Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Spyware problems


  • This topic is locked This topic is locked
4 replies to this topic

#1 pleasehelp

pleasehelp

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:06:55 AM

Posted 29 May 2005 - 02:48 PM

hi
im back again, except this time my mom is having a real hard time with her computer. Its very slow and locks up constantly. Im guessing its spyware so i ran a hijack this log and this is it. I really hope she doesnt have to completely redo her computer because she has alot of pics on there she doesnt want to lose. thanks in advance.


Logfile of HijackThis v1.99.1
Scan saved at 3:44:53 PM, on 29/05/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\HPConfig.exe
C:\WINDOWS\system32\RadioSvr.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\essspk.exe
C:\WINDOWS\System32\Xtplyv.exe
C:\WINDOWS\System32\Ihoxom.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\r?gsvr32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Application Data\odla.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\swqvt.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\swqvt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\barql.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\barql.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\swqvt.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\barql.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul...//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {90249E41-37D9-295E-6D52-9EF0209033A1} - C:\WINDOWS\system32\mskx32.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [MDN] MDNS.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Xtplyv.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Ihoxom.exe
O4 - HKLM\..\Run: [sdkjn.exe] C:\WINDOWS\system32\sdkjn.exe
O4 - HKLM\..\Run: [sdkfz32.exe] C:\WINDOWS\system32\sdkfz32.exe
O4 - HKLM\..\Run: [apioa32.exe] C:\WINDOWS\system32\apioa32.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [crms32.exe] C:\WINDOWS\system32\crms32.exe
O4 - HKLM\..\RunServices: [MDN] MDNS.exe
O4 - HKLM\..\RunServicesOnce: [Iomega CD-RW Setup] D:\Iomega_CD-RW.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\wtta.exe
O4 - HKCU\..\Run: [Atbddgu] C:\WINDOWS\System32\?ttrib.exe
O4 - HKCU\..\Run: [Aeoa] C:\Documents and Settings\Owner\Application Data\odla.exe
O4 - HKCU\..\Run: [Ycbfxv] C:\WINDOWS\System32\r?gsvr32.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {26AFD6EF-C017-4063-B2B1-E515DE98A1B7} - http://download.kodak.com/digital/software...2_1/install.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200211...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {9AE283A5-DF43-4C83-B6AA-7EBDBDB0204A} (VacPro.canada_ver10) - http://advnt01.com/dialer/canada_ver10.CAB
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/...ymmapi_0727.dll
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://www.pcpowerscan.com/pcpowerscan.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta...cdetection3.cab
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} (Util Class) - https://isupport4.hp.com/motivedocs/linklauncher/MotUtil.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) - http://www.photolab.ca/activex/PCAXSetup.cab?
O17 - HKLM\System\CCS\Services\Tcpip\..\{567A0B44-21ED-4E37-9E66-3989D44345A3}: NameServer = 206.47.244.60 206.47.244.104
O23 - Service: Network Security Service (NSS) ( 11F#`I) - Unknown owner - C:\WINDOWS\system32\appxa32.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: HP Configuration Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\System32\HPConfig.exe
O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe

BC AdBot (Login to Remove)

 


#2 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,652 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:06:55 AM

Posted 30 May 2005 - 12:13 AM

Hello pleasehelp and welcome to BleepingCompuer.

she has alot of pics on there she doesnt want to lose

Anytime you have data on a machine that you do not want to lose, you really need to have some way to back up that data. In the case of pictures, burning them to CD is probably a reasonable way to back them up. I strongly suggest you do that - not because there is anything uncleanable on the machine now, but for next time when it crashes fatally.


Your log shows that you are seriously behind on windows updates. It is essential that you update your operating system as otherwise any infections we remove could reoccur. After we get you all cleaned up, be sure to go to Windows Update and if it asks to install software, allow it to do so. Install the offered Critical and Security updates, reboot as requested and return until you have installed all available Critical and Security updates.


Open the Control Panel then double click on Add/Remove Programs. Look for the following and uninstall them if found:
- Media Access


Download the following file and save it to your desktop: DelDomains.inf
- Right-click on the deldomains.inf file and select Install.


