Unsolved

This post is more than 5 years old

81 Posts

8090

May 29th, 2006 03:00

Computer destroyed

Hi all,
 
Thank you all for your help on this issue, I appreciate everyone's helps and support with all the new virus and spyware problems.  My computer is acting very slow, many programs do not work, and most importantly, the internet has shut down completely (comcast and dell support has ruled OUT both hardware and internet problems as the cause, saying it is software).  Here is my HJT log...
 
Logfile of HijackThis v1.99.1
Scan saved at 11:56:02 PM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\mrlhqxd.exe
C:\WINDOWS\wmapsrvs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\mrlhqxdA.exe
C:\WINDOWS\sys010913258112.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.xosearchox.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blingo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Tz] C:\documents and settings\scott\local settings\temp\Tz.exe
O4 - HKLM\..\Run: [nkx] C:\WINDOWS\nkx.exe
O4 - HKLM\..\Run: [d38] C:\documents and settings\scott\local settings\temp\d38.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
O4 - HKLM\..\Run: [VR7Bo] C:\windows\VR7Bo.exe
O4 - HKLM\..\Run: [IWfsJVD8r] C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
O4 - HKLM\..\Run: [doKx] C:\documents and settings\scott\local settings\temp\doKx.exe
O4 - HKLM\..\Run: [Iaeqgqdw] C:\Program Files\Qccg\Fxsc.exe
O4 - HKLM\..\Run: [EZXrpX] C:\documents and settings\scott\local settings\temp\EZXrpX.exe
O4 - HKLM\..\Run: [gZ] C:\documents and settings\scott\local settings\temp\gZ.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\veev5995.dll"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [vrjdjta] c:\windows\system32\vrjdjta.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Ms Java] C:\Documents and Settings\Scott new\zangme.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [keyboard] C:\\keyboard22.exe
O4 - HKLM\..\Run: [newname] C:\\newname22.exe
O4 - HKLM\..\Run: [mrlhqxdA] C:\WINDOWS\mrlhqxdA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [sys010913258112] C:\WINDOWS\sys010913258112.exe
O4 - HKLM\..\Run: [w25f697f.dll] RUNDLL32.EXE w25f697f.dll,I2 001045e2025f697f
O4 - HKCU\..\Run: [COM Service] C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [fB04RWj4V] dbnxcl40.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: qescp.exe.tmp
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra 'Tools' menuitem: Popup Blocker Options - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\mrlhqxd.exe
O23 - Service: Microsoft WMI Performance Adapter AddOn (WMIPerAddOn) - Unknown owner - C:\WINDOWS\wmapsrvs.exe
 
If anyone has any input on what may be the cause and possible solutions, please contact me at ski9855@yahoo.com

81 Posts

June 4th, 2006 16:00

I am running it through my personal account.  There are only two on the computer, and when I boot in safe mode the account "administrator" shows up but I never go to it

June 4th, 2006 20:00

do you know if your personal account is an 'administrator' account?

if not, you'll need to log in as the administrator and run the tools.


if the administrator account is not shown at the XP logon screen, you can press "Ctrl + alt + dlt" simultaneously, which should bring up the traditional logon screen in which you can type in a user name. Type in administrator and your administrator password (if you set one) to logon.

81 Posts

June 9th, 2006 00:00

Hi,

my account IS an administrator's account and can access all tools necessary

99 Posts

June 9th, 2006 20:00

Hi imrahil!

'monk is away doing finals at the moment... I'm going to try and see if I can help you out with this. As you've said... your computer is destroyed. It may be beyond the point where we can properly fix it and even if we do get it working good again a reformat and reinstall of Windows may be needed as you have some severely nasty infections that really mess Windows up... including the Sony RootKit and a Keylogger that has been logging all your Keystrokes to a file(mslg.blf). Your computer has been totally comprimised.

Though I will try my best to clean this up for you... I cannot guarantee the security of your System afterwards. As such, I really do think a format of you hard drive and a clean reinstall of Windows is your best course of action.

With that said, if you wish to try and clean it, please do the following.

