I've used spybot and there are things that pop up that spybot won't delete. I downloaded the suggested hijackthis program, and here is my log. Can anyone help me please?
Logfile of HijackThis v1.99.0
Scan saved at 1:39:34 PM, on 1/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\documents and settings\heather\local settings\temp\r9tEv.exe
C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
C:\documents and settings\heather\local settings\temp\sg.exe
C:\documents and settings\heather\local settings\temp\Da3a.exe
C:\documents and settings\heather\local settings\temp\Bqs.exe
C:\Program Files\SED\SED.exe
C:\WINDOWS\system32\wkwiwi.exe
C:\windows\system32\XDJINI.exe
C:\WINDOWS\SYSTEM32\XDJINI.exe
C:\windows\system32\K5IlSA.exe
C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
C:\documents and settings\heather\local settings\temp\ONHLKe.exe
C:\PROGRA~1\AIM95\aim.exe
C:\Documents and Settings\Heather\Application Data\eetu.exe
C:\WINDOWS\system32\w?nword.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Dell\Support\Alert\bin\AlertView.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Heather\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
There's alot of 'bad' or suspicious programs running in that log, so before we begin, let's backup the entire registry and let some programs do most of the work for us.
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) "
Auto Clean".
3. Click "
Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
If you don't already have it, download, install and run
AdAware SE Personal.
-
Next, check for, and download any available updates:
1. click "
Check for updates now".
2. Click "
Connect".
3. If updates(definitions) are available click "
Ok", otherwise, click "
Ok".
4. Click "
Finish".
-
Next, configure
AdAware to be as effective as possible:
1. Click the '
gear' in the upper-right hand corner of the
AdAware Window.
2. Click Scanning, and check(tick) the following:
Scan within archives Scan active processes Scan registry Deep-scan registry Scan my IE Favorites for banned URLs Scan my Hosts file
3. Click "
Tweak".
4. Click "
Scanning Engine", then check(tick) the following:
Unload recognized proceses & modules during scan
5. Click "
Cleaning Engine", then check(tick) then following:
>
Always try to unload modules before deletion During removal, unload Explorer and IE if necessary Let Winodws remove files in use at next reboot Delete quarantined objects after retoring
6. Then click "
Proceed"
-
Now, let
AdAware locate and remove anything it finds, by:
1. Click "
Start".
2. Check(tick) "
perform full system scan".
3. Click "
Next".
-
Exit the program.
Go to
Add/Remove programs and remove(uninstall) the following, if present:
The above could appear anywhere within the entry. Be careful not to remove any
personal or
system software.
Download
LSPFix and unzip to your desktop, then run it. Now, we need to:
1. check(tick) "
I know what i'm doing".
2. click on (highlight) each occurance of the following, one at a time:
aklsp.dll dolsp.dll
3. then click "
>>", moving each one, individually, to the 'Remove' pane.
4.
(double-check, and make sure that only the above files are in the 'Remove'pane.) 5. click "
Finish >>"
1. Click "
Config..."
2. Click "
Misc Tools"
3. Click "
Open Process manager"
-
Next, while holding down the
CTRL key, locate (
if present) and click on (
highlight) each of the following:
C:\documents and settings\heather\local settings\temp\r9tEv.exe C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe C:\documents and settings\heather\local settings\temp\sg.exe C:\documents and settings\heather\local settings\temp\Da3a.exe C:\documents and settings\heather\local settings\temp\Bqs.exe C:\Program Files\SED\SED.exe C:\WINDOWS\system32\wkwiwi.exe C:\windows\system32\XDJINI.exe C:\windows\system32\K5IlSA.exe C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe C:\documents and settings\heather\local settings\temp\ONHLKe.exe C:\Documents and Settings\Heather\Application Data\eetu.exe C:\WINDOWS\system32\w?nword.exe
Now double-check and make sure that only those item(s) above are highlighted, then click "
Kill process". Now, click "
Refresh", check again, and repeat this step if any remain.
Now, let's open a
command prompt and unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u vLE91XN3.dll
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to a command prompt to save on the typing.
Before we begin, let's move
HiJackThis to it's own folder; like
c:\HJT. When we're done '
cleaning' off your system, we're going to '
flush' the temporary folders which, with
HiJackThisin it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.
Also move the "
Backups" folder, for
HiJackThis, if present.
Run
HiJackThis and click "
Scan", then check(tick) the following, if present:
When your done with all the steps in that fix, post back a new new log. When we've got that cleaned up, we'll try the online scan again (just to see if the cleanup removed them), then manually remove the files that cannot be deleted.
Logfile of HijackThis v1.99.0
Scan saved at 8:06:19 PM, on 1/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Ok, it looks like all the above decided to shift into a bad vx2 infection, so we'll tackle that next. I'm almost certain it's going to be the newer more difficult (not impossible) to remove version, but we'll try the VX2 cleaner for AdAware SE first. We'll be using this later in the cleanup process anyway.
-
Let's get started...
