.sys
2004-08-04 오전 01:00 66,176 udfs.sys
2004-08-04 오전 12:58 209,408 update.sys
2004-08-04 오전 01:04 12,672 usb8023.sys
2004-08-04 오전 01:04 12,672 usb8023x.sys
2003-04-09 오전 07:00 23,808 usbcamd.sys
2003-04-09 오전 07:00 23,936 usbcamd2.sys
2003-04-09 오전 07:00 4,736 usbd.sys
2004-08-04 오전 01:08 26,624 usbehci.sys
2004-08-04 오전 01:08 57,600 usbhub.sys
2004-08-04 오전 01:08 16,000 usbintel.sys
2004-08-04 오전 01:08 142,976 usbport.sys
2004-08-04 오전 01:01 25,856 usbprint.sys
2004-08-04 오전 01:08 26,496 usbstor.sys
2004-08-04 오전 01:08 20,480 usbuhci.sys
2004-08-04 오전 01:10 78,464 usbvideo.sys
2004-09-09 오전 09:19 <DIR> user
2005-01-03 오후 12:40 1,006,189 v3engine.sys
2004-08-04 오전 02:53 11,325 vchnt5.dll
2003-04-09 오전 07:00 58,112 vdmindvd.sys
2004-08-04 오전 01:07 20,992 vga.sys
2004-08-04 오전 01:07 42,240 viaagp.sys
2004-08-04 오전 01:07 79,744 videoprt.sys
2004-08-04 오전 02:43 50,048 volsnap.sys
2004-11-15 오후 03:41 30,336 VSHOOK.sys
2003-03-15 오후 11:55 2,390,528 w70n51.sys
2004-08-04 오전 01:04 13,568 wacompen.sys
2004-08-04 오전 12:29 11,807 wadv07nt.sys
2004-08-04 오전 12:29 11,295 wadv08nt.sys
2004-08-04 오전 12:29 11,871 wadv09nt.sys
2004-08-04 오전 12:29 11,935 wadv11nt.sys
2004-08-04 오전 01:04 34,560 wanarp.sys
2004-08-04 오전 12:29 22,271 watv06nt.sys
2004-08-04 오전 12:29 25,471 watv10nt.sys
2004-08-04 오전 01:15 82,944 wdmaud.sys
2003-04-09 오전 07:00 4,352 wmilib.sys
2003-04-09 오전 07:00 12,032 ws2ifsl.sys
2004-08-04 오전 01:10 19,328 wstcodec.sys
2004-09-29 오후 01:47 6,646 xprtect.sys
2001-12-10 오후 08:46 3,524 XSpaceWG.sys
331개 파일 33,028,800 바이트
C:\WINDOWS\system32\drivers\disdn 디렉터리
2004-06-17 오전 09:15 <DIR> .
2004-06-17 오전 09:15 <DIR> ..
0개 파일 0 바이트
C:\WINDOWS\system32\drivers\etc 디렉터리
2005-02-17 오후 11:56 <DIR> .
2005-02-17 오후 11:56 <DIR> ..
2005-02-17 오후 11:56 734 hosts
2005-02-17 오전 12:33 734 hosts.bho
2005-02-19 오후 02:17 442 hosts.ics
2003-04-09 오전 07:00 3,683 lmhosts.sam
2003-04-09 오전 07:00 407 networks
2003-04-09 오전 07:00 799 protocol
2003-04-09 오전 07:00 7,116 services
7개 파일 13,915 바이트
C:\WINDOWS\system32\drivers\user 디렉터리
2004-09-09 오전 09:19 <DIR> .
2004-09-09 오전 09:19 <DIR> ..
2004-09-09 오전 09:19 313,856 bms.dll
2004-08-26 오후 02:12 6,436 dic.db
2004-08-14 오후 10:34 304,128 keybox.exe
2004-08-18 오전 10:56 1,796 keydic3.db
2004-08-14 오후 10:34 13,312 keymon.dll
2004-09-09 오전 09:19 129,536 keyservice.exe
2004-09-09 오전 09:19 256 keyword.idx
2004-09-09 오전 09:19 140,800 mygaurd.exe
2004-09-08 오후 09:39 686 search.db
9개 파일 910,806 바이트
전체 파일:
347개 파일 33,953,521 바이트
11개 디렉터리 2,699,251,712 바이트 남음
Open C:\Windows\System32\drivers and delete the folder named user.
Empty the recycle bin.
Download this zip file and extract to it's own folder. Open the folder, close all IE windows and double click the RemoveDomains.reg Allow it to merge to the registry, then run the ResetDomains.reg allowing it to merge. **This will remove ALL sites from the trusted zone.
Hmmmm I've attached another to this post. Right click after downloading and select extract. Click OK on the following prompts and you will end up with a folder the same name, with the files inside.
Here's the new hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 오후 4:59:20, on 2005-02-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Only problem I see now is the lingering 023 service.
Download "Registry Search Tool" (RegSrch.vbs) from here http://www.billsway.com/vbspage/
start it and paste in bfjhwoliaxrj, wait, hit ok. Then when wordpad opens, copy that back here please. (If you're comfortable with regedit, you could just delete the corresponding entries/keys found.)
Go ahead and re-enable system restore and create a manual restore point.
Also recommend you open Spybot and click mode on the toolbar, then advanced mode. Click immunize in the left pane, then immunize again, this time from above with the green + beside it. Click the link below that for SpywareBlaster, download, install, enable all protection and update. Check for updates regularly. Then, still in Spybot, click tools button, then IE tweaks and at least lock the HOSTS file.
Then download and install IESpyad.
That will give you some added layers of protection against unwanted parasites.
When I hit enter on the search program, I just kept getting runtime errors.
So I wasn't able to erase the registry...
Is this a big problem and can it be solved?
It may be that your Norton Script Blocking service may be preventing the script from running. Disconnect from the internet and click start>run, then type services.msc and hit enter. Locate ScriptBlocking Service and right click>stop. Then try running the script. Restart the service when done.