I have several adwar removal programs. I use them all frequently. However, after a few days, they seem to come back. I have a particualr problem with a file called csmss.exe. In addition, I know that I have a Coolweb issue, as my notepad.exe file keeps getting replaced. I assume that it is a hidden file reinfecting my system, but I can't find it. Below is the most current HJT log. Can anyone A) help me remove whatever problems HJT shows, B) get rid of CSMSS.exe, and C) find the hidden file?
Jim
Logfile of HijackThis v1.98.2
Scan saved at 10:48:11 PM, on 1/21/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Let's start with HJT first. It looks like your system has picked up VX2 or a variant of it. We're going to try the VX2 cleaner first, if AdAware 'crashes' or cannot clean it up, then we'll switch to a different methong of removal.
If you don't already have it, download, install and run
AdAware SE Personal.
-
Next, check for, and download any available updates:
1. click "
Check for updates now".
2. Click "
Connect".
3. If updates(definitions) are available click "
Ok", otherwise, click "
Ok".
4. Click "
Finish".
-
Next, configure
AdAware to be as effective as possible:
1. Click the '
gear' in the upper-right hand corner of the
AdAware Window.
2. Click Scanning, and check(tick) the following:
Scan withing archives Scan active processes Scan registry Deep-scan registry Scan my IE Favorites for banned URLs Scan my Hosts file
3. Click "
Tweak".
4. Click "
Scanning Engine", then check(tick) the following:
Unload recognized proceses & modules during scan
5. Click "
Cleaning Engine", then check(tick) then following:
>
Always try to unload modules before deletion During removal, unload Explorer and IE if necessary Let Winodws remove files in use at next reboot Delete quarantined objects after retoring
6. Then click "
Proceed"
-
Now, let
AdAware locate and remove anything it finds, by:
1. Click "
Start".
2. Check(tick) "
perform full system scan".
3. Click "
Next".
-
Exit the program.
If you don't already have it, let's go to
Lavasoft'sVX2 Cleaner web-page, and follow the instructions to download and install the utility.
-
Next, run
AdAware SE Personal, then:
1. Click "
Add-Ons".
2. Double-click "
VX2 Cleaner"
3. Click "
Ok", to "
Execute this tool".
4. If nothing is found, click "
Ok", then exit the program.
(or)
4. If
VX2 has been found on your system, click "
Clean System"
5. Then when it's complelely done, reboot your computer.
6. Repeat steps 1-4 again.
Be sure to follow any instructions it might give while using it.
Download, then unzip to "
C:\HJT", the newest version of
HiJackThis;
version 1.99.0. Then repost your log, either now, or after following the steps in the solution (
if provided in this post).
This version has features that might help in 'cleaning' up your system.
Run
HiJackThis and click "
Scan", then check(tick) the following, if present:
I ran adarware. It located several processes, including coolweb. It also found 18 vx2 files and something called redirect host, as well as a bunch of cookies. However, whenever I try to delete/quarantine the files, adaware locks up. What do I do next? I also could not find the file gexzn.exe in windows\system. Posted below is the most current hjt
Logfile of HijackThis v1.99.0
Scan saved at 2:58:05 PM, on 1/22/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Whwnever i run adaware, it picks up 2 processes running, these are the coolweb infection systems. They are the files that mucked up deleting vx2. I ran the add on twice, and both times it said system clean. I deleted the things from HJT like you asked. Note, however, that the trusted ip ranges and the 3 hosts files pop up on the very next scan. How do i keep them off my system? Posted below is the next HJT log
Your help and instructions have been supreb so far. I can't thank you enough.
Jim
Logfile of HijackThis v1.99.0
Scan saved at 6:03:39 PM, on 1/22/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Thanks for all of your help. I ran the CWS shredder, and it seemed to work fine. I also downloaded the other programs. Here is a logfile of the dll compare:
* DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________
C:\WINDOWS\SYSTEM\sxmscrpt.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\rsclts6.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\sctup4.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\wplp32t.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\rocltc1.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\arippaxx.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\ssi_ci.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\arivs2xx.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\mjvcp60.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\maacm.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\rgrc16.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\sorrun.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\mzorc32r.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\ayctres.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\muident.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\dutmsft.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\rmcltscm.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\ufl.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\hefprl15.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K C:\WINDOWS\SYSTEM\mcihnd.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K ________________________________________________
865 items found: 865 files (20 H/S), 0 directories. Total of file sizes: 154,149,189 bytes 147.01 M
After entering the last file, when prompted to "Reboot Now", select "Yes".
