How about you read some of the recent threads.Originally Posted by stix
How about you read some of the recent threads.Originally Posted by stix
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:13:11 PM, on 6/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Process Lasso\processgovernor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Process Lasso\ProcessLasso.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Administrator\My Documents\ffassist2_b17-8\FFAssist2.exe
C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Combined Community Codec Pack\Zoom Player\zplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ProcessGovernor] C:\Program Files\Process Lasso\processgovernor.exe
O4 - HKLM\..\Run: [Clean System Memory 120 Sec. After Startup] C:\Windows\system32\CleanMem.exe 120
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [WallpaperChanger] C:\Program Files\Wallpaper Master\Wallpaper.exe
O4 - HKCU\..\Run: [ProcessSupervisorGUI] C:\Program Files\Process Lasso\ProcessLasso.exe /tray
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.v bs" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 6318443656
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
--
End of file - 6448 bytes
This is my log. D:
Well I could search through about a half a dozen random and disorganized stickies/threads I see on the first page or someone who might care about the spread of such attacks in the community could maybe give me (and anyone else reading) a one sentence answer. 's all good though.Originally Posted by cdgreguh
POL Window is resizable. That should mess up the readings yea?Originally Posted by senoska
I was recently hacked and just got my account back yesterday.
Using Mafai's suggested CurrProcess, I have located wzcsvbxm.dll within my POL module.
I'm not very computer savvy, so any advice as to how I could delete this?
Format Q_QOriginally Posted by Jontale
...why do people even ask?
I said it in LS chat a couple days ago.. I'm gonna repartition my HD, install a dual-boot of Ubuntu and ONLY use a web browser from that environment. Screw this shit.
Originally Posted by senoska
Are you running in full-screen mode? I think I had this problem running the game on my mac whenever the game launched from the pol viewer. Changed it to windowed mode and it ran just fine.
Not sure if this it even helps, but I always type in my password in random order. I'll enter one letter of the password and click in the input box where the next letter I want to add will go.Originally Posted by The Blackrose
For instance, if my password is "s3TuPb0mB", I might type in "sTP0B," then click between the letters to add in "3ubm."
i think i might be at risk, would un installing pol and reinstalling help?
If your PC has been infected just wipe your HDD clean, format everything and reinstall from scratch. Uninstalling and reinstalling POL won't get rid of a virus elsewhere in your PC.Originally Posted by bungie
you have other options. you can run a separate OS of your choice in a VM session and do your web browsing from there. that way you dont have to dualboot and can still do your web browsing while FFXI is open with no worries.Originally Posted by Olo401
http://www.vmware.com/
http://www.virtualbox.org/
http://bochs.sourceforge.net/
http://www.thefreecountry.com/emulators/pc.shtml
also last wedn. my account was hacked aswell. Got my password reset and log in to find everything that could be sold was gone. Account currently in rollback. But ive run hjt report, virus scan, trend micro house call, currprocess for pol and never found the smart.dll or the wzcsvbxm.dll file. I'll post the currprocess in another post for someone who knows alot more then me to take a look at. My question tho now is should I just reformat my pc or since I cant find these virus's am I still safe to play on pc? I NOW have firefox with no script adblock and updated flash. I used to use IE had trend micro and firewall on and honestly thought that would be good. I was wrong and paid dearly.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:55:19 AM, on 7/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
C:\Documents and Settings\Rick\Desktop\cprocess\CProcess.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ShowLOMControl]
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Rick\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Rick\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1203981728546
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 8008 bytes
and here is the currprocess I ran on pol
Created by using CurrProcess
Process Name pol.exe
ProcessID 2892
Priority Normal
Product Name PlayOnline Viewer
Version 1.18.07
Description PlayOnline Viewer
Company SQUARE ENIX CO., LTD.
