Unsolved

This post is more than 5 years old

13 Posts

3391

February 13th, 2005 01:00

need help on my hijack log

Hi there: I'm having much difficulty with trojans (being costantly caught by MacAfee) and IE shut downs, and I'm not that computer literate. Can someone please look at this log and give me some advice! Your time is deeply appreciated -sc Logfile of HijackThis v1.99.0 Scan saved at 6:58:51 PM, on 2/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\WINDOWS\system32\sle.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\DSentry.exe C:\WINDOWS\BCMSMMSG.exe C:\WINDOWS\System32\hphmon05.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\sysmonnt.exe C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\drivers\KodakCCS.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\ScsiAccess.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\HPZipm12.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Juno\bin\juno.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\HiJack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R3 - Default URLSearchHook is missing O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing) O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll (file missing) O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dll O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: SDWin32 Class - {282A2F19-9E87-4112-9DCE-1FF2232DC605} - C:\WINDOWS\System32\solhl.dll O2 - BHO: SDWin32 Class - {4600BAD1-175C-4ED5-B3DD-379D9A315BF7} - C:\WINDOWS\System32\qgnib.dll O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - C:\WINDOWS\system32\fcpyvaxr.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - C:\WINDOWS\system32\xngzhckl.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [zox] C:\WINDOWS\zox.exe O4 - HKLM\..\Run: [qgnibc] C:\WINDOWS\System32\qgnibc.exe O4 - HKLM\..\Run: [solhlc] C:\WINDOWS\System32\solhlc.exe O4 - HKLM\..\Run: [sle] C:\WINDOWS\system32\sle.exe O4 - HKLM\..\Run: [xapsdmh] C:\WINDOWS\xapsdmh.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe" O4 - Startup: PowerReg Scheduler V3.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A9DC6C-D7C9-4521-B8B3-2E3C0F4BDB5F}: NameServer = 66.51.205.100 66.51.206.100 O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: cobfavfewrwy - Unknown - C:\WINDOWS\system32\msupd6.exe (file missing) O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE

4.8K Posts

February 13th, 2005 01:00

scenoch,

Can you post that log back, but this time include the line-feeds, so each entry appears on the same line.

Mike.

13 Posts

February 13th, 2005 03:00

I thought I did. I'll try it again. But in case, can you tell me what zox.exe and qgnibc.exe are?

Thanks

sc

Logfile of HijackThis v1.99.0
Scan saved at 9:10:39 PM, on 2/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\sle.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\sysmonnt.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Juno\bin\juno.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll (file missing)
O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dll
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SDWin32 Class - {282A2F19-9E87-4112-9DCE-1FF2232DC605} - C:\WINDOWS\System32\solhl.dll
O2 - BHO: SDWin32 Class - {4600BAD1-175C-4ED5-B3DD-379D9A315BF7} - C:\WINDOWS\System32\qgnib.dll
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - C:\WINDOWS\system32\fcpyvaxr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - C:\WINDOWS\system32\xngzhckl.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [zox] C:\WINDOWS\zox.exe
O4 - HKLM\..\Run: [qgnibc] C:\WINDOWS\System32\qgnibc.exe
O4 - HKLM\..\Run: [solhlc] C:\WINDOWS\System32\solhlc.exe
O4 - HKLM\..\Run: [sle] C:\WINDOWS\system32\sle.exe
O4 - HKLM\..\Run: [xapsdmh] C:\WINDOWS\xapsdmh.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A9DC6C-D7C9-4521-B8B3-2E3C0F4BDB5F}: NameServer = 66.51.205.100 66.51.206.100
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: cobfavfewrwy - Unknown - C:\WINDOWS\system32\msupd6.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE

4.8K Posts

February 13th, 2005 14:00

sc,

I would guess those two are randomly named trojans; we can find more out if we submit those files to Kaspersky's for analysis, which we'll need to do for at lease one file.

-

Let's get started...