Download Killbox. Extract it to its own folder on your Desktop. Don't run it yet.

Copy/paste the rest of these instructions into a new notepad document for reference during the fix and save it to your Desktop.

Click Start>Run type in appwiz.cpl and hit Enter. From the list uninstall the following:

Bald Head Island Screen Saver
I.E. Host
Microsoft AntiSpyware(this beta is over and is useless now)
SafeGuard Popup Blocker Pro FREE Edition
Snowy Scenes Screen Saver
Viewpoint Media Player
Web Browser Component Manager
Windows SR 2.0


Click Start>Run type in "C:\Program Files\SurfSidekick 3\Ssk.exe" /u

Click Start>Run type in services.msc and hit Enter. From the list look for .NET Framework Service. Right click on it and choose Properties. Stop the service and change the StartUp Type to Disabled. Do the same for each of the following:

AutoComplete Service
Windows Overlay Components
Microsoft WMI Performance Adapter AddOn


Exit the Services console.

Run and scan with HijackThis. With all browsers and windows closed(including this one), place checks beside the following and fix:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.xosearchox.com/sp2.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blingo.com/
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=userinit.exe,abejtsm.exe
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Tz] C:\documents and settings\scott\local settings\temp\Tz.exe
O4 - HKLM\..\Run: [nkx] C:\WINDOWS\nkx.exe
O4 - HKLM\..\Run: [d38] C:\documents and settings\scott\local settings\temp\d38.exe
O4 - HKLM\..\Run: [VR7Bo] C:\windows\VR7Bo.exe
O4 - HKLM\..\Run: [IWfsJVD8r] C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
O4 - HKLM\..\Run: [doKx] C:\documents and settings\scott\local settings\temp\doKx.exe
O4 - HKLM\..\Run: [Iaeqgqdw] C:\Program Files\Qccg\Fxsc.exe
O4 - HKLM\..\Run: [EZXrpX] C:\documents and settings\scott\local settings\temp\EZXrpX.exe
O4 - HKLM\..\Run: [gZ] C:\documents and settings\scott\local settings\temp\gZ.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\veev5995.dll"
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [vrjdjta] c:\windows\system32\vrjdjta.exe
O4 - HKLM\..\Run: [Ms Java] C:\Documents and Settings\Scott new\zangme.exe
O4 - HKLM\..\Run: [MalwareWipe] C:\Program Files\MalwareWipe\MalwareWipe.exe /h
O4 - HKLM\..\Run: [w25f697f.dll] RUNDLL32.EXE w25f697f.dll,I2 001045e2025f697f
O4 - HKCU\..\Run: [COM Service] C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [fB04RWj4V] dbnxcl40.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O9 - Extra 'Tools' menuitem: Popup Blocker Options - {D5770C25-E0F4-4bb9-BCB6-DB17F7BFBB7F} - C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\hr2205foe.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\i0420ahoed4c0.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\i0420ahoed4c0.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\INTERN~2\autocomp.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\mrlhqxd.exe (file missing)
O23 - Service: Microsoft WMI Performance Adapter AddOn (WMIPerAddOn) - Unknown owner - C:\WINDOWS\wmapsrvs.exe (file missing

Still in HijackThis... click the Config button. Then click the Misc Tools button. Then click the Delete an NT Service button. In the Text Field of the window that pops up type in .NET Framework Service and click OK. Do the same for each of the following:

AutoComplete Service
Windows Overlay Components
Microsoft WMI Performance Adapter AddOn


Run KillBox. From the Tools Menu header... click Delete Temp Files. Select the Delete on Reboot option. Click the All Files button. Copy/paste the following list to your clipboard by hiliting them and pressing Ctrl+C:

