Help - Search - Members - Calendar
Full Version: Hijackthis logfile, Please HELP
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
lmb77
Sorry if this is the wrong place, but I know I have the coolwwwsearch.bootconf trojan. Problem is I can't even get Hijackthis to complete a scan without shutting down. What do I do now?
lmb77
Here's a log from the older version. 1.99 keeps crashing on me.

Logfile of HijackThis v1.98.2
Scan saved at 10:29:18 AM, on 01/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
C:\WINDOWS\system32\grpndmgr.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\WINDOWS\system32\gprmine.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kpkgyi.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\PROGRA~1\Toolbar\TBPSSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis1982\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [432h35l] grpndmgr.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [L0tnRRJ2h] gprmine.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://cluster.jdpa.com/download/CfxIEAx.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
lmb77
I finally got hijackthis to run, although it is the older version. Let me know what you think. Thanks

Logfile of HijackThis v1.98.2
Scan saved at 12:24:02 PM, on 01/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
C:\WINDOWS\system32\grpndmgr.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\WINDOWS\system32\gprmine.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kpkgyi.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\PROGRA~1\Toolbar\TBPSSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Reynolds\ERALink32\ERALink32.exe
C:\PROGRA~1\Reynolds\ERALIN~1\wIntegSM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\hijackthis1982\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [432h35l] grpndmgr.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [L0tnRRJ2h] gprmine.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://cluster.jdpa.com/download/CfxIEAx.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
Bobbi Flekman
Hi lmb77,

you have multiple infections so this is going to take some time...

Open "Add/Remove Programs" in the Control Panel. Select the following items:
  • WinTools
and click "Remove" for each of them.

You might want to save this page on your favorites, so you can find it again when you return. You can also click on your name and click on "Find All Posts" to find your thread.

Run HijackThis, click on "Scan" and check the boxes next to all these items.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa

R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch

O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll

O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll

SpySpotter is on Spyware Warrior's Rogue List. Uninstall this program!

O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [432h35l] grpndmgr.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKCU\..\Run: [L0tnRRJ2h] gprmine.exe

O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll


Then close all windows, and browsers, except HijackThis. Tell HijackThis to "Fix checked".

Restart your computer in Safe Mode. How do I Safe Boot my computer?

Show hidden files. How do I show hidden files?

Delete the following files in red (it could be that they are deleted already):

C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
C:\WINDOWS\system32\grpndmgr.exe
C:\WINDOWS\system32\gprmine.exe

Delete the following folders in red (it could be that they are deleted already):

C:\Program Files\Toolbar
C:\Program Files\SPYSPO~1
C:\Program Files\Common Files\WinTools

Restart your computer and post a new log in this thread.

Can you download and extract this file. There is a batch file in it named Find.bat. This will create a log, please post it.
lmb77
Here's the findit file. Thank you Very much

Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

Find.bat is running from: C:\findit\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/12/2005 02:19 PM 223,711 JLSD400.DLL
01/12/2005 02:19 PM 224,227 i6jq0g15e6.dll
01/12/2005 09:10 AM 223,711 dnno0153e.dll
01/11/2005 04:36 PM <DIR> DLLCACHE
01/11/2005 09:59 AM 223,711 mvl0l93m1.dll
01/11/2005 09:32 AM 223,711 lv2809fue.dll
01/10/2005 02:00 PM 223,711 n6l8lg3u16.dll
01/10/2005 10:19 AM 225,255 l44qleh51h4.dll
01/06/2005 12:29 PM 223,122 MZC71ENU.DLL
01/06/2005 12:29 PM 223,606 o4840elqehqe0.dll
01/04/2005 09:55 AM 224,170 hrn8055ue.dll
12/30/2004 10:29 AM 222,374 en8ml1l11.dll
12/28/2004 12:47 PM 222,366 jt0607dse.dll
12/27/2004 08:40 AM 222,773 jt0407dqe.dll
12/24/2004 10:42 AM 222,337 lvn2095oe.dll
12/24/2004 09:20 AM 222,364 g2jo0c13ef.dll
12/23/2004 05:28 PM 226,190 ozeprn.dll
12/23/2004 03:58 PM 226,190 fp0203doe.dll
12/23/2004 03:54 PM 226,190 kt4ql7h51.dll
12/23/2004 10:38 AM 226,190 u8ruli9918.dll
12/23/2004 09:35 AM 226,190 enn2l15o1.dll
12/23/2004 09:26 AM 226,190 o484lelq1hqe.dll
12/22/2004 09:17 PM 225,111 l88mlil118q.dll
12/22/2004 07:01 PM 224,133 dn0u01d9e.dll
12/22/2004 01:23 PM 389,120 ??chost.exe
11/12/2003 03:03 AM <DIR> Microsoft
24 File(s) 5,546,653 bytes
2 Dir(s) 34,418,655,232 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/12/2005 02:17 PM <DIR> wsxsvc
01/11/2005 04:36 PM <DIR> DLLCACHE
01/08/2005 11:18 AM <DIR> vmss
12/22/2004 01:23 PM 389,120 ??chost.exe
09/03/2002 01:33 PM 488 logonui.exe.manifest
09/03/2002 01:33 PM 488 WindowsLogon.manifest
09/03/2002 01:33 PM 749 sapi.cpl.manifest
09/03/2002 01:33 PM 749 nwc.cpl.manifest
09/03/2002 01:33 PM 749 ncpa.cpl.manifest
09/03/2002 01:33 PM 749 wuaucpl.cpl.manifest
09/03/2002 01:33 PM 749 cdplayer.exe.manifest
8 File(s) 393,841 bytes
3 Dir(s) 34,418,651,136 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------ Temp Files in System32 Directory ------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\dnno0153e.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

C:\WINDOWS\SYSTEM32\
dn0u01~1.dll Wed Dec 22 2004 7:01:50p ..S.R 224,133 218.88 K
dnno01~1.dll Wed Jan 12 2005 9:10:16a ..S.R 223,711 218.46 K
en8ml1~1.dll Thu Dec 30 2004 10:29:02a ..S.R 222,374 217.16 K
enn2l1~1.dll Thu Dec 23 2004 9:35:36a ..S.R 226,190 220.89 K
fp0203~1.dll Thu Dec 23 2004 3:58:04p ..S.R 226,190 220.89 K
g2jo0c~1.dll Fri Dec 24 2004 9:20:10a ..S.R 222,364 217.15 K
hrn805~1.dll Tue Jan 4 2005 9:55:34a ..S.R 224,170 218.91 K
i6jq0g~1.dll Wed Jan 12 2005 2:19:50p ..S.R 224,227 218.97 K
jlsd400.dll Wed Jan 12 2005 2:19:50p ..S.R 223,711 218.46 K
jt0407~1.dll Mon Dec 27 2004 8:40:10a ..S.R 222,773 217.55 K
jt0607~1.dll Tue Dec 28 2004 12:47:10p ..S.R 222,366 217.15 K
kt4ql7~1.dll Thu Dec 23 2004 3:55:00p ..S.R 226,190 220.89 K
l44qle~1.dll Mon Jan 10 2005 10:19:20a ..S.R 225,255 219.97 K
l88mli~1.dll Wed Dec 22 2004 9:17:36p ..S.R 225,111 219.83 K
lv2809~1.dll Tue Jan 11 2005 9:32:52a ..S.R 223,711 218.46 K
lvn209~1.dll Fri Dec 24 2004 10:42:34a ..S.R 222,337 217.13 K
mvl0l9~1.dll Tue Jan 11 2005 9:59:38a ..S.R 223,711 218.46 K
mzc71enu.dll Thu Jan 6 2005 12:29:02p ..S.R 223,122 217.89 K
n6l8lg~1.dll Mon Jan 10 2005 2:00:20p ..S.R 223,711 218.46 K
o4840e~1.dll Thu Jan 6 2005 12:29:02p ..S.R 223,606 218.36 K
o484le~1.dll Thu Dec 23 2004 9:26:44a ..S.R 226,190 220.89 K
ozeprn.dll Thu Dec 23 2004 5:28:16p ..S.R 226,190 220.89 K
u8ruli~1.dll Thu Dec 23 2004 10:38:02a ..S.R 226,190 220.89 K
chost~1.exe Wed Dec 22 2004 1:23:16p ..SHR 389,120 380.00 K

24 items found: 24 files, 0 directories.
Total of file sizes: 5,546,653 bytes 5.29 M