Go to www.kaspersky.com, then:

1.  Click "Online virus scanner"
2.  Click "Browse", then browse to, then doubleclick on the following file(s), one at a time:

  • C:\WINDOWS\system32\sle.exe
  • C:\WINDOWS\zox.exe

 3.  Click "Submit"
 4.  Post back the results.



If you haven't ran HouseCall lately, let's go back to www.trendmicro.com, download the latest definitions, and run it.



Download, unzip to your desktop CWShredder and run it, then:
 
1.  Click " Check For Update"
 
   ( If an update isn't available, skip to step #4.)
 
2.  Click " Click here to Download the upate".
3.  When the new version has been downloaded, click " Save".
4.  Click " Fix ->"
 


Run HiJackThis then:
 
1.  Click " Config..."
2.  Click " Misc Tools"
3.  Click " Open Process manager"
 
-
 
Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:
 
    C:\WINDOWS\System32\sysmonnt.exe
   
Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
 


Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:
 
regsvr32  /u  CSBB.DLL
regsvr32  /u  Helper101.dll
regsvr32  /u  solhl.dll
regsvr32  /u  qgnib.dll
regsvr32  /u  fcpyvaxr.dll
regsvr32  /u  xngzhckl.dll
 
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.



Run HiJackThis and click " Scan", then check(tick) the following, if present:
 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank 
 
R3 - Default URLSearchHook is missing 
 
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000002230} - C:\Program Files\CSBB\CSBB.DLL 
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing) 
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll (file missing) 
O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - C:\WINDOWS\Helper101.dll 
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) 
O2 - BHO: SDWin32 Class - {282A2F19-9E87-4112-9DCE-1FF2232DC605} - C:\WINDOWS\System32\solhl.dll 
O2 - BHO: SDWin32 Class - {4600BAD1-175C-4ED5-B3DD-379D9A315BF7} - C:\WINDOWS\System32\qgnib.dll 
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - C:\WINDOWS\system32\fcpyvaxr.dll 
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) 
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - C:\WINDOWS\system32\xngzhckl.dll 
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) 
 
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) 
 
O4 - HKLM\..\Run: [zox> C:\WINDOWS\zox.exe 
O4 - HKLM\..\Run: [qgnibc> C:\WINDOWS\System32\qgnibc.exe 
O4 - HKLM\..\Run: [solhlc> C:\WINDOWS\System32\solhlc.exe 
O4 - HKLM\..\Run: [xapsdmh> C:\WINDOWS\xapsdmh.exe 
O4 - HKCU\..\Run: [sysmonnt> C:\WINDOWS\System32\sysmonnt 
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{F2A9DC6C-D7C9-4521-B8B3-2E3C0F4BDB5F}: NameServer = 66.51.205.100 66.51.206.100 
 
O23 - Service: cobfavfewrwy - Unknown - C:\WINDOWS\system32\msupd6.exe (file missing) 

 
Now, with all windows closed except HiJackThis, click " Fix checked".
 


Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
 
folders...
 
    C:\Program Files\CSBB
   
files...
 
    C:\WINDOWS\System32\sysmonnt.exe
    C:\WINDOWS\Helper101.dll
    C:\WINDOWS\System32\solhl.dll
    C:\WINDOWS\System32\qgnib.dll
    C:\WINDOWS\system32\fcpyvaxr.dll
    C:\WINDOWS\system32\xngzhckl.dll
    C:\WINDOWS\System32\qgnibc.exe
    C:\WINDOWS\System32\solhlc.exe
    C:\WINDOWS\xapsdmh.exe
-
 
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
 


Post back a new log, and let me know how everything goes.
 
-
 
Mike.
 

13 Posts

February 14th, 2005 23:00

Scanned file:   sle.exe

 

sle.exeWarning: Trojan-Downloader.Win32.Lastad.d
sle.exeWarning:

 

zox eliminated by uping adaware’s settings

 

What is qgnibd.exe?

It was next to qgnibc.exe

 

Thanks for your time. Our machine is running much better already.

