Here you go, again thank you very much. Thanks, Will
Here's the findfile.bat output.
Volume in drive C has no label.
Volume Serial Number is E44D-6A5E
Directory of C:\WINDOWS\System32
08/04/2004 01:56 AM 14,336 svchost.exe
12/22/2004 01:23 PM 389,120 ??chost.exe
2 File(s) 403,456 bytes
Directory of C:\Documents and Settings\joe\Desktop
Find.bat is running from: C:\findit\Find It NT-2K-XP
------- System Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is E44D-6A5E
Directory of C:\WINDOWS\System32
01/13/2005 09:38 AM 222,935 rlgwizc.dll
01/13/2005 09:37 AM 225,087 fppo0373e.dll
01/13/2005 09:28 AM 222,935 l4n4le5q1h.dll
01/13/2005 08:13 AM 225,634 gp2ul3f91.dll
01/11/2005 04:36 PM <DIR> DLLCACHE
12/22/2004 01:23 PM 389,120 ??chost.exe
11/12/2003 03:03 AM <DIR> Microsoft
5 File(s) 1,285,711 bytes
2 Dir(s) 34,452,402,176 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is E44D-6A5E
Directory of C:\WINDOWS\System32
01/12/2005 02:17 PM <DIR> wsxsvc
01/11/2005 04:36 PM <DIR> DLLCACHE
01/08/2005 11:18 AM <DIR> vmss
12/22/2004 01:23 PM 389,120 ??chost.exe
09/03/2002 01:33 PM 488 logonui.exe.manifest
09/03/2002 01:33 PM 488 WindowsLogon.manifest
09/03/2002 01:33 PM 749 sapi.cpl.manifest
09/03/2002 01:33 PM 749 nwc.cpl.manifest
09/03/2002 01:33 PM 749 ncpa.cpl.manifest
09/03/2002 01:33 PM 749 wuaucpl.cpl.manifest
09/03/2002 01:33 PM 749 cdplayer.exe.manifest
8 File(s) 393,841 bytes
3 Dir(s) 34,452,398,080 bytes free
------------ Files Named "Guard" ---------------
Volume in drive C has no label.
Volume Serial Number is E44D-6A5E
Directory of C:\WINDOWS\System32
------ Temp Files in System32 Directory ------
Volume in drive C has no label.
Volume Serial Number is E44D-6A5E
Directory of C:\WINDOWS\System32
------------------ User Agent ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=""
------------- Keys Under Notify -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\l4n4le5q1h.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
------------- Locate.com Results -------------
C:\WINDOWS\SYSTEM32\
fppo03~1.dll Thu Jan 13 2005 9:37:34a ..S.R 225,087 219.81 K
gp2ul3~1.dll Thu Jan 13 2005 8:13:04a ..S.R 225,634 220.34 K
l4n4le~1.dll Thu Jan 13 2005 9:28:34a ..S.R 222,935 217.71 K
rlgwizc.dll Thu Jan 13 2005 9:38:28a ..S.R 222,935 217.71 K
chost~1.exe Wed Dec 22 2004 1:23:16p ..SHR 389,120 380.00 K
5 items found: 5 files, 0 directories.
Total of file sizes: 1,285,711 bytes 1.22 M
-------- Strings.exe Qoologic Results --------
C:\WINDOWS\SYSTEM32\iuipzn.dll: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lmlupa.exe: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lzlugq.dll: updates.qoologic.com
--------- Strings.exe Aspack Results ---------
C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack
C:\WINDOWS\SYSTEM32\vovuyg.exe: .aspack
C:\WINDOWS\SYSTEM32\wywuqk.dat: .aspack
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\kpkgyi.exe: .aspack
-------------- HKLM Run Key ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_05\\bin\\jusched.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"myCIO.com ASaP"="C:\\WINDOWS\\myCIO\\Agent\\myagttry.exe"
"myCIO.com Splash"="C:\\WINDOWS\\myCIO\\VScan\\Splash.exe"
"VBundleOuterDL"="C:\\Program Files\\VBouncer\\BundleOuter.EXE"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"432h35l"="stcans32.exe"
"ErrorGuard"="C:\\Program Files\\ErrorGuard\\ErrorGuard.Exe"
"SpySpotter"="C:\\PROGRA~1\\SPYSPO~1\\SpySpotter.exe"
"Narrator"="C:\\WINDOWS\\system32\\vovuyg.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
_____________________________________________________
Here's the hijackthis log
Logfile of HijackThis v1.99.0
Scan saved at 9:56:03 AM, on 01/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\system32\stcans32.exe
C:\WINDOWS\system32\sruaemon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kpkgyi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [432h35l] stcans32.exe
O4 - HKLM\..\Run: [ErrorGuard] C:\Program Files\ErrorGuard\ErrorGuard.Exe
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [L0tnRRJ2h] sruaemon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) -
http://cluster.jdpa.com/download/CfxIEAx.cabO16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) -
http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cabO16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} -
http://download.spyspotter.com/spyspotter/...tterInstall.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McShield - Network Associates, Inc. - C:\WINDOWS\myCIO\VScan\McShield.exe
O23 - Service: McAfee Agent - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
O23 - Service: OmniForm Printer - Dell Computer Corporation - (no file)
O23 - Service: SonicWALL Agent Service - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\swAgent.exe