UNSOLVED

hilde112

updated

22 years ago

H

hilde112

15 Posts

0

20386

January 22nd, 2005 17:00

please help

I've used spybot and there are things that pop up that spybot won't delete.  I downloaded the suggested hijackthis program, and here is my log.  Can anyone help me please?
 
Logfile of HijackThis v1.99.0
Scan saved at 1:39:34 PM, on 1/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\documents and settings\heather\local settings\temp\r9tEv.exe
C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
C:\documents and settings\heather\local settings\temp\sg.exe
C:\documents and settings\heather\local settings\temp\Da3a.exe
C:\documents and settings\heather\local settings\temp\Bqs.exe
C:\Program Files\SED\SED.exe
C:\WINDOWS\system32\wkwiwi.exe
C:\windows\system32\XDJINI.exe
C:\WINDOWS\SYSTEM32\XDJINI.exe
C:\windows\system32\K5IlSA.exe
C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
C:\documents and settings\heather\local settings\temp\ONHLKe.exe
C:\PROGRA~1\AIM95\aim.exe
C:\Documents and Settings\Heather\Application Data\eetu.exe
C:\WINDOWS\system32\w?nword.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Dell\Support\Alert\bin\AlertView.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Heather\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - Default URLSearchHook is missing
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Heather\Local Settings\Temp\vLE91XN3.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\Heather\LOCALS~1\Temp\TB_ANI~1.EXE /dcheck
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [MS Decryption Software] C:\active.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [nodovpn] C:\WINDOWS\System32\mnsnzd.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [r9tEv] C:\documents and settings\heather\local settings\temp\r9tEv.exe
O4 - HKLM\..\Run: [8n8WjZsIc] C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
O4 - HKLM\..\Run: [N5EM2mrA] C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
O4 - HKLM\..\Run: [YZqxLiFcj] C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
O4 - HKLM\..\Run: [WfPqtS8eb] C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
O4 - HKLM\..\Run: [sg] C:\documents and settings\heather\local settings\temp\sg.exe
O4 - HKLM\..\Run: [Da3a] C:\documents and settings\heather\local settings\temp\Da3a.exe
O4 - HKLM\..\Run: [Bqs] C:\documents and settings\heather\local settings\temp\Bqs.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [ntechin] C:\Documents and Settings\Heather\n20050308.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix
O4 - HKLM\..\Run: [XDJINI.exe] c:\windows\system32\XDJINI.exe
O4 - HKLM\..\Run: [K5IlSA] C:\windows\system32\K5IlSA.exe
O4 - HKLM\..\Run: [1x4u4xGxL] C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
O4 - HKLM\..\Run: [ONHLKe] C:\documents and settings\heather\local settings\temp\ONHLKe.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpyBlast] C:\Program Files\SpyBlast\SpyBlast.exe /autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Heather\Application Data\eetu.exe
O4 - HKCU\..\Run: [Yyc] C:\WINDOWS\system32\w?nword.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Help - {07136CD1-8EAB-498F-A12E-3F288C35B3CA} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {4BFE5664-D092-4C35-BE65-473FE43CE968} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Support - {9B818C83-650B-4BB2-B923-3B6BEE26D291} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1441/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
 
  • Midnight Star

    4791 Posts

    564

    0

    Posted January 22nd, 2005 18:00

    hilde,

    There's alot of 'bad' or suspicious programs running in that log, so before we begin, let's backup the entire registry and let some programs do most of the work for us.

    -

    Let's get started...



    Before we begin, let's backup the entire registry.



    Go to www.trendmicro.com, and then:

    1. Click " Free Online Scan".
    2. Click " Scan now, it's free".

    It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:

    1. Select all available drives.
    2. Check(tick) " Auto Clean".
    3. Click " Scan".

    When it completes, post back the full filename of any files that cannot be cleaned or deleted.



    If you don't already have it, download, install and run AdAware SE Personal.

    -

    Next, check for, and download any available updates:

    1. click " Check for updates now".
    2. Click " Connect".
    3. If updates(definitions) are available click " Ok", otherwise, click " Ok".
    4. Click " Finish".