 

Logfile of HijackThis v1.99.0

Scan saved at 5:42:09 PM, on 2/14/2005

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\mcafee.com\agent\mcagent.exe

C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

C:\Program Files\Common Files\Dell\EUSW\Support.exe

C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

c:\progra~1\mcafee.com\vso\mcvsescn.exe

C:\Program Files\Dell\Media Experience\PCMService.exe

C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\WINDOWS\System32\hkcmd.exe

C:\WINDOWS\System32\DSentry.exe

C:\WINDOWS\BCMSMMSG.exe

C:\WINDOWS\System32\hphmon05.exe

C:\WINDOWS\SysCheckBop32.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe

C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe

C:\WINDOWS\system32\cisvc.exe

C:\WINDOWS\system32\drivers\KodakCCS.exe

c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\ScsiAccess.EXE

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\HPZipm12.exe

c:\PROGRA~1\mcafee.com\vso\mcshield.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\system32\cidaemon.exe

C:\Program Files\HiJack This\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask

O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe

O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"

O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe

O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32

O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"

O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe

O4 - Startup: PowerReg Scheduler V3.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab

O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab

O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab

O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll

O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE

 

13 Posts

February 15th, 2005 00:00

awile ago I saw qgnibd.exe pop up and close in the Task Manages processes tab. http://www.kaspersky.com  said the following when I submitted the file:

Scanned file:   qgnibd.exe

qgnibd.exe - infected by not-a-virus:AdWare.Adstart.b

That file doesnt appear in HijackThis. What do I do about that? :smileyindifferent:

13 Posts

February 15th, 2005 02:00

I decided to go through suspicious files at http://www.kaspersky.com

Scanned file:   BO2804040113.exe

BO2804040113.exe - infected by not-a-virus:AdWare.VirtualBouncer.d

Scanned file:   CP18.exe

 

CP18.exe - infected by Trojan-Downloader.Win32.Small.ahx

Scanned file:   randreco.exe

 

randreco.exe - infected by not-a-virus:AdWare.BetterInternet

Scanned file:   wsxsvc.exe

 

wsxsvc.exe - infected by not-a-virus:AdWare.DelphinMediaViewer.c

 

Scanned file:   systb.exe

 

systb.exe/systb.dll - infected by not-a-virus:AdWare.ToolBar.ImiBar.d

Scanned file:   1stpublisher.exe

 

1stpublisher.exe/data0001 - OK
1stpublisher.exe/data0002 - infected by not-a-virus:AdWare.ToolBar.HotSearchBar.b

 

58kd52fg.exe    - does not even scan. Loads a blank page

activeshopper.exe    - does not even scan. Loads a blank page

adl_dh.exe    - does not even scan. Loads a blank page

adl_hl.exe    - does not even scan. Loads a blank page

Scanned file:   adl_mteststub.exe

 

adl_mteststub.exe - infected by not-a-virus:AdWare.EZula.ah

adl_zeno.exe

AdSmartMedia_bundle.exe

adv0ltc0m.exe

ast_5_adsav.exe

b2s-162813.exe

Beryllium1.exe

Beryllium.exe

bs5-goodyr1.exe

CSv12P108.exe

cxt_big.exe

cxt_wmg.exe

cxtpls_loader.exe

d_ic.exe

Decade.exe

dh_vl.exe

e2g51.exe

EDow_vl.exe

ei51.exe

Scanned file:   ezStub_ropwo.exe

 

ezStub_ropwo.exe - infected by not-a-virus:AdWare.EZula.ah

gogotoolsSILAWO8pi.exe

 

Scanned file:   HelperInstaller.exe

 

HelperInstaller.exe - infected by Trojan-Dropper.Win32.Delf.z

HLInstaller.exe

icmedia2_56.exe

ICMMedia_1cmm3d1a.exe

iehost.exe

installcasino.exe

KnNe1.exe

Scanned file:   mfs.exe

 

