Unsolved

This post is more than 5 years old

25 Posts

1735

November 7th, 2005 13:00

Viruses Got Me

Logfile of HijackThis v1.99.1
Scan saved at 9:13:15 AM, on 11/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\fzelqks.exe
C:\WINDOWS\System32\zvxmwns.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\finch\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50141
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=10345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
F2 - REG:system.ini: UserInit=userinit.exe
N1 - Netscape 4: user_pref("browser.startup.homepage", " http://www.google.com/"); (C:\Program Files\Netscape\Users\indiator\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [vnfomc] C:\WINDOWS\System32\vnfomc.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [vidmon] C:\WINDOWS\System32\vidmon\vidmon.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [jnbvop] C:\WINDOWS\System32\kcybo\jnbvop.exe
O4 - HKLM\..\Run: [omilpax] c:\windows\system32\omilpax.exe -start
O4 - HKLM\..\Run: [vsogpfyt] C:\WINDOWS\System32\gyxplvp\vsogpfyt.exe
O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
O4 - HKLM\..\Run: [rcwljn] C:\WINDOWS\System32\ihuykvl\rcwljn.exe
O4 - HKLM\..\Run: [iplmsa] C:\WINDOWS\System32\apgpyhom\iplmsa.exe
O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [qxlmglq] C:\WINDOWS\System32\fdjffn.exe r
O4 - HKLM\..\Run: [win3208547818305] C:\WINDOWS\win3208547818305.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [nhnsdjk] C:\WINDOWS\System32\zvxmwns.exe r
O4 - HKLM\..\Run: [tpkzvg] C:\WINDOWS\System32\mkdgcq.exe r
O4 - HKCU\..\Run: [Jipjkmrr] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - HKCU\..\Run: [mvueac] C:\WINDOWS\System32\mvueac.exe
O4 - HKCU\..\Run: [syszdl] c:\windows\system32\syszdl.exe
O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Adtc] "C:\Program Files\maat\oiao.exe" -vt rbnd
O4 - HKCU\..\RunOnce: [strrvi] C:\windows\system32\strrvi.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Program Files\Q330994.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
O20 - Winlogon Notify: Vfwwdm - C:\WINDOWS\system32\o0nsla571d.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: vsogpfytgyxplvp - Unknown owner - C:\WINDOWS\System32\gyxplvp\vsogpfyt.exe
 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 7th, 2005 18:00

First, you should move HJT from your Desktop:

C:\Documents and Settings\finch\Desktop\HijackThis.exe

into a separate folder of its own... We recommend using folder C:\HJT , so that it will then appear in your log under running processes as C:\HJT\HijackThis.exe

This is important because HJT generates log files, and backup files, in the folder from which it is run. So at present, all these logs/backups will just "clutter-up" your Desktop. And if you simply delete them from there, you'll lose the important backup information, which may be needed in case you have to "undo" [restore] some of the things you "FIX" incorrectly.

 
After you move HJT, as i've just instructed:
 
Among other things, you have a NAIL/(triple) epolvy/SvcProc infection... I'm going to try to help you to remove this first.   This fix involves using Ad-Aware, and its VX2-cleaner.   It is critical that you use the current versions as indicated below... if you use an older/obsolete version, the fix will not work.
 
If you don't already have it, download Ad-Aware SE Personal 1.06 from http://www.majorgeeks.com/Ad-Aware_SE_Personal_d506.html
[Note:  If you have an older "build" of Ad-Aware SE --- or even worse, if you're still using Ad-Aware 6 --- you must upgrade to this version/build,  SE 1.06 ]
 
Install the Ad-Aware program (following any indicated directions).   [As part of the installation, it will check to see if you already have an older version of Ad-Aware installed, and if one is found, it will ask ("advise") you to allow the older one to be removed...  so if asked, please allow it.]
 
Open/start Ad-Aware SE.     Click on Check for Updates Now, and Connect .  if found, follow the directions to download/install the latest reference file, till you FINISH.
 