Go to
Add/Remove programs and remove(uninstall) the following, if present:
Web Offers
The above could appear anywhere within the entry. Be careful not to remove any
personal or
system software. Let me know if your wanting to keep this, or if you just can't locate it to remove it.
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) "
Auto Clean".
3. Click "
Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
If you don't already have it, let's go to
Lavasoft'sVX2 Cleaner web-page, and follow the instructions to download and install the utility.
-
Next, run
AdAware SE Personal, then:
1. Click "
Add-Ons".
2. Double-click "
VX2 Cleaner"
3. Click "
Ok", to "
Execute this tool".
4. If nothing is found, click "
Ok", then exit the program.
(or)
4. If
VX2 has been found on your system, click "
Clean System"
5. Then when it's complelely done, reboot your computer.
6. Repeat steps 1-4 again.
Be sure to follow any instructions it might give while using it.
Run
HiJackThis and click "
Scan", then check(tick) the following, if present:
I keep on trying to delete the 01 hosts that you told me too, but everytime I do a scan they still appear to be there. When I run AdAware too, it says that i have VX2 on my computer, but then when i ran the VX2 cleaner it said that my computer was clean.
Logfile of HijackThis v1.99.0
Scan saved at 5:50:25 PM, on 01/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Ok, then your system has the newest version of VX2, and it'll take us a few posts to get it resolved, so let's go ahead and get started. The most important thing to remember with this infection is to not reboot your system until your instructed to; it creates new files on every reboot and will complicate the cleanup.
Let's get started...
Let's see if we can try and fix this; it might get a little complicated, so, if you have questions at any time, just post back.
First, let start off by looking where no-hijack has looked before:
* DLLCompare Log version()
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM32\hr8o05~1.dll Tue Jan 25 2005 6:36:36p ..S.R 223,862 218.61 K
C:\WINDOWS\SYSTEM32\hrpm05~1.dll Fri Jan 21 2005 10:02:14p ..S.R 223,407 218.17 K
C:\WINDOWS\SYSTEM32\itsecsnp.dll Tue Jan 25 2005 6:36:36p ..S.R 223,477 218.24 K
C:\WINDOWS\SYSTEM32\k5ilsa.dll Fri Jan 21 2005 10:03:00p A..H. 106 0.10 K
C:\WINDOWS\SYSTEM32\o2lu0c~1.dll Sat Jan 22 2005 2:06:46p ..S.R 223,477 218.24 K
C:\WINDOWS\SYSTEM32\xdjini.dll Sat Jan 22 2005 10:03:40p ..SH. 475 0.46 K
________________________________________________
1,299 items found: 1,299 files (6 H/S), 0 directories.
Total of file sizes: 266,976,850 bytes 254.61 M
Midnight Star
4791 Posts
564
0
Posted January 22nd, 2005 18:00
There's alot of 'bad' or suspicious programs running in that log, so before we begin, let's backup the entire registry and let some programs do most of the work for us.
-
Let's get started...
Before we begin, let's backup the entire registry.
Go to www.trendmicro.com, and then:
1. Click " Free Online Scan".
2. Click " Scan now, it's free".
It'll take a few minutes to download (especially with a dialup connection), so be patient. When it's down:
1. Select all available drives.
2. Check(tick) " Auto Clean".
3. Click " Scan".
When it completes, post back the full filename of any files that cannot be cleaned or deleted.
If you don't already have it, download, install and run AdAware SE Personal.
-
Next, check for, and download any available updates:
1. click " Check for updates now".
2. Click " Connect".
3. If updates(definitions) are available click " Ok", otherwise, click " Ok".
4. Click " Finish".
-
Next, configure AdAware to be as effective as possible:
1. Click the ' gear' in the upper-right hand corner of the AdAware Window.
2. Click Scanning, and check(tick) the following:
Scan within archives
Scan active processes
Scan registry
Deep-scan registry
Scan my IE Favorites for banned URLs
Scan my Hosts file
3. Click " Tweak".
4. Click " Scanning Engine", then check(tick) the following:
Unload recognized proceses & modules during scan
5. Click " Cleaning Engine", then check(tick) then following:
> Always try to unload modules before deletion
During removal, unload Explorer and IE if necessary
Let Winodws remove files in use at next reboot
Delete quarantined objects after retoring
6. Then click " Proceed"
-
Now, let AdAware locate and remove anything it finds, by:
1. Click " Start".
2. Check(tick) " perform full system scan".
3. Click " Next".
-
Exit the program.
Go to Add/Remove programs and remove(uninstall) the following, if present:
Deals Online
Ebates MoeMoney
WildTangent
Virtual Bouncer
The above could appear anywhere within the entry. Be careful not to remove any personal or system software.
Download LSPFix and unzip to your desktop, then run it. Now, we need to:
1. check(tick) " I know what i'm doing".
2. click on (highlight) each occurance of the following, one at a time:
aklsp.dll
dolsp.dll
3. then click " >>", moving each one, individually, to the 'Remove' pane.