mfs.exe/INSTALL.EXE - OK
mfs.exe/README.TXT - OK
mfs.exe/MAGIC.EXE - OK
mfs.exe/MFX - OK
mfs.exe/TB.EXE - OK
mfs.exe/MF.CHM/#IDXHDR - OK
mfs.exe/MF.CHM/#STRINGS - OK
mfs.exe/MF.CHM/#SYSTEM - OK
mfs.exe/MF.CHM/#TOPICS - OK
mfs.exe/MF.CHM/#URLSTR - OK
mfs.exe/MF.CHM/#URLTBL - OK
mfs.exe/MF.CHM/Auto_hiding_of_visible_folders.htm - OK
mfs.exe/MF.CHM/Automatic_Encryption.htm - OK
mfs.exe/MF.CHM/Backups.htm - OK
mfs.exe/MF.CHM/Batch_file_operation.htm - OK
mfs.exe/MF.CHM/Can_t_rename_parent_of_hidden_folder.htm - OK
mfs.exe/MF.CHM/Choosing_a_hot_key.htm - OK
mfs.exe/MF.CHM/Cleaning_of_My_Documents.htm - OK
mfs.exe/MF.CHM/Creating_your_list_of_Magic_Folders.htm - OK
mfs.exe/MF.CHM/Desktop_icon_problems.htm - OK
mfs.exe/MF.CHM/Don_t_hide_critical_system_files.htm - OK
mfs.exe/MF.CHM/dwnex.gif - OK
mfs.exe/MF.CHM/FirstTopic.htm - OK
mfs.exe/MF.CHM/Hidden_files_and_the_Recycle_Bin.htm - OK
mfs.exe/MF.CHM/How_do_I_uninstall.htm - OK
mfs.exe/MF.CHM/How_Much_.htm - OK
mfs.exe/MF.CHM/htmlhelp.css - OK
mfs.exe/MF.CHM/I_forgot_my_password.htm - OK
mfs.exe/MF.CHM/I_m_getting_a_blue_screen_when_I_use_CDs.htm - OK
mfs.exe/MF.CHM/Icon_and_Driver_naming.htm - OK
mfs.exe/MF.CHM/Images/mf2.ICO - OK
mfs.exe/MF.CHM/Inputting_the_Master_Account_password.htm - OK
mfs.exe/MF.CHM/Invisible_folders_are_still_visible.htm - OK
mfs.exeMF.CHM/Making_your_Magic_Folders_Visible_or_Invisible.htm - OK
mfs.exe/MF.CHM/master.js - OK
mfs.exe/MF.CHM/mf.hhc - OK
mfs.exe/MF.CHM/mf.hhk - OK
mfs.exe/MF.CHM/mf_decrypt.htm - OK
mfs.exe/MF.CHM/Moving_or_Copying_your_hidden_files.htm - OK
mfs.exe/MF.CHM/Multiple_Accounts.htm - OK
mfs.exe/MF.CHM/Multiple_Accounts2.htm - OK
mfs.exe/MF.CHM/Multiple_Boot_Systems.htm - OK
mfs.exe/MF.CHM/Mutliple_Account_Operation.htm - OK
mfs.exe/MF.CHM/Network_installation.htm - OK
mfs.exe/MF.CHM/Network_Overview.htm - OK
mfs.exe/MF.CHM/No_network_drives_listed.htm - OK
mfs.exe/MF.CHM/Operation.htm - OK
mfs.exe/MF.CHM/Overview.htm - OK
mfs.exe/MF.CHM/Removable_Drives.htm - OK
mfs.exe/MF.CHM/rtex.gif - OK
mfs.exe/MF.CHM/Run_Install_exe.htm - OK
mfs.exe/MF.CHM/Scrambling_of_Filenames.htm - OK
mfs.exe/MF.CHM/stranded_files.htm - OK
mfs.exe/MF.CHM/System_folders.htm - OK
mfs.exe/MF.CHM/Technical_Support.htm - OK
mfs.exe/MF.CHM/Thank_you_.htm - OK
mfs.exe/MF.CHM/Updates.htm - OK
mfs.exe/MF.CHM - OK
mfs.exe/CPY.EXE - OK
mfs.exe/EDECRYPT.EXE - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/ALI.EXE - OK
mfs.exe/MF.TXX - OK
mfs.exe/SYSTRAY.EXE - OK
mfs.exe/CDLOCK.DLL - OK
mfs.exe/INSTALL.EXE - OK
mfs.exe/README.TXT - OK
mfs.exe/MAGIC.EXE - OK
mfs.exe/MFX - OK
mfs.exe/TB.EXE - OK
mfs.exe/MF.CHM - OK
mfs.exe/CPY.EXE - OK
mfs.exe/EDECRYPT.EXE - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/FLDRVW51.OCX - OK
mfs.exe/ALI.EXE - OK
mfs.exe/MF.TXX - OK
mfs.exe/SYSTRAY.EXE - OK
mfs.exe/CDLOCK.DLL - OK
mfs.exe - OK