After updating, from the STATUS screen, click on START.  
then make sure you have a RED X in front of "Search for negligible risk entries
(if you see a GREEN CHECK, then CLICK on it, to change it to the RED X )
then hit NEXT to perform a S mart Scan.  Allow it to remove any problems founds.
 
Close-down Ad-Aware.  
 
then download the VX2-cleaner add-on by clicking-on the link near the bottom of
This will download the file  vx2cleaner_inst.exe ; click on it, and follow the directions to install the VX2-cleaner.
 
Start Ad-Aware SE again.  Click on the Add-Ons button.   Click on the VX2-Cleaner.  Click on Run Tool, and then click OK .    If it finds any VX2 problems, follow all the directions to CLEAN things.   (I believe this will include a reboot, and directions to run another smart scan.   Follow all indicated directions [i.e., various/multiple scans] until it tells you you're clean of VX2.
 
This should have removed all traces of NAIL/Aurora/epolvy.  Please generate and post a new HiJackThis log, appending it to this same thread.

Message Edited by ky331 on 11-07-2005 04:55 PM

25 Posts

November 7th, 2005 19:00

Thanks ky331, You guys don't know how glad I am for this support, I would be lost without it, so you guys rock! To bad the Green Bay Packers didn't...ha...they got rocked by Pittsburg...anyway I am very happy to talk to someone who has experience in virus removal!

I had installed the HJT folder as instructed into the C: drive. But my CPU is so hammered I have trouble keeping the computer going for any length of time without going into SAFE MODE. So I think this is why it showed on the desktop? Anyway later on a virus hammered my .exe that was in the folder and now is made useless.

So is it ok to run the ADAWARE SE Personal, just new version loaded yesterday, and then get Ad ons for VX2 removal in SAFE MODE?

Thanks

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 7th, 2005 22:00

if at all possible, see how much you can run in NORMAL mode... but if it's absolutely impossible, it certainly couldn't hurt to try running some/all of these in safe mode....
 
[by the way, my goal with you is to take care of the NAIL/epolvy/SvcProc problem... and maybe a few more minor points... after which, the plan is to call in someone else for the remainder of your problems.   so if it turns out you're having any "major" problems in getting things to run because of your "hammered" system and/or a need to run in SAFE mode, please let me know ASAP, and if need be, we'll put out that "rescue" call sooner than later...]
 
if you can't access the internet on your bad PC, then you'll have to do your downloads on another "good" PC (at work?  a friend's?), and then copy/transfer the files... by floppy, CD/RW, or memory-stick... from the good PC to the infected one.
 
 ****************
 
if i understand what you said, you've lost your copy of hijackthis.exe ?  if so, you can download a self extracting copy of HijackThis from http://downloads.malwareremoval.com/hijackthis_sfx.exe and save it to your desktop. Double-click on the file hijackthis_sfx.exe file and it will self extract into its own folder in C:\Program Files\HijackThis
 
***************

you say you just got Ad-Aware SE  yesterday?  did you also get the updated definition/reference file at the same time?  if not, you can also perform this update onto your good machine, and then, [assuming you've accepted the Ad-Aware defaults], transfer the file:

C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref

*****************

and we certainly need to download/install the VX2-cleaner add-on.


25 Posts

November 8th, 2005 00:00

Ok, I ran all this NORMAL mode, ran the Adware SE after udpate defs and did a Smart Scan and delete, the got the VX2 cleaner downloaded ok and ran the tool. Then had to get the HiJackThis.exe back and copy and pasted into HJT folder and ran and made this current log.

