Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT - henryx


  • This topic is locked This topic is locked
33 replies to this topic

#1 henryx

henryx

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 01 May 2005 - 05:33 PM

Hi! Here are the list of some infos and problems i have encountered in my pc that might help in your reccomendations after analyzing my Hijackthis log.

1. After performing system scan using Ad-aware and quarantine all the results, I cannot open my Kazaa and error message says that "Couldn't load library TopSearch.dll.

2. When playing yahoo games(literati, dominoes, etc), there are times when after loading the applet theres this error message saying like 'performing Illegal Operation' and then all open windows will automatically closed. I think that its related to Kernel32.dll.

3. After booting, there are lots of rundll32s on my program list and its a habit to end-tasked all those program though i know that its a good program anyway, later in my browsing theres this one who still manage to comeback.

Posted Image

4. I cant delete the iSearch and spotresults.

5. There are lots of weird exe files (no results in google) in my startup list and I disabled them.

Posted Image

6. These past few hours, a PC-cillin window already pops-up 4 times saying that i was infected by VBS_REDLOF.A2 and cannot be cleaned/quarantined. The PC-cillin Server response already 'timed-out' so it was'nt updated for the long time. Can you suggest a good free anti-virus on the net?
---------------

My log:

Logfile of HijackThis v1.99.1
Scan saved at 6:01:36 AM, on 5/2/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCIOMON.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCPFW.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\TRAYICON.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCGUIDE.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCCLIENT.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\POP3TRAP.EXE
C:\WINDOWS\SYSTEM\E_S4I3T1.EXE
C:\PROGRAM FILES\GOLDENSOFT\CDGHOST 21ST\MNDLSVR.EXE
C:\WINDOWS\MNIMPR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\WEBTRAP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\MY DOCUMENTS\SETUP\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_6_0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System\TrayIcon.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCIOMON.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCIOMON.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [hsp] C:\WINDOWS\hsp.exe
O4 - HKLM\..\Run: [jup] C:\WINDOWS\jup.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\SYSTEM\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O5 "LPT1:" /M "Stylus C45"
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\WINUP2DATE.DLL,SHStart
O4 - HKLM\..\Run: [Goldensoft_MndlSvr] C:\PROGRA~1\GOLDEN~1\CDGHOS~1\MndlSvr.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\mnimpr.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [PCCIOMON.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCIOMON.exe"
O4 - HKLM\..\RunServices: [PCCPFW] C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\SYSTEM\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /M "Stylus C45" /EF "HKCU"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ptrp.exe
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5.yahoo.com/c174/chat.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://yog55.games.scd.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab

------------

Thank You very much for the time. :thumbsup:

BC AdBot (Login to Remove)

 


#2 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 01 May 2005 - 05:40 PM

5.  There are lots of weird exe files (no results in google) in my startup list and I disabled them. 

Posted Image

Ooops!

Should I check them all and re-scan again with Hijackthis for better analyzation of my log. Here's the complete list:

Posted Image

:thumbsup:

#3 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:24 AM

Posted 02 May 2005 - 03:30 AM

Hello henryx and welcome to the BC forums. Yes, we will need you to disable MsConfig from limiting the startup entries to properly analyze your HijackThis log so please do that in your next post. You can do this by clicking on the Normal Startup button on the General tab.

Prior to posting a new log let's run some of the basic scans and see what they turn up. Please proceed with the following steps in order.

Step #1

Run On-line virus scans

Please run at least 2 of the following on-line virus scans:Trend Micro Housecall
BitDefender On-Line Virus Scan
Panda ActiveScan
Make sure that you choose "fix" or "clean".

Step #2

Run Spybot Search & Destroy

Download, install, update and run a scan with Spybot S&D:
  • Download and Install Spybot Search & Destroy, accepting the Default Settings.
  • In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.
  • Close ALL windows except Spybot S&D
  • Click the button to ‘Search for Updates’ and then download and install all available Updates.
  • Next click the button ‘Check for Problems’
  • When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
Step #3