Please download CWShredder.exe to your desktop.
- Open CWShedder.exe.
- Click on Check for Update to be sure you have the most current version.
- Close CWShredder, we will use it later.


Download AboutBuster.zip to your desktop.
- Unzip the contents of AboutBuster.zip and an AboutBuster folder will be created.
- Navigate to the AboutBuster folder and double-click on AboutBuster.exe.
- Click OK at the prompt with instructions.
- Click Update and then Check For Update to begin the update process.
- If any updates exist please download them by clicking Download Update.
- Close AboutBuster by clicking on Exit. AboutBuster will be used later.


Open Notepad, (Start button, click on Run, type in Notepad, and click OK) copy & pastes the following block of text into Notepad.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]

Click on 'File', then 'Save as'
Select 'Save as type:' as All Files,
Save the file to the desktop as fix.reg. Close Notepad. This file will be used later.


Configure Windows to enable viewing of Hidden and System files.


Click on Start, then Run and type in services.msc.
- Locate and double click on Network Security Service (NSS).
- Set the Startup type: to Disabled, click Apply.
- Click on Stop and OK your way out.


Reboot into Safe Mode.


Open CWShredder.
- Run CWShredder by clicking on the FIX button, and allow it to complete.


Start HJT and click on the SCAN button. Put a check mark in front of the following lines if they still show:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\swqvt.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\swqvt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\barql.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\barql.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\swqvt.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\barql.dll/sp.html#37049
R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {90249E41-37D9-295E-6D52-9EF0209033A1} - C:\WINDOWS\system32\mskx32.dll (file missing)

O4 - HKLM\..\Run: [MDN] MDNS.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Xtplyv.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\System32\Ihoxom.exe
O4 - HKLM\..\Run: [sdkjn.exe] C:\WINDOWS\system32\sdkjn.exe
O4 - HKLM\..\Run: [sdkfz32.exe] C:\WINDOWS\system32\sdkfz32.exe
O4 - HKLM\..\Run: [apioa32.exe] C:\WINDOWS\system32\apioa32.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [crms32.exe] C:\WINDOWS\system32\crms32.exe
O4 - HKLM\..\RunServices: [MDN] MDNS.exe
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\wtta.exe
O4 - HKCU\..\Run: [Atbddgu] C:\WINDOWS\System32\?ttrib.exe
O4 - HKCU\..\Run: [Aeoa] C:\Documents and Settings\Owner\Application Data\odla.exe
O4 - HKCU\..\Run: [Ycbfxv] C:\WINDOWS\System32\r?gsvr32.exe

23 - Service: Network Security Service (NSS) ( 11F#`I) - Unknown owner - C:\WINDOWS\system32\appxa32.exe (file missing)

With ALL OTHER WINDOWS CLOSED, click on Fix Checked.


Open Windows Explorer (Windows key+e), navigate to and delete the following files (Don't be concerned if they can not be found):

C:\WINDOWS\barql.dll <--Files
C:\WINDOWS\system32\swqvt.dll
C:\WINDOWS\system32\mskx32.dll
C:\WINDOWS\system32\MDNS.exe
C:\WINDOWS\System32\Xtplyv.exe
C:\WINDOWS\System32\Ihoxom.exe
C:\WINDOWS\system32\sdkjn.exe
C:\WINDOWS\system32\sdkfz32.exe
C:\WINDOWS\system32\apioa32.exe
C:\WINDOWS\system32\crms32.exe
C:\WINDOWS\system32\appxa32.exe
C:\Documents and Settings\Owner\Application Data\wtta.exe
C:\Documents and Settings\Owner\Application Data\odla.exe

C:\WINDOWS\System32\r?gsvr32.exe -- Caution, do not delete valid Windows file regsvr32.exe
C:\WINDOWS\System32\?ttrib.exe -- Caution, do not delete valid Windows file attrib.exe

C:\Program Files\Media Access\ <--Folder


Then double-click on the fix.reg file previously saved to the desktop.
- When it prompts to add or merge, say yes. This will clear some registry entries left behind by the malware.


