UNSOLVED

Taliesa

updated

20 years ago

T

Taliesa

28 Posts

0

1544

December 31st, 2006 18:00

updatedlog--hangs on shutdown, freezes, please help

Here is my updatedHijackthis log.    I know there are some malware programs operating, but not sure how to find/remove them--I don't think there's a virus, just some memory hogs or tracker.  Also, if any processes are unnecessary or duplicated, I'd like to get rid of them.   Any expert advice much appreciated!
 
Logfile of HijackThis v1.99.1
Scan saved at 3:21:59 PM, on 12/31/06
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXES
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
D:\PROGRAM FILES\PCCTLCOM.EXE
C:\WINDOWS\EXPLORER.EXE
D:\PROGRAM FILES\PCCIOMON.EXE
D:\PROGRAM FILES\TMPFW.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
D:\PROGRAM FILES\PCCGUIDE.EXE
D:\PROGRAM FILES\TMPROXY.EXE
C:\WINDOWS\FREECELL.EXE
C:\PROGRAM FILES\BIN\JUNO.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\PEOPLEPC\ISP6230\BROWSER\BARTSHEL.EXE
C:\PROGRAM FILES\PEOPLEPC\ISP6230\BROWSER\BARTSHEL.EXE
C:\PROGRAM FILES\PEOPLEPC\ISP6230\BROWSER\PPSHARED.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
D:\PROGRAM FILES\EASYCLEANER\EASYCLEA.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
D:\UTIL DOWNLDS\ANTIVIRUS & MISC SHAREWARE\WINZIP\WINZIP32.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search/
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\BIN\REGIST~1.EXE
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [pccguide.exe] "D:\Program Files\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [PcCtlCom] D:\PROGRAM FILES\PCCTLCOM.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRAMS\SPYWAR~1\TOOLS\IESDPB.DLL (file missing)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://dl.iwin.com
O15 - Trusted Zone: http://www.iwin.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003050501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLCD.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - https://a248.e.akamai.net/7/248/11498/v1/www.moveonpac.org/content/qt/qtplugin.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/17267a9ab97cd5242719/netzip/RdxIE601.cab
O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab
 
  • Bugbatter

    4 Apprentice

    20487 Posts

    579

    0

    Posted December 31st, 2006 19:00

    Hello, again. :)

    If you are still using Spyware Doctor, please disable it so it does not interfere with our fix.
    To disable Spyware Doctor from running on your system startup:
    1. First, disable the OnGuard Tools. This way, when you exit Spyware Doctor, these tools won't stay resident in the background.
    2. Click the "Settings" button on the left side.
    3. Click the "Startup Settings" link.
    4. Uncheck "Run at Windows Startup".
    5. Click the "Apply" button.
    Exit by a right-click on the "Spyware Doctor" icon in the system tray and choose "Exit".
    [To enable Spyware Doctor when you are finished, open the program, Settings>Startup Settings> CHECK "Run at Windows Startup">APPLY
    Exit. Reboot.]

    To disable PCTools Browser Monitor: If you are running Internet Explorer, click Tools > Manage Add-ons. If PCTools Browser Monitor is on the list, click it & select Disable. You will need to restart your browser after making the change.


    If you are not using it, and that Spyware Doctor just an old registry entry, please let me know, so we can fix it later.

    Please launch HijackThis and plasce a checkmark next to these:


    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O15 - Trusted Zone: http://dl.iwin.com
    O15 - Trusted Zone: http://www.iwin.com


    If you did not set this restriction, please fix this as well:
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    Close all windows except HijackThis and click "Fix Checked".

    Reboot.

    Please download Ad-Aware SE Personal and install it. If you already have Ad-Aware SE, please configure it as indicated below. If you have a previous version of Ad-Aware, please uninstall your current version and install the newest version SE 1.06.
    1) Run Ad-Aware, and click Check for updates now.
    2) Select Configurations (click the Gear wheel at the top) as follows:
    • General Button > Safety & Settings: Check (Green) all three.
    • Tweak Button > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
    Click Proceed.3) To start the scan, Click > "Scan Now" at left
    • Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
    • Select "Search for low-risk threats"
    • Select "Perform full system scan"
    • Click Next
    4) When the scan has completed, select Next.
    • In the Scanning Results window, select the "Critical Objects" tab.
    • Right-click on the screen and choose "Select all objects"
    • In the "Scan Summary" tab, check the box next to each additional "target family" you wish to remove.
    • Click Next to remove the objects selected, and click OK to the prompt.
    • Restart the computer.


    Download and scan with Spybot S&D 1.4.