    -

    Next, configure AdAware to be as effective as possible:

    1. Click the ' gear' in the upper-right hand corner of the AdAware Window.
    2. Click Scanning, and check(tick) the following:

    Scan within archives
    Scan active processes
    Scan registry
    Deep-scan registry
    Scan my IE Favorites for banned URLs
    Scan my Hosts file


    3. Click " Tweak".
    4. Click " Scanning Engine", then check(tick) the following:

    Unload recognized proceses & modules during scan

    5. Click " Cleaning Engine", then check(tick) then following:

    > Always try to unload modules before deletion
    During removal, unload Explorer and IE if necessary
    Let Winodws remove files in use at next reboot
    Delete quarantined objects after retoring


    6. Then click " Proceed"

    -

    Now, let AdAware locate and remove anything it finds, by:

    1. Click " Start".
    2. Check(tick) " perform full system scan".
    3. Click " Next".

    -

    Exit the program.



    Go to Add/Remove programs and remove(uninstall) the following, if present:


    Deals Online
    Ebates MoeMoney
    WildTangent
    Virtual Bouncer

    The above could appear anywhere within the entry. Be careful not to remove any personal or system software.



    Download LSPFix and unzip to your desktop, then run it. Now, we need to:

    1. check(tick) " I know what i'm doing".
    2. click on (highlight) each occurance of the following, one at a time:

    aklsp.dll
    dolsp.dll

    3. then click " >>", moving each one, individually, to the 'Remove' pane.
    4. (double-check, and make sure that only the above files are in the 'Remove'pane.)
    5. click " Finish >>"




    Let's download the Symantec VirtuMundo removal tool, and run it.



    Run HiJackThis then:

    1. Click " Config..."
    2. Click " Misc Tools"
    3. Click " Open Process manager"

    -

    Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

    C:\documents and settings\heather\local settings\temp\r9tEv.exe
    C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
    C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
    C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
    C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
    C:\documents and settings\heather\local settings\temp\sg.exe
    C:\documents and settings\heather\local settings\temp\Da3a.exe
    C:\documents and settings\heather\local settings\temp\Bqs.exe
    C:\Program Files\SED\SED.exe
    C:\WINDOWS\system32\wkwiwi.exe
    C:\windows\system32\XDJINI.exe
    C:\windows\system32\K5IlSA.exe
    C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
    C:\documents and settings\heather\local settings\temp\ONHLKe.exe
    C:\Documents and Settings\Heather\Application Data\eetu.exe
    C:\WINDOWS\system32\w?nword.exe

    Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



    Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:

    regsvr32 /u vLE91XN3.dll

    It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to a command prompt to save on the typing.




    Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.

    Also move the " Backups" folder, for HiJackThis, if present.



    Run HiJackThis and click " Scan", then check(tick) the following, if present:


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost

    R3 - Default URLSearchHook is missing

    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Heather\Local Settings\Temp\vLE91XN3.dll

    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

    O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\Heather\LOCALS~1\Temp\TB_ANI~1.EXE /dcheck
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
    O4 - HKLM\..\Run: [MS Decryption Software] C:\active.exe
    O4 - HKLM\..\Run: [nodovpn] C:\WINDOWS\System32\mnsnzd.exe
    O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
    O4 - HKLM\..\Run: [r9tEv] C:\documents and settings\heather\local settings\temp\r9tEv.exe
    O4 - HKLM\..\Run: [8n8WjZsIc] C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
    O4 - HKLM\..\Run: [N5EM2mrA] C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
    O4 - HKLM\..\Run: [YZqxLiFcj] C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
    O4 - HKLM\..\Run: [WfPqtS8eb] C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
    O4 - HKLM\..\Run: [sg] C:\documents and settings\heather\local settings\temp\sg.exe
    O4 - HKLM\..\Run: [Da3a] C:\documents and settings\heather\local settings\temp\Da3a.exe
    O4 - HKLM\..\Run: [Bqs] C:\documents and settings\heather\local settings\temp\Bqs.exe
    O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
    O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
    O4 - HKLM\..\Run: [ntechin] C:\Documents and Settings\Heather\n20050308.exe
    O4 - HKLM\..\Run: [XDJINI.exe] c:\windows\system32\XDJINI.exe
    O4 - HKLM\..\Run: [K5IlSA] C:\windows\system32\K5IlSA.exe
    O4 - HKLM\..\Run: [1x4u4xGxL] C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
    O4 - HKLM\..\Run: [ONHLKe] C:\documents and settings\heather\local settings\temp\ONHLKe.exe
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Heather\Application Data\eetu.exe
    O4 - HKCU\..\Run: [Yyc] C:\WINDOWS\system32\w?nword.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?