Browse to where you saved AboutBuster and run AboutBuster.exe.
- Click OK at the directions prompt.
- Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.
- Click Yes to allow it to shutdown explorer.exe.
- It will begin to scan your computer. If it asks to do a second pass, allow it to do so.
- When it has finished, click Save Log.


Reboot normally and post the AboutBuster log along with a fresh HJT log.
Derfram
~~~~~~

#3 pleasehelp

pleasehelp
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:06:55 AM

Posted 06 June 2005 - 02:11 PM

Sorry it took so long to get back to you, here are the recent scans.


AboutBuster 5.0 reference file 28
Scan started on [6/6/2005] at [2:57:16 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\000001_.tmp:dlibcq
Removed Stream! C:\WINDOWS\1.00:mztygy
Removed Stream! C:\WINDOWS\1.00:ozibhd
Removed Stream! C:\WINDOWS\apgen.drv:ndaefv
Removed Stream! C:\WINDOWS\atloe.exe:dnlfth
Removed Stream! C:\WINDOWS\atloe.exe:legpv
Removed Stream! C:\WINDOWS\Bbss2.exe:voesvs
Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:eezcx
Removed Stream! C:\WINDOWS\button3.ico:lkxlbi
Removed Stream! C:\WINDOWS\button3.ico:ofrir
Removed Stream! C:\WINDOWS\button3.ico:yelxbh
Removed Stream! C:\WINDOWS\cdPlayer.ini:gdgpnd
Removed Stream! C:\WINDOWS\cdPlayer.ini:mszblj
Removed Stream! C:\WINDOWS\CDRipper.ini:neegob
Removed Stream! C:\WINDOWS\chjkp.txt:bgohqc
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:ffpljl
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:pjuyne
Removed Stream! C:\WINDOWS\comsetup.log:bmlwob
Removed Stream! C:\WINDOWS\comsetup.log:gmsjrf
Removed Stream! C:\WINDOWS\comsetup.log:xlcliw
Removed Stream! C:\WINDOWS\comsetup.log:xxqbxd
Removed Stream! C:\WINDOWS\control.ini:efgtjl
Removed Stream! C:\WINDOWS\control.ini:ikmlhp
Removed Stream! C:\WINDOWS\crvf32.exe:ralpnl
Removed Stream! C:\WINDOWS\crvf32.exe:xgrhlv
Removed Stream! C:\WINDOWS\crvf32.exe:zsrjzx
Removed Stream! C:\WINDOWS\CTRYLOC.REG:fapdhn
Removed Stream! C:\WINDOWS\d3nf.dll:sbpjpk
Removed Stream! C:\WINDOWS\d3wr32.exe:mnwpko
Removed Stream! C:\WINDOWS\d3wr32.exe:qcsova
Removed Stream! C:\WINDOWS\d3wr32.exe:roduos
Removed Stream! C:\WINDOWS\dahotfix.log:eikfoz
Removed Stream! C:\WINDOWS\DgnSetup.log:dtjojg
Removed Stream! C:\WINDOWS\DHCPUPG.LOG:atybgc
Removed Stream! C:\WINDOWS\DHCPUPG.LOG:knhut
Removed Stream! C:\WINDOWS\DigiStitch.INI:tiwqzc
Removed Stream! C:\WINDOWS\DigiStitch.INI:yfpgz
Removed Stream! C:\WINDOWS\DYNAZIP.LOG:coazv
Removed Stream! C:\WINDOWS\FaxSetup.log:rwqwwq
Removed Stream! C:\WINDOWS\fghym.dat:nuwnp
Removed Stream! C:\WINDOWS\fghym.dat:omtldb
Removed Stream! C:\WINDOWS\fjapv.txt:gmsgny
Removed Stream! C:\WINDOWS\fwscq.txt:cgusf
Removed Stream! C:\WINDOWS\Gone Fishing.bmp:sprgzx
Removed Stream! C:\WINDOWS\Greenstone.bmp:efmnye