mfsetup.exe

Scanned file:   mstub-pal_nmw_a352_r15800.exe

 

mstub-pal_nmw_a352_r15800.exe - OK

new_vcm.exe

newmb.exe

NzI0MDo4OjEy.exe

Scanned file:   OTY2MTo4OjEy.exe

 

OTY2MTo4OjEy.exe - infected by not-a-virus:AdWare.ToolBar.ISearch.d

package8033_MARKETING5.exe

Scanned file:   pounder.exe

 

pounder.exe/Script - OK
pounder.exe/data0001/EXE-file - OK
pounder.exe/data0001 - OK
pounder.exe - OK

rop_marketing_1_168.exe

ropbundle.exe

runsearch.exe

sahagent-dectest1001.exe

sahagent-onlinetrafficbroker1001.exe

sahagent-seedcorn1002.exe

Scanned file:   saie1101.exe

 

saie1101.exe - infected by Trojan-Dropper.Win32.Small.mr

search_toolbar.exe

seedcorn.exe

Setup1171.exe

setup_Incredifind_TrafficSpec.exe

setupactiv2.exe

SetupCasino.exe

Scanned file:   shopinst.exe

 

shopinst.exe - infected by Trojan-Downloader.Win32.Small.wj

ssee.exe

The size of a file exceeds 1024 Kb

Scanned file:   SSK_B5.EXE

 

SSK_B5.EXE - infected by Trojan-Dropper.Win32.SurfSide.a

stlb2_seed.exe

Scanned file:   thin-8-1-x-x.exe

 

thin-8-1-x-x.exe - infected by not-a-virus:AdWare.BetterInternet

Scanned file:   tinko_vcm.exe

 

tinko_vcm.exe/data0001 - OK
tinko_vcm.exe/data0002 - OK
tinko_vcm.exe/data0003 - OK
tinko_vcm.exe/data0004 - OK
tinko_vcm.exe/data0005 - OK
tinko_vcm.exe/data0006 - OK
tinko_vcm.exe/data0007 - OK
tinko_vcm.exe/data0008 - OK
tinko_vcm.exe/data0009 - OK
tinko_vcm.exe/data0010 - OK
tinko_vcm.exe/data0011 - OK
tinko_vcm.exe/data0012 - OK
tinko_vcm.exe/data0013 - OK
tinko_vcm.exe/data0014 - OK
tinko_vcm.exe/data0015 - OK
tinko_vcm.exe/data0016 - OK
tinko_vcm.exe/data0017/#IDXHDR Corrupted
tinko_vcm.exe/data0017/#STRINGS Corrupted
tinko_vcm.exe/data0017/#SYSTEM - OK
tinko_vcm.exe/data0017/#TOPICS Corrupted
tinko_vcm.exe/data0017/#URLSTR Corrupted
tinko_vcm.exe/data0017/#URLTBL Corrupted
tinko_vcm.exe/data0017/$OBJINST Corrupted
tinko_vcm.exe/data0017/$WWAssociativeLinks/Property Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/BTree Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/Data Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/Map Corrupted
tinko_vcm.exe/data0017/$WWKeywordLinks/Property Corrupted
tinko_vcm.exe/data0017/Email.htm - OK
tinko_vcm.exe/data0017/Email.jpg - OK
tinko_vcm.exe/data0017/Favorite.htm - OK
tinko_vcm.exe/data0017/Favorites.jpg - OK
tinko_vcm.exe/data0017/Features.htm - OK
tinko_vcm.exe/data0017/Index.hhk - OK
tinko_vcm.exe/data0017/Search.htm - OK
tinko_vcm.exe/data0017/Search.jpg Corrupted
tinko_vcm.exe/data0017/Table of Contents.hhc - OK
tinko_vcm.exe/data0017/TinkoPal.jpg - OK
tinko_vcm.exe/data0017/Uninstall.htm - OK
tinko_vcm.exe/data0017/Uninstall.jpg Corrupted
tinko_vcm.exe/data0017/Weather.htm - OK
tinko_vcm.exe/data0017/Weather.jpg - OK
tinko_vcm.exe/data0017/Website.htm - OK
tinko_vcm.exe/data0017/Welcome.htm - OK
tinko_vcm.exe/data0017 - OK
tinko_vcm.exe/data0018 - OK
tinko_vcm.exe/data0019 - OK
tinko_vcm.exe/data0020Warning: Trojan-Downloader.Win32.Lastad.d
tinko_vcm.exe/data0021 - OK
tinko_vcm.exe/data0022 - OK
tinko_vcm.exe/data0023 - OK
tinko_vcm.exe/data0024 - OK
tinko_vcm.exe/data0025 - OK
tinko_vcm.exe/data0026 - OK
tinko_vcm.exe/data0027 - OK
tinko_vcm.exe/data0028 - OK
tinko_vcm.exe/data0029 - OK
tinko_vcm.exe/data0030 - OK
tinko_vcm.exe/data0031 - OK
tinko_vcm.exe/data0032 - OK
tinko_vcm.exe/data0033 - OK
tinko_vcm.exe/data0034 - OK
tinko_vcm.exe/data0035 - OK
tinko_vcm.exe/data0036 - OK
tinko_vcm.exe/data0036Warning: Trojan-Downloader.Win32.Lastad.d

