Unsolved
This post is more than 5 years old
81 Posts
0
8090
May 29th, 2006 03:00
Computer destroyed
Hi all,
Thank you all for your help on this issue, I appreciate everyone's helps and support with all the new virus and spyware problems. My computer is acting very slow, many programs do not work, and most importantly, the internet has shut down completely (comcast and dell support has ruled OUT both hardware and internet problems as the cause, saying it is software). Here is my HJT log...
Logfile of HijackThis v1.99.1
Scan saved at 11:56:02 PM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan saved at 11:56:02 PM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\mrlhqxd.exe
C:\WINDOWS\wmapsrvs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\mrlhqxdA.exe
C:\WINDOWS\sys010913258112.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\mrlhqxd.exe
C:\WINDOWS\wmapsrvs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\mrlhqxdA.exe
C:\WINDOWS\sys010913258112.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://www.xosearchox.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blingo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Tz] C:\documents and settings\scott\local settings\temp\Tz.exe
O4 - HKLM\..\Run: [nkx] C:\WINDOWS\nkx.exe
O4 - HKLM\..\Run: [d38] C:\documents and settings\scott\local settings\temp\d38.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
O4 - HKLM\..\Run: [VR7Bo] C:\windows\VR7Bo.exe
O4 - HKLM\..\Run: [IWfsJVD8r] C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
O4 - HKLM\..\Run: [doKx] C:\documents and settings\scott\local settings\temp\doKx.exe
O4 - HKLM\..\Run: [Iaeqgqdw] C:\Program Files\Qccg\Fxsc.exe
O4 - HKLM\..\Run: [EZXrpX] C:\documents and settings\scott\local settings\temp\EZXrpX.exe
O4 - HKLM\..\Run: [gZ] C:\documents and settings\scott\local settings\temp\gZ.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\veev5995.dll"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [vrjdjta] c:\windows\system32\vrjdjta.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Ms Java] C:\Documents and Settings\Scott new\zangme.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [keyboard] C:\\keyboard22.exe
O4 - HKLM\..\Run: [newname] C:\\newname22.exe
O4 - HKLM\..\Run: [mrlhqxdA] C:\WINDOWS\mrlhqxdA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [sys010913258112] C:\WINDOWS\sys010913258112.exe
O4 - HKLM\..\Run: [w25f697f.dll] RUNDLL32.EXE w25f697f.dll,I2 001045e2025f697f
O4 - HKCU\..\Run: [COM Service] C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [fB04RWj4V] dbnxcl40.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: qescp.exe.tmp
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra 'Tools' menuitem: Popup Blocker Options - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\mrlhqxd.exe
O23 - Service: Microsoft WMI Performance Adapter AddOn (WMIPerAddOn) - Unknown owner - C:\WINDOWS\wmapsrvs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blingo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Tz] C:\documents and settings\scott\local settings\temp\Tz.exe
O4 - HKLM\..\Run: [nkx] C:\WINDOWS\nkx.exe
O4 - HKLM\..\Run: [d38] C:\documents and settings\scott\local settings\temp\d38.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
O4 - HKLM\..\Run: [VR7Bo] C:\windows\VR7Bo.exe
O4 - HKLM\..\Run: [IWfsJVD8r] C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
O4 - HKLM\..\Run: [doKx] C:\documents and settings\scott\local settings\temp\doKx.exe
O4 - HKLM\..\Run: [Iaeqgqdw] C:\Program Files\Qccg\Fxsc.exe
O4 - HKLM\..\Run: [EZXrpX] C:\documents and settings\scott\local settings\temp\EZXrpX.exe
O4 - HKLM\..\Run: [gZ] C:\documents and settings\scott\local settings\temp\gZ.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\veev5995.dll"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [vrjdjta] c:\windows\system32\vrjdjta.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Ms Java] C:\Documents and Settings\Scott new\zangme.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [keyboard] C:\\keyboard22.exe
O4 - HKLM\..\Run: [newname] C:\\newname22.exe
O4 - HKLM\..\Run: [mrlhqxdA] C:\WINDOWS\mrlhqxdA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [sys010913258112] C:\WINDOWS\sys010913258112.exe
O4 - HKLM\..\Run: [w25f697f.dll] RUNDLL32.EXE w25f697f.dll,I2 001045e2025f697f
O4 - HKCU\..\Run: [COM Service] C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [fB04RWj4V] dbnxcl40.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: qescp.exe.tmp
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra 'Tools' menuitem: Popup Blocker Options - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\mrlhqxd.exe
O23 - Service: Microsoft WMI Performance Adapter AddOn (WMIPerAddOn) - Unknown owner - C:\WINDOWS\wmapsrvs.exe
If anyone has any input on what may be the cause and possible solutions, please contact me at
ski9855@yahoo.com
No Events found!