Logfile of HijackThis v1.99.1
Scan saved at 8:51:06 PM, on 11/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atievxx.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\WINDOWS\System32\nfomon\nfomon.exe
C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
C:\WINDOWS\System32\kcybo\jnbvop.exe
C:\WINDOWS\System32\cwtscs\pwwj.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\SysCheckBop32.exe
C:\Program Files\maat\oiao.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=10345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: UserInit=userinit.exe
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.google.com/"); (C:\Program Files\Netscape\Users\indiator\prefs.js)
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {54075D5A-C1C7-CA15-EB49-B7EEFAF7BDE8} - C:\WINDOWS\System32\pkbgqrlw.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [vnfomc] C:\WINDOWS\System32\vnfomc.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [jnbvop] C:\WINDOWS\System32\kcybo\jnbvop.exe
O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [win3208547818305] C:\WINDOWS\win3208547818305.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Jipjkmrr] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - HKCU\..\Run: [mvueac] C:\WINDOWS\System32\mvueac.exe
O4 - HKCU\..\Run: [syszdl] c:\windows\system32\syszdl.exe
O4 - HKCU\..\Run: [Adtc] "C:\Program Files\maat\oiao.exe" -vt rbnd
O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Program Files\Q330994.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\p0p6la7s1d.dll (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 8th, 2005 01:00

Great work so far.  While there's still a lot more to do, it seems that you've successfully removed the NAIL/ (triple) epolvy /SvcProc problem... Have you noticed any difference (probably in terms of popups from "Aurora")?... does the system seem ANY more responsive yet?

At this point, I'm gonna ask someone else to step-in, to help you with your remaining problems.   Please be patient, as we're very much "understaffed" and "overworked" here at the moment. 

Good luck.

 

P.S.  If i'm not mistaken, you have MANY virus infections (which the next person will hopefully tend to)... my question:   do you keep your anti-virus subscription, and its definitions/signatures up to date?  I strongly recommend you check for updates every time you log onto the internet.  [and you should do a complete system scan at least once a month.]  

25 Posts

November 8th, 2005 01:00

Thanks KY,

Things to seem to be running less CPU intensive, but get lots of Ads running from SSK..or Sidekick? When I connect on the net and start a browser, pop ups will start coming in and I have to continually close these before the computer loads up and crashes. But yes I think currently I see some improvment. This computer was inherited from a friend and he did not keep windows updated and did not have a antivirus program, so he just used it until it crawled. Now have McAfee on it; and then trying to run his Windows Updates that he never ran either. When I ran McAfee scan it showed I had Downloader-KL and Adware-Gator, but ran the Adware-Gator tool from Symantic but could not find anything. McAfee could not fix Downloader-KL or Gator so should I quarantine these, or delete them? Thanks very much for all of your kind help!!

2 Intern

 • 

5.9K Posts

November 8th, 2005 13:00


Start, Control Panel, Add/Remove Programs and see if you can find Surf SideKick and remove it.  IF not then
Start, Run, cmd, OK to bring up the black cmd screen.  Type:

cd "\Program Files\SurfSideKick 3"
ssk.exe /u

(that should uninstall it.  Close the window.  You can copy each line of the above =>highlight and ctrl + c then move to the cmd screen and right click to paste it)

 

Download the Hoster from:


http://www.funkytoad.com/

Unpack to your desktop and run it.  If you have green print at the top then just press Restore Original Hosts then OK. 
IF you have red print then press make Hosts Writeable first.
 

 

Get DelDomain.inf from:
 
http://www.mvps.org/winhelp2002/DelDomains.inf  and then right click on it and Install. 

Nothing obvious will happen.


Download and install ccleaner.exe from http://www.ccleaner.com. Don't let
it clean anything yet. 

Download the killbox:

http://www.bleepingcomputer.com/files/killbox.php

Unzip it to your desktop but don't run it.


Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.