C:\WINDOWS\nkx.exe
C:\windows\VR7Bo.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\mrlhqxd.exe
C:\WINDOWS\wmapsrvs.exe
C:\WINDOWS\system32\ogwfj.exe
C:\WINDOWS\system32\abejtsm.exe
C:\WINDOWS\system32\mscnt.exe
C:\WINDOWS\system32\veev5995.dll
C:\WINDOWS\system32\Dyf0p5.exe
C:\WINDOWS\system32\winshost.exe
c:\windows\system32\vrjdjta.exe
C:\WINDOWS\system32\dmonwv.dll
C:\WINDOWS\system32\hr2205foe.dll
C:\WINDOWS\system32\i0420ahoed4c0.dll
C:\WINDOWS\system32\onbcconf.dll
C:\WINDOWS\System32\hr8s05l7e.dll
C:\WINDOWS\System32\SY2EVNT1.DLL
C:\WINDOWS\System32\enl6l13s1.dll
C:\WINDOWS\System32\fTultrep.dll
C:\WINDOWS\System32\lxawd12n.dll
C:\WINDOWS\System32\m628lgfu1628.dll
C:\WINDOWS\System32\MFVCR71.dll
C:\WINDOWS\System32\mv6ql9j51.dll
C:\WINDOWS\System32\inwphbk.dll
C:\WINDOWS\System32\njmssvc.dll
C:\WINDOWS\System32\lv2409fqe.dll
C:\WINDOWS\System32\fp0m03d1e.dll
C:\WINDOWS\System32\sjcbase.dll
C:\WINDOWS\System32\ir8ml5l11.dll
C:\WINDOWS\System32\MCVCP71.dll
C:\WINDOWS\System32\q686lgls16q6.dll
C:\WINDOWS\System32\devxdec_0411.dll
C:\WINDOWS\System32\dnp6017se.dll
C:\WINDOWS\System32\mfwstr10.dll
C:\WINDOWS\System32\karberos.dll
C:\WINDOWS\System32\lyfax10N.dll
C:\WINDOWS\System32\ir66l5js1.dll
C:\WINDOWS\System32\iwrtrmgr.dll
C:\WINDOWS\System32\kt2sl7f71.dll
C:\WINDOWS\System32\s4pule791h.dll
C:\WINDOWS\System32\sicurity.dll
C:\WINDOWS\System32\l2l6lc3s1f.dll
C:\WINDOWS\System32\jtj8071ue.dll
C:\WINDOWS\System32\m0pola731d.dll
C:\WINDOWS\System32\aecmgr.dll
C:\WINDOWS\System32\Oxve9.4ed
C:\WINDOWS\System32\Ywt4.kls
C:\WINDOWS\System32\FmrCj.b90
C:\WINDOWS\System32\GnsDk.b90
C:\WINDOWS\System32\4A159A46B7.sys
C:\WINDOWS\System32\mslg.blf
C:\WINDOWS\System32\VarEdQ6.4sn
C:\WINDOWS\System32\IpuFmd.017
C:\WINDOWS\System32\TafqX5mo.dvc
C:\Program Files\Qccg\Fxsc.exe
C:\Program Files\MalwareWipe\MalwareWipe.exe
C:\Program Files\SafeGuard Popup Blocker Pro\PBOptions.exe
C:\Documents and Settings\Scott new\zangme.exe
C:\documents and settings\scott\local settings\temp\Tz.exe
C:\documents and settings\scott\local settings\temp\d38.exe
C:\documents and settings\scott\local settings\temp\IWfsJVD8r.exe
C:\documents and settings\scott\local settings\temp\doKx.exe
C:\documents and settings\scott\local settings\temp\EZXrpX.exe
C:\documents and settings\scott\local settings\temp\gZ.exe
C:\Documents and Settings\Scott new\Local Settings\Application Data\Microsoft\Windows\msdbkx.com


Return to Killbox and paste the files into the Text Field by clicking in it and pressing Ctrl+V. Click the Remove Menu header and select RemovePendingFileRenameOperations if it isn't greyed out. Click the red and white "X" button. Then follow the prompts to reboot your computer.

Once your Computer had rebooted... Post a new HijackThis log please.

81 Posts

June 10th, 2006 03:00

Hi
 
Thanks for the additional info, i hope it will work!
 
I ran everything and did everything you said, some of the processes were already stopped and some things weren't in HJT on the comp when I went to fix them. 
Also, I am not sure if everything deleted on Killbox.
 