    O9 - Extra button: Help - {07136CD1-8EAB-498F-A12E-3F288C35B3CA} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: ComcastHSI - {4BFE5664-D092-4C35-BE65-473FE43CE968} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
    O9 - Extra button: Support - {9B818C83-650B-4BB2-B923-3B6BEE26D291} - http://www.comcastsupport.com (file missing) (HKCU)

    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1441/ftp.coupons.com/v3123/cpbrkpie.cab
    O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab


    Now, with all windows closed except HiJackThis, click " Fix checked".



    Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

    folders...

    C:\Program Files\SED
    C:\Program Files\WildTangent
    C:\Program Files\Ebates_MoeMoneyMaker
    C:\Program Files\VBouncer

    files...

    C:\WINDOWS\system32\wkwiwi.exe
    C:\windows\system32\XDJINI.exe
    C:\windows\system32\K5IlSA.exe
    C:\Documents and Settings\Heather\Application Data\eetu.exe
    C:\active.exe
    C:\WINDOWS\System32\mnsnzd.exe
    C:\Documents and Settings\Heather\n20050308.exe
    c:\windows\system32\aklsp.dll
    c:\windows\system32\dolsp.dll

    -

    Run " Disk Cleanup" and allow it to remove everything it finds.



    Don't reboot your system just yet and post back a new log.

    -

    Mike.
  • hilde112

    15 Posts

    564

    0

    Posted January 23rd, 2005 03:00

    The files that couldn't be cleaned when i ran the free online scan were:

    Troj Agent.Bt located at C://Documents and settings/heather/local settings/akrules.dll

    Troj Agent.Bt  located at C://Windows/system32/akrules.dll

    Troj Narrator.A  located at C://Windows/system32/cpcycy.dll

    Troj Brdupdate.D located at C://Windows/system32/e6f1873b.dll

    Troj Narrator.A  located at C://Windows/system32/hqhzhz.exe

  • Midnight Star

    4791 Posts

    564

    0

    Posted January 23rd, 2005 14:00

    hilde,
     
    When your done with all the steps in that fix, post back a new new log. When we've got that cleaned up, we'll try the online scan again (just to see if the cleanup removed them), then manually remove the files that cannot be deleted. 
     
    How's it going?
     
    Mike.
     
  • hilde112

    15 Posts

    564

    0

    Posted January 24th, 2005 00:00

    Logfile of HijackThis v1.99.0
    Scan saved at 8:06:19 PM, on 1/23/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\PROGRA~1\AIM95\aim.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\Program Files\SpyKiller\spykiller.exe
    C:\Program Files\BestPopupKiller\BestPopupKiller.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\explorer.exe
    C:\PROGRA~1\eZula\mmod.exe
    C:\PROGRA~1\WEBOFF~1\wo.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Hjcthis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
    O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [SpyBlast] C:\Program Files\SpyBlast\SpyBlast.exe /autorun
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
    O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
    O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
    O4 - Global Startup: hnhuhu.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_58/QDow_AS2.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
     
  • Midnight Star

    4791 Posts

    564

    0

    Posted January 24th, 2005 05:00

    hilde,
     
    Ok, it looks like all the above decided to shift into a bad vx2 infection, so we'll tackle that next. I'm almost certain it's going to be the newer more difficult (not impossible) to remove version, but we'll try the VX2 cleaner for AdAware SE first. We'll be using this later in the cleanup process anyway.
     
    -
     
    Let's get started...
     


    Go to Add/Remove programs and remove(uninstall) the following, if present:

    Web Offers
     
    The above could appear anywhere within the entry. Be careful not to remove any personal or system software. Let me know if your wanting to keep this, or if you just can't locate it to remove it.
     


    Go to www.trendmicro.com, and then:
     
    1.  Click " Free Online Scan".
    2.  Click " Scan now, it's free".
     
    It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
     
    1.  Select all available drives.
    2.  Check(tick) " Auto Clean".
    3.  Click " Scan".
     
    When it completes, post back the full filename of any files that cannot be cleaned or deleted.
     


    If you don't already have it, let's go to Lavasoft's VX2 Cleaner web-page, and follow the instructions to download and install the utility.
     
    -
     
    Next, run AdAware SE Personal, then:
     
    1.  Click " Add-Ons".
    2.  Double-click " VX2 Cleaner"
    3.  Click " Ok", to " Execute this tool".
    4.  If nothing is found, click " Ok", then exit the program.
     
       (or)
     
    4.  If VX2 has been found on your system, click " Clean System"
    5.  Then when it's complelely done, reboot your computer.
    6.  Repeat steps 1-4 again.
     