Removed Stream! C:\WINDOWS\iety32.exe:hpcisq
Removed Stream! C:\WINDOWS\iety32.exe:jclyic
Removed Stream! C:\WINDOWS\iety32.exe:vhpgr
Removed Stream! C:\WINDOWS\ieuninst.exe:njriaq
Removed Stream! C:\WINDOWS\ieuninst.exe:tizcfd
Removed Stream! C:\WINDOWS\imvzk.txt:fwlsyp
Removed Stream! C:\WINDOWS\INSTLOG.TXT:dcdubq
Removed Stream! C:\WINDOWS\iomqs2.dat:jrntpk
Removed Stream! C:\WINDOWS\iomqs2.dat:ylnnng
Removed Stream! C:\WINDOWS\iPlayer.INI:xwdfsa
Removed Stream! C:\WINDOWS\ISCONECT.EXE:wcvava
Removed Stream! C:\WINDOWS\ixvom.dll:hxqlb
Removed Stream! C:\WINDOWS\javadk32.exe:xsqxka
Removed Stream! C:\WINDOWS\jdarj.dat:qxokvc
Removed Stream! C:\WINDOWS\kabliif.drv:aulvay
Removed Stream! C:\WINDOWS\KB823182.log:tvebca
Removed Stream! C:\WINDOWS\KB824141.log:epvttf
Removed Stream! C:\WINDOWS\KB828028.log:whngvq
Removed Stream! C:\WINDOWS\KB828741.log:wzimui
Removed Stream! C:\WINDOWS\KB833330Uninst.log:zpckms
Removed Stream! C:\WINDOWS\KB833987.log:hzarot
Removed Stream! C:\WINDOWS\KB833987.log:nevywg
Removed Stream! C:\WINDOWS\KB834707-IE6-20040929.115007.log:qozsqj
Removed Stream! C:\WINDOWS\KB834707-IE6-20040929.115007.log:wmkaa
Removed Stream! C:\WINDOWS\KB834707-IE6SP1-20040929.091901.log:aexbb
Removed Stream! C:\WINDOWS\KB835732.log:ffnmyi
Removed Stream! C:\WINDOWS\KB837001.log:gynro
Removed Stream! C:\WINDOWS\KB837001.log:sqvpgv
Removed Stream! C:\WINDOWS\KB837001.log:thqmik
Removed Stream! C:\WINDOWS\KB837001.log:xjzxxj
Removed Stream! C:\WINDOWS\KB839643.log:bvkucq
Removed Stream! C:\WINDOWS\KB840987.log:zzgwi
Removed Stream! C:\WINDOWS\KB841356.log:lhbrcv
Removed Stream! C:\WINDOWS\KB841533.log:uvdieb
Removed Stream! C:\WINDOWS\KB842773.log:rryck
Removed Stream! C:\WINDOWS\KB873339.log:eitwff
Removed Stream! C:\WINDOWS\KB873339.log:eyzlxy
Removed Stream! C:\WINDOWS\KB873339.log:trvigg
Removed Stream! C:\WINDOWS\KB873376.log:etdcn
Removed Stream! C:\WINDOWS\KB873376.log:mwvnyd
Removed Stream! C:\WINDOWS\KB885835.log:nswskl
Removed Stream! C:\WINDOWS\KB885836.log:woniik
Removed Stream! C:\WINDOWS\lijci.txt:gnvvq
Removed Stream! C:\WINDOWS\liveup.ini:ftgxmv
Removed Stream! C:\WINDOWS\liveup.ini:pacwtt
Removed Stream! C:\WINDOWS\liveup.ini:xtwih
Removed Stream! C:\WINDOWS\LIVING~1.ini:ehznun
Removed Stream! C:\WINDOWS\logimail.INI:hhzafx
Removed Stream! C:\WINDOWS\logimail.INI:pugnk
Removed Stream! C:\WINDOWS\LUINSTALL.LOG:allwr
Removed Stream! C:\WINDOWS\MailPlay.txt:pcabhi
Removed Stream! C:\WINDOWS\MailPlay.txt:picyqz
Removed Stream! C:\WINDOWS\MF_C421.lfa:aedlev
Removed Stream! C:\WINDOWS\MF_C421.lfa:uveldq
Removed Stream! C:\WINDOWS\ModemLog_ESS SuperLink-M Data Fax Voice Modem.txt:enhuh
Removed Stream! C:\WINDOWS\MPLAYER.INI:wnpeum
Removed Stream! C:\WINDOWS\msdfmap.ini:fwhdzl
Removed Stream! C:\WINDOWS\msgsocm.log:wgrzk
Removed Stream! C:\WINDOWS\msnavpklog.txt:xxzjto