Run HijackThis and just do a Scan only. Check then Fix Checked the following:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {54075D5A-C1C7-CA15-EB49-B7EEFAF7BDE8} - C:\WINDOWS\System32\pkbgqrlw.dll

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll

O4 - HKLM\..\Run: [vnfomc] C:\WINDOWS\System32\vnfomc.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [Nfo] C:\WINDOWS\System32\nfomon\nfomon.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [jnbvop] C:\WINDOWS\System32\kcybo\jnbvop.exe
O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [win3208547818305] C:\WINDOWS\win3208547818305.exe
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Jipjkmrr] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [SysCheck32] C:\WINDOWS\SysCheckBop32.exe
O4 - HKCU\..\Run: [mvueac] C:\WINDOWS\System32\mvueac.exe
O4 - HKCU\..\Run: [syszdl] c:\windows\system32\syszdl.exe
O4 - HKCU\..\Run: [Adtc] "C:\Program Files\maat\oiao.exe" -vt rbnd
O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Program Files\Q330994.exe
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer2005ScannerInstall.cab
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\p0p6la7s1d.dll (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)


Run ccleaner.exe, uncheck everything on the first page except the two entries
with Temporary and then Run Cleaner.


Run killbox.  Where it says Full Path of File to Delete you need to type or copy (Hightlight and Ctrl + c)
and Paste (move to the killbox and place the cursor in the box and Ctrl + V):

C:\Program Files\TBONAS

Then check the Delete on Reboot box and DELTREE box  then the red button. 
Agree you want to remove the file but do not let it reboot yet.

Repeat for:
C:\WINDOWS\System32\kcybo
C:\WINDOWS\System32\cwtscs
C:\WINDOWS\System32\kemx
C:\WINDOWS\System32\nfomon
C:\Program Files\maat
C:\Program Files\SurfSideKick 3 (it may not find it)

Repeat with only Delete on Reboot:

C:\Program Files\Q330994.exe
C:\WINDOWS\dinst.exe

If it doesn't find one then just go on to the next.

Let it reboot after the last one.

 


Run another HijackThis log and post it as a reply. Let's
see how we did.

Ron

25 Posts

November 8th, 2005 17:00

Hi RKinner,

Thanks very much for taking me on! I apreciate all of you guys.

Stupid me, I did not see that Sidekick way down below the Windows Updates in the Remove Programs Menu otherwise I would have killed the darn thing faster than lightning. So last night after my last post I found it and deleted the program.

So now do I continue with what you advised after that, from Download Hoster on down?

2 Intern

 • 

5.9K Posts

November 8th, 2005 18:00

Yes.  Just don't worry if you can't find a line or a file.  Probably removed by Surf SideKick when it went.

Ron

25 Posts

November 8th, 2005 18:00

Ok Ron,

Thanks, I am at work now, but will try to do this after 6 pm tonight and send a new HiJack Log. By the way I ran a McAffee virus check this morning and shows no viruses. I have also had to uncheck several programs in my msconfig Start to keep from overwhelming the CPU when startup, so should I keep these unchecked or go full speed ahead?

I am also low on Hard Disk Space with only 5 to 10 percent free when I use System Restore and I could not run a defrag so I turned off System Restore and have now 15 percent so I can Defrag ok. Should I keep System Restore always going, or leave off? I also plan on moving some files to another external disk to free up some much needed Free Space, as currently it is choking.

2 Intern

 • 

5.9K Posts

November 8th, 2005 19:00

Leave the files in msconfig unchecked until we get the first batch sorted out then we will turn everything back on and see what else needs to be removed.

I do not like to run without System Restore.

Download and install ccleaner.exe from http://www.ccleaner.com.  Then

Run ccleaner.exe, uncheck everything on the first page except the two entries
with Temporary and  the one with the recycle bin then Run Cleaner.  This will free up a lot of space. 

If you are on a fast link you can run IE then Tools, Internet Options, Settings then slide the slider all the way to the left and say OK.

You can also:

Right click on Start and select Explore.  Then in the new window find the Views icon (bottom right of the two toolbars at the top.  Looks like a little window with a down arrow.  Press it and select Details.  Then select Tools, Folder Options, check Use Windows Classic Folders, Apply then View, check Show Hidden Files and Folders, and uncheck the two that start with Hide. (ignore the warning) then say Apply.  Then press Like Current Folder.  OK.

Now locate the Windows folder (My Computer=>  Local Disk C: => Windows and click once on it.  In the right pane will be an alphabetical list of folders and files. 