imrahil388
81 Posts
0
June 4th, 2006 16:00
agrarianmonk
71 Posts
0
June 4th, 2006 20:00
if not, you'll need to log in as the administrator and run the tools.
if the administrator account is not shown at the XP logon screen, you can press "Ctrl + alt + dlt" simultaneously, which should bring up the traditional logon screen in which you can type in a user name. Type in administrator and your administrator password (if you set one) to logon.
imrahil388
81 Posts
0
June 9th, 2006 00:00
Hi,
my account IS an administrator's account and can access all tools necessary
_KotaGuy
99 Posts
0
June 9th, 2006 20:00
'monk is away doing finals at the moment... I'm going to try and see if I can help you out with this. As you've said... your computer is destroyed. It may be beyond the point where we can properly fix it and even if we do get it working good again a reformat and reinstall of Windows may be needed as you have some severely nasty infections that really mess Windows up... including the Sony RootKit and a Keylogger that has been logging all your Keystrokes to a file(mslg.blf). Your computer has been totally comprimised.
Though I will try my best to clean this up for you... I cannot guarantee the security of your System afterwards. As such, I really do think a format of you hard drive and a clean reinstall of Windows is your best course of action.
With that said, if you wish to try and clean it, please do the following.
Download Killbox. Extract it to its own folder on your Desktop. Don't run it yet.
Copy/paste the rest of these instructions into a new notepad document for reference during the fix and save it to your Desktop.
Click Start>Run type in appwiz.cpl and hit Enter. From the list uninstall the following:
Bald Head Island Screen Saver
I.E. Host
Microsoft AntiSpyware(this beta is over and is useless now)
SafeGuard Popup Blocker Pro FREE Edition
Snowy Scenes Screen Saver
Viewpoint Media Player
Web Browser Component Manager
Windows SR 2.0
Click Start>Run type in "C:\Program Files\SurfSidekick 3\Ssk.exe" /u
Click Start>Run type in services.msc and hit Enter. From the list look for .NET Framework Service. Right click on it and choose Properties. Stop the service and change the StartUp Type to Disabled. Do the same for each of the following:
AutoComplete Service
Windows Overlay Components
Microsoft WMI Performance Adapter AddOn
Exit the Services console.