-------- Strings.exe Qoologic Results --------

C:\WINDOWS\SYSTEM32\iuipzn.dll: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lmlupa.exe: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lzlugq.dll: updates.qoologic.com

--------- Strings.exe Aspack Results ---------

C:\WINDOWS\SYSTEM32\Incinerator.dll: .aspack
C:\WINDOWS\SYSTEM32\installer.exe: .aspack
C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack
C:\WINDOWS\SYSTEM32\vovuyg.exe: .aspack
C:\WINDOWS\SYSTEM32\wywuqk.dat: .aspack
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\kpkgyi.exe: .aspack

-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_05\\bin\\jusched.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"myCIO.com ASaP"="C:\\WINDOWS\\myCIO\\Agent\\myagttry.exe"
"myCIO.com Splash"="C:\\WINDOWS\\myCIO\\VScan\\Splash.exe"
"VBundleOuterDL"="C:\\Program Files\\VBouncer\\BundleOuter.EXE"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"432h35l"="stcans32.exe"
"ErrorGuard"="C:\\Program Files\\ErrorGuard\\ErrorGuard.Exe"
"Narrator"="C:\\WINDOWS\\system32\\vovuyg.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"



Bobbi Flekman
Hi lmb77,

you haven't posted a log from Hijack This.

Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

QUOTE
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Narrator"=-
Locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Download Killbox by Option^Explicit. Extract it from the zip file then double-click on Killbox.exe to run it. Click on "Delete on Reboot", in the "Full Path of File to Delete" box, enter C:\WINDOWS\System32\Guard.tmp and click on the button with the white cross in a red circle. You will get a question "File will be Deleted on Next Reboot" answer Yes, followed by "File will be Removed on Reboot, Do you want to reboot now?", answer "No". Do the same for these files:
C:\WINDOWS\SYSTEM32\iuipzn.dll
C:\WINDOWS\SYSTEM32\lmlupa.exe
C:\WINDOWS\SYSTEM32\lzlugq.dll
C:\WINDOWS\SYSTEM32\Incinerator.dll
C:\WINDOWS\SYSTEM32\installer.exe
C:\WINDOWS\SYSTEM32\vovuyg.exe
C:\WINDOWS\SYSTEM32\wywuqk.dat
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\kpkgyi.exe: .aspack
C:\WINDOWS\System32\JLSD400.DLL
C:\WINDOWS\System32\i6jq0g15e6.dll
C:\WINDOWS\System32\dnno0153e.dll
C:\WINDOWS\System32\mvl0l93m1.dll
C:\WINDOWS\System32\lv2809fue.dll
C:\WINDOWS\System32\n6l8lg3u16.dll
C:\WINDOWS\System32\l44qleh51h4.dll
C:\WINDOWS\System32\MZC71ENU.DLL
C:\WINDOWS\System32\o4840elqehqe0.dll
C:\WINDOWS\System32\hrn8055ue.dll
C:\WINDOWS\System32\en8ml1l11.dll
C:\WINDOWS\System32\jt0607dse.dll
C:\WINDOWS\System32\jt0407dqe.dll
C:\WINDOWS\System32\lvn2095oe.dll
C:\WINDOWS\System32\g2jo0c13ef.dll
C:\WINDOWS\System32\ozeprn.dll
C:\WINDOWS\System32\fp0203doe.dll
C:\WINDOWS\System32\kt4ql7h51.dll
C:\WINDOWS\System32\u8ruli9918.dll
C:\WINDOWS\System32\enn2l15o1.dll
C:\WINDOWS\System32\o484lelq1hqe.dll
C:\WINDOWS\System32\l88mlil118q.dll
C:\WINDOWS\System32\dn0u01d9e.dll
after the last one click the button and answer "Yes" on the "Reboot now?" question. Let Killbox do it's work. Afterwards ost a new log from Find.bat.

Launch Notepad, and copy/paste the box below into a new text file. Save it as FindFile.bat and save it on your Desktop.

CODE
dir C:\WINDOWS\System32\??chost.exe /a h > files.txt
notepad files.txt


Locate FindFile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the text here.

Don't forget to post a log from HijackThis.
lmb77
Here you go, again thank you very much. Thanks, Will

Here's the findfile.bat output.