I went to Windows/System32 and mslg.blf was still there... (maybe i only did the first one even though i clicked all files?)
 
Anyways here is the new HJT log
 
Logfile of HijackThis v1.99.1
Scan saved at 11:54:54 PM, on 6/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\gpl6l33s1.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\lslmb12n.dll
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 
 
Oh and also, am i still being hacked and being keystroked (with this info being sent to someone?)

99 Posts

June 10th, 2006 04:00

Looking a bit better :)



Oh and also, am i still being hacked and being keystroked (with this info being sent to someone?)




If that Keylogger file is still there... its possible, yes. I'd advise you to keep this machine off the net as much as possible. If you have it networked with any others wherever it is(home/business)... I suggest keeping it off that network as well to prevent the spread of the infections to any other machines.

OK... with most of that other junk out of the way... hopefully some of the tools I will need to use will work. Seems you have been having problems with them.

First though... visit this page and follow the instructions laid out by Grinler to remove the Sony RootKit.

Then I need you to run Option 1 of L2MFix that 'monk had you download earlier. Post the log when it has finished its scan.

Thanks!

Message Edited by _KotaGuy on 06-09-200611:34 PM

Message Edited by _KotaGuy on 06-09-200611:36 PM

81 Posts

June 11th, 2006 02:00

second half of report (sorry it couldn't fit in one page)

"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{F802F260-519B-11D1-BB5D-0060974C6013}"="ICQ Shell Extension"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{BB7DF450-F119-11CD-8465-00AA00425D90}"="Microsoft Access Custom Icon Handler"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{5464D816-CF16-4784-B9F3-75C0DB52B499}"="Yahoo! Mail"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{0A8CE102-FA03-4612-9BEE-7FE5452F4CB1}"="Search Bar"
"{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Context Menu Shell Extension"
"{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 DragDrop Shell Extension"
"{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Context Menu Shell Extension"
"{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6 Property Sheet Shell Extension"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}"=""
"{4C9AD2A2-1DCC-45C8-B761-FF2053A6D167}"=""
"{CC680CC8-DEDE-49F1-B613-5223E2216B4F}"=""
"{3D1D54C1-2C26-4F48-A07B-C670AB2C3363}"=""
"{D7934647-A59A-4D27-902E-BB783CF9C4A2}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A08B985D-4CC2-41F9-B05C-5CAD23F4E314}\InprocServer32]
@="C:\\WINDOWS\\system32\\dytmsft.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CC680CC8-DEDE-49F1-B613-5223E2216B4F}\InprocServer32]
@="C:\\WINDOWS\\system32\\sosvc.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D7934647-A59A-4D27-902E-BB783CF9C4A2}\InprocServer32]
@="C:\\WINDOWS\\system32\\jrdw400.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:
Directory Listing of system files:
 Volume in drive C has no label.
 Volume Serial Number is 7CA7-1973

 Directory of C:\WINDOWS\System32

06/10/2006  11:01 PM           234,783 jrdw400.dll
06/09/2006  11:56 PM           234,288 k2260cfsef260.dll
06/09/2006  11:51 PM   