    1. Install Spybot. Be sure to UNCHECK TeaTimer when presented with the option to install.
    2. Run Spybot, go to the Menu Bar at the top choose Mode and make certain that " Default mode" has a check mark beside it.
    3. Click the button " Search for Updates".
    4. If any updates are found, install them by placing a checkmark next to each one and clicking " Download Updates".

    If you encounter any error messages while downloading the updates, manually download them from here.

    5. Click on " Immunize". When it detects what has or has not been blocked, block all remaining items by clicking the green plus sign next to immunize at the top.
    6. Click the button " Check for Problems".
    7. When Spybot is complete, it will be showing RED entries, bold BLACK entries and GREEN entries in the window.
    8. Make certain there is a check mark beside all of the RED entries ONLY.
    9. Choose " Fix Selected Problems" and allow Spybot to fix the RED entries.
    10. REBOOT to complete the scan and clear memory.

    Note: After Windows loads, Spybot may run again to clean some files that it could not clean during the prior session. Follow the same procedure.
  • Taliesa

    28 Posts

    579

    0

    Posted January 1st, 2007 14:00

    Great-thanks!  I'm getting on with the project.  I just have an evaluation copy of Spyware Dr.  It is not set to run on startup and the OnGuard is turned off, also the browser tools.  I do have pccillin running, which also has some spyware search engine--do I need to disable that, as well?
     
    I used to have adaware & spybot, but after a while, they seemed to stop catching things, so I deleted them.  I will dl the latest versions
  • Bugbatter

    4 Apprentice

    20487 Posts

    579

    0

    Posted January 1st, 2007 18:00

    PC-cillin is an anti-virus. It is okay to leave that running.
  • Taliesa

    28 Posts

    578

    0

    Posted January 2nd, 2007 15:00

    I completed the adaware and spybot scans.  Spybot hung up on the reboot, so I removed it from the startup.  while I was doing the adaware, pccillin came on and said I had a virus-but I forgot to write it down.  There was also a fatal exception, but when I rebooted and ran it again, it worked.  Here is my new hijack this file:
     

    Logfile of HijackThis v1.99.1

    Scan saved at 11:54:03 AM, on 1/2/07

    Platform: Windows 98 Gold (Win9x 4.10.1998)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL

    C:\WINDOWS\SYSTEM\MSGSRV32.EXE

    C:\WINDOWS\SYSTEM\MPREXE.EXE

    C:\WINDOWS\SYSTEM\mmtask.tsk

    C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe

    D:\PROGRAM FILES\PCCTLCOM.EXE

    D:\PROGRAM FILES\PCCIOMON.EXE

    D:\PROGRAM FILES\TMPFW.EXE

    C:\WINDOWS\EXPLORER.EXE

    C:\WINDOWS\SYSTEM\SYSTRAY.EXE

    C:\WINDOWS\SYSTEM\STIMON.EXE

    D:\PROGRAM FILES\PCCGUIDE.EXE

    C:\WINDOWS\SYSTEM\QTTASK.EXE

    D:\PROGRAM FILES\TMPROXY.EXE

    C:\WINDOWS\SYSTEM\DDHELP.EXE

    C:\WINDOWS\FREECELL.EXE

    C:\PROGRAM FILES\PEOPLEPC\ISP6230\BROWSER\BARTSHEL.EXE

    C:\PROGRAM FILES\PEOPLEPC\ISP6230\BROWSER\BARTSHEL.EXE

    C:\PROGRAM FILES\PEOPLEPC\ISP6230\BROWSER\PPSHARED.EXE

    C:\WINDOWS\SYSTEM\RNAAPP.EXE

    C:\WINDOWS\SYSTEM\TAPISRV.EXE

    C:\WINDOWS\SYSTEM\PSTORES.EXE

    C:\HIJACK THIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search/

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRAMS\SPYBOT~1\SDHELPER.DLL

    O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\BIN\REGIST~1.EXE

    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe

    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE

    O4 - HKLM\..\Run: [pccguide.exe] "D:\Program Files\pccguide.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

    O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe

    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme

    O4 - HKLM\..\RunServices: [PcCtlCom] D:\PROGRAM FILES\PCCTLCOM.EXE

    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL

    O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003050501/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLCD.CAB

    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - https://a248.e.akamai.net/7/248/11498/v1/www.moveonpac.org/content/qt/qtplugin.cab

    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/17267a9ab97cd5242719/netzip/RdxIE601.cab

    O16 - DPF: {192F9A01-8030-48CE-9BC6-B03DE3E613C6} (PeoplePC Web Installer) - https://www.peoplepc.com/ppcos/ISP60/Download/ppcwebi.cab

    Thanks, Taliesa t:)

  • Bugbatter

    4 Apprentice

    20487 Posts

    578

    0

    Posted January 2nd, 2007 16:00

    There is one item that we can fix in HijackThis:
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/17267a9ab97cd5242719/netzip/RdxIE601.cab

    Close all windows except HijackThis and click "Fix Checked"

    Reboot.