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

08/04/2004 01:56 AM 14,336 svchost.exe
12/22/2004 01:23 PM 389,120 ??chost.exe
2 File(s) 403,456 bytes

Directory of C:\Documents and Settings\joe\Desktop




Find.bat is running from: C:\findit\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/13/2005 09:38 AM 222,935 rlgwizc.dll
01/13/2005 09:37 AM 225,087 fppo0373e.dll
01/13/2005 09:28 AM 222,935 l4n4le5q1h.dll
01/13/2005 08:13 AM 225,634 gp2ul3f91.dll
01/11/2005 04:36 PM <DIR> DLLCACHE
12/22/2004 01:23 PM 389,120 ??chost.exe
11/12/2003 03:03 AM <DIR> Microsoft
5 File(s) 1,285,711 bytes
2 Dir(s) 34,452,402,176 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/12/2005 02:17 PM <DIR> wsxsvc
01/11/2005 04:36 PM <DIR> DLLCACHE
01/08/2005 11:18 AM <DIR> vmss
12/22/2004 01:23 PM 389,120 ??chost.exe
09/03/2002 01:33 PM 488 logonui.exe.manifest
09/03/2002 01:33 PM 488 WindowsLogon.manifest
09/03/2002 01:33 PM 749 sapi.cpl.manifest
09/03/2002 01:33 PM 749 nwc.cpl.manifest
09/03/2002 01:33 PM 749 ncpa.cpl.manifest
09/03/2002 01:33 PM 749 wuaucpl.cpl.manifest
09/03/2002 01:33 PM 749 cdplayer.exe.manifest
8 File(s) 393,841 bytes
3 Dir(s) 34,452,398,080 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------ Temp Files in System32 Directory ------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\l4n4le5q1h.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

C:\WINDOWS\SYSTEM32\
fppo03~1.dll Thu Jan 13 2005 9:37:34a ..S.R 225,087 219.81 K
gp2ul3~1.dll Thu Jan 13 2005 8:13:04a ..S.R 225,634 220.34 K
l4n4le~1.dll Thu Jan 13 2005 9:28:34a ..S.R 222,935 217.71 K
rlgwizc.dll Thu Jan 13 2005 9:38:28a ..S.R 222,935 217.71 K
chost~1.exe Wed Dec 22 2004 1:23:16p ..SHR 389,120 380.00 K

5 items found: 5 files, 0 directories.
Total of file sizes: 1,285,711 bytes 1.22 M

-------- Strings.exe Qoologic Results --------

C:\WINDOWS\SYSTEM32\iuipzn.dll: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lmlupa.exe: updates.qoologic.com
C:\WINDOWS\SYSTEM32\lzlugq.dll: updates.qoologic.com

--------- Strings.exe Aspack Results ---------

C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack
C:\WINDOWS\SYSTEM32\vovuyg.exe: .aspack
C:\WINDOWS\SYSTEM32\wywuqk.dat: .aspack
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\kpkgyi.exe: .aspack

-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_05\\bin\\jusched.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"myCIO.com ASaP"="C:\\WINDOWS\\myCIO\\Agent\\myagttry.exe"
"myCIO.com Splash"="C:\\WINDOWS\\myCIO\\VScan\\Splash.exe"
"VBundleOuterDL"="C:\\Program Files\\VBouncer\\BundleOuter.EXE"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"432h35l"="stcans32.exe"
"ErrorGuard"="C:\\Program Files\\ErrorGuard\\ErrorGuard.Exe"
"SpySpotter"="C:\\PROGRA~1\\SPYSPO~1\\SpySpotter.exe"
"Narrator"="C:\\WINDOWS\\system32\\vovuyg.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

_____________________________________________________

Here's the hijackthis log

Logfile of HijackThis v1.99.0
Scan saved at 9:56:03 AM, on 01/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\system32\stcans32.exe
C:\WINDOWS\system32\sruaemon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\kpkgyi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [432h35l] stcans32.exe
O4 - HKLM\..\Run: [ErrorGuard] C:\Program Files\ErrorGuard\ErrorGuard.Exe
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [L0tnRRJ2h] sruaemon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://cluster.jdpa.com/download/CfxIEAx.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McShield - Network Associates, Inc. - C:\WINDOWS\myCIO\VScan\McShield.exe
O23 - Service: McAfee Agent - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
O23 - Service: OmniForm Printer - Dell Computer Corporation - (no file)
O23 - Service: SonicWALL Agent Service - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\swAgent.exe
Bobbi Flekman
Hi lmb77,

Download LSPfix here: www.cexx.org/lspfix.htm
Start the application, and click the "I know what I'm doing" checkbox.
Check all instances of [c:\windows\system32\calsp.dll] (and nothing else), and move them to the "Remove" pane.
Then click Finish and reboot.

Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

QUOTE
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Narrator"=-
Locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Double-click on Killbox.exe to run it. Click on "Delete on Reboot", in the "Full Path of File to Delete" box, enter C:\WINDOWS\System32\Guard.tmp
and click on the button with the white cross in a red circle. You will get a question "File will be Deleted on Next Reboot" answer Yes, followed by "File will be Removed on Reboot, Do you want to reboot now?", answer "No". Do the same for these files:
C:\WINDOWS\SYSTEM32\iuipzn.dll
C:\WINDOWS\SYSTEM32\lmlupa.exe
C:\WINDOWS\SYSTEM32\lzlugq.dll
C:\WINDOWS\SYSTEM32\vovuyg.exe
C:\WINDOWS\SYSTEM32\wywuqk.dat
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\kpkgyi.exe
C:\WINDOWS\System32\rlgwizc.dll
C:\WINDOWS\System32\fppo0373e.dll
C:\WINDOWS\System32\4n4le5q1h.dll
C:\WINDOWS\System32\gp2ul3f91.dll
after the last one click the button and answer "Yes" on the "Reboot now?" question. Let Killbox do it's work.

Run HijackThis, click on "Scan" and check the boxes next to all these items.

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch

O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [432h35l] stcans32.exe
O4 - HKLM\..\Run: [ErrorGuard] C:\Program Files\ErrorGuard\ErrorGuard.Exe

SpySpotter is on Spyware Warrior's Rogue List. Uninstall this program!

O4 - HKLM\..\Run: [SpySpotter] C:\PROGRA~1\SPYSPO~1\SpySpotter.exe

O4 - HKCU\..\Run: [L0tnRRJ2h] sruaemon.exe

O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/...tterInstall.cab


Then close all windows, and browsers, except HijackThis. Tell HijackThis to "Fix checked".

Restart your computer in Safe Mode. How do I Safe Boot my computer?

Show hidden files. How do I show hidden files?

Folders and files with a tilde (~), means that there is a file/folder that starts with the six characters in front of the tilde, note that there may be spaces in the name. If there are more than one, please report them back and do not delete!

Delete the following files in red (it could be that they are deleted already):

C:\WINDOWS\System32\??chost.exe <-- Take care you do not delete svchost.exe. This is a valid part of Windows. The file you want to delete is dated 12/22/2004 and is 389,120 bytes in size
C:\WINDOWS\System32\stcans32.exe
C:\WINDOWS\System32\sruaemon.exe

Delete the following folders in red (it could be that they are deleted already):

C:\Program Files\VBouncer
C:\Program Files\AutoUpdate
C:\Program Files\ErrorGuard
C:\Program Files\SPYSPO~1

Restart your computer and post a new log in this thread. Also post a new log from Find.bat.
lmb77
Ok, here goes. I think it's getting better.

Find.bat is running from: C:\findit\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/14/2005 09:45 AM 225,143 cncdll.dll
01/14/2005 09:45 AM 223,114 o0rola931d.dll
01/14/2005 09:43 AM 223,114 OSESVR.DLL
01/14/2005 09:41 AM 225,143 m6julg1916.dll
01/14/2005 09:39 AM 225,143 dDdim700.dll
01/14/2005 09:31 AM 222,935 AQRACE.DLL
01/13/2005 05:36 PM 223,293 k8no0i53e8.dll
01/13/2005 04:32 PM 224,716 en8sl1l71.dll
01/11/2005 04:36 PM <DIR> DLLCACHE
11/12/2003 03:03 AM <DIR> Microsoft
8 File(s) 1,792,601 bytes
2 Dir(s) 34,239,848,448 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/12/2005 02:17 PM <DIR> wsxsvc
01/11/2005 04:36 PM <DIR> DLLCACHE
01/08/2005 11:18 AM <DIR> vmss
09/03/2002 01:33 PM 488 WindowsLogon.manifest
09/03/2002 01:33 PM 488 logonui.exe.manifest
09/03/2002 01:33 PM 749 sapi.cpl.manifest
09/03/2002 01:33 PM 749 nwc.cpl.manifest
09/03/2002 01:33 PM 749 ncpa.cpl.manifest
09/03/2002 01:33 PM 749 cdplayer.exe.manifest
09/03/2002 01:33 PM 749 wuaucpl.cpl.manifest
7 File(s) 4,721 bytes
3 Dir(s) 34,239,844,352 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------ Temp Files in System32 Directory ------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Uninstall]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\m6julg1916.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

