Unsolved

This post is more than 5 years old

14 Posts

21733

February 22nd, 2005 11:00

I NEED HELP PLEASE--I WANT MY COMPUTER BACK!!!!!!

My computer has been acting up lately.  It started with at boot-up my computer would lock up.  If I hit "CTRL-ALT-DELETE", there was something called "Windoldap" in the screen.  I found that if I could end task on that, that the computer would run fine.
 
A few days ago, my Avast kept showing virus alerts and I told it to put all files into the chest (quarrentine), ran a full scan, and all files were temp files so I deleted them.  Every time I boot up now along with the Windoldap there are lots of other things, and they either won't "end" or come back.  They are: prutqct, wo, mmod, ogsupy,winupdt, tm, route
 
I get pop up windows all of the time.  I have 2 search bars that I didn't ask for and can't figure out how to get rid of which are Begin2Search.com bar and MySearch Bar.  Spybot keeps telling me that I have an "unknown hijacker", it says that it fixes the problem, and when I run the scan again, it is right back.
 
If you can't tell, I am not really savvy.  I have handled some problems in the past, but always with easy solutions, and with this I am at a loss.  I have been reading your forums and am just hoping and praying that you can help me through this dilema.
 
This is what I have done so far:
 
I ran Trend Micro and there are files that is says are not cleanable or not accessable and says I have a TROJ NARRATOR.A virus.
Here are the results of the scan:
not cleanable   C:\Windows\Start Menu\kkkukki.exe
not cleanable   C:\Windows\wwawwk.dat
Can not access  C:\Windows\iioiin.dll
Can not access  C:\windows\vvivvg.exe
not cleanable   C:\Windows\llzlla.exe
not cleanable   C:\Windows\llyllq.dll
 
I told it to delete them and it says that it deleted all but the 2 that it said that it can not access.
 
I also ran Hijack this and here is the log that it gave me:
Logfile of HijackThis v1.99.1
Scan saved at 7:38:53 AM, on 2/22/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\TANGO MANAGER\APP\TANGOMANAGER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\WINDOWS\VVIVVG.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE
C:\PROGRAM FILES\OLYMPUS\CAMEDIA MASTER 4.0\CM_CAMERA.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TEMP\ZGTEMP\FINDIT NT-2K-XP\TM.EXE
C:\WINDOWS\TEMP\ZGTEMP\FINDIT NT-2K-XP\WVER2.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ZIPGENIUS 5\ZIPGENIUS.EXE
C:\WINDOWS\TEMP\ZGTEMP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://216.130.185.122/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wepaid.com/portal.php?member=cbouchez
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.130.185.122/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
O3 - Toolbar: i&Won Co-Pilot - {CA0B9B71-C2AF-11D3-B376-0800460222F0} - C:\PROGRAM FILES\IWON\IWONBAR\2.BIN\IWONBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN1\YCOMP5_5_7_0.DLL
O3 - Toolbar: Begin2Search.com Bar - {207AEF46-0596-4966-A7BF-098F247E85BB} - C:\WINDOWS\SYSTEM\IC2_WIN.DLL (file missing)
O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\PROGRAM FILES\MYSEARCH\BAR\2.BIN\S4BAR.DLL (file missing)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TangoManager] C:\PROGRA~1\EFFICI~1\TANGOM~1\APP\TANGOM~1.EXE
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ashWebSv.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\SYSTEM\KAYZBO.exe
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\vvivvg.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [PRUTQCT] C:\WINDOWS\SYSTEM\PRUTQCT.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: CAMEDIA Master.lnk = C:\Program Files\OLYMPUS\CAMEDIA Master 4.0\CM_camera.exe
O4 - Startup: kkukki.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZPihp001
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\MOMMA\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: MyPoints - file://C:\PROGRAM FILES\MYPOINTS_POINTALERT\Sy800\Tp800\scri800a.htm
O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Point Alert - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - file://C:\PROGRAM FILES\MYPOINTS_POINTALERT\Sy800\Tp800\scri800a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {4EE301F2-2A6A-4BE0-9FBD-97CDAA40E3E4} - http://i1img.com/images/nocache/copilot/iWonInitialSetup1.0.0.5.exe
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://cc.iwon.com/ct/pm3/iwonpm_12_1,0,2,5.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} (shizmoo Class) - http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/bingame/rtlw/default/ReflexiveWebGameLoader.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} (PopCapLoaderCtrl Class) - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20041208/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} - http://www.alwaysupdatednews.com/install/aun_0010.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
 