Run and scan with HijackThis. With all browsers and windows closed(including this one), place checks beside the following and fix:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.xosearchox.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blingo.com/
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=userinit.exe,abejtsm.exe
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Tz] C:\documents and settings\scott\local settings\temp\Tz.exe
O4 - HKLM\..\Run: [nkx] C:\WINDOWS\nkx.exe
O4 - HKLM\..\Run: [d38] C:\documents and settings\scott\local settings\temp\d38.exe
O4 - HKLM\..\Run: [VR7Bo] C:\windows\VR7Bo.exe
O4 - HKLM\..\Run: [IWfsJVD8r] C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
O4 - HKLM\..\Run: [doKx] C:\documents and settings\scott\local settings\temp\doKx.exe
O4 - HKLM\..\Run: [Iaeqgqdw] C:\Program Files\Qccg\Fxsc.exe
O4 - HKLM\..\Run: [EZXrpX] C:\documents and settings\scott\local settings\temp\EZXrpX.exe
O4 - HKLM\..\Run: [gZ] C:\documents and settings\scott\local settings\temp\gZ.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\veev5995.dll"
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [vrjdjta] c:\windows\system32\vrjdjta.exe
O4 - HKLM\..\Run: [Ms Java] C:\Documents and Settings\Scott new\zangme.exe
O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
O4 - HKLM\..\Run: [w25f697f.dll] RUNDLL32.EXE w25f697f.dll,I2 001045e2025f697f
O4 - HKCU\..\Run: [COM Service] C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [fB04RWj4V] dbnxcl40.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra 'Tools' menuitem: Popup Blocker Options - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\hr2205foe.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\i0420ahoed4c0.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\i0420ahoed4c0.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\mrlhqxd.exe (file missing)
O23 - Service: Microsoft WMI Performance Adapter AddOn (WMIPerAddOn) - Unknown owner - C:\WINDOWS\wmapsrvs.exe (file missing
Still in HijackThis... click the Config button. Then click the Misc Tools button. Then click the Delete an NT Service button. In the Text Field of the window that pops up type in .NET Framework Service and click OK. Do the same for each of the following:
AutoComplete Service
Windows Overlay Components
Microsoft WMI Performance Adapter AddOn
Run KillBox. From the Tools Menu header... click Delete Temp Files. Select the Delete on Reboot option. Click the All Files button. Copy/paste the following list to your clipboard by hiliting them and pressing Ctrl+C:
C:\WINDOWS\nkx.exe
C:\windows\VR7Bo.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\mrlhqxd.exe
C:\WINDOWS\wmapsrvs.exe
C:\WINDOWS\system32\ogwfj.exe
C:\WINDOWS\system32\abejtsm.exe
C:\WINDOWS\system32\mscnt.exe
C:\WINDOWS\system32\veev5995.dll
C:\WINDOWS\system32\Dyf0p5.exe
C:\WINDOWS\system32\winshost.exe
c:\windows\system32\vrjdjta.exe
C:\WINDOWS\system32\dmonwv.dll
C:\WINDOWS\system32\hr2205foe.dll
C:\WINDOWS\system32\i0420ahoed4c0.dll
C:\WINDOWS\system32\onbcconf.dll
C:\WINDOWS\System32\hr8s05l7e.dll
C:\WINDOWS\System32\SY2EVNT1.DLL
C:\WINDOWS\System32\enl6l13s1.dll
C:\WINDOWS\System32\fTultrep.dll
C:\WINDOWS\System32\lxawd12n.dll
C:\WINDOWS\System32\m628lgfu1628.dll
C:\WINDOWS\System32\MFVCR71.dll
C:\WINDOWS\System32\mv6ql9j51.dll
C:\WINDOWS\System32\inwphbk.dll
C:\WINDOWS\System32\njmssvc.dll
C:\WINDOWS\System32\lv2409fqe.dll
C:\WINDOWS\System32\fp0m03d1e.dll
C:\WINDOWS\System32\sjcbase.dll
C:\WINDOWS\System32\ir8ml5l11.dll