Run AdAware SE

Download, install, update, configure and run a scan with Ad-aware SE:
  • Download and Install AdAware SE Personal, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window:
    • In the ‘General’ window make sure the following are selected in green:
      • Under Safety:
        • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to update outdated definitions - set the number of days
  • Click on the ‘Scanning’ button on the left and select in green:
    • Under Driver, Folders & Files:
      • Scan Within Archives
    • Under Select drives & folders to scan:
      • choose all hard drives
    • Under Memory & Registry: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL’s
      • Scan my Hosts file
  • Click on the ‘Advanced’ button on the left and select in green:
    • Under Shell Integration:
      • Move deleted files to recycle bin
    • Under Logfile Detail Level: all green
      • include addtional object information
      • DESELECT - include negligible objects information
      • include environment information
    • Under Alternate Data Streams:
      • Don't log streams smaller than 0 bytes
      • Don't log ADS with the following names: CA_INOCULATEIT
  • Click the ‘Tweak’ button and select in green:
    • Under ‘Scanning Engine’:
      • Unload recognized processes during scanning
      • Scan registry for all users instead of current user only
    • Under ‘Cleaning Engine’:
      • Let Windows remove files in use at next reboot
    • Under Log Files:
      • Include basic Ad-aware SE settings in logfile
      • Include additional Ad-aware SE settings in logfile
      • Please do not check: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
  • Choose 'Perform Full System Scan'
  • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
  • Save the log file when it asks and then click ‘Finish’
  • REBOOT to complete the removal of what Ad-Aware SE found.
Step #4

Next, let's clean up the temporary folders:
  • Download CleanUp! and install.
  • Start CleanUp! and click the CleanUp! button. Let it run to completion.
Step #5

OK. Reboot your computer normally, start HijackThis and perform a new scan. Post your new log file back here as a relpy to this topic and I will review it.

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS SOME OF THE FILES ARE LEGITIMATE AND VITAL TO THE FUNCTION OF YOUR COMPUTER

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#4 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 05 May 2005 - 12:45 AM

Thanks for the Instructions

Heres my new log:

----------------------------

Logfile of HijackThis v1.99.1
Scan saved at 1:38:10 PM, on 5/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 SP1 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCIOMON.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCPFW.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\TRAYICON.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCGUIDE.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCCLIENT.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\POP3TRAP.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\E_S4I3T1.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\GOLDENSOFT\CDGHOST 21ST\MNDLSVR.EXE
C:\N20050308.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\WEBTRAP.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\LOADWC.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\MY DOCUMENTS\SETUP\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5_1_6_0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINDOWS\System\TrayIcon.exe
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCIOMON.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCIOMON.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [hsp] C:\WINDOWS\hsp.exe
O4 - HKLM\..\Run: [jup] C:\WINDOWS\jup.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\SYSTEM\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O5 "LPT1:" /M "Stylus C45"
O4 - HKLM\..\Run: [Goldensoft_MndlSvr] C:\PROGRA~1\GOLDEN~1\CDGHOS~1\MndlSvr.exe
O4 - HKLM\..\Run: [Create A Monster] C:\Program Files\Kudd.com\createAMonster.exe -run
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [ehatupmd] C:\WINDOWS\ehatupmd.exe
O4 - HKLM\..\Run: [vatqjkb] C:\WINDOWS\vatqjkb.exe
O4 - HKLM\..\Run: [anwxqf] C:\WINDOWS\anwxqf.exe
O4 - HKLM\..\Run: [tchspil] C:\WINDOWS\tchspil.exe
O4 - HKLM\..\Run: [ijej] C:\WINDOWS\ijej.exe
O4 - HKLM\..\Run: [vwdyv] C:\WINDOWS\vwdyv.exe
O4 - HKLM\..\Run: [ypuzcb] C:\WINDOWS\ypuzcb.exe
O4 - HKLM\..\Run: [vovez] C:\WINDOWS\vovez.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Kernel32] C:\WINDOWS\SYSTEM\Kernel.dll
O4 - HKLM\..\Run: [ylwn] C:\WINDOWS\ylwn.exe
O4 - HKLM\..\Run: [dedkb] C:\WINDOWS\dedkb.exe
O4 - HKLM\..\Run: [ziv] C:\WINDOWS\ziv.exe
O4 - HKLM\..\Run: [qfmtajmt] C:\WINDOWS\qfmtajmt.exe
O4 - HKLM\..\Run: [wbodcp] C:\WINDOWS\wbodcp.exe
O4 - HKLM\..\Run: [zelwdkh] C:\WINDOWS\zelwdkh.exe
O4 - HKLM\..\Run: [ytajml] C:\WINDOWS\ytajml.exe
O4 - HKLM\..\Run: [zehebwv] C:\WINDOWS\zehebwv.exe
O4 - HKLM\..\Run: [ctmvqfkv] C:\WINDOWS\ctmvqfkv.exe
O4 - HKLM\..\Run: [ixev] C:\WINDOWS\ixev.exe
O4 - HKLM\..\Run: [eryn] C:\WINDOWS\eryn.exe
O4 - HKLM\..\Run: [ydwzor] C:\WINDOWS\ydwzor.exe
O4 - HKLM\..\Run: [Norton Antivirus AV] C:\WINDOWS\FVProtect.exe
O4 - HKLM\..\Run: [ntechin] C:\N20050308.EXE
O4 - HKLM\..\Run: [VCDTower] C:\PROGRA~1\GOLDEN~1\CDGHOS~1\VCDTower.exe
O4 - HKLM\..\Run: [nsvcin] C:\N20050308.EXE
O4 - HKLM\..\Run: [avast! Web Scanner] C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [PCCIOMON.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCIOMON.exe"
O4 - HKLM\..\RunServices: [PCCPFW] C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\SYSTEM\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /M "Stylus C45" /EF "HKCU"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat 1.3 - http://cs5.chat.sc5.yahoo.com/c174/chat.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://yog55.games.scd.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