Window Title PlayOnline Viewer Ver.1.18.10c
File Size 1,691,648
File Created Date 2/27/2005 1:47:24 AM
File Modified Date 3/14/2008 1:09:57 AM
Filename C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe
Base Address 0x00400000
Created On 7/27/2008 12:10:31 PM
Visible Windows 1
Hidden Windows 4
User Name DELL\Rick
Mem Usage 35480 K
Mem Usage Peak 38132 K
Page Faults 15631
Pagefile Usage 70124 K
Pagefile Peak Usage 73116 K
File Attributes A
Module Name Base Address Module Size Version Description Company Product Name Modified Date File Size Filename File Attributes
pol.exe 0x00400000 0x001A0000 1.18.07 PlayOnline Viewer SQUARE ENIX CO., LTD. PlayOnline Viewer 3/13/2008 9:09:57 PM 1,691,648 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\pol.e xe A
ntdll.dll 0x7C900000 0x000B0000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) NT Layer DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 708,096 C:\WINDOWS\system32\ntdll.dll A
kernel32.dll 0x7C800000 0x000F5000 5.1.2600.3119 (xpsp_sp2_gdr.070416-1301) Windows NT BASE API Client DLL Microsoft Corporation Microsoft® Windows® Operating System 4/16/2007 11:52:53 AM 984,576 C:\WINDOWS\system32\kernel32.dll A
PolHook.dll 0x10000000 0x00010000 1.18.07 PlayOnline Viewer polhook Module SQUARE ENIX CO., LTD. PlayOnline Viewer 3/13/2008 9:10:04 PM 61,440 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\PolHo ok.dll A
USER32.dll 0x7E410000 0x00090000 5.1.2600.3099 (xpsp_sp2_gdr.070308-0222) Windows XP USER API Client DLL Microsoft Corporation Microsoft® Windows® Operating System 3/8/2007 11:36:28 AM 577,536 C:\WINDOWS\system32\USER32.dll A
GDI32.dll 0x77F10000 0x00047000 5.1.2600.3316 (xpsp_sp2_gdr.080219-1316) GDI Client DLL Microsoft Corporation Microsoft® Windows® Operating System 2/20/2008 2:51:05 AM 282,624 C:\WINDOWS\system32\GDI32.dll A
IMM32.DLL 0x76390000 0x0001D000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows XP IMM32 API Client DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 110,080 C:\WINDOWS\system32\IMM32.DLL A
ADVAPI32.dll 0x77DD0000 0x0009B000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Advanced Windows 32 Base API Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 616,960 C:\WINDOWS\system32\ADVAPI32.dll A
RPCRT4.dll 0x77E70000 0x00091000 5.1.2600.3173 (xpsp_sp2_qfe.070709-0052) Remote Procedure Call Runtime Microsoft Corporation Microsoft® Windows® Operating System 7/9/2007 9:16:16 AM 582,656 C:\WINDOWS\system32\RPCRT4.dll A
WINMM.dll 0x76B40000 0x0002D000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) MCI API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 176,128 C:\WINDOWS\system32\WINMM.dll A
DDRAW.dll 0x73760000 0x00049000 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft DirectDraw Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 266,240 C:\WINDOWS\system32\DDRAW.dll A
msvcrt.dll 0x77C10000 0x00058000 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT CRT DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 343,040 C:\WINDOWS\system32\msvcrt.dll A
DCIMAN32.dll 0x73BC0000 0x00006000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) DCI Manager Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 8,704 C:\WINDOWS\system32\DCIMAN32.dll A
ole32.dll 0x774E0000 0x0013D000 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) Microsoft OLE for Windows Microsoft Corporation Microsoft® Windows® Operating System 7/26/2005 12:39:48 AM 1,285,120 C:\WINDOWS\system32\ole32.dll A
OLEAUT32.dll 0x77120000 0x0008B000 5.1.2600.3266 Microsoft Corporation 12/4/2007 2:38:13 PM 550,912 C:\WINDOWS\system32\OLEAUT32.dll A
LPK.DLL 0x629C0000 0x00009000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Language Pack Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 22,016 C:\WINDOWS\system32\LPK.DLL A
USP10.dll 0x74D90000 0x0006B000 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158) Uniscribe Unicode script processor Microsoft Corporation Microsoft(R) Uniscribe Unicode script processor 8/10/2004 6:00:00 AM 406,528 C:\WINDOWS\system32\USP10.dll A
uxtheme.dll 0x5AD70000 0x00038000 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Microsoft UxTheme Library Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 218,624 C:\WINDOWS\system32\uxtheme.dll A