ucmoreiex.exe

ventura1.exe

Scanned file:   videoinst.exe

 

videoinst.exe - infected by Trojan-Downloader.Win32.Small.wj

vrinstall_icmedia.exe

Scanned file:   WebRebates_Auto_InstallSilent.exe

 

WebRebates_Auto_InstallSilent.exe/data0001 - OK
WebRebates_Auto_InstallSilent.exe/data0002 - OK
WebRebates_Auto_InstallSilent.exedata0003/data0001 - infected by not-a-virus:AdWare.WebRebates.g
WebRebates_Auto_InstallSilent.exe/data0003 - infected by not-a-virus:AdWare.WebRebates.d
WebRebates_Auto_InstallSilent.exe/data0004 - infected by not-a-virus:AdWare.WebRebates.d
WebRebates_Auto_InstallSilent.exe/data0005 - infected by not-a-virus:AdWare.WebRebates.c
WebRebates_Auto_InstallSilent.exe/data0006 - OK
WebRebates_Auto_InstallSilent.exe/data0007 - OK
WebRebates_Auto_InstallSilent.exe/data0008 - OK
WebRebates_Auto_InstallSilent.exe/data0009 - OK
WebRebates_Auto_InstallSilent.exe/data0010 - OK
WebRebates_Auto_InstallSilent.exe/data0011 - OK
WebRebates_Auto_InstallSilent.exe/data0012 - OK
WebRebates_Auto_InstallSilent.exe/data0013 - OK
WebRebates_Auto_InstallSilent.exe/data0014 - OK
WebRebates_Auto_InstallSilent.exe/data0015 - OK
WebRebates_Auto_InstallSilent.exe/data0016 - OK
WebRebates_Auto_InstallSilent.exe/data0017 - OK
WebRebates_Auto_InstallSilent.exe/data0018 - OK
WebRebates_Auto_InstallSilent.exe/data0019 - OK
WebRebates_Auto_InstallSilent.exe/data0020 - OK
WebRebates_Auto_InstallSilent.exe/data0021 - OK
WebRebates_Auto_InstallSilent.exe/data0022 - OK
WebRebates_Auto_InstallSilent.exe/data0023 - OK
WebRebates_Auto_InstallSilent.exe/data0024 - OK
WebRebates_Auto_InstallSilent.exe/data0025 - OK
WebRebates_Auto_InstallSilent.exe/data0026 - OK
WebRebates_Auto_InstallSilent.exe/data0027 - OK
WebRebates_Auto_InstallSilent.exe/data0028 - OK
WebRebates_Auto_InstallSilent.exe/data0029 - OK
WebRebates_Auto_InstallSilent.exe/data0030 - OK
WebRebates_Auto_InstallSilent.exe/data0031 - OK