#5 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:24 AM

Posted 05 May 2005 - 03:07 PM

Hi henryx. If looks like we have a few different infections to deal with here. since we can't deal with all of them at the same time let's start with the worst one. I want to verify that there is an L2m infection here so please do the following:

L2mFix for Win98
Download Agent Ransack and install it.
  • Start Agent Ransack.
  • Put a check in the Expert User checkbox (upper right-hand corner).
  • Copy/paste the line below into the Containing text field:
    • (UMonitor|IsProcessorFeaX|NictechNetworks)+
  • Copy/paste the line below into the Look in: field:C:\windows\system
  • Uncheck the box to Search subfolders.
  • Click the Start search button.
  • When the search is finished go to File>Save Results and
    • Select Clipboard.
    • Uncheck File contents.
    • Now click the Save button.
The data will now be on the clipboard. Please use the Add Reply button and paste the data from the clipboard back into this topic.

I will review the information when it comes in.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#6 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 05 May 2005 - 08:35 PM

Posted Image

Excuse me sir, but where is the clipboard? Is that the one in red rectangle above? If so, when highlighting it seems that i cant paste it here

When pressing the Save Results and Save, where does the file go?

#7 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:24 AM

Posted 05 May 2005 - 09:12 PM

Hi henryx. the Clipboard is just in memory. When the program saves the scan to the clipboard then you can come back here to the topic, click the Add Reply button and click in the editbox (like where you have been posting your logs and the picture above). Then press the Ctrl key and the V key at the same time to 'paste' the data on the Clipboard to the editbox.

Add any further comments and you're all set.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#8 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 05 May 2005 - 10:36 PM

...delete delete...

Edited by henryx, 06 May 2005 - 06:11 PM.


#9 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 05 May 2005 - 10:43 PM

Oooops! Wrong post, im just experimenting :thumbsup:

#10 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 05 May 2005 - 10:45 PM

Finally...
OMG! What the hell are these...