MSCTF.dll 0x74720000 0x0004B000 5.1.2600.3319 (xpsp_sp2_gdr.080222-1435) MSCTF Server DLL Microsoft Corporation Microsoft® Windows® Operating System 2/26/2008 7:59:50 AM 294,912 C:\WINDOWS\system32\MSCTF.dll A
CLBCATQ.DLL 0x76FD0000 0x0007F000 2001.12.4414.308 Microsoft Corporation COM Services 7/26/2005 12:39:43 AM 498,688 C:\WINDOWS\system32\CLBCATQ.DLL A
COMRes.dll 0x77050000 0x000C5000 2001.12.4414.258 Microsoft Corporation COM Services 8/10/2004 6:00:00 AM 792,064 C:\WINDOWS\system32\COMRes.dll A
VERSION.dll 0x77C00000 0x00008000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Version Checking and File Installation Libraries Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 18,944 C:\WINDOWS\system32\VERSION.dll A
xpsp2res.dll 0x20000000 0x002C5000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Service Pack 2 Messages Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 2,897,920 C:\WINDOWS\system32\xpsp2res.dll A
SHLWAPI.dll 0x77F60000 0x00076000 6.00.2900.3268 (xpsp_sp2_gdr.071206-1518) Shell Light-weight Utility Library Microsoft Corporation Microsoft® Windows® Operating System 12/6/2007 9:07:13 PM 474,112 C:\WINDOWS\system32\SHLWAPI.dll A
comctl32.dll 0x773D0000 0x00103000 6.0 (xpsp.060825-0040) User Experience Controls Library Microsoft Corporation Microsoft® Windows® Operating System 8/25/2006 11:45:55 AM 1,054,208 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll A
COMCTL32.dll 0x5D090000 0x0009A000 5.82 (xpsp.060825-0040) Common Controls Library Microsoft Corporation Microsoft® Windows® Operating System 8/25/2006 11:45:58 AM 617,472 C:\WINDOWS\system32\COMCTL32.dll A
dsound.dll 0x73F10000 0x0005C000 5.3.2600.2180 (xpsp_sp2_rtm.040803-2158) DirectSound Microsoft Corporation Microsoft(R) Windows(R) Operating System 8/10/2004 6:00:00 AM 367,616 C:\WINDOWS\system32\dsound.dll A
msctfime.ime 0x755C0000 0x0002E000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Text Frame Work Service IME Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 177,152 C:\WINDOWS\system32\msctfime.ime A
msi.dll 0x7D1E0000 0x002BE000 3.1.4000.4039 Windows Installer Microsoft Corporation Windows Installer - Unicode 4/18/2007 12:12:23 PM 2,854,400 C:\WINDOWS\system32\msi.dll A
polcore.dll 0x01270000 0x0044F000 1.18.07 PlayOnline Viewer POLCore Module SQUARE ENIX CO., LTD. PlayOnline Viewer 7/9/2008 11:06:01 PM 544,768 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\polcore.dll A
DINPUT8.dll 0x6CE10000 0x00038000 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft DirectInput Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 181,760 C:\WINDOWS\system32\DINPUT8.dll A
WS2_32.dll 0x71AB0000 0x00017000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 32-Bit DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 82,944 C:\WINDOWS\system32\WS2_32.dll A
WS2HELP.dll 0x71AA0000 0x00008000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 Helper for Windows NT Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 19,968 C:\WINDOWS\system32\WS2HELP.dll A
app.dll 0x019D0000 0x00B88000 1.18.07 PlayOnline Viewer App Module SQUARE ENIX CO., LTD. PlayOnline Viewer 7/9/2008 11:05:53 PM 4,299,264 C:\Program Files\PlayOnline\SquareEnix\PlayOnlineViewer\viewe r\com\app.dll A
iphlpapi.dll 0x76D60000 0x00019000 5.1.2600.2912 (xpsp_sp2_gdr.060519-0003) IP Helper API Microsoft Corporation Microsoft® Windows® Operating System 5/19/2006 8:59:41 AM 94,720 C:\WINDOWS\system32\iphlpapi.dll A
SHELL32.dll 0x7C9C0000 0x00817000 6.00.2900.3241 (xpsp_sp2_qfe.071025-1245) Windows Shell Common Dll Microsoft Corporation Microsoft® Windows® Operating System 10/25/2007 11:34:01 PM 8,460,288 C:\WINDOWS\system32\SHELL32.dll A
HID.DLL 0x688F0000 0x00009000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Hid User Library Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 20,992 C:\WINDOWS\system32\HID.DLL A
SETUPAPI.dll 0x77920000 0x000F3000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Setup API Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 983,552 C:\WINDOWS\system32\SETUPAPI.dll A
WINTRUST.dll 0x76C30000 0x0002E000 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Trust Verification APIs Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 176,640 C:\WINDOWS\system32\WINTRUST.dll A