C:\WINDOWS\SYSTEM32\
aqrace.dll Fri Jan 14 2005 9:31:58a ..S.R 222,935 217.71 K
cncdll.dll Fri Jan 14 2005 9:45:52a ..S.R 225,143 219.86 K
dddim700.dll Fri Jan 14 2005 9:39:14a ..S.R 225,143 219.86 K
en8sl1~1.dll Thu Jan 13 2005 4:32:48p ..S.R 224,716 219.45 K
k8no0i~1.dll Thu Jan 13 2005 5:36:10p ..S.R 223,293 218.06 K
m6julg~1.dll Fri Jan 14 2005 9:41:14a ..S.R 225,143 219.86 K
o0rola~1.dll Fri Jan 14 2005 9:45:02a ..S.R 223,114 217.88 K
osesvr.dll Fri Jan 14 2005 9:43:02a ..S.R 223,114 217.88 K

8 items found: 8 files, 0 directories.
Total of file sizes: 1,792,601 bytes 1.71 M

-------- Strings.exe Qoologic Results --------


--------- Strings.exe Aspack Results ---------

C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack

-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_05\\bin\\jusched.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"myCIO.com ASaP"="C:\\WINDOWS\\myCIO\\Agent\\myagttry.exe"
"myCIO.com Splash"="C:\\WINDOWS\\myCIO\\VScan\\Splash.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"


______________________________________________________________


Logfile of HijackThis v1.99.0
Scan saved at 9:59:34 AM, on 01/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\WINDOWS\system32\olemps.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [L0tnRRJ2h] olemps.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://cluster.jdpa.com/download/CfxIEAx.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McShield - Network Associates, Inc. - C:\WINDOWS\myCIO\VScan\McShield.exe
O23 - Service: McAfee Agent - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
O23 - Service: OmniForm Printer - Dell Computer Corporation - (no file)
O23 - Service: SonicWALL Agent Service - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\swAgent.exe
Bobbi Flekman
Hi lmb77,

Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

QUOTE
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=-
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Uninstall]
Locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Double-click on Killbox.exe to run it. Click on "Delete on Reboot", in the "Full Path of File to Delete" box, enter C:\WINDOWS\System32\olemps.exe and click on the button with the white cross in a red circle. You will get a question "File will be Deleted on Next Reboot" answer Yes, followed by "File will be Removed on Reboot, Do you want to reboot now?", answer "No". Do the same for these files:
C:\WINDOWS\System32\cncdll.dll
C:\WINDOWS\System32\o0rola931d.dll
C:\WINDOWS\System32\OSESVR.DLL
C:\WINDOWS\System32\m6julg1916.dll
C:\WINDOWS\System32\dDdim700.dll
C:\WINDOWS\System32\AQRACE.DLL
C:\WINDOWS\System32\k8no0i53e8.dll
C:\WINDOWS\System32\en8sl1l71.dll
C:\WINDOWS\System32\Guard.tmp
after the last one click the button and answer "Yes" on the "Reboot now?" question. Let Killbox do it's work.

Run HijackThis, click on "Scan" and check the boxes next to all these items.