C:\WINDOWS\System32\MCVCP71.dll
C:\WINDOWS\System32\q686lgls16q6.dll
C:\WINDOWS\System32\devxdec_0411.dll
C:\WINDOWS\System32\dnp6017se.dll
C:\WINDOWS\System32\mfwstr10.dll
C:\WINDOWS\System32\karberos.dll
C:\WINDOWS\System32\lyfax10N.dll
C:\WINDOWS\System32\ir66l5js1.dll
C:\WINDOWS\System32\iwrtrmgr.dll
C:\WINDOWS\System32\kt2sl7f71.dll
C:\WINDOWS\System32\s4pule791h.dll
C:\WINDOWS\System32\sicurity.dll
C:\WINDOWS\System32\l2l6lc3s1f.dll
C:\WINDOWS\System32\jtj8071ue.dll
C:\WINDOWS\System32\m0pola731d.dll
C:\WINDOWS\System32\aecmgr.dll
C:\WINDOWS\System32\Oxve9.4ed
C:\WINDOWS\System32\Ywt4.kls
C:\WINDOWS\System32\FmrCj.b90
C:\WINDOWS\System32\GnsDk.b90
C:\WINDOWS\System32\4A159A46B7.sys
C:\WINDOWS\System32\mslg.blf
C:\WINDOWS\System32\VarEdQ6.4sn
C:\WINDOWS\System32\IpuFmd.017
C:\WINDOWS\System32\TafqX5mo.dvc
C:\Program Files\Qccg\Fxsc.exe
C:\Program Files\MalwareWipe\MalwareWipe.exe
C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
C:\Documents and Settings\Scott new\zangme.exe
C:\documents and settings\scott\local settings\temp\Tz.exe
C:\documents and settings\scott\local settings\temp\d38.exe
C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
C:\documents and settings\scott\local settings\temp\doKx.exe
C:\documents and settings\scott\local settings\temp\EZXrpX.exe
C:\documents and settings\scott\local settings\temp\gZ.exe
C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com
Return to Killbox and paste the files into the Text Field by clicking in it and pressing Ctrl+V. Click the Remove Menu header and select RemovePendingFileRenameOperations if it isn't greyed out. Click the red and white "X" button. Then follow the prompts to reboot your computer.
Once your Computer had rebooted... Post a new HijackThis log please.
imrahil388
81 Posts
0
June 10th, 2006 03:00
Scan saved at 11:54:54 PM, on 6/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\gpl6l33s1.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\lslmb12n.dll
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
_KotaGuy
99 Posts
0
June 10th, 2006 04:00
If that Keylogger file is still there... its possible, yes. I'd advise you to keep this machine off the net as much as possible. If you have it networked with any others wherever it is(home/business)... I suggest keeping it off that network as well to prevent the spread of the infections to any other machines.
OK... with most of that other junk out of the way... hopefully some of the tools I will need to use will work. Seems you have been having problems with them.
First though... visit this page and follow the instructions laid out by Grinler to remove the Sony RootKit.
Then I need you to run Option 1 of L2MFix that 'monk had you download earlier. Post the log when it has finished its scan.
Thanks!
Message Edited by _KotaGuy on 06-09-200611:34 PM
Message Edited by _KotaGuy on 06-09-200611:36 PM
imrahil388
81 Posts
0
June 11th, 2006 02:00
second half of report (sorry it couldn't fit in one page)
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{F802F260-519B-11D1-BB5D-0060974C6013}"="ICQ Shell Extension"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{BB7DF450-F119-11CD-8465-00AA00425D90}"="Microsoft Access Custom Icon Handler"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{0A8CE102-FA03-4612-9BEE-7FE5452F4CB1}"="Search Bar"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Property Sheet Shell Extension"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}"=""
"{4C9AD2A2-1DCC-45C8-B761-FF2053A6D167}"=""