Removed Stream! C:\WINDOWS\msnsetuplog.bak:zospqz
Removed Stream! C:\WINDOWS\msoffice.ini:qysowy
Removed Stream! C:\WINDOWS\NogaTw.INI:ardyf
Removed Stream! C:\WINDOWS\ntsautodial.ini:envus
Removed Stream! C:\WINDOWS\n_dbichl.dat:cqtpmr
Removed Stream! C:\WINDOWS\n_gjdrgi.dat:hsool
Removed Stream! C:\WINDOWS\n_hxytgg.dat:fspnlo
Removed Stream! C:\WINDOWS\n_ilvzid.txt:chaepj
Removed Stream! C:\WINDOWS\n_jbohbu.dat:xthsfq
Removed Stream! C:\WINDOWS\n_mqikfv.log:nadxmv
Removed Stream! C:\WINDOWS\n_okfshj.txt:gbwcgg
Removed Stream! C:\WINDOWS\n_pjpfar.dat:xkbrf
Removed Stream! C:\WINDOWS\n_pjpfar.dat:ycpqaq
Removed Stream! C:\WINDOWS\n_xlvhvo.dat:dufpog
Removed Stream! C:\WINDOWS\n_xlvhvo.dat:qifbp
Removed Stream! C:\WINDOWS\ocgen.log:wsylme
Removed Stream! C:\WINDOWS\ODBC.INI:nafagm
Removed Stream! C:\WINDOWS\ODBCINST.INI:edezhe
Removed Stream! C:\WINDOWS\ODBCINST.INI:ltgwed
Removed Stream! C:\WINDOWS\ODBCINST.INI:wnnzu
Removed Stream! C:\WINDOWS\oeuninst.exe:gtljks
Removed Stream! C:\WINDOWS\oeuninst.exe:nwiilb
Removed Stream! C:\WINDOWS\OEWABLog.txt:ztjdiz
Removed Stream! C:\WINDOWS\oobeact.log:zgktg
Removed Stream! C:\WINDOWS\orun32.ini:ybleep
Removed Stream! C:\WINDOWS\orun32.isu:ovkhbq
Removed Stream! C:\WINDOWS\orun32.isu:pehkdr
Removed Stream! C:\WINDOWS\ouuzg.txt:xmfhm
Removed Stream! C:\WINDOWS\PCSPATS.DAT:hvcuva
Removed Stream! C:\WINDOWS\PhotoJam3.ini:zwnaxl
Removed Stream! C:\WINDOWS\PowerReg.dat:myyvx
Removed Stream! C:\WINDOWS\PPSETUP.LOG:oexajt
Removed Stream! C:\WINDOWS\PPSETUP.LOG:oppqub
Removed Stream! C:\WINDOWS\PPSETUP.LOG:rxacca
Removed Stream! C:\WINDOWS\Q308402.log:gqivwl
Removed Stream! C:\WINDOWS\Q308677.log:heqfed
Removed Stream! C:\WINDOWS\Q311967.log:zfalgn
Removed Stream! C:\WINDOWS\Q313450.log:jxtirx
Removed Stream! C:\WINDOWS\Q313450.log:yuzwxn
Removed Stream! C:\WINDOWS\Q315000.log:cqenuh
Removed Stream! C:\WINDOWS\Q315000.log:rvsbsy
Removed Stream! C:\WINDOWS\Q315403.log:rjvnuf
Removed Stream! C:\WINDOWS\Q316397.log:jsqfso
Removed Stream! C:\WINDOWS\Q317277.log:jwcgui
Removed Stream! C:\WINDOWS\Q317277.log:urxsos
Removed Stream! C:\WINDOWS\Q317277.log:zuydbo
Removed Stream! C:\WINDOWS\Q317277Uninst.log:byoemj
Removed Stream! C:\WINDOWS\Q318138.log:btjluz
Removed Stream! C:\WINDOWS\Q318138.log:yplph
Removed Stream! C:\WINDOWS\Q319580.log:covmol
Removed Stream! C:\WINDOWS\Q319580.log:edcnzs
Removed Stream! C:\WINDOWS\Q319580.log:rsxok
Removed Stream! C:\WINDOWS\Q319580.log:svqqvr
Removed Stream! C:\WINDOWS\Q319580.log:urzreq
Removed Stream! C:\WINDOWS\Q319949.log:anchj
Removed Stream! C:\WINDOWS\Q319949.log:blgxqs
Removed Stream! C:\WINDOWS\Q319949.log:lrxzr
Removed Stream! C:\WINDOWS\Q323172.log:nnpljn
Removed Stream! C:\WINDOWS\Q323172.log:uyhrom
Removed Stream! C:\WINDOWS\Q323255.log:uutyoj
Removed Stream! C:\WINDOWS\Q324096.log:jlveye