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch

O4 - HKCU\..\Run: [L0tnRRJ2h] olemps.exe


Then close all windows, and browsers, except HijackThis. Tell HijackThis to "Fix checked". Restart your computer and post a new log in this thread. Also post a log from Find.bat.
lmb77
Here we go again. Thanks

Find.bat is running from: C:\findit\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/14/2005 12:07 PM 223,114 IZXMONTR.DLL
01/14/2005 12:07 PM 224,253 mvlml9311.dll
01/14/2005 11:42 AM 223,114 dn0q01d5e.dll
01/14/2005 11:00 AM 225,143 j40sled71h0.dll
01/11/2005 04:36 PM <DIR> DLLCACHE
11/12/2003 03:03 AM <DIR> Microsoft
4 File(s) 895,624 bytes
2 Dir(s) 34,227,183,616 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/12/2005 02:17 PM <DIR> wsxsvc
01/11/2005 04:36 PM <DIR> DLLCACHE
01/08/2005 11:18 AM <DIR> vmss
09/03/2002 01:33 PM 488 WindowsLogon.manifest
09/03/2002 01:33 PM 488 logonui.exe.manifest
09/03/2002 01:33 PM 749 sapi.cpl.manifest
09/03/2002 01:33 PM 749 nwc.cpl.manifest
09/03/2002 01:33 PM 749 ncpa.cpl.manifest
09/03/2002 01:33 PM 749 cdplayer.exe.manifest
09/03/2002 01:33 PM 749 wuaucpl.cpl.manifest
7 File(s) 4,721 bytes
3 Dir(s) 34,227,179,520 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------ Temp Files in System32 Directory ------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\dn0q01d5e.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

C:\WINDOWS\SYSTEM32\
dn0q01~1.dll Fri Jan 14 2005 11:42:10a ..S.R 223,114 217.88 K
izxmontr.dll Fri Jan 14 2005 12:07:26p ..S.R 223,114 217.88 K
j40sle~1.dll Fri Jan 14 2005 11:00:52a ..S.R 225,143 219.86 K
mvlml9~1.dll Fri Jan 14 2005 12:07:26p ..S.R 224,253 218.99 K

4 items found: 4 files, 0 directories.
Total of file sizes: 895,624 bytes 874.63 K

-------- Strings.exe Qoologic Results --------


--------- Strings.exe Aspack Results ---------

C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack

-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_05\\bin\\jusched.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"myCIO.com ASaP"="C:\\WINDOWS\\myCIO\\Agent\\myagttry.exe"
"myCIO.com Splash"="C:\\WINDOWS\\myCIO\\VScan\\Splash.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"


________________________________________________________


Logfile of HijackThis v1.99.0
Scan saved at 12:21:29 PM, on 01/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [L0tnRRJ2h] olemps.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://cluster.jdpa.com/download/CfxIEAx.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McShield - Network Associates, Inc. - C:\WINDOWS\myCIO\VScan\McShield.exe
O23 - Service: McAfee Agent - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
O23 - Service: OmniForm Printer - Dell Computer Corporation - (no file)
O23 - Service: SonicWALL Agent Service - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\swAgent.exe
Bobbi Flekman
Hi lmb77,


Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

QUOTE
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn]
Locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Double-click on Killbox.exe to run it. Click on "Delete on Reboot", in the "Full Path of File to Delete" box, enter C:\WINDOWS\System32\Guard.tmp and click on the button with the white cross in a red circle. You will get a question "File will be Deleted on Next Reboot" answer Yes, followed by "File will be Removed on Reboot, Do you want to reboot now?", answer "No". Do the same for these files:
C:\WINDOWS\System32\IZXMONTR.DLL
C:\WINDOWS\System32\mvlml9311.dll
C:\WINDOWS\System32\dn0q01d5e.dll
C:\WINDOWS\System32\j40sled71h0.dll
after the last one click the button and answer "Yes" on the "Reboot now?" question. Let Killbox do it's work.


Run HijackThis, click on "Scan" and check the boxes next to all these items.

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch

O4 - HKCU\..\Run: [L0tnRRJ2h] olemps.exe


Then close all windows, and browsers, except HijackThis. Tell HijackThis to "Fix checked".

Restart your computer in Safe Mode. How do I Safe Boot my computer?

Show hidden files. How do I show hidden files?

Folders and files with a tilde (~), means that there is a file/folder that starts with the six characters in front of the tilde, note that there may be spaces in the name. If there are more than one, please report them back and do not delete!

Delete the following files in red (it could be that they are deleted already):

c:\Windows\System32\olemps.exe

Restart your computer and post a new log in this thread.
lmb77
Here we go, one more time.