Please help me through this.  Let me thank you ahead of time for any assistance that you can be to me.
 
Thank you,
 
Carla
 

4 Apprentice

 • 

8.8K Posts

February 22nd, 2005 16:00

EDIT: If you haven't done the below please do this first:
Please go to here
and download AdAwareSE and delete what it finds. Then while using
AdAware, click on add-ons and get their plug-in for the VX2 variant,
and run that and delete what it finds.
After that go to here
and download SpyBot and run that and delete what it finds.


Before we begin, let's move HiJackThis to it's own folder; like C:\HJT

Run HiJackThis then:

1. Click "Config..."
2. Click "Misc Tools"
3. Click "Open Process manager"

-
Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following

C:\WINDOWS\VVIVVG.EXE
C:\WINDOWS\SYSTEM\KAYZBO.exe
C:\WINDOWS\SYSTEM\PRUTQCT.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE
Startup: kkukki.exe


Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



Now scan again and tick these entries in HJT:

C:\WINDOWS\VVIVVG.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.130.185.122/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
O4 - HKLM\..\Run: [version] C:\WINDOWS\SYSTEM\KAYZBO.exe
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\vvivvg.exe
O4 - Startup: kkukki.exe
O4 - HKCU\..\Run: [PRUTQCT] C:\WINDOWS\SYSTEM\PRUTQCT.exe


Now with all applications except HJT closed hit the FIX button.

Reboot, rescan and repost a new log and also see if the system behaves better?

Steve

EDIT: Try deleteing those other files in Safe Mode

Message Edited by zbestwun2001 on 02-22-2005 11:01 AM

4.8K Posts

February 22nd, 2005 22:00

Carla,

We have at least 3 good identifiable 'problems' on that system, so take your time, and if you have any questions at all, just post back.

-

Let's get started...



Download, unzip to your desktop CWShredder and run it, then:

1. Click " Check For Update"

( If an update isn't available, skip to step #4.)

2. Click " Click here to Download the upate".
3. When the new version has been downloaded, click " Save".

4. Click " Fix ->"



Download and unzip FindIt NT-2K-XP, then:

1. Double-click " FintIt NT-2K-XP.zip" folder.
2. Double-click " FindIt NT-2K-XP" folder.
3. Double-click " FindNarrator.bat"

4. Click " Extract All"
5. Click " Next"
6. Click " Next".
7. Click " Finish"

( If you've already downloaded and unzipped it before, skip the above steps.)

8. Double-click " FindIt NT-2K-XP" folder.
9. Double-click " FindNarrator.bat".

( Wait until the scan completes.)

10. When notepad comes up post back the contents of FindNarrator.txt.
11. Close notepad.



Go to Add/Remove programs and remove(uninstall) the following, if present:

E2 Give
MyWebSearch
Web Related

The above could appear anywhere within the entry. Be careful not to remove any personal or system software.



Let's see if we can try and fix this; it might get a little complicated, so, if you have questions at any time, just post back.

First, let start off by looking where no-hijack has looked before:

1. Downolad Dllcompare, and Killbox to your desktop<.

2. click " Run locate.com".

When the scan is complete, you will see: Completed the scan, Click Compare to Continue

3. click " Compare".

In a few minutes it be Completed


4. click " Make a Log of what was Found".

5. Post that back as a reply to this post.



Run HiJackThis then:

1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"

-

Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:

C:\WINDOWS\VVIVVG.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE

Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.



Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:

regsvr32 /u IWONBAR.DLL

It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to the command prompt to save on the typing.




Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.

Also move the " Backups" folder, for HiJackThis, if present.



Run HiJackThis and click " Scan", then check(tick) the following, if present:


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://216.130.185.122/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wepaid.com/portal.php?member=cbouchez
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.130.185.122/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://216.130.185.122/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com

O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)

O3 - Toolbar: i&Won Co-Pilot - {CA0B9B71-C2AF-11D3-B376-0800460222F0} - C:\PROGRAM FILES\IWON\IWONBAR\2.BIN\IWONBAR.DLL
O3 - Toolbar: Begin2Search.com Bar - {207AEF46-0596-4966-A7BF-098F247E85BB} - C:\WINDOWS\SYSTEM\IC2_WIN.DLL (file missing)
O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\PROGRAM FILES\MYSEARCH\BAR\2.BIN\S4BAR.DLL (file missing)

O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\vvivvg.exe
O4 - HKCU\..\Run: [PRUTQCT] C:\WINDOWS\SYSTEM\PRUTQCT.exe
O4 - Startup: kkukki.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O16 - DPF: {4EE301F2-2A6A-4BE0-9FBD-97CDAA40E3E4} - http://i1img.com/images/nocache/copilot/iWonInitialSetup1.0.0.5.exe
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://cc.iwon.com/ct/pm3/iwonpm_12_1,0,2,5.cab


Now, with all windows closed except HiJackThis, click " Fix checked".



Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

folders...

C:\PROGRAM FILES\IWON

files...

C:\WINDOWS\VVIVVG.EXE
C:\WINDOWS\SYSTEM\PRUTQCT.EXE

Search for...

kkukki.exe

...using " Start | Search...".

-

Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".



Post back a new log, and let me know how everything goes.

-

Mike.

14 Posts

February 23rd, 2005 00:00

HI,
 
Thanks for all of the advice, I am picking through one item at a time.  I have done the CWShredder.  I just completed the FindIt NT-2k-XP and these are the results of that log that came up in notepad.  I am working on the next step, but being blonde, I am afraid if I don't do one at a time, I will miss something.....LOL.
Carla
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
 
********* Date/Time ********
 
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- FindNarrator NT-2K-XP ----------------
 
Warning! This utility will find legitimate files in addition to malware. 
Do not remove anything unless you are sure you know what you're doing.
 
***** Operating System *****
 
Microsoft Windows 98 SE 
********* Date/Time ********
 
Tuesday, February 22, 2005 (2/22/05)
9:31 PM, Eastern Standard Time
 
*********** Path ***********
 
FindNarrator.bat is running from:
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Qoologic Results ----------------
 
 
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
---------------- Strings.exe Aspack Results ----------------
 
 
---------------- Active Setup Installed Components ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
 
---------------- Context Menu Handlers ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- Run Key ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------
---------------- FindNarrator NT-2K-XP ----------------

4.8K Posts

February 23rd, 2005 00:00

Carla,
 
Just do the best you can (which will be more than enough), and let me pick up any pieces that fall ... :smileyhappy:
 


Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
 
files...
 
    C:\Windows\Start Menu\kkkukki.exe
    C:\Windows\iioiin.dll
    C:\windows\vvivvg.exe
    C:\Windows\llzlla.exe
    C:\Windows\llyllq.dll
 
-
 
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".
 

 
We'll see if we can use HouseCall to fix the Narrator trojan (by finding these files for us), instead of using FindNarrator.bat, since it only works with certain operating systems.
 
-
 
Mike.
 

Message Edited by Midnight Star on 02-22-2005 08:52 PM

13 Posts

February 23rd, 2005 02:00

 :smileywink: for a temperary fix run msconfig and unselect windoldap. :smileywink:

14 Posts

February 23rd, 2005 02:00

Mike,

Thank you for your patience with me.  This is where I am so far.  I went to add remove programs and got rid of the things that you told me to, with these exceptions.  I have something called "My Search Bar"  When I clicked to remove it, I got an error message saying  "C:\Progra~1\mysearch\bar\2.bin\s4bar.dll-----system cannot find path specified, so that is still there.  I had 2 other entries named  "Win-dh" and "Weboffer".  When I click to remove them, it acts like it is doing something, but they are still there. 