CRYPT32.dll 0x77A80000 0x00094000 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Crypto API32 Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 597,504 C:\WINDOWS\system32\CRYPT32.dll A
MSASN1.dll 0x77B20000 0x00012000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ASN.1 Runtime APIs Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 57,344 C:\WINDOWS\system32\MSASN1.dll A
IMAGEHLP.dll 0x76C90000 0x00028000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Image Helper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 144,384 C:\WINDOWS\system32\IMAGEHLP.dll A
rsaenh.dll 0x0FFD0000 0x00028000 5.1.2600.2161 (xpsp.040706-1629) Microsoft Enhanced Cryptographic Provider Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 152,576 C:\WINDOWS\system32\rsaenh.dll A
userenv.dll 0x769C0000 0x000B3000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Userenv Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 723,456 C:\WINDOWS\system32\userenv.dll A
Secur32.dll 0x77FE0000 0x00011000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Security Support Provider Interface Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 55,808 C:\WINDOWS\system32\Secur32.dll A
NETAPI32.dll 0x5B860000 0x00054000 5.1.2600.2976 (xpsp_sp2_gdr.060817-0106) Net Win32 API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/17/2006 8:28:27 AM 332,288 C:\WINDOWS\system32\NETAPI32.dll A
cryptnet.dll 0x75E60000 0x00013000 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Crypto Network Related API Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 63,488 C:\WINDOWS\system32\cryptnet.dll A
WLDAP32.dll 0x76F60000 0x0002C000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Win32 LDAP API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 172,032 C:\WINDOWS\system32\WLDAP32.dll A
WINHTTP.dll 0x4D4F0000 0x00058000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows HTTP Services Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 351,232 C:\WINDOWS\system32\WINHTTP.dll A
SensApi.dll 0x722B0000 0x00005000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) SENS Connectivity API DLL Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 6,656 C:\WINDOWS\system32\SensApi.dll A
D3DIM700.DLL 0x73940000 0x000D0000 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Direct3D Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 825,344 C:\WINDOWS\system32\D3DIM700.DLL A
wdmaud.drv 0x72D20000 0x00009000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) WDM Audio driver mapper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 23,552 C:\WINDOWS\system32\wdmaud.drv A
msacm32.drv 0x72D10000 0x00008000 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 20,480 C:\WINDOWS\system32\msacm32.drv A
MSACM32.dll 0x77BE0000 0x00015000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft ACM Audio Filter Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 71,680 C:\WINDOWS\system32\MSACM32.dll A
midimap.dll 0x77BD0000 0x00007000 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft MIDI Mapper Microsoft Corporation Microsoft® Windows® Operating System 8/10/2004 6:00:00 AM 18,944 C:\WINDOWS\system32\midimap.dll A
KsUser.dll 0x73EE0000 0x00004000 5.3.2600.2180 (xpsp_sp2_rtm.040803-2158) User CSA Library Microsoft Corporation Microsoft(R) Windows(R) Operating System 8/4/2004 1:56:44 AM 4,096 C:\WINDOWS\system32\KsUser.dll A
There's a very good reason why we all say not to use IE.
Yes, reformat your PC before playing. Get firefox & noscript and keep flash etc up to date.
since I have some people who asked me about this today (I guess it wasn't clear yet that wzcvbxm.dll is a trojan heh) here's a link to information about it courtesy of trend micro
it is a trojan, appears to be an auto-run hook, may self-contain the keylogger; may just provide a service so the keylogger can run. (unfortunately, trend micro is mostly concerned about system melting malware, so something that just scoops MMO passes doesn't cause much alarm over there.)
IF YOU HAVE WZCVBXM.DLL, remove it first (trend micro has some suggestions on how) and then change your passwords promptly. it is a trojan.