winversion.exe

Scanned file:   wrapperouter.exe

 

wrapperouter.exe/WISE0000.BIN - OK
wrapperouter.exe/WISE0001.BIN - OK
wrapperouter.exe/WISE0002.BIN - OK
wrapperouter.exe/WISE0003.BIN - OK
wrapperouter.exe/WISE0004.BIN - OK
wrapperouter.exe/WISE0005.BIN - OK
wrapperouter.exe/WISE0006.BIN - infected by not-a-virus:AdWare.VirtualBouncer.c
wrapperouter.exe/WISE0007.BIN/WISE0000.BIN - OK
wrapperouter.exeWISE0007.BIN/WISE0001.BIN - infected by not-a-virus:AdWare.VirtualBouncer.j
wrapperouter.exe/WISE0007.BIN/WISE0002.BIN - OK
wrapperouter.exe/WISE0007.BIN/WISE0003.BIN - OK
wrapperouter.exe/WISE0007.BIN/WISE0004.BIN - OK
wrapperouter.exe/WISE0007.BIN/WISE0005.BIN - OK

 

 

 



 

 

 

 

 

 

 

 

This following file has no info except size and date created - 1-31-05

Scanned file:   cp.exe

 

cp.exe/EXE-file/Script - OK
cp.exe/EXE-file/data0001/EXE-file - OK
cp.exe/EXE-file/data0001/EXE-file - OK
cp.exe/EXE-file/data0001 - OK
cp.exe/EXE-file - OK
cp.exe - OK

 

servedby.advertising.com advertising.com and atdmt.com wanted to "store a file called a cookie" on my computer just randomly FOUR times. I hadn't clicked on anything in a while all four times times.

4.8K Posts

February 15th, 2005 12:00

scenoch,
 
That log is looking so much better!
 
-
 
Let's see if MWAV can find all those items, and allow you to post the back here more easily. That way, i'll be able to see the full path of all those files, in an easier format to read.
 


Run HiJackThis then:
 
1.  Click " Config..."
2.  Click " Misc Tools"
3.  Click " Open Process manager"
 
-
 
Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:
 
    C:\WINDOWS\SysCheckBop32.exe
 
Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
 


Run HiJackThis and click " Scan", then check(tick) the following, if present:
 

O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
 

Now, with all windows closed except HiJackThis, click " Fix checked".
 


Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
 
folders...
 
    C:\PROGRA~1\ezula
 
files...
 
    C:\WINDOWS\SysCheckBop32.exe
 
-
 
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
 


Download mwav.exe from MicroWorld, then:
 
1.  Double-click the mwav.exe icon to run it ( it'll self extract).
2.  Click " Scan".
3.  When it completes, post back the results from the 'Virus log information' pane.
 

 
Mike.
 

13 Posts

February 20th, 2005 02:00

I could not get rid of
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
even in safe mode.
spybot keeps deleting ezula. It's done it several times.
 

File C:\WINDOWS\systb.exe infected by "not-a-virus:AdWare.ToolBar.ImiBar.d" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\BO2802040113.dll infected by "not-a-virus:AdWare.VirtualBouncer.d" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\BO2804040113.exe infected by "not-a-virus:AdWare.VirtualBouncer.d" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\CP18.exe infected by "Trojan-Downloader.Win32.Small.ahx" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\msbb321.dll infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\qgnibd.exe infected by "not-a-virus:AdWare.Adstart.b" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\qgnibf.exe infected by "not-a-virus:AdWare.Adstart.d" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\randreco.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\setup_incred_8.exe infected by "Trojan-Downloader.Win32.Keenval.e" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\solhld.exe infected by "not-a-virus:AdWare.Adstart.i" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\system32\solhlf.exe infected by "not-a-virus:AdWare.Adstart.d" Virus. Action Taken: No Action Taken.

 

Thank you for your time!