I had checked back and did have to go to safe mode but did get rid of all of the things that you listed above.  Startup is not going a little better.  I am still getting a popup saying that a program is trying to work, do I want to work offline, or try again.  It doesn't say what program.

Should I continue with the remaining above steps now?

Thanks,

Carla

14 Posts

February 23rd, 2005 02:00

Thanks for the advice about winoldap,scenoch, I don't see it in the msconfig settings at all.  I went on with the DLL Compare, and here is the log that I got.
 
*    DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM\mhxmlr.dll     Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\io41_qcx.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mmdamg9x.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\jsbexec.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mdyuv.dll      Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\srorts.dll     Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\sftupwbv.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\nddll.dll      Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\lcimg12n.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mgacm32.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\sdsdetmg.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\pzwerold.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mzxml4a.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
________________________________________________
877 items found:  877 files (13 H/S), 0 directories.
Total of file sizes:  166,444,347 bytes    158.73 M
--------------------End log---------------------
Again, I can't thank everyone enough for this help and advice.  I thought I was going to lose this old girl.  :smileysurprised:
 
Thanks,
 
Carla
UPDATE:  I ran HiJackThis again, and do not see either of these:
C:\Windows\vvivvg.exe   or C:\Windows\System\PRUTQCT.EXE
 
I am begining to feel a little success finally!!!!!!:smileyhappy:
 
Carla

Message Edited by cbouchez on 02-22-2005 10:50 PM

14 Posts

February 23rd, 2005 03:00

I have been a brave blonde person..............muddled through the remaining steps and this is my last HiJackThis log.  Please let me know if I need to do more,
Logfile of HijackThis v1.99.1
Scan saved at 12:11:18 AM, on 2/23/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\TANGO MANAGER\APP\TANGOMANAGER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\VIRUS KILLER\SPYSUB.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TangoManager] C:\PROGRA~1\EFFICI~1\TANGOM~1\APP\TANGOM~1.EXE
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ashWebSv.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: CAMEDIA Master.lnk = C:\Program Files\OLYMPUS\CAMEDIA Master 4.0\CM_camera.exe
O4 - Startup: SpySubtract.lnk = C:\Virus Killer\SpySub.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\MOMMA\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: MyPoints - file://C:\PROGRAM FILES\MYPOINTS_POINTALERT\Sy800\Tp800\scri800a.htm
O8 - Extra context menu item: &eBay Search - res://C:\PROGRAM FILES\EBAY\EBAY TOOLBAR2\eBayTb.dll/RCSearch.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Point Alert - {67B50696-04BA-48ea-A697-28AA0EAA9C26} - file://C:\PROGRAM FILES\MYPOINTS_POINTALERT\Sy800\Tp800\scri800a.htm (file missing) (HKCU)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} - http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/bingame/rtlw/default/ReflexiveWebGameLoader.cab
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) - http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} (PopCapLoaderCtrl Class) - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20041208/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} - http://www.alwaysupdatednews.com/install/aun_0010.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
 
 
Thanks again for all of your help with this.
 
Carla

4.8K Posts

February 23rd, 2005 12:00

Carla,

Sorry for not being able to stay online to catch your posts, but i'm on a limited dialup account until they switch DSL back over to here (should be by Thursday).

Your doing just fine - and blonde is a fantastic color! At least one of the infections that system has is ranked among the worst, but I believe we're going to be able to get it cleaned up. The most important thing is to stay with it, until we've gotten this VX2 problem under control.


Now, let's run KillBox, then:

-----

1.  check(tick) "Replace on reboot"

2.  enter C:\WINDOWS\SYSTEM\io41_qcx.dll, in "Full Path of File to Delete".