Removed Stream! C:\WINDOWS\Q324096.log:tommd
Removed Stream! C:\WINDOWS\Q324380.log:fghymp
Removed Stream! C:\WINDOWS\Q324380.log:mzzwiw
Removed Stream! C:\WINDOWS\Q326830.log:yprvxq
Removed Stream! C:\WINDOWS\Q328310.log:bmgjso
Removed Stream! C:\WINDOWS\Q328310.log:ftkcbd
Removed Stream! C:\WINDOWS\Q328310.log:hefyvn
Removed Stream! C:\WINDOWS\Q328310.log:lpfrf
Removed Stream! C:\WINDOWS\Q328310.log:lxmjsn
Removed Stream! C:\WINDOWS\Q329048.log:xakckg
Removed Stream! C:\WINDOWS\Q329834.log:vzpupa
Removed Stream! C:\WINDOWS\Q331953.log:cgizlj
Removed Stream! C:\WINDOWS\Q331953.log:qdzcod
Removed Stream! C:\WINDOWS\Q810833.log:nzevxc
Removed Stream! C:\WINDOWS\Q811493.log:ipagbt
Removed Stream! C:\WINDOWS\Q814033.log:urenvb
Removed Stream! C:\WINDOWS\Q815021.log:nhlshv
Removed Stream! C:\WINDOWS\Q815021.log:ukghzh
Removed Stream! C:\WINDOWS\Q817287.log:ihnrfy
Removed Stream! C:\WINDOWS\Q819696.log:fiexcg
Removed Stream! C:\WINDOWS\Q828026.log:thidt
Removed Stream! C:\WINDOWS\Q828026.log:upxkqs
Removed Stream! C:\WINDOWS\qhsnb.txt:mlhkzs
Removed Stream! C:\WINDOWS\QuickCam.lnk:utksh
Removed Stream! C:\WINDOWS\regedit.exe:fridmn
Removed Stream! C:\WINDOWS\regedit.exe:idwhjv
Removed Stream! C:\WINDOWS\REGLOCS.OLD:btbftu
Removed Stream! C:\WINDOWS\REGLOCS.OLD:kuvmfw
Removed Stream! C:\WINDOWS\REGLOCS.OLD:ntymip
Removed Stream! C:\WINDOWS\REGLOCS.OLD:pnsvvf
Removed Stream! C:\WINDOWS\REGLOCS.OLD:qcguvg
Removed Stream! C:\WINDOWS\regopt.log:obyni
Removed Stream! C:\WINDOWS\Rhododendron.bmp:aeomdf
Removed Stream! C:\WINDOWS\Rhododendron.bmp:igdaqp
Removed Stream! C:\WINDOWS\River Sumida.bmp:ycrsc
Removed Stream! C:\WINDOWS\River Sumida.bmp:yesor
Removed Stream! C:\WINDOWS\rtqbb.dll:yjulek
Removed Stream! C:\WINDOWS\SchedLgU.Txt:lgthbu
Removed Stream! C:\WINDOWS\SchedLgU.Txt:pnfpx
Removed Stream! C:\WINDOWS\sdkmb.exe:cdqjdh
Removed Stream! C:\WINDOWS\setupact.log:apstio
Removed Stream! C:\WINDOWS\setupapi.log.1.old:lwuoim
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:wxfheh
Removed Stream! C:\WINDOWS\SWImport Xtra.PRF:qgnqvl
Removed Stream! C:\WINDOWS\SYSTEM$$.VIZ:jgfvpv
Removed Stream! C:\WINDOWS\SYSTEM$$.VIZ:nxcjsm
Removed Stream! C:\WINDOWS\system.ini:zgkpzz
Removed Stream! C:\WINDOWS\Thumbs.db:ifbsms
Removed Stream! C:\WINDOWS\Thumbs.db:jshzk
Removed Stream! C:\WINDOWS\Thumbs.db:shdutb
Removed Stream! C:\WINDOWS\TSMLite.INI:emjuir
Removed Stream! C:\WINDOWS\tsoc.log:bgufgu
Removed Stream! C:\WINDOWS\twain_32.dll:ivmqr
Removed Stream! C:\WINDOWS\uccspecb.sys:fmqey
Removed Stream! C:\WINDOWS\uccspecb.sys:tmevbv
Removed Stream! C:\WINDOWS\ulead32.ini:mnwaeg
Removed Stream! C:\WINDOWS\ulead32.ini:pmoior
Removed Stream! C:\WINDOWS\ulead32.ini:zjimfe
Removed Stream! C:\WINDOWS\uneng.exe:ynaka
Removed Stream! C:\WINDOWS\UNIDRV.cfg:apsrim
Removed Stream! C:\WINDOWS\UNIDRV.exe:cvmyce