-----
You can copy/paste these file name(s) to save on typing.
Now, let's go back and run DLLCompare again, just like we did in the previous post, and post back the results.
Be sure not to reboot your computer while we're working on this, otherwise we'll have a whole new set of program(s) to check for - this thing has a habit of changing the above names on reboot ...
I rebooted and reran dllcompare. here is the result:
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM\sxmscrpt.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
C:\WINDOWS\SYSTEM\rmr20.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
C:\WINDOWS\SYSTEM\iset16.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
C:\WINDOWS\SYSTEM\ditmsft.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
C:\WINDOWS\SYSTEM\nitdi.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
C:\WINDOWS\SYSTEM\iretcomm.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
C:\WINDOWS\SYSTEM\sorrun.dll Fri Jan 21 2005 8:19:20p ..S.R 222,568 217.35 K
________________________________________________
870 items found: 870 files (7 H/S), 0 directories.
Total of file sizes: 155,262,029 bytes 148.07 M
--------------------End log---------------------
On a side note, i reran cws shredder and it picked up and deleted the same file that it had said it deleted earlier. I then ran adaware, and it is still picking up coolweb as a running process. It also repicked up the vx2 virus. Is this a problem?
Midnight Star
4791 Posts
704
0
Posted January 22nd, 2005 04:00
Let's start with HJT first. It looks like your system has picked up VX2 or a variant of it. We're going to try the VX2 cleaner first, if AdAware 'crashes' or cannot clean it up, then we'll switch to a different methong of removal.
If you don't already have it, download, install and run AdAware SE Personal.
-
Next, check for, and download any available updates:
1. click " Check for updates now".
2. Click " Connect".
3. If updates(definitions) are available click " Ok", otherwise, click " Ok".
4. Click " Finish".
-
Next, configure AdAware to be as effective as possible:
1. Click the ' gear' in the upper-right hand corner of the AdAware Window.
2. Click Scanning, and check(tick) the following:
Scan withing archives
Scan active processes
Scan registry
Deep-scan registry
Scan my IE Favorites for banned URLs
Scan my Hosts file
3. Click " Tweak".
4. Click " Scanning Engine", then check(tick) the following:
Unload recognized proceses & modules during scan
5. Click " Cleaning Engine", then check(tick) then following:
> Always try to unload modules before deletion
During removal, unload Explorer and IE if necessary
Let Winodws remove files in use at next reboot
Delete quarantined objects after retoring
6. Then click " Proceed"
-
Now, let AdAware locate and remove anything it finds, by:
1. Click " Start".
2. Check(tick) " perform full system scan".
3. Click " Next".
-
Exit the program.
If you don't already have it, let's go to Lavasoft's VX2 Cleaner web-page, and follow the instructions to download and install the utility.
-
Next, run AdAware SE Personal, then:
1. Click " Add-Ons".
2. Double-click " VX2 Cleaner"
3. Click " Ok", to " Execute this tool".
4. If nothing is found, click " Ok", then exit the program.
(or)
4. If VX2 has been found on your system, click " Clean System"
5. Then when it's complelely done, reboot your computer.
6. Repeat steps 1-4 again.
Be sure to follow any instructions it might give while using it.
Download, then unzip to " C:\HJT", the newest version of HiJackThis; version 1.99.0. Then repost your log, either now, or after following the steps in the solution ( if provided in this post). This version has features that might help in 'cleaning' up your system.
Run HiJackThis and click " Scan", then check(tick) the following, if present:
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKCU\..\Run: [Eukmw] C:\WINDOWS\SYSTEM\gexzn.exe
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/23d80ed2585f21dc7417/netzip/RdxIE601.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50203/QDow_AS2.cab
Now, with all windows closed except HiJackThis, click " Fix checked".
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
C:\WINDOWS\SYSTEM\gexzn.exe
Post back a new log.
-
Mike.