3.  check(tick) "Use Dummy".

4.  click the red-x, just right of where you entered the file to delete.

5.  Confirm that you want to replace the 'bad' file with the 'dummy'.

6.  When prompted to "Reboot Now", select "No".

7. Now repease steps #1 - #6 for the following files:

C:\WINDOWS\SYSTEM\jsbexec.dll
C:\WINDOWS\SYSTEM\lcimg12n.dll
C:\WINDOWS\SYSTEM\mdyuv.dll
C:\WINDOWS\SYSTEM\mgacm32.dll
C:\WINDOWS\SYSTEM\mhxmlr.dll
C:\WINDOWS\SYSTEM\mmdamg9x.dll
C:\WINDOWS\SYSTEM\mzxml4a.dll
C:\WINDOWS\SYSTEM\nddll.dll
C:\WINDOWS\SYSTEM\pzwerold.dll
C:\WINDOWS\SYSTEM\sdsdetmg.dll
C:\WINDOWS\SYSTEM\sftupwbv.dll
C:\WINDOWS\SYSTEM\srorts.dll

C:\Windows\System32\Guard.tmp

After entering the last file, when prompted to "Reboot Now", select "Yes".

-----

You can copy/paste these file name(s) to save on typing.


Now, let's go back and run DLLCompare again, just like we did in the previous post, and post back the results.

-

Mike.

 

14 Posts

February 23rd, 2005 13:00

Mike,

I understand the dialup thing, and all that I can say is words can't express enough my appreciation for the help that I am receiving.  I did the above things and this is the log from dllcompare:

*    DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINDOWS\SYSTEM\cuusalgo.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mmdamg9x.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
________________________________________________

867 items found:  867 files (2 H/S), 0 directories.
Total of file sizes:  164,218,667 bytes    156.61 M

--------------------End log---------------------
I also ran Hijack this again and this is the latest from that:

Logfile of HijackThis v1.99.1
Scan saved at 10:18:54 AM, on 2/23/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\TANGO MANAGER\APP\TANGOMANAGER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\OLYMPUS\CAMEDIA MASTER 4.0\CM_CAMERA.EXE
C:\VIRUS KILLER\SPYSUB.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\SETUP\AVAST.SETUP
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TangoManager] C:\PROGRA~1\EFFICI~1\TANGOM~1\APP\TANGOM~1.EXE
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ashWebSv.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [App32dll] C:\WINDOWS\SYSTEM\MSNAVC32.EXE lee0105
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Z0psRWGnj] I81RIPT.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: CAMEDIA Master.lnk = C:\Program Files\OLYMPUS\CAMEDIA Master 4.0\CM_camera.exe
O4 - Startup: SpySubtract.lnk = C:\Virus Killer\SpySub.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\MOMMA\INCRED~1\bin\resources\WebMenuImg.htm
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
 
 
I am still getting a popup at bootup saying that a program is trying to start and not finding an internet connection.
 
I have to go to work, so will check back this evening to see what is next.
 
Again, thank you for your help with all of this.
 
Carla

4.8K Posts

February 23rd, 2005 14:00

Carla,
 
You are, as always, more than welcome.
 


Run HiJackThis and click " Scan", then check(tick) the following, if present:
 

O4 - HKCU\..\Run: [Z0psRWGnj] I81RIPT.EXE
 

Now, with all windows closed except HiJackThis, click " Fix checked".
 


Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
Search for...
 
    I81RIPT.EXE
 
...using " Start | Search...".
 
-
 
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".

Now, let's run KillBox, then:

-----

1.  check(tick) "Replace on reboot"

2.  enter C:\WINDOWS\SYSTEM\cuusalgo.dll, in "Full Path of File to Delete".

3.  check(tick) "Use Dummy".

4.  click the red-x, just right of where you entered the file to delete.