Removed Stream! C:\WINDOWS\UNIDRV.exe:rksrzh
Removed Stream! C:\WINDOWS\uninst.exe:hbaotm
Removed Stream! C:\WINDOWS\uninst.exe:hcaukz
Removed Stream! C:\WINDOWS\uninst.exe:tpcwkx
Removed Stream! C:\WINDOWS\UNINST32.EXE:emlowo
Removed Stream! C:\WINDOWS\UNINST32.EXE:rnrske
Removed Stream! C:\WINDOWS\UNINST32.EXE:vwxewp
Removed Stream! C:\WINDOWS\unvise32.exe:adshej
Removed Stream! C:\WINDOWS\unvise32.exe:nphfv
Removed Stream! C:\WINDOWS\UPGRADE.TXT:yxiwtc
Removed Stream! C:\WINDOWS\vb.ini:chulhr
Removed Stream! C:\WINDOWS\vb.ini:oecsbq
Removed Stream! C:\WINDOWS\vbaddin.ini:mmzsmn
Removed Stream! C:\WINDOWS\VEMERA.INI:wkyuau
Removed Stream! C:\WINDOWS\vminst.log:fnrxox
Removed Stream! C:\WINDOWS\vminst.log:glkpug
Removed Stream! C:\WINDOWS\vminst.log:jdzdvt
Removed Stream! C:\WINDOWS\Warranties.chm:ciohom
Removed Stream! C:\WINDOWS\Warranties.chm:hhebmg
Removed Stream! C:\WINDOWS\Warranties.chm:olccuq
Removed Stream! C:\WINDOWS\Warranties.chm:xockii
Removed Stream! C:\WINDOWS\Warranties.chm:ymcuoj
Removed Stream! C:\WINDOWS\Warranties.chm:zggcxd
Removed Stream! C:\WINDOWS\WCE_SearchHistory.INI:berrxv
Removed Stream! C:\WINDOWS\WebshotsUninstall.exe:nkmmro
Removed Stream! C:\WINDOWS\WebshotsUninstall.exe:rmvzit
Removed Stream! C:\WINDOWS\WIN$$.VIZ:zfnnrd
Removed Stream! C:\WINDOWS\win.ini:fxwwtj
Removed Stream! C:\WINDOWS\win.ini:gbvjke
Removed Stream! C:\WINDOWS\winnt.bmp:jochaw
Removed Stream! C:\WINDOWS\WINNT32.LOG:bmexly
Removed Stream! C:\WINDOWS\winsx.inf:bpvndg
Removed Stream! C:\WINDOWS\WMSysPrf.PRX:fbetsv
Removed Stream! C:\WINDOWS\wsdu.log:fjgdco
Removed Stream! C:\WINDOWS\wsdu.log:tbvngb
Removed Stream! C:\WINDOWS\yacs.log:xgznbv
Removed Stream! C:\WINDOWS\zkdgl.txt:unfmog
Removed Stream! C:\WINDOWS\_default.pif:byigkl
Removed Stream! C:\WINDOWS\_default.pif:dxxikq
Removed Stream! C:\WINDOWS\_detmp.1:klyvaf
Removed Stream! C:\WINDOWS\_detmp.1:zapws
Removed Stream! C:\WINDOWS\_detmp.2:ktkxc
------------------------------------------------
Removed File! : C:\Windows\chgjg.dat
Removed File! : C:\Windows\ejqlt.dat
Removed File! : C:\Windows\hltvp.dat
Removed File! : C:\Windows\jdarj.dat
Removed File! : C:\Windows\nwuri.dat
Removed File! : C:\Windows\qbato.dat
Removed File! : C:\Windows\System32\eipvx.dat
Removed File! : C:\Windows\System32\kybwm.dat
Removed File! : C:\Windows\System32\nwxoy.dat
Removed File! : C:\Windows\System32\nxmgm.dat
Removed File! : C:\Windows\System32\pombj.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 2:59:09 PM


Logfile of HijackThis v1.99.1
Scan saved at 3:11:14 PM, on 6/6/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\essspk.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\HPConfig.exe
C:\WINDOWS\system32\RadioSvr.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\hj\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hp.com/notebooks/pavilion/e-center