Find.bat is running from: C:\findit\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/11/2005 04:36 PM <DIR> DLLCACHE
11/12/2003 03:03 AM <DIR> Microsoft
0 File(s) 0 bytes
2 Dir(s) 34,235,514,880 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32

01/12/2005 02:17 PM <DIR> wsxsvc
01/11/2005 04:36 PM <DIR> DLLCACHE
01/08/2005 11:18 AM <DIR> vmss
09/03/2002 01:33 PM 488 WindowsLogon.manifest
09/03/2002 01:33 PM 488 logonui.exe.manifest
09/03/2002 01:33 PM 749 sapi.cpl.manifest
09/03/2002 01:33 PM 749 nwc.cpl.manifest
09/03/2002 01:33 PM 749 ncpa.cpl.manifest
09/03/2002 01:33 PM 749 cdplayer.exe.manifest
09/03/2002 01:33 PM 749 wuaucpl.cpl.manifest
7 File(s) 4,721 bytes
3 Dir(s) 34,235,510,784 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------ Temp Files in System32 Directory ------

Volume in drive C has no label.
Volume Serial Number is E44D-6A5E

Directory of C:\WINDOWS\System32


------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{F0666897-5C34-470B-9324-A28AD2946215}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Control Panel]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\mvlml9311.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

No matches found.

-------- Strings.exe Qoologic Results --------


--------- Strings.exe Aspack Results ---------

C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack

-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_05\\bin\\jusched.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"myCIO.com ASaP"="C:\\WINDOWS\\myCIO\\Agent\\myagttry.exe"
"myCIO.com Splash"="C:\\WINDOWS\\myCIO\\VScan\\Splash.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"


______________________________________________


Logfile of HijackThis v1.99.0
Scan saved at 4:55:36 PM, on 01/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\myCIO\Agent\swAgent.exe
C:\WINDOWS\myCIO\VScan\McShield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\myCIO\Agent\myagttry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [myCIO.com ASaP] C:\WINDOWS\myCIO\Agent\myagttry.exe
O4 - HKLM\..\Run: [myCIO.com Splash] C:\WINDOWS\myCIO\VScan\Splash.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://cluster.jdpa.com/download/CfxIEAx.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://virusscanasap.mcafeeasap.com/VS2/So...in/myCioAgt.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O17 - HKLM\System\CS2\Services\Tcpip\..\{1E3950E9-6415-480E-9D36-08E23608AEA0}: NameServer = 205.242.92.2,205.242.176.103
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\WINDOWS\myCIO\Agent\myRmProt2.8.1.107.dll
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McShield - Network Associates, Inc. - C:\WINDOWS\myCIO\VScan\McShield.exe
O23 - Service: McAfee Agent - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\myAgtSvc.exe
O23 - Service: OmniForm Printer - Dell Computer Corporation - (no file)
O23 - Service: SonicWALL Agent Service - Network Associates, Inc. - C:\WINDOWS\myCIO\Agent\swAgent.exe
Bobbi Flekman
Hi lmb77,

It seems we have beaten VX2!! Now... this infection is known to mess with your computer. Can you create a file and delete it. Does it go to the Recycle Bin? Or not? Can you print? Is there anything strange going on?

This is some cleanup code that also has to be done. The first line (about Control Panel) is a leftover from the previous fix, the rest is clean up.

Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

CODE
REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Control Panel]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{DDFFA75A-E81D-4454-89FC-B9FD0631E726}"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop]
"Taskbar"=-
"Toolbars"=-

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StuckRects2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
Locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".
lmb77
Thank you very much. Everything seems to be working great, other than the recycle bin never "empties" now. What do I need to do now?
Bobbi Flekman
Hi lmb77,
QUOTE
Everything seems to be working great, other than the recycle bin never "empties" now.
We're gonna deal with that now. Launch Notepad, and copy/paste the box below into a new text file. Save it as RepBin.bat and save it on your Desktop.

CODE
attrib -h -s c:\recycler\desktop.ini
del c:\recycler\desktop.ini


Locate RepBin.bat on your Desktop and double-click on it.
Close the window and restart your computer.
Is it okay now?
lmb77
Seems to be great, thank you Very much.
Bobbi Flekman
Great!

Can you post a final log from HijackThis and Find.bat to make sure that there is no malware lingering in some way.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.