    Be sure to follow any instructions it might give while using it.
     


    Run HiJackThis and click " Scan", then check(tick) the following, if present:
     

    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
     
    O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
    O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
    O4 - Global Startup: hnhuhu.exe
     

    Now, with all windows closed except HiJackThis, click " Fix checked".
     


    Post back a new log.
     
    -
     
    Mike.
     
  • hilde112

    15 Posts

    564

    0

    Posted January 25th, 2005 21:00

    I ran the scan check again and the file that cannot be cleaned is:
     
    Troj Small.CB located at C://Windows/System32/appsetup.exe
  • hilde112

    15 Posts

    564

    0

    Posted January 25th, 2005 21:00

    I keep on trying to delete the 01 hosts that you told me too, but everytime I do a scan they still appear to be there.  When I run AdAware too, it says that i have VX2 on my computer, but then when i ran the VX2 cleaner it said that my computer was clean.
     
    Logfile of HijackThis v1.99.0
    Scan saved at 5:50:25 PM, on 01/25/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\PROGRA~1\AIM95\aim.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Nikon\NkView6\NkvMon.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\Program Files\SpyKiller\spykiller.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\vmss\vmss.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Hjcthis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
    O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix
    O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
    O4 - HKLM\..\Run: [ntechin] C:\WINDOWS\system32\n20050308.exe
    O4 - HKLM\..\Run: [vmss] C:\WINDOWS\system32\vmss\vmss.exe
    O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [SpyBlast] C:\Program Files\SpyBlast\SpyBlast.exe /autorun
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
    O4 - HKCU\..\RunOnce: [Web Offer] Command /c del C:\WINDOWS\system32\EZPOPS~1.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_58/QDow_AS2.cab
    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
    O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/SpSp29952.22opt/SpySpotterInstall.cab
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
     
  • Midnight Star

    4791 Posts

    564

    0

    Posted January 26th, 2005 00:00

    hilde,

    Ok, then your system has the newest version of VX2, and it'll take us a few posts to get it resolved, so let's go ahead and get started. The most important thing to remember with this infection is to not reboot your system until your instructed to; it creates new files on every reboot and will complicate the cleanup.

    Let's get started...


    Let's see if we can try and fix this; it might get a little complicated, so, if you have questions at any time, just post back.

    First, let start off by looking where no-hijack has looked before:

    1.  Downolad Dllcompare, and Killbox to your desktop.

    2.  click "Run locate.com".

         When the scan is complete, you will see: Completed the scan, Click Compare to Continue

    3. click "Compare".

        In a few minutes it be Completed


    4. click "Make a Log of what was Found".

    5. Post that back as a reply to this post.


    Mike.

  • hilde112

    15 Posts

    562

    0

    Posted January 26th, 2005 01:00

    Here's the log
     
    *    DLLCompare Log version()
    Files Found that Windows does not See or cannot Access
    *Not everything listed here means you are infected!
    ________________________________________________
    C:\WINDOWS\SYSTEM32\hr8o05~1.dll   Tue Jan 25 2005   6:36:36p  ..S.R        223,862   218.61 K
    C:\WINDOWS\SYSTEM32\hrpm05~1.dll   Fri Jan 21 2005  10:02:14p  ..S.R        223,407   218.17 K
    C:\WINDOWS\SYSTEM32\itsecsnp.dll   Tue Jan 25 2005   6:36:36p  ..S.R        223,477   218.24 K
    C:\WINDOWS\SYSTEM32\k5ilsa.dll     Fri Jan 21 2005  10:03:00p  A..H.            106     0.10 K
    C:\WINDOWS\SYSTEM32\o2lu0c~1.dll   Sat Jan 22 2005   2:06:46p  ..S.R        223,477   218.24 K
    C:\WINDOWS\SYSTEM32\xdjini.dll     Sat Jan 22 2005  10:03:40p  ..SH.            475     0.46 K
    ________________________________________________
    1,299 items found:  1,299 files (6 H/S), 0 directories.
    Total of file sizes:  266,976,850 bytes    254.61 M
    Administrator Account =  True
    --------------------End log---------------------
  • hilde112

    15 Posts

    307

    0

    Posted January 26th, 2005 02:00

    C:/Windows/system32/hr8o05l3e.dll which is located in the control panel folder

    C:/Windows/system32/Navlogon.dll located in the Navlogon folder