You should be able to see a bunch of folders in the right panel with names starting with $NtUninstall...

These are all copies of your old files that were replaced by newer versions.  If you are not planning on backing out any of the updates then you can get back a lot of space.

You can select all of the folders that start with $NtUninstall then delete them.  Then empty the recycle bin. 

Ron

25 Posts

November 9th, 2005 00:00

Ok Ron, Here you go...Thanks again for taking your time for me!
 
Logfile of HijackThis v1.99.1
Scan saved at 8:40:33 PM, on 11/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atievxx.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\taskmgr.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=10345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
N1 - Netscape 4: user_pref("browser.startup.homepage", " http://www.google.com/"); (C:\Program Files\Netscape\Users\indiator\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
 

2 Intern

 • 

5.9K Posts

November 9th, 2005 00:00

Log looks a lot better.  I hope things are running better now.

 

There is one line that is playing hard to get.

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)

but we got its file so it can't do anything.  Under Misc Tools in HijackTHis there is an option to remove NT Services.  If you tell it to remove

cmdService

 

it may be able to remove it completely for us.

 

You can now put msconfig back to normal and let's see what is hiding there.  (post a new HJT log as a reply.)

Ron

 

25 Posts

November 9th, 2005 01:00

Logfile of HijackThis v1.99.1
Scan saved at 9:17:09 PM, on 11/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atievxx.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\snss\snss.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\lfgif10N.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\dvdupgrd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Common Files\services.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=10345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
N1 - Netscape 4: user_pref("browser.startup.homepage", " http://www.google.com/"); (C:\Program Files\Netscape\Users\indiator\prefs.js)
O2 - BHO: Internet Explorer Web Content Catcher  - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [YourMonitor] C:\WINDOWS\Sys98
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\igudtn.exe reg_run
O4 - HKLM\..\Run: [vsogpfyt] C:\WINDOWS\System32\gyxplvp\vsogpfyt.exe
O4 - HKLM\..\Run: [TagASaurus] C:\Program Files\TagASaurus\TagASaurus
O4 - HKLM\..\Run: [SystemCheck] 
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [seli] C:\WINDOWS\exe82.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Qyvkbi.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [rcwljn] C:\WINDOWS\System32\ihuykvl\rcwljn.exe
O4 - HKLM\..\Run: [pwwj] C:\WINDOWS\System32\cwtscs\pwwj.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [ms03302707794] C:\WINDOWS\ms03302707794.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [lwjv] C:\WINDOWS\System32\kemx\lwjv.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [iplmsa] C:\WINDOWS\System32\apgpyhom\iplmsa.exe
O4 - HKLM\..\Run: [inwmg] C:\WINDOWS\system32\w130713.Stub.EXE
O4 - HKLM\..\Run: [g$p$] C:\WINDOWS\exe82.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async9x
O4 - HKLM\..\Run: [dheng] C:\WINDOWS\System32\guwmegfe\dheng.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [54cec6941c00] C:\WINDOWS\System32\lfgif10N.exe
O4 - HKLM\..\Run: [2fMUA5] "C:\WINDOWS\system32\cxtpls_loader.EXE" /PC=CP.AOP2
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [Sys98] C:\WINDOWS\Sys98.exe
O4 - HKCU\..\Run: [strrvi] C:\windows\system32\strrvi.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000106.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000106.exe
O4 - HKCU\..\Run: [cgwjhkdo] c:\windows\system32\cgwjhkdo.exe -start
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\Program Files\InetGet\stubinstaller6002.exe"
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZmluY2gA\command.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
 

25 Posts

November 9th, 2005 01:00

Wow Ron, this computer is really speedy now...amazed and stunned!

I went to the Delete an NT service and tried to delete:
cmdService but got an error in Hijack This v.1.991

"The service cmdService is enabled and/or running. Disable it first using HiJackThis Itself (from the scan results) or the Services.msc window. ---Click OK---

Went back and did a scan and checked it but and Fix Checked, did another scan, but still there?
No Events found!

Top