"{CC680CC8-DEDE-49F1-B613-5223E2216B4F}"=""
"{3D1D54C1-2C26-4F48-A07B-C670AB2C3363}"=""
"{D7934647-A59A-4D27-902E-BB783CF9C4A2}"=""
**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}]
@=""
"IDEx"="ADDR"
[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}\InprocServer32]
@="C:\\WINDOWS\\system32\\dytmsft.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}\InprocServer32]
@="C:\\WINDOWS\\system32\\sosvc.dll"
"ThreadingModel"="Apartment"
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}\InprocServer32]
@="C:\\WINDOWS\\system32\\jrdw400.dll"
"ThreadingModel"="Apartment"
**********************************************************************************
Files Found are not all bad files:
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 7CA7-1973
Directory of C:\WINDOWS\System32
06/10/2006 11:01 PM 234,783 jrdw400.dll
06/09/2006 11:56 PM 234,288 k2260cfsef260.dll
06/09/2006 11:51 PM
06/09/2006 11:48 PM 234,288 dodskres.dll
06/04/2006 04:00 PM 234,288 m8ls0i37e8.dll
06/04/2006 03:28 PM 234,783 gpl6l33s1.dll
06/04/2006 11:22 AM 234,783 sosvc.dll
06/03/2006 03:34 PM 234,288 mlxml3.dll
06/03/2006 11:42 AM 234,783 apvpack.dll
06/02/2006 11:21 AM 234,288 uderenv.dll
06/02/2006 11:11 AM 234,288 mfdtctm.dll
06/01/2006 11:38 PM 234,601 g240lchm1f4a.dll
06/01/2006 11:27 PM 234,601 uwnpui.dll
06/01/2006 05:22 PM 234,303 wksdmoe2.dll
06/01/2006 05:22 PM 234,288 wcpshell.dll
06/01/2006 05:20 PM 234,063 enjul1191.dll
06/01/2006 05:08 PM 234,063 cbm.dll
06/01/2006 03:53 PM 234,288 ihrnonce.dll
06/01/2006 02:08 AM 234,063 p2p6lc7s1f.dll
06/01/2006 12:13 AM 234,063 mzrapi.dll
06/01/2006 12:13 AM 235,920 ktn8l75u1.dll
06/01/2006 12:01 AM 234,063 FBNFCOPY.dll
05/31/2006 11:59 PM 236,345 j44o0eh3eh4.dll
05/31/2006 11:25 AM 236,345 nytapi32.dll
05/31/2006 10:00 AM 234,063 onbcconf.dll
05/30/2006 09:30 PM 236,345 SY2EVNT1.DLL
05/30/2006 09:18 PM 235,510 fTultrep.dll
05/30/2006 10:03 AM 235,510 lxawd12n.dll
05/29/2006 08:31 PM 235,510 m628lgfu1628.dll
05/29/2006 08:31 PM 235,510 MFVCR71.dll
05/29/2006 08:31 PM 237,079 mv6ql9j51.dll
05/29/2006 08:21 PM 234,080 inwphbk.dll
05/29/2006 08:01 PM 234,080 njmssvc.dll
05/29/2006 05:53 PM 234,080 lv2409fqe.dll
05/27/2006 09:44 AM 234,183 fp0m03d1e.dll
05/27/2006 12:53 AM 234,080 sjcbase.dll
05/27/2006 12:52 AM 236,015 ir8ml5l11.dll
05/27/2006 12:22 AM 236,015 MCVCP71.dll
05/26/2006 11:35 AM 234,080 q686lgls16q6.dll
05/26/2006 11:22 AM 234,080 devxdec_0411.dll
05/26/2006 11:22 AM 234,751 dnp6017se.dll
05/25/2006 09:45 PM 235,904 mfwstr10.dll
05/25/2006 09:20 PM 234,080 karberos.dll
05/25/2006 05:01 PM 235,904 lyfax10N.dll
05/25/2006 05:01 PM 234,080 ir66l5js1.dll
05/25/2006 02:49 PM 235,904 iwrtrmgr.dll
05/25/2006 02:49 PM 234,111 kt2sl7f71.dll
05/24/2006 06:47 PM 235,584 s4pule791h.dll
05/24/2006 06:08 PM 235,904 sicurity.dll
05/24/2006 05:04 PM 235,904 l2l6lc3s1f.dll
05/23/2006 11:25 PM 235,089 jtj8071ue.dll
05/23/2006 11:20 PM 235,642 m0pola731d.dll
12/29/2005 12:54 AM 475 aecmgr.dll
05/31/2005 08:09 PM 846 Oxve9.4ed
02/28/2005 05:49 PM 846 Ywt4.kls
02/27/2005 05:49 PM 846 FmrCj.b90
02/23/2005 04:46 PM 846 GnsDk.b90
01/29/2005 09:33 PM 56 4A159A46B7.sys
01/29/2005 09:33 PM 1,682 KGyGaAvL.sys
05/24/2004 10:46 PM 1,188 VarEdQ6.4sn
05/12/2004 05:51 PM 1,104 IpuFmd.017
05/07/2004 06:48 PM 1,104 TafqX5mo.dvc
01/17/2003 09:37 AM
61 File(s) 11,987,936 bytes
2 Dir(s) 8,530,018,304 bytes free
imrahil388
81 Posts
0
June 11th, 2006 02:00
Hi,
the computer doesn't seem to lock up as badly anymore! but maybe I'm just looking for that too happen.