5.  Confirm that you want to replace the 'bad' file with the 'dummy'.

6.  When prompted to "Reboot Now", select "No".

7. Now repease steps #1 - #6 for the following files:

C:\WINDOWS\SYSTEM\mmdamg9x.dll

C:\Windows\System32\Guard.tmp

After entering the last file, when prompted to "Reboot Now", select "Yes".

-----

You can copy/paste these file name(s) to save on typing.


Now, let's go back and run DLLCompare again, just like we did in the previous post, and post back the results - this time, it should come up clean.

-

Mike.

 

14 Posts

February 24th, 2005 00:00

Mike,
I did all of the things that you said, including telling killbox to replace mmdamg9x.dll 4 times.  It won't go away.  Computer is dragging a little tonight.  Let me know what to do next.  As long as you are willing to stick with me through this, I will keep plugging at it.
 
Thanks,
 
Carla
 
*    DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM\mmdamg9x.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
________________________________________________
869 items found:  869 files (1 H/S), 0 directories.
Total of file sizes:  164,663,803 bytes    157.04 M
--------------------End log---------------------

14 Posts

February 24th, 2005 12:00

Mike,

Just a quick note.  I spent last night redoing all of the steps that you had me do before.  I don't know what's going on, but a lot of the stuff had found it's way back into my computer.  I am only connecting to get new messages or to post, so these critters are quick.  I am waiting to hear back from you for what to do next, so I will keep checking.  Please let me know what to do next.

Thanks,

Carla

4.8K Posts

February 24th, 2005 22:00

Carla,

Yes they are! Let me see a new HiJackThis log, along with the dllcompare log, and i'll see what they've been upto ... :) - we'll fight this thing as long as it takes!, but I might need to get you over to someone who knows Windows 98 better than me to help you find the 'reinfector' that's hiding on that operating system.

-

Mike.

 

14 Posts

February 25th, 2005 11:00

Mike,

Here we go again........There is a little progress, or at least I think so, the last few times I booted up, the popup saying something is trying to connect hasn't popped up (maybe I jinxed myself by typing this.....:smileysurprised:)

Here are the Hijack this log and dll compare:

 

Logfile of HijackThis v1.99.1
Scan saved at 8:40:54 AM, on 2/25/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\TANGO MANAGER\APP\TANGOMANAGER.EXE
C:\PROGRAM FILES\LEXMARKX83\ACMONITOR_X83.EXE
C:\PROGRAM FILES\LEXMARKX83\ACBTNMGR_X83.EXE
C:\WINDOWS\SYSTEM\PRINTRAY.EXE
C:\N20050308.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\NEW FOLDER\SPYSUB.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TangoManager] C:\PROGRA~1\EFFICI~1\TANGOM~1\APP\TANGOM~1.EXE
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [App32dll] C:\WINDOWS\SYSTEM\MSNAVC32.EXE lee0105
O4 - HKLM\..\Run: [nsvcin] C:\N20050308.EXE
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\vvivvg.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: CAMEDIA Master.lnk = C:\Program Files\OLYMPUS\CAMEDIA Master 4.0\CM_camera.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\New Folder\SpySub.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\MOMMA\INCRED~1\bin\resources\WebMenuImg.htm
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
 
 
    DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM\mgwsock.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mmdamg9x.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\sbdocvw.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\idmigrat.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\sytupwbv.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\dmwsock.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\lbaut12n.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mgnet32.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mksign32.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mtpwl32.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\rysapi32.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\drd8.dll       Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\cbmpobj.dll    Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\mqrepl40.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\liitg12n.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\ope32.dll      Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\sgmsetup.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
C:\WINDOWS\SYSTEM\lpcal12n.dll   Sat Feb 19 2005  11:17:36a  ..S.R        222,568   217.35 K
________________________________________________
890 items found:  890 files (18 H/S), 0 directories.
Total of file sizes:  168,884,619 bytes    161.06 M
--------------------End log---------------------
The comparedll log is getting longer again.......
 
I will be here for a while, but then will check back this evening if I don't hear back this morning.
 
Thank you Mike for all of your help, and any that you may recruit. 
 
Carla
No Events found!

Top