Start a Conversation

Unsolved

This post is more than 5 years old

644

September 29th, 2005 04:00

please help me soft through these programs

​ Logfile of HijackThis v1.99.1 ​
​Scan saved at 8:39:03 AM, on 4/11/2005 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\System32\wltrysvc.exe ​
​C:\WINDOWS\System32\bcmwltry.exe ​
​C:\WINDOWS\system32\LEXBCES.EXE ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\WINDOWS\system32\LEXPPS.EXE ​
​C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe ​
​c:\program files\mcafee.com\agent\mcdetect.exe ​
​c:\PROGRA~1\mcafee.com\vso\mcshield.exe ​
​c:\PROGRA~1\mcafee.com\agent\mctskshd.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe ​
​C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\Explorer.exe ​
​C:\WINDOWS\system32\hkcmd.exe ​
​C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ​
​C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ​
​C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ​
​C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe ​
​C:\Program Files\Dell\QuickSet\quickset.exe ​
​C:\WINDOWS\system32\WLTRAY.exe ​
​C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe ​
​C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe ​
​C:\PROGRA~1\mcafee.com\agent\mcagent.exe ​
​C:\WINDOWS\system32\dla\tfswctrl.exe ​
​C:\Program Files\McAfee.com\VSO\mcvsshld.exe ​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe ​
​C:\Program Files\McAfee.com\VSO\oasclnt.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe ​
​C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe ​
​C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe ​
​C:\Program Files\Dell Support\DSAgnt.exe ​
​C:\WINDOWS\system32\ctfmon.exe ​
​C:\Program Files\Dell AIO Printer A940\dlbabmon.exe ​
​c:\progra~1\mcafee.com\vso\mcvsescn.exe ​
​C:\Program Files\America Online 9.0\aoltray.exe ​
​C:\Program Files\Digital Line Detect\DLG.exe ​
​C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\DOCUME~1\Brittany\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe ​
​ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://www.dell4me.com/mywaybiz​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = ​​http://bfc.myway.com/search/de_srchlft.html​​ ​
​R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.dell4me.com/mywaybiz​​ ​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://www.dell4me.com/mywaybiz​​ ​
​R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file) ​
​F2 - REG:system.ini: Shell=Explorer.exe ​
​O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing) ​
​O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\ddayy.dll ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll ​
​O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll ​
​O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll (file missing) ​
​O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll ​
​O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file) ​
​O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe ​
​O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe ​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe ​
​O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ​
​O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ​
​O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe ​
​O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe ​
​O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY ​
​O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" ​
​O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r ​
​O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" ​
​O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask ​
​O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe ​
​O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe ​
​O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe ​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ​
​O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe ​
​O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe ​
​O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" ​
​O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" ​
​O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup ​
​O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe ​
​O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe ​
​O4 - Global Startup: Digital Line Detect.lnk = ? ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll ​
​O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\WINDOWS\system32\shdocvw.dll ​
​O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL ​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - ​​http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab​​ ​
​O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - ​​http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab​​ ​
​O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - ​​http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab​​ ​
​O20 - Winlogon Notify: ddayy - C:\WINDOWS\SYSTEM32\ddayy.dll ​
​O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll ​
​O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe ​
​O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE ​
​O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe ​
​O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe ​
​O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe ​
​O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe ​
​O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe ​
​O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe ​
​O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe ​
​O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) ​
​O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe ​
​ ​

5.9K Posts

September 29th, 2005 15:00

If you have trouble with Safe Mode then try it in regular mode.
 
The paths the program asks you for would be:
 
C:\WINDOWS\SYSTEM32\ddayy.dll
and
C:\WINDOWS\SYSTEM32\yyadd.*
(this is the same as the first path but with the name of the dll written backwards and .* instead of .dll.
Do not use the paths given in the article.  They won't work for your infection.
If you get a blue screen just restart Windows. 
If HijackTHis does not run by itself then run it manually.
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\ddayy.dll
O20 - Winlogon Notify: ddayy - C:\WINDOWS\SYSTEM32\ddayy.dll

You will know that it worked if the above lines
either drop out of the scan or say File Missing. 

If you see any of them then check them and Fix Checked to remove them.
 
The ActiveScan is optional.

Post a new HijackThis scan as a REPLY when you are done. 
 
Ron
No Events found!

Top