Anyways I tried to delete the rootkit file and got this message: (and the aries file wasn't in the system32 folder).
"[SC] OpenService FAILED 1060:
The specified service does not exist as an installed service."
Here is the new log for l2fix in multiple posts:
L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ModuleUsage]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\gpl6l33s1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MSSYCLM]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\m8ls0i37e8.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
**********************************************************************************
useragent:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48690FE4-FD37-1EA2-28EB-42ED3079A72D}"=""
**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
imrahil388
81 Posts
0
June 11th, 2006 03:00
Hi,
Yes, the cmd thing i copied directly and it still says does not exist.
Anyways I ran l2m fix option 2 and it asked for a password again. There is a log in the l2m folder where it stores if it doesn't open on its own. Here is that log...
_KotaGuy
99 Posts
0
June 11th, 2006 03:00
This cmd /k sc delete $sys$aries would be this...
cmd[space]/k[space]sc[space]delete[space]$sys$aries
Is that how you entered the command or did you not leave any spaces where I've put in [space]?
Anyways... though I know L2MFix has choked on you trying this step... can your try Option 2 in L2MFix again for me please.
I'm hoping that with some of the other junk out of the way the tool will work properly now.
If it works... post the log please... if not let me know... we may need to do this the hard way.
Message Edited by _KotaGuy on 06-10-200610:10 PM
imrahil388
81 Posts
0
June 11th, 2006 03:00
L2mfix 051206
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*
zip error: Nothing to do! (backup.zip)
updating: backregs/notibac.reg (164 bytes security) (deflated 87%)
_KotaGuy
99 Posts
0
June 11th, 2006 04:00
We won't worry about that tool then.
Download Dr.Web CureIt to the desktop.
Message Edited by _KotaGuy on 06-10-200611:06 PM
imrahil388
81 Posts
0
June 11th, 2006 21:00
imrahil388
81 Posts
0
June 11th, 2006 22:00
sorry, this is a bit hard to read...
FIRST HALF
ywgbjn.exe;C:\WINDOWS\system32;Trojan.Qoologic;Will be cured after reboot.;
ogwfj.exe;C:\WINDOWS\system32;Trojan.Qoologic;Will be cured after reboot.;
explorer.exe;C:\WINDOWS\APPATC~1;Adware.ClickSpring;;
sosvc.dll;C:\WINDOWS\system32;Adware.Look2me;;
f4j20e1oeh.dll;C:\WINDOWS\system32;Adware.Look2me;;
sysdrv.bat;C:\;Adware.DollarRevenue;;
w25f697f.dll;C:\bintheredunthat;Adware.Lc;;
WxBug.EXE;C:\Program Files\AIM\Sysfiles;Adware.Aws;;
CA304F30-139B-4CD3-A67F-BF00DF;C:\Program Files\Microsoft AntiSpyware\Quarantine\11509694-EA6B-4C88-89EC-A25697;Trojan.AproposAd;Deleted.;
1E911C9F-7069-49E0-BD35-72CDB3;C:\Program Files\Microsoft AntiSpyware\Quarantine\5AEFB14F-266B-4B0E-91F1-A1FF4B;Trojan.AproposAd;Deleted.;
C1A12506-66E3-4450-A023-70D788;C:\Program Files\Microsoft AntiSpyware\Quarantine\5AEFB14F-266B-4B0E-91F1-A1FF4B;Trojan.AproposAd;Deleted.;
1C5D6FFB-13EB-4653-AC20-A22DC5;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
513921D9-DB0A-4851-8BEC-6CE9CB;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
B600EC81-6CEA-406F-A9F0-0BE6D4;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
D86A6FDF-4EA0-4E38-BCB9-E684AA;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
FF5374EA-79FB-4E7A-B8BE-AF7C72;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
195DB8D3-5D70-4A3F-B2C9-3679A0;C:\Program Files\Microsoft AntiSpyware\Quarantine\68361A23-1ED2-4287-B4D4-5A6D09;Adware.nCase;;
44FB0227-32A1-439B-BB74-ECC98C;C:\Program Files\Microsoft AntiSpyware\Quarantine\85BCE34F-268B-42F4-9CB0-CD9565;Adware.nCase;;
8A81DBE9-2E99-452C-B3C5-50B31E;C:\Program Files\Microsoft AntiSpyware\Quarantine\A2FAE294-BEDB-4CC2-8E53-DAF374;Trojan.AproposAd;Deleted.;
234465E3-0907-4BE3-922C-1AC0BA;C:\Program Files\Microsoft AntiSpyware\Quarantine\CF541902-EDE0-4F8B-A84A-4C3329;Trojan.AproposAd;Deleted.;
4670DF8C-8231-4A42-AD36-8529E0;C:\Program Files\Microsoft AntiSpyware\Quarantine\EA534964-404F-453F-8E68-7C6819;Trojan.AproposAd;Deleted.;
nicociru.html\Javascript.0;C:\Program Files\Movie Maker\nicociru.html;Trojan.Click.1237;;
nicociru.html;C:\Program Files\Movie Maker;Archive contains infected objects;Moved.;
A0460471.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.9440;Deleted.;
A0460727.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Probably BACKDOOR.Trojan;;
A0461445.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;BackDoor.Generic.1219;Deleted.;
A0461446.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;BackDoor.Generic.1219;Deleted.;
A0461447.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Enbrow;;
A0461448.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Nexus;;
A0461449.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.NewDotNet;;
A0462445.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0462456.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.8290;Deleted.;
A0462457.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.DollarRevenue;;
A0462458.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.10113;Deleted.;
A0462459.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.DollarRevenue;;
A0462460.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.8453;Deleted.;
A0462461.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.DollarRevenue;;
A0462462.EXE;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.NewDotNet;;
