TWAIN-TEC Spyware Terrorists
#######################################################
twain tec crap:
http://www.pcsympathy.com/ftopic211.html
Twain-Tech LLC
Jessie Dayan
1347 3rd avenue, #22a
new york, ny 10021
US
Phone: 646-213-4415
Email: jessie@twain-tech.com
Registrar Name....: Register.com
Registrar Whois...: whois.register.com
Registrar Homepage: hxxp://www.register.com
Domain Name: TWAIN-TECH.COM
Created on..............: Fri, Sep 05, 2003
Expires on..............: Sun, Sep 05, 2004
Record last updated on..: Mon, Dec 01, 2003
Administrative Contact:
Twain-Tech LLC
Jessie Dayan
1347 3rd avenue, #22a
new york, ny 10021
US
Phone: 646-213-4415
Email: jessie@twain-tech.com
Technical Contact:
Twain-Tech LLC
Jessie Dayan
1347 3rd avenue, #22a
new york, ny 10021
US
Phone: 646-213-4415
Email: jessie@twain-tech.com
Zone Contact:
Twain-Tech LLC
Jessie Dayan
1347 3rd avenue, #22a
new york, ny 10021
US
Phone: 646-213-4415
Email: jessie@twain-tech.com
Domain servers in listed order:
NS5.READYHOSTING.COM 63.99.209.103
NS6.READYHOSTING.COM 63.99.209.104
ABETTERINTERNET.COM
Server Type: Microsoft-IIS/5.0
Website Status: Active
Reverse IP: Web server hosts 626 websites
IP Address: 63.99.224.43
IP Location: United States - Texas - Houston - Ready Hosting
Record Type: Domain Name
Name Server: NS1.HOSTPOOL.NET NS2.HOSTPOOL.NET
ICANN Registrar: REGISTER.COM, INC.
Created: 27-may-2003
Expires: 27-may-2005
Status: ACTIVE
Organization:
BetterInternet
Reg Services
PO Box 50729
Henderson, NV 89016
US
Phone: 888-813-1230
Email:
Registrar Name....: Register.com
Registrar Whois...: whois.register.com
Registrar Homepage: http://www.register.com
Domain Name: ABETTERINTERNET.COM
Created on..............: Tue, May 27, 2003
Expires on..............: Fri, May 27, 2005
Record last updated on..: Thu, Mar 04, 2004
Administrative Contact:
BetterInternet
Reg Services
PO Box 50729
Henderson, NV 89016
US
Phone: 888-813-1230
Technical Contact:
BetterInternet
Reg Services
PO Box 50729
Henderson, NV 89016
US
Phone: 888-813-1230
Zone Contact:
BetterInternet
Reg Services
PO Box 50729
Henderson, NV 89016
US
Phone: 888-813-1230
Domain servers in listed order:
NS1.HOSTPOOL.NET 64.191.159.6
NS2.HOSTPOOL.NET 64.191.159.7
Terrorists Hosts:
64.191.159.6
[Server: whois.arin.net]
OrgName: QX.Net
Address: 333 West Vine Street Suite 210
City: Lexington
StateProv: KY
PostalCode: 40507
Country: US
Comment:
RegDate: 1999-08-16
Updated: 2003-06-22
AdminHandle: JB13105-ARIN
AdminName: Barker, Jonathan
AdminPhone: +1-606-312-5241
AdminEmail: jonathan@qx.net
NOCHandle: KPS-ARIN
NOCName: STOLTZ, Kenny P
NOCPhone: +1-859-255-1928
NOCEmail: kstoltz@qx.net
TechHandle: BKN-ARIN
TechName: Nichols, Brian K
TechPhone: +1-859-255-1928
TechEmail: bnichols@qx.net
# ARIN WHOIS database, last updated 2004-04-11 19:15
# Enter ? for additional hints on searching ARIN's WHOIS database.
OrgID: QXNET
Address: 333 West Vine Street Suite 210
City: Lexington
StateProv: KY
PostalCode: 40507
Country: US
NetRange: 64.191.128.0 - 64.191.159.255
CIDR: 64.191.128.0/19
NetName: QX-NET
NetHandle: NET-64-191-128-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: NS.QX.NET
NameServer: NS2.QX.NET
Comment:
RegDate: 2003-06-27
Updated: 2003-06-27
OrgNOCHandle: KPS-ARIN
OrgNOCName: STOLTZ, Kenny P
OrgNOCPhone: +1-859-255-1928
OrgNOCEmail: kstoltz@qx.net
OrgTechHandle: BKN-ARIN
OrgTechName: Nichols, Brian K
OrgTechPhone: +1-859-255-1928
OrgTechEmail: bnichols@qx.net
QUOTE
Twain-Tech is a software development company. We have developed a series of ad
targeting applications such as Twain-Tech.dll that help advertisers deliver targeted
ads. In addition to our software development, we also provide certain support services
to the distributors of our software.
Third party companies license and distribute our software, typically as part of their
sponsorship of free software or free content. As part of any licensing of our software,
Twain-Tech contractually requires all distributors to give notice concerning the
presence of our software and to provide consumers access to a Twain-Tech supplied
targeting applications such as Twain-Tech.dll that help advertisers deliver targeted
ads. In addition to our software development, we also provide certain support services
to the distributors of our software.
Third party companies license and distribute our software, typically as part of their
sponsorship of free software or free content. As part of any licensing of our software,
Twain-Tech contractually requires all distributors to give notice concerning the
presence of our software and to provide consumers access to a Twain-Tech supplied
redirection crap:
http://ctl.twain-tech.com/twain/servlet/Tw...wain?adcontext=
Removal Instructions
QUOTE
If the twaintech.dll is detected in a hijackthis log DO NOT FIX IT! Do the following:
This is the manual way to remove the twaintech.dll transponder variant manually when detected in a hijackthis log
Using their removal instructions:
http://www.twain-tech.com/uninstall.htm
After getting the twaintech.dll installed, hijackthis will detect it as a BHO but must not be removed using hijackthis because of the registery entries and files left over. Instead use the following method:
1. Add/Remove Programs
2. Uninstall Twain-Tech
3. Reboot the computer
4. in windows explorer
5. winnt or windows
6. Delete twaintech.dll and twaintec.ini
If twaintech.dll is in use, then you would need to rename it and reboot the computer, then delete it.
This will remove all 9 registry entries (3 which is detected by AAW scan)
This is the manual way to remove the twaintech.dll transponder variant manually when detected in a hijackthis log
Using their removal instructions:
http://www.twain-tech.com/uninstall.htm
After getting the twaintech.dll installed, hijackthis will detect it as a BHO but must not be removed using hijackthis because of the registery entries and files left over. Instead use the following method:
1. Add/Remove Programs
2. Uninstall Twain-Tech
3. Reboot the computer
4. in windows explorer
5. winnt or windows
6. Delete twaintech.dll and twaintec.ini
If twaintech.dll is in use, then you would need to rename it and reboot the computer, then delete it.
This will remove all 9 registry entries (3 which is detected by AAW scan)
QUOTE
Using Add/Remove for the Twaintech.dll
If not removed immediately when the twaintech.dll transmits its check to the ad sever, it can create multiple folders that will drop the twain twaintec.cab into.
Files before Add/Remove:
Temp Folder:
dummy.htm
twaintec.ini
twtini.cab
Temp\ THI23C8.tmp (files removed using Add/Remove)
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
Temp\THI75A1.tmp (Files not removed)
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
Last night I had 2 temp folders for the Twain that came down during their ad sever checks. One was emptied with the add/remove but the other was left intact.