    Download and scan with CCleaner:
    http://www.ccleaner.com/downloadbuilds.asp
    ** Select to download the BASIC version.
    1. Before first use, select Options > Advanced and UNCHECK
    " Only delete files in Windows Temp folder older than 48 hours"
    2. Then select the items you wish to clean up.
    In the Windows Tab:
    • Clean all entries in the "Internet Explorer" section except Cookies (if you want to keep those).
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.
    In the Applications Tab:
    • Clean all except cookies (if you want to keep those) in the Firefox/Mozilla section if you use it.
    • Clean all in the Opera section if you use it.
    • Clean Sun Java in the Internet Section.
    • Clean any others that you choose.
    3. Click the " Run Cleaner" button.
    4. A pop up box will appear advising this process will permanently delete files from your system.
    5. Click " OK" and it will scan and clean your system.
    6. Click " exit" when done.

    REBOOT into Safemode:
    Turn on the computer.
    Immediately begin tapping the F8 key
    Use the arrow keys to highlight Safe Mode and press the Enter key.

    While in Safemode, scan with PC-Cillin, and let's see if it finds and cleans that virus it was alerting you of before. (It may have just conflicted with a filename that is in Ad-aware's definitions.)

    Please let me know how things are running after that. Thanks.
  • Taliesa

    28 Posts

    578

    0

    Posted January 4th, 2007 17:00

    Okay--I finally got back into the thread after a call to Dell tech help and a review of my cookie acceptance!  I'm not sure whether my cookie settings require further adjustment:  I now have "prompt" for first and third person cookies, and checked "accept all session cookies"  Is this okay, or will it get me in trouble?
     
    I completed ccleaner project and comp is no longer hanging on shut down--also browser pages are loading faster.  In safe mode, pccillin imdicated a troj_generic.Z in C:/Windows/system\lwr2.dll.  What should I do about it?
  • Bugbatter

    4 Apprentice

    20487 Posts

    578

    0

    Posted January 4th, 2007 19:00

    That's okay as long as you get a prompt and know that the website you are on is reliable if it is asking for cookie acceptance.

    If PC-cillin wants to clean or quarantine that file, let it do that. Make sure you are in Safemode when you run the scan. That eliminates the possibility that the file is running (in which case it would refuse to leave). Let me know how you make out. Good luck!
  • Taliesa

    28 Posts

    578

    0

    Posted January 5th, 2007 12:00

    Hmmm--it seems it would have cleaned or quarentined it on the last scan, or when it first popped up with it.  I'll do the safemode scan again & see whether I can get it to clean.
     
    I still have some trouble with freezing frames when web surfing --I think it is because there is too much stuff on my c drive.  It has even less freespace now than before, although I dl'ed and installed the cleanup programs in d, where there's much more room.
     
    Thanks,
    t:)
     
  • Bugbatter

    4 Apprentice

    20487 Posts

    578

    0

    Posted January 6th, 2007 04:00

    It cannot be cleaned if the file is running. That is why we are using Safemode.
    How old is that Win 98 computer? How much RAM do you have? As you probably know, Microsoft does not support Win 98 anymore. The tools and applications that you are running have been updated over the years -- including Internet Explorer with all its patches. All that is taking up space. It is assumed by the developers that most people are using Windows XP. If your root drive is pretty full, that may be why you are having problems.
  • Bugbatter

    4 Apprentice

    20487 Posts

    322

    0

    Posted January 6th, 2007 15:00

    It's not a matter of knowing how Win98 works, but today's tools use resources, and it sounds like you don't have HD space or RAM to spare. I believe that filename is from BargainBuddy -- something you may have had a while ago.

    Before I have you download a yet another removal tool, let's see if we can manually delete that file in Safemode.

    After rebooting into Safemode, double-click the My Computer icon on the Windows desktop.
    Click the View menu, and then click Options or Folder Options.
    Click the View tab.
    In the Advanced settings box, under the "Hidden files" folder, select Show all files.
    Click Apply, and then click OK.

    See if you can browse to this location and delete the file:
    C:/Windows/system\ lwr2.dll --file

    Reboot.

    Go back and rehide files:
    Double-click the My Computer icon on the Windows desktop.
    Click the View menu, and then click Options or Folder Options.
    Click the View tab.
    In the Advanced settings box, under the "Hidden files" folder, DE-select Show all files.
    Click Apply, and then click OK.

    If that doesn't work, we'll have you kill it with a tool.