          dllcache
06/09/2006  11:48 PM           234,288 dodskres.dll
06/04/2006  04:00 PM           234,288 m8ls0i37e8.dll
06/04/2006  03:28 PM           234,783 gpl6l33s1.dll
06/04/2006  11:22 AM           234,783 sosvc.dll
06/03/2006  03:34 PM           234,288 mlxml3.dll
06/03/2006  11:42 AM           234,783 apvpack.dll
06/02/2006  11:21 AM           234,288 uderenv.dll
06/02/2006  11:11 AM           234,288 mfdtctm.dll
06/01/2006  11:38 PM           234,601 g240lchm1f4a.dll
06/01/2006  11:27 PM           234,601 uwnpui.dll
06/01/2006  05:22 PM           234,303 wksdmoe2.dll
06/01/2006  05:22 PM           234,288 wcpshell.dll
06/01/2006  05:20 PM           234,063 enjul1191.dll
06/01/2006  05:08 PM           234,063 cbm.dll
06/01/2006  03:53 PM           234,288 ihrnonce.dll
06/01/2006  02:08 AM           234,063 p2p6lc7s1f.dll
06/01/2006  12:13 AM           234,063 mzrapi.dll
06/01/2006  12:13 AM           235,920 ktn8l75u1.dll
06/01/2006  12:01 AM           234,063 FBNFCOPY.dll
05/31/2006  11:59 PM           236,345 j44o0eh3eh4.dll
05/31/2006  11:25 AM           236,345 nytapi32.dll
05/31/2006  10:00 AM           234,063 onbcconf.dll
05/30/2006  09:30 PM           236,345 SY2EVNT1.DLL
05/30/2006  09:18 PM           235,510 fTultrep.dll
05/30/2006  10:03 AM           235,510 lxawd12n.dll
05/29/2006  08:31 PM           235,510 m628lgfu1628.dll
05/29/2006  08:31 PM           235,510 MFVCR71.dll
05/29/2006  08:31 PM           237,079 mv6ql9j51.dll
05/29/2006  08:21 PM           234,080 inwphbk.dll
05/29/2006  08:01 PM           234,080 njmssvc.dll
05/29/2006  05:53 PM           234,080 lv2409fqe.dll
05/27/2006  09:44 AM           234,183 fp0m03d1e.dll
05/27/2006  12:53 AM           234,080 sjcbase.dll
05/27/2006  12:52 AM           236,015 ir8ml5l11.dll
05/27/2006  12:22 AM           236,015 MCVCP71.dll
05/26/2006  11:35 AM           234,080 q686lgls16q6.dll
05/26/2006  11:22 AM           234,080 devxdec_0411.dll
05/26/2006  11:22 AM           234,751 dnp6017se.dll
05/25/2006  09:45 PM           235,904 mfwstr10.dll
05/25/2006  09:20 PM           234,080 karberos.dll
05/25/2006  05:01 PM           235,904 lyfax10N.dll
05/25/2006  05:01 PM           234,080 ir66l5js1.dll
05/25/2006  02:49 PM           235,904 iwrtrmgr.dll
05/25/2006  02:49 PM           234,111 kt2sl7f71.dll
05/24/2006  06:47 PM           235,584 s4pule791h.dll
05/24/2006  06:08 PM           235,904 sicurity.dll
05/24/2006  05:04 PM           235,904 l2l6lc3s1f.dll
05/23/2006  11:25 PM           235,089 jtj8071ue.dll
05/23/2006  11:20 PM           235,642 m0pola731d.dll
12/29/2005  12:54 AM               475 aecmgr.dll
05/31/2005  08:09 PM               846 Oxve9.4ed
02/28/2005  05:49 PM               846 Ywt4.kls
02/27/2005  05:49 PM               846 FmrCj.b90
02/23/2005  04:46 PM               846 GnsDk.b90
01/29/2005  09:33 PM                56 4A159A46B7.sys
01/29/2005  09:33 PM             1,682 KGyGaAvL.sys
05/24/2004  10:46 PM             1,188 VarEdQ6.4sn
05/12/2004  05:51 PM             1,104 IpuFmd.017
05/07/2004  06:48 PM             1,104 TafqX5mo.dvc
01/17/2003  09:37 AM              Microsoft
             61 File(s)     11,987,936 bytes
              2 Dir(s)   8,530,018,304 bytes free

81 Posts

June 11th, 2006 02:00

Hi,

the computer doesn't seem to lock up as badly anymore! but maybe I'm just looking for that too happen.

Anyways I tried to delete the rootkit file and got this message: (and the aries file wasn't in the system32 folder).

"[SC] OpenService FAILED 1060:

The specified service does not exist as an installed service."

Here is the new log for l2fix in multiple posts:

L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
 6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
 6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ModuleUsage]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\gpl6l33s1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MSSYCLM]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\m8ls0i37e8.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
 6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
 6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
 6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48690FE4-FD37-1EA2-28EB-42ED3079A72D}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"

81 Posts

June 11th, 2006 03:00

Hi,

Yes, the cmd thing i copied directly and it still says does not exist.