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\RunServicesOnce: [Iomega CD-RW Setup] D:\Iomega_CD-RW.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {26AFD6EF-C017-4063-B2B1-E515DE98A1B7} - http://download.kodak.com/digital/software...2_1/install.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200211...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {9AE283A5-DF43-4C83-B6AA-7EBDBDB0204A} (VacPro.canada_ver10) - http://advnt01.com/dialer/canada_ver10.CAB
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/...ymmapi_0727.dll
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://www.pcpowerscan.com/pcpowerscan.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup.cab
O16 - DPF: {E9348280-2D74-4933-BE25-73D946926795} (DeviceEnum Class) - http://h20270.www2.hp.com/ediags/gmn/insta...cdetection3.cab
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} (Util Class) - https://isupport4.hp.com/motivedocs/linklauncher/MotUtil.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) - http://www.photolab.ca/activex/PCAXSetup.cab?
O17 - HKLM\System\CCS\Services\Tcpip\..\{567A0B44-21ED-4E37-9E66-3989D44345A3}: NameServer = 206.47.244.60 206.47.244.104
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: HP Configuration Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\System32\HPConfig.exe
O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe

#4 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,652 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:06:55 AM

Posted 06 June 2005 - 02:48 PM

Very good pleasehelp.


The following is not malware, but appears 'stuck'. It should have cleared itself after one run.
Start HJT and click on the SCAN button. Put a check mark in front of the following lines if they still show:

O4 - HKLM\..\RunServicesOnce: [Iomega CD-RW Setup] D:\Iomega_CD-RW.exe

With ALL OTHER WINDOWS CLOSED, click on Fix Checked.



This infection may have deleted the windows file 'shell.dll' and corrupted the 'hosts' file.

Download the Hoster from here.
- Unzip hoster.zip into it's own folder.
- Run Hoster.
- Press 'Restore Original Hosts' and press 'OK'
- Exit Program.


Check for the existance of shell.dll in both the 'C:\WINDOWS\System' and 'C:\WINDOWS\System32' folders. If it is missing, then:

Please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following folders:

C:\WINDOWS\System\
C:\WINDOWS\System32\


Please post one more HJT log. How are things running?
Derfram
~~~~~~

#5 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,652 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:06:55 AM

Posted 21 June 2005 - 12:16 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
Derfram
~~~~~~




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users