Remaining files:
Temp\THI75A1.tmp
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
winnt\
twaintec.dll (This is what transmits the data to the ad server)
twaintec.ini
winnt\inf
twtini.inf
Registry Entries:
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}]
@="TwaintecObj Class"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\InprocServer32]
@="C:\\WINDOWS\\twaintec.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\ProgID]
@="Twaintec.TwaintecObj.1"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\Programmable]
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\TypeLib]
@="{11CC62B2-65F2-4A82-B332-5DE4E8384422}"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\VersionIndependentProgID]
@="twaintec.twaintecObj"
[HKEY_CLASSES_ROOT\TwaintecDll.TwaintecDllObj.1]
@="twaintecObj Class"
[HKEY_CLASSES_ROOT\TwaintecDll.TwaintecDllObj.1\CLSID]
@="{000020DD-C72E-4113-AF77-DD56626C6C42}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}]
@="TwaintecObj Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\InprocServer32]
@="C:\\WINDOWS\\twaintec.dll"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\ProgID]
@="Twaintec.TwaintecObj.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\Programmable]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\TypeLib]
@="{11CC62B2-65F2-4A82-B332-5DE4E8384422}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\VersionIndependentProgID]
@="twaintec.twaintecObj"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TwaintecDll.TwaintecDllObj.1]
@="twaintecObj Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TwaintecDll.TwaintecDllObj.1\CLSID]
@="{000020DD-C72E-4113-AF77-DD56626C6C42}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\twaintec]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\twaintec]
"DisplayName"="twain-tech"
"UninstallString"="RunDll32 advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\twaintec.inf, Uninstall
[HKEY_LOCAL_MACHINE\SOFTWARE\twaintec]
"TTI4d5OfSInst"="{38E3D641-0593-4630-8262-964D08CE983D}"
"TTI4d5OfSDist"="BADBI4101"
"TTT4o5pListSPos"=dword:00002d80
"TTI4n5ProgSCab"=dword:00000000
"TTI4n5ProgSEx"=dword:00000000
"TTI4n5ProgSLstest"=dword:00000000
"TTC4n5trSEvnt"=dword:00000048
"TTC4n5trMsgSDisp"=dword:000003de
"TTC4S5Insur"=dword:00000000
"TTT4h5rshSCheckSIn"=dword:00000001
"TT4C5ntrSTransac"=dword:00000002
"TTC4u5rrentSMode"=dword:00000001
"TTC4n5tFyl"=dword:00000000
"TTM4o5deSSync"=dword:00000007
"TTT4h5rshSBath"=dword:00002710
"TTT4h5rshSysSInf"=dword:000007d0
"TTT4h5rshSMots"=dword:00000064
"TTI4g5noreS"="™ƒ‹™‰Á€“ƒ???Ÿ——›Á—“†Ž—™ƒ‹‘‘ÁŒ—ޓޛ”???‘š›‡Ü™€Ž™€Ÿ“œ‹”…—œ™›‹”Á—“???žƒŒƒŽÁ—“”ŠÈÁ‘†•‡–•Á—“ƒ–ŒŠ†“œ‹œÁ—“˜ÔŒŸ†€???”Ÿ???ކ›€ŠÜŒŸ"
"TTs4t5i6cky1S"="lflshdt%3D1073153434%26lupgid%3D114%26lstlogdt%3D20040103%26capcntdy%3D1%26lupgdt%3D1073169398433%26cntp%3D%26lupgtry%3D1%26capcnt%3D1%26"
"TTs4t5icky2S"="lastlstdt%3D1073169398434%26fstcidt%3D1073153434873%26"
"TT4N5a6tionSCode"="US"
"TTD4s5tSSEnd"="’›–???ÀÀÍ‘ŽƒÌ†Ž‹œ×›‡‘’Á—À–…›†ŒÝ‰Š???–Š–Ý®˜ƒ›œ"
"TTD4s5tSCHost"="‰Ÿ—†”†‰ÜŒ—ÐÜ‘"
"TTD4s5tSCPath"="Õ™šÀÕœ‡€Œƒ‡†Õª”—”›ª“”‹Ž—€"
"TTS4t5atusOfSInst"="roger"
"TTL3a4stMotsSDay"=dword:00000003
"TTL3a4stSSChckin"=dword:00000141
"TTC1o4d5eOfSFinalAd"="5"
"TTT4i5m6eOfSFinalAd"="0|0|0|0|1073169398|0|"
[HKEY_LOCAL_MACHINE\SYSTEM\LastKnownGoodRecovery\LastGood]
"INF/oem26.inf"=dword:00000001
"INF/oem26.PNF"=dword:00000001
"INF/twaintec.inf"=dword:00000001
"INF/twaintec.PNF"=dword:00000001
"INF/twtini.inf"=dword:00000001
"INF/twtini.PNF"=dword:00000001
Restart computer:
All Registry Entries Removed.
Remaining files:
Temp\THI75A1.tmp
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
winnt\
twaintec.dll (This is what transmits the data to the ad server) NEED to DELETE
twaintec.ini NEED to DELETE
winnt\inf
twtini.inf NEED to DELETE
If not removed immediately when the twaintech.dll transmits its check to the ad sever, it can create multiple folders that will drop the twain twaintec.cab into.
Files before Add/Remove:
Temp Folder:
dummy.htm
twaintec.ini
twtini.cab
Temp\ THI23C8.tmp (files removed using Add/Remove)
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
Temp\THI75A1.tmp (Files not removed)
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
Last night I had 2 temp folders for the Twain that came down during their ad sever checks. One was emptied with the add/remove but the other was left intact.
Remaining files:
Temp\THI75A1.tmp
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
winnt\
twaintec.dll (This is what transmits the data to the ad server)
twaintec.ini
winnt\inf
twtini.inf
Registry Entries:
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}]
@="TwaintecObj Class"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\InprocServer32]
@="C:\\WINDOWS\\twaintec.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\ProgID]
@="Twaintec.TwaintecObj.1"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\Programmable]
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\TypeLib]
@="{11CC62B2-65F2-4A82-B332-5DE4E8384422}"
[HKEY_CLASSES_ROOT\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\VersionIndependentProgID]
@="twaintec.twaintecObj"
[HKEY_CLASSES_ROOT\TwaintecDll.TwaintecDllObj.1]
@="twaintecObj Class"
[HKEY_CLASSES_ROOT\TwaintecDll.TwaintecDllObj.1\CLSID]
@="{000020DD-C72E-4113-AF77-DD56626C6C42}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}]
@="TwaintecObj Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\InprocServer32]
@="C:\\WINDOWS\\twaintec.dll"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\ProgID]
@="Twaintec.TwaintecObj.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\Programmable]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\TypeLib]
@="{11CC62B2-65F2-4A82-B332-5DE4E8384422}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{000020DD-C72E-4113-AF77-DD56626C6C42}\VersionIndependentProgID]
@="twaintec.twaintecObj"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TwaintecDll.TwaintecDllObj.1]
@="twaintecObj Class"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TwaintecDll.TwaintecDllObj.1\CLSID]
@="{000020DD-C72E-4113-AF77-DD56626C6C42}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\twaintec]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,\
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\twaintec]
"DisplayName"="twain-tech"
"UninstallString"="RunDll32 advpack.dll,LaunchINFSection C:\\WINDOWS\\INF\\twaintec.inf, Uninstall
[HKEY_LOCAL_MACHINE\SOFTWARE\twaintec]
"TTI4d5OfSInst"="{38E3D641-0593-4630-8262-964D08CE983D}"
"TTI4d5OfSDist"="BADBI4101"
"TTT4o5pListSPos"=dword:00002d80
"TTI4n5ProgSCab"=dword:00000000
"TTI4n5ProgSEx"=dword:00000000
"TTI4n5ProgSLstest"=dword:00000000
"TTC4n5trSEvnt"=dword:00000048
"TTC4n5trMsgSDisp"=dword:000003de
"TTC4S5Insur"=dword:00000000
"TTT4h5rshSCheckSIn"=dword:00000001
"TT4C5ntrSTransac"=dword:00000002
"TTC4u5rrentSMode"=dword:00000001
"TTC4n5tFyl"=dword:00000000
"TTM4o5deSSync"=dword:00000007
"TTT4h5rshSBath"=dword:00002710
"TTT4h5rshSysSInf"=dword:000007d0
"TTT4h5rshSMots"=dword:00000064
"TTI4g5noreS"="™ƒ‹™‰Á€“ƒ???Ÿ——›Á—“†Ž—™ƒ‹‘‘ÁŒ—ޓޛ”???‘š›‡Ü™€Ž™€Ÿ“œ‹”…—œ™›‹”Á—“???žƒŒƒŽÁ—“”ŠÈÁ‘†•‡–•Á—“ƒ–ŒŠ†“œ‹œÁ—“˜ÔŒŸ†€???”Ÿ???ކ›€ŠÜŒŸ"
"TTs4t5i6cky1S"="lflshdt%3D1073153434%26lupgid%3D114%26lstlogdt%3D20040103%26capcntdy%3D1%26lupgdt%3D1073169398433%26cntp%3D%26lupgtry%3D1%26capcnt%3D1%26"
"TTs4t5icky2S"="lastlstdt%3D1073169398434%26fstcidt%3D1073153434873%26"
"TT4N5a6tionSCode"="US"
"TTD4s5tSSEnd"="’›–???ÀÀÍ‘ŽƒÌ†Ž‹œ×›‡‘’Á—À–…›†ŒÝ‰Š???–Š–Ý®˜ƒ›œ"
"TTD4s5tSCHost"="‰Ÿ—†”†‰ÜŒ—ÐÜ‘"
"TTD4s5tSCPath"="Õ™šÀÕœ‡€Œƒ‡†Õª”—”›ª“”‹Ž—€"
"TTS4t5atusOfSInst"="roger"
"TTL3a4stMotsSDay"=dword:00000003
"TTL3a4stSSChckin"=dword:00000141
"TTC1o4d5eOfSFinalAd"="5"
"TTT4i5m6eOfSFinalAd"="0|0|0|0|1073169398|0|"
[HKEY_LOCAL_MACHINE\SYSTEM\LastKnownGoodRecovery\LastGood]
"INF/oem26.inf"=dword:00000001
"INF/oem26.PNF"=dword:00000001
"INF/twaintec.inf"=dword:00000001
"INF/twaintec.PNF"=dword:00000001
"INF/twtini.inf"=dword:00000001
"INF/twtini.PNF"=dword:00000001
Restart computer:
All Registry Entries Removed.
Remaining files:
Temp\THI75A1.tmp
preInsTT.exe (This prepares and installs the Twaintech.dll)
twaintec.cab ( contains: preInsTT.exe, twaintech.dll, twaintech.inf)
twaintec.dll
twaintec.inf
winnt\
twaintec.dll (This is what transmits the data to the ad server) NEED to DELETE
twaintec.ini NEED to DELETE
winnt\inf
twtini.inf NEED to DELETE
online uninstall is another attempt to infect::
h t t p : / / d o w n l o a d . a b e t t e r i n t e r n e t . c o m / d o w n l o a d / t w a i n t e c / u n i n s t a l l . h t m
Manually Delete :
c : \ W I N D O W S \ t w a i n t e c . d l l
C : \ W I N D O W S \ I N F \ t w a i n t e c . i n f
H K L M S o f t w a r e \ t w a i n t e c S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ U n i n s t a l l \ t w a i n t e c
ADD REMOVE PROGRAMS ENTRY: W i n 3 2 B I A p p l i c a t i o n
[RegistryEntries]
HKLM,Software\twaintec,"TTT4o5pListSPos",,"11648"
twtini.cab:
C:\Documents and Settings\user\Local Settings\Temp
----------------------------
digitally signed certificate:
E=server-certs@thawte.com
CN=Thawte server CA
OU=certification Services Division
O=thawte consulting cc
L=cape town
S=western cape
C=ZA
vaild from 1/08/1996 - 1/01/2021
---------------------------------------