Anyways I ran l2m fix option 2 and it asked for a password again.  There is a log in the l2m folder where it stores if it doesn't open on its own.  Here is that log...

99 Posts

June 11th, 2006 03:00

OK... just to check that you entered the command in properly... you probably did... I just need to make sure.

This cmd /k sc delete $sys$aries would be this...

cmd[space]/k[space]sc[space]delete[space]$sys$aries

Is that how you entered the command or did you not leave any spaces where I've put in [space]?

Anyways... though I know L2MFix has choked on you trying this step... can your try Option 2 in L2MFix again for me please.

I'm hoping that with some of the other junk out of the way the tool will work properly now.

If it works... post the log please... if not let me know... we may need to do this the hard way.

Message Edited by _KotaGuy on 06-10-200610:10 PM

81 Posts

June 11th, 2006 03:00

L2mfix 051206
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
 Granting SeDebugPrivilege to L2MFIX   ... successful
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
 zip warning: name not matched: dlls\*.*

zip error: Nothing to do! (backup.zip)
updating: backregs/notibac.reg (164 bytes security) (deflated 87%)

99 Posts

June 11th, 2006 04:00

OK...

We won't worry about that tool then.

Download Dr.Web CureIt to the desktop.

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously along with a new HJT log in your next reply.

Message Edited by _KotaGuy on 06-10-200611:06 PM

81 Posts

June 11th, 2006 21:00

I am running the scan now, and a lot of the adaware picked up seems to come from "look2me".  I thought that was a program meant to help the computer?

81 Posts

June 11th, 2006 22:00

sorry, this is a bit hard to read...

 