4.8K Posts

February 22nd, 2005 20:00

scenoch,

Ok, let's see what we have left; post back a new HiJackThis log after removing these files...



Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

files...

    C:\WINDOWS\systb.exe
    C:\WINDOWS\system32\BO2802040113.dll
    C:\WINDOWS\system32\BO2804040113.exe
    C:\WINDOWS\system32\CP18.exe
    C:\WINDOWS\system32\msbb321.dll
    C:\WINDOWS\system32\qgnibd.exe
    C:\WINDOWS\system32\qgnibf.exe
    C:\WINDOWS\system32\randreco.exe
    C:\WINDOWS\system32\setup_incred_8.exe
    C:\WINDOWS\system32\solhld.exe
    C:\WINDOWS\system32\solhlf.exe

-

Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode".


Mike.

 

13 Posts

February 23rd, 2005 02:00

Thanks a lot, Mike. You have been a lot of help. We are almost free of malware!


how do I get rid of
wsxsvc.exe - infected by not-a-virus:AdWare.DelphinMediaViewer.c
or DMVlite?

Is the uninstall program worth downloading?

I could not get rid of
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
even in safe mode.

4.8K Posts

February 24th, 2005 19:00

scenoch,

Try going to Add/Remove programs and uninstall(remove), the following:

Delfin Media Viewer


Let me see a fresh log to see what we have left to fix.

-

Mike.

 

4.8K Posts

February 24th, 2005 19:00

scenoch,
 
Your more than welcome!
 
-
 
Which uninstaller were you trying to download?
 

 
Mike.
 

Message Edited by Midnight Star on 02-24-2005 03:36 PM

13 Posts

February 26th, 2005 00:00

Logfile of HijackThis v1.99.0
Scan saved at 6:37:58 PM, on 2/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\sys11-1673214046.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\Enoch Family\Application Data\Mozilla\Profiles\default\tz2zi4r4.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Enoch Family\Application Data\Mozilla\Profiles\default\tz2zi4r4.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{D946675D-1D6C-4dc8-9E0D-B4B8EAA30EAA}\hphupd05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [sys11-1673214046] C:\WINDOWS\sys11-1673214046.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE

13 Posts

February 26th, 2005 00:00

If I go to Add/Remove programs and click uninstall(remove) on Delfin Media Viewer then it takes me to their site and wants me to download their program that says it uninstalls Delfin Media Viewer. Is is safe to download and run? Thank you.

4.8K Posts

February 26th, 2005 02:00

scenoch,

On that i'm not 100% sure, but i'd venture to guess yes. If I wanted to uninstall it from my system, i'd try their uninstaller first, before doing anything else, just to make sure it removed (or at least should), everything that it installed on my system. Can you post back the link and take a quick look?

-

Let's take the next pass...



Download, then unzip to " C:\HJT", the newest version of HiJackThis; version 1.99.1. Then repost your log, either now, or after following the steps in the solution ( if provided in this post). This version has features that might be more helpful in 'cleaning' up your system.



Run HiJackThis then:

1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"

-

Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

C:\WINDOWS\sys11-1673214046.exe

Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



Run HiJackThis and click " Scan", then check(tick) the following, if present:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com

R3 - Default URLSearchHook is missing

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Enoch Family\Application Data\Mozilla\Profiles\default\tz2zi4r4.slt\prefs.js)

O2 - BHO: (no name) - {4F528B0B-7396-BF53-49EB-F262D50CF02F} - (no file)
O2 - BHO: (no name) - {5FC17529-BFDB-C205-2755-5C6A8F4A868B} - (no file)

O4 - HKLM\..\Run: [sys11-1673214046] C:\WINDOWS\sys11-1673214046.exe


Now, with all windows closed except HiJackThis, click " Fix checked".




When your done, rescan your system and make sure the following isn't present:

N3 - Netscape ... 5CSBWeb_01.src

If it is, then fix that entry again; sometimes it'll take more than one pass. The actual entry is ok, and won't be deleted, it's the java wrapper marked in red that needs to be removed.



Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

files...

C:\WINDOWS\sys11-1673214046.exe

-

Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



Post back a new log, and let me know how everything goes.

-

Mike
No Events found!

Top