4. (double-check, and make sure that only the above files are in the 'Remove'pane.)
5. click " Finish >>"
Let's download the Symantec VirtuMundo removal tool, and run it.
Run HiJackThis then:
1. Click " Config..."
2. Click " Misc Tools"
3. Click " Open Process manager"
-
Next, while holding down the CTRL key, locate ( if present) and click on ( highlight) each of the following:
C:\documents and settings\heather\local settings\temp\r9tEv.exe
C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
C:\documents and settings\heather\local settings\temp\sg.exe
C:\documents and settings\heather\local settings\temp\Da3a.exe
C:\documents and settings\heather\local settings\temp\Bqs.exe
C:\Program Files\SED\SED.exe
C:\WINDOWS\system32\wkwiwi.exe
C:\windows\system32\XDJINI.exe
C:\windows\system32\K5IlSA.exe
C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
C:\documents and settings\heather\local settings\temp\ONHLKe.exe
C:\Documents and Settings\Heather\Application Data\eetu.exe
C:\WINDOWS\system32\w?nword.exe
Now double-check and make sure that only those item(s) above are highlighted, then click " Kill process". Now, click " Refresh", check again, and repeat this step if any remain.
Now, let's open a command prompt and unregister the dll(s) we're going to remove, by entering the following:
regsvr32 /u vLE91XN3.dll
It's ok, if these aren't found or 'error' out. If you want, just copy and paste the individual lines to a command prompt to save on the typing.
Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done ' cleaning' off your system, we're going to ' flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.
Also move the " Backups" folder, for HiJackThis, if present.
Run HiJackThis and click " Scan", then check(tick) the following, if present:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - Default URLSearchHook is missing
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Heather\Local Settings\Temp\vLE91XN3.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\Heather\LOCALS~1\Temp\TB_ANI~1.EXE /dcheck
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [MS Decryption Software] C:\active.exe
O4 - HKLM\..\Run: [nodovpn] C:\WINDOWS\System32\mnsnzd.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Program Files\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [r9tEv] C:\documents and settings\heather\local settings\temp\r9tEv.exe
O4 - HKLM\..\Run: [8n8WjZsIc] C:\documents and settings\heather\local settings\temp\8n8WjZsIc.exe
O4 - HKLM\..\Run: [N5EM2mrA] C:\documents and settings\heather\local settings\temp\N5EM2mrA.exe
O4 - HKLM\..\Run: [YZqxLiFcj] C:\documents and settings\heather\local settings\temp\YZqxLiFcj.exe
O4 - HKLM\..\Run: [WfPqtS8eb] C:\documents and settings\heather\local settings\temp\WfPqtS8eb.exe
O4 - HKLM\..\Run: [sg] C:\documents and settings\heather\local settings\temp\sg.exe
O4 - HKLM\..\Run: [Da3a] C:\documents and settings\heather\local settings\temp\Da3a.exe
O4 - HKLM\..\Run: [Bqs] C:\documents and settings\heather\local settings\temp\Bqs.exe
O4 - HKLM\..\Run: [SESync] "C:\Program Files\SED\SED.exe"
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [ntechin] C:\Documents and Settings\Heather\n20050308.exe
O4 - HKLM\..\Run: [XDJINI.exe] c:\windows\system32\XDJINI.exe
O4 - HKLM\..\Run: [K5IlSA] C:\windows\system32\K5IlSA.exe
O4 - HKLM\..\Run: [1x4u4xGxL] C:\documents and settings\heather\local settings\temp\1x4u4xGxL.exe
O4 - HKLM\..\Run: [ONHLKe] C:\documents and settings\heather\local settings\temp\ONHLKe.exe
O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Heather\Application Data\eetu.exe
O4 - HKCU\..\Run: [Yyc] C:\WINDOWS\system32\w?nword.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: Help - {07136CD1-8EAB-498F-A12E-3F288C35B3CA} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {4BFE5664-D092-4C35-BE65-473FE43CE968} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Support - {9B818C83-650B-4BB2-B923-3B6BEE26D291} - http://www.comcastsupport.com (file missing) (HKCU)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1441/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
Now, with all windows closed except HiJackThis, click " Fix checked".
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
folders...
C:\Program Files\SED
C:\Program Files\WildTangent
C:\Program Files\Ebates_MoeMoneyMaker
C:\Program Files\VBouncer
files...
C:\WINDOWS\system32\wkwiwi.exe
C:\windows\system32\XDJINI.exe
C:\windows\system32\K5IlSA.exe
C:\Documents and Settings\Heather\Application Data\eetu.exe
C:\active.exe
C:\WINDOWS\System32\mnsnzd.exe
C:\Documents and Settings\Heather\n20050308.exe
c:\windows\system32\aklsp.dll
c:\windows\system32\dolsp.dll
-
Run " Disk Cleanup" and allow it to remove everything it finds.
Don't reboot your system just yet and post back a new log.
-
Mike.