FIRST HALF

ywgbjn.exe;C:\WINDOWS\system32;Trojan.Qoologic;Will be cured after reboot.;
ogwfj.exe;C:\WINDOWS\system32;Trojan.Qoologic;Will be cured after reboot.;
explorer.exe;C:\WINDOWS\APPATC~1;Adware.ClickSpring;;
sosvc.dll;C:\WINDOWS\system32;Adware.Look2me;;
f4j20e1oeh.dll;C:\WINDOWS\system32;Adware.Look2me;;
sysdrv.bat;C:\;Adware.DollarRevenue;;
w25f697f.dll;C:\bintheredunthat;Adware.Lc;;
WxBug.EXE;C:\Program Files\AIM\Sysfiles;Adware.Aws;;
CA304F30-139B-4CD3-A67F-BF00DF;C:\Program Files\Microsoft AntiSpyware\Quarantine\11509694-EA6B-4C88-89EC-A25697;Trojan.AproposAd;Deleted.;
1E911C9F-7069-49E0-BD35-72CDB3;C:\Program Files\Microsoft AntiSpyware\Quarantine\5AEFB14F-266B-4B0E-91F1-A1FF4B;Trojan.AproposAd;Deleted.;
C1A12506-66E3-4450-A023-70D788;C:\Program Files\Microsoft AntiSpyware\Quarantine\5AEFB14F-266B-4B0E-91F1-A1FF4B;Trojan.AproposAd;Deleted.;
1C5D6FFB-13EB-4653-AC20-A22DC5;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
513921D9-DB0A-4851-8BEC-6CE9CB;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
B600EC81-6CEA-406F-A9F0-0BE6D4;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
D86A6FDF-4EA0-4E38-BCB9-E684AA;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
FF5374EA-79FB-4E7A-B8BE-AF7C72;C:\Program Files\Microsoft AntiSpyware\Quarantine\5DDD4B89-FA94-437B-AEDD-00EBDF;Trojan.AproposAd;Deleted.;
195DB8D3-5D70-4A3F-B2C9-3679A0;C:\Program Files\Microsoft AntiSpyware\Quarantine\68361A23-1ED2-4287-B4D4-5A6D09;Adware.nCase;;
44FB0227-32A1-439B-BB74-ECC98C;C:\Program Files\Microsoft AntiSpyware\Quarantine\85BCE34F-268B-42F4-9CB0-CD9565;Adware.nCase;;
8A81DBE9-2E99-452C-B3C5-50B31E;C:\Program Files\Microsoft AntiSpyware\Quarantine\A2FAE294-BEDB-4CC2-8E53-DAF374;Trojan.AproposAd;Deleted.;
234465E3-0907-4BE3-922C-1AC0BA;C:\Program Files\Microsoft AntiSpyware\Quarantine\CF541902-EDE0-4F8B-A84A-4C3329;Trojan.AproposAd;Deleted.;
4670DF8C-8231-4A42-AD36-8529E0;C:\Program Files\Microsoft AntiSpyware\Quarantine\EA534964-404F-453F-8E68-7C6819;Trojan.AproposAd;Deleted.;
nicociru.html\Javascript.0;C:\Program Files\Movie Maker\nicociru.html;Trojan.Click.1237;;
nicociru.html;C:\Program Files\Movie Maker;Archive contains infected objects;Moved.;
A0460471.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.9440;Deleted.;
A0460727.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Probably BACKDOOR.Trojan;;
A0461445.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;BackDoor.Generic.1219;Deleted.;
A0461446.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;BackDoor.Generic.1219;Deleted.;
A0461447.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Enbrow;;
A0461448.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Nexus;;
A0461449.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.NewDotNet;;
A0462445.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0462456.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.8290;Deleted.;
A0462457.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.DollarRevenue;;
A0462458.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.10113;Deleted.;
A0462459.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.DollarRevenue;;
A0462460.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.DownLoader.8453;Deleted.;
A0462461.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.DollarRevenue;;
A0462462.EXE;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.NewDotNet;;
A0462469.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Dh;;
A0462470.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463445.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463476.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463477.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463485.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463486.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463494.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Trojan.Qoologic;Deleted.;
A0463495.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463514.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0463522.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP950;Adware.Look2me;;
A0464546.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464547.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464552.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464553.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464555.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464564.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464566.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Trojan.Qoologic;Deleted.;
A0464567.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464569.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464574.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464587.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464588.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Trojan.Qoologic;Deleted.;
A0464589.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Adware.Look2me;;
A0464590.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951;Trojan.Qoologic;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP951\snapshot;Trojan.Qoologic;Deleted.;
A0464601.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464602.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464608.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0464616.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464617.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464618.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464620.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464621.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464630.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464632.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464634.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464639.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464652.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464653.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0464654.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464655.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0464666.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0464673.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0465675.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0465682.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
A0466682.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0466700.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Trojan.Qoologic;Deleted.;
A0466701.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952;Adware.Look2me;;
MFEX-1.DAT;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP952\snapshot;Trojan.Qoologic;Deleted.;
A0466713.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466714.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466719.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0466729.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466732.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466733.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466734.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466741.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466777.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466778.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466785.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466786.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466787.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466788.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466790.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466791.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466798.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466800.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466802.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466807.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466820.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466821.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0466822.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0466823.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0466831.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467831.exe;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Trojan.Qoologic;Deleted.;
A0467845.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467846.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467847.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467848.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}\RP953;Adware.Look2me;;
A0467849.dll;C:\System Volume Information\_restore{451E5AA2-0745-4540-BE44-B2F7581E4C0A}

81 Posts

June 11th, 2006 22:00

hi!
 
here are the new logs.  A lot of the adaware found in the program wasn't deleted, and I wasn't sure whether or not to manually click delete or cure for each one, so i just closed the program.
 
HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 7:07:23 PM, on 6/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\lxamsp32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Webshots\webshots.scr
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe
C:\Documents and Settings\Scott new\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ogwfj.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,abejtsm.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\system32\Dyf0p5.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [xnksjl] C:\WINDOWS\system32\ywgbjn.exe reg_run
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ukrtk] C:\WINDOWS\system32\ywgbjn.exe reg_run
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: qescp.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\e8200ifme82a0.dll
O20 - Winlogon Notify: URL - C:\WINDOWS\system32\f4j20e1oeh.dll
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

 

No Events found!

Top