C:\windows\system\OXBC32GT.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\SWD401LC.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\LDRT.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MYJINT40.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OKSSQ400.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OLBCCU32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\CWUSALGO.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DVKMAINT.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\WFBVW.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MVJAVA.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\WAPDINFO.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\IF32_32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DXNPUT8.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\McRTEDIT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MFPISTUB.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SXntf32.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OCUI400.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\UEDM16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\WSBVW.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AFDENC32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\UOER.EXE (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NMTOS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NsTOS.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\FAAMEBUF.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\CWMPOBJ.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\IKS.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NCRSJA.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MQDEMUI.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\RNCLTSCM.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NlSWAN16.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NITOS.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MHVCRT40.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\GQU32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DXMSSHRN.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\EQS4E3T1.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OHFIL400.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\ACCODC32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\TXPELIB.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OVCACHE.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NHRSES.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MZIQTZ32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MLAPSSPC.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\VKAME.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SXTUP4.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NDTAPI32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DPMAP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MVVCRT40.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\CFET16.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\mfihnd.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\CEYPTEXT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\VQODEC32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\meihnd.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\WQBCHECK.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\PFNMAP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\LAEXPAND.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NrTDI.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\DHNET.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NcNDS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\psgfilt.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\xflparse.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NARSZHT.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IcNPSTUB.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MMXML.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\psmas.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\SPSTHUNK.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\cvdrules.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\SPORAGE.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\JQSH400.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DUBENG.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\RUSAPI32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\azl.dll (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\NRSWAN32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\IhSETUP.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NbQTwk.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OIE2DISP.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DBSCRIPT.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DNNIM.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DVTMSFT3.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OVPDX32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OFBCCU32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DKIME.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\IKFG95.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\wwtdecod.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MKEXCH40.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DOMSSHRN.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\GAI32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NuSWAN16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NNTAPI32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MMJET40.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\IUFG95.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\NkTOS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MpTCP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RwCLTC1.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\RpASETUP.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\FLAMEBUF.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\FGSRCH.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\OLCACHE.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DEIMAN.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DEDMO.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OJBCCR32.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\EUH4E3T1.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DLLAYX.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\msg200.cpy.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\MPSTDFMT.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OLTLWAB.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\DYTMSFT3.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\IPSENG.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\RVCLTS3.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\SARAPI.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\rilesak.dll (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\ECPSRV.DLL (218 KB, 1/22/05 4:15:06 AM)
C:\windows\system\OCPDX32.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\QNV.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\MVORCL32.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\CTUTIL.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\MrLOCUSR.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\PEBASE.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\DXDRM.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\MDVFW32.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\NtTAPI.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\rdched20.dll (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\IbFRARED.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\LNEXPAND.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\SVLSTR.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\FSAMEBUF.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\ACPartners.dll (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\MHCD30.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\chfview.dll (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\IBETCPLC.DLL (222 KB, 3/9/05 3:22:20 AM)
C:\windows\system\DNMSVINN.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IYETRES.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\JRSD400.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MPXML3R.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ETS4E3T1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NzTDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MKI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NjTOS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EFDPUI03.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OFBCINT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IRFG95.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IXGUTIL.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MyLOCUSR.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\LDEXPAND.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MNXML.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IQDICDLL.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OQDBSE32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ITS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DNBAND.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\UHDMXFRM.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RgASETUP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ESIGUECT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SEDOCVW.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RrCLTC1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IyNPSTUB.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RqCLTC1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MWMIXMGR.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\LTEXPAND.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SXLWID.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DI8VB.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\Fy20.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RkCLTC5.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\PnPNDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DKDXOF.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DU8VB.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MMEXCH40.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\mxihnd.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MBEXCH40.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MMJDBC10.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NITDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MPIMRT16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\wanupd.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AIYCFILT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MWIMRT16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ppdrv.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\wjtdecod.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\QASNAME.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NFSWAN32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\phdrv.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MZLOCUSR.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\rxaenh.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SNSTHUNK.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\CeGWIZ.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RiCLTC1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\crreak.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MRINCP16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\Fp20.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\solb2.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DLOUND3D.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AVCTRES.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NnTOS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RZASMM.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EDS490T1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MEIMRT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IiHLPAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\VGAME.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\QPSNAME.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NiSWAN32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DHRAW.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MXIMUSIC.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IlSETUP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SFSTHUNK.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EZH4E3T1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NoSWAN16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\uvp10.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SwRAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SCRIALUI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\WWNALIGN.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OPBCTRAC.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EFS490T1.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IcSETUP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\HVFCSA32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ECABLE3.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AJIFIL32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SPLSRV32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\cYbinet.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\WXNALIGN.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MUVCRT40.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\mlihnd.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NeSWAN16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SAntf16.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\WjOCK32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RygAcc.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\PXPD.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OMBC32GT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NwTDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MiTCP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NWTAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EXABLE3.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\LKRT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ptdrv.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DHLAYX.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\CXYPT32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AZDCXC32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NrNDS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NxTAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IJNPSTUB.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SkRAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IwFRARED.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\PDNMAP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NQTAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DRIMAN32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\irengine.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\wzhext.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\CUL3D.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IWSCLASS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\QEV.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RICLTSCM.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NLTAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MlTCP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SLREAMCI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OUEACCRC.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\JZMD400.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\QAAP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NsNDS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DQVENUM.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MQSTDFMT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ERUSBIN.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\CRM.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IhNPSTUB.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\QKSNAME.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\JKMD400.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\evshared.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DHSTYLE.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MYPRINT2.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\TOAPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\SVTUP4.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NtSWAN16.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NtSWAN32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MIORCL32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EZUSBIN.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MnTCP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RvCLTC5.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\EYIGUECT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MVEXCH40.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\Ff20.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AOICAP32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MDRTEDIT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\swnsapi.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\AXKRNL32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\CSYPTEXT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RYSAPI32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NaTOS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NoNDS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NKRSZHT.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NpNDS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\PhPNDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\pwgfilt.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MtRTEDIT.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\Fk20.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DpCNDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ERABLE3.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NlTDI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\ppmas.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\RNCLTSPX.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\mxc42.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\NyTOS.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\DAIME.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IWETCPLC.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\iectl.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MuTCP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MCWEBDVD.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IjFRARED.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\MPSIGN32.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\mec42.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\IdSETUP.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\inctl.dll (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\TMPI.DLL (222 KB, 3/16/05 3:37:54 AM)
C:\windows\system\OREAUT32.DLL (222 KB, 3/16/05 3:37:54 AM)

Thanks!

Edited by henryx, 05 May 2005 - 10:47 PM.


#11 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:24 AM

Posted 06 May 2005 - 01:13 PM

Hi henryx. That's a pretty good infection. I'd like to try a special tool to eradicate it rather than trying to do it manually so please do the following:
  • Download VX2Finder9x(126).exe to your desktop.
  • Locate the VX2Finder9x(126).