1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive are these files bad?

Discussion in 'Malware and Virus Removal Archive' started by dispatch trophy, 2012/01/15.

  1. 2012/01/15
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    [Inactive] are these files bad?

    Malwarebytes detected the following files it calls spyware / online games.

    I am thinking these files might be connected to a Canon scanner, so perhaps they are not really harmful, but I would like an opinion here.

    some files Malwarebytes flags, like AutoCrop.dll are really necessary to some applications, so should be kept.

    Below are the files flagged and deleted. I would appreciate it if anyone knows about them they could give me an opinion.

    Memory Modules Detected: 27
    C:\Program Files\AutoCrop.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\codecvt.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\dcexport.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\dcfr.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\imgtool.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\memio.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMCSY.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMDAN.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMDUT.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMENG.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMFIN.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMFRA.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMGER.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMGRE.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMITA.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMNON.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMNOR.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMPLK.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMPTG.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMSPN.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMSWE.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMTRK.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\OCRUtil.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\pccrsdk.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\post.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\Recogn.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\Segment.dll (Spyware.OnlineGames) -> Delete on reboot.


    Files Detected: 50
    C:\Program Files\AutoCrop.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\ccmllnk.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\codecvt.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\dcexport.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\dcfr.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\ExeBud32.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\fid.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\Fioall.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\FioExt32.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\imgtool.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\lcppn22.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\memio.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\nextpwd.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\NGRMCSY.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMDAN.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMDUT.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMENG.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMFIN.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMFRA.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMGER.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMGRE.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMITA.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMNON.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMNOR.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMPLK.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMPTG.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMRUS.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\NGRMSPN.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMSWE.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NGRMTRK.DLL (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\NsFip.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\NTSTHK16.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\NTSTHK32.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\OCRUtil.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\OLDPNG32.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\pack.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\pccrsdk.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\pmdata.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\PMExeBud.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\PMXpsView.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\post.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\PrnDrvSetup.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\Recogn.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\Segment.dll (Spyware.OnlineGames) -> Delete on reboot.
    C:\Program Files\UFSE.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\umxnts32.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\UNPACK.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\UXFSE.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\VideoData.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
    C:\Program Files\XpsCreator.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
     
  2. 2012/01/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116

  3. to hide this advert.

  4. 2012/01/15
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    when I boot up a message comes on telling me "the application could not start because it could not find AutoCrop.dll

    I think Malwarebytes deleted it.

    I think but, I am not sure, that the file belongs to a canon scanner program.
     
  5. 2012/01/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I suggest you reinstall scanner software.
     
  6. 2012/01/16
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    I have already been using Avast and Malwarebytes regularly.

    These files seem to be connected to the programs and applications that come with a Canon flatbed scanner.
     
  7. 2012/01/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I suggest you reinstall Canon flatbed scanner software.
     
  8. 2012/01/20
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    Yes, I reinstalled the Canon software.

    Now I get this message when I boot up:

    "Pmsb.exe - Unable to locate component

    This application has failed to start because codecvt.dll was not found. Re-installing the application may fix this problem. "

    A search on Pmsb.exe shows it is one of the applications of the Canon scanner.

    The problem is that Malwarebytes is calling some of these dll files malware.

    This is an important application for the scanner. But this file is now in Malwarbytes quarantine, labelled "Spyware.Online Games."

    Should I restore these files? Is Malwarebytes making a mistake?
     
  9. 2012/01/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  10. 2012/01/22
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    These files are in "quarantine" in Malwarebytes.

    That means I can restore them from there.

    So are you advising to restore them from malwarebytes then run a separate scan with "virustotal.com "?
     
  11. 2012/01/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes...
     
  12. 2012/01/24
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    I restored all the files from Malwarebytes quarantine,

    then ran a VirusTotal check on two of them.

    The results in both cases was that they were 0 on a scale of -100 to 100.
     
  13. 2012/01/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very well then.

    Good luck :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.