A0462469.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Dh;;
A0462470.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463445.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463476.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463477.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463485.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463486.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463494.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463495.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463514.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463522.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0464546.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464547.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464552.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464553.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464555.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464564.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464566.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Trojan.Qoologic;Deleted.;
A0464567.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464569.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464574.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464587.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464588.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Trojan.Qoologic;Deleted.;
A0464589.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464590.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Trojan.Qoologic;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951\snapshot;Trojan.Qoologic;Deleted.;
A0464601.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464602.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464608.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0464616.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464617.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464618.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464620.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464621.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464630.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464632.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464634.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464639.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464652.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464653.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0464654.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464655.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0464666.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464673.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0465675.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0465682.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0466682.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0466700.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0466701.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
MFEX-1.DAT;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952\snapshot;Trojan.Qoologic;Deleted.;
A0466713.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466714.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466719.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0466729.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466732.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466733.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466734.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466741.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466777.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466778.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466785.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466786.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466787.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466788.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466790.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466791.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466798.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466800.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466802.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466807.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466820.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466821.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0466822.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466823.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0466831.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467831.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0467845.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467846.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467847.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467848.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467849.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}
imrahil388
81 Posts
0
June 11th, 2006 22:00
Logfile of HijackThis v1.99.1
Scan saved at 7:07:23 PM, on 6/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [xnksjl] C:\WINDOWS\system32\ywgbjn.exe reg_run
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ukrtk] C:\WINDOWS\system32\ywgbjn.exe reg_run
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: qescp.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\e8200ifme82a0.dll
O20 - Winlogon Notify: URL - C:\WINDOWS\system32\f4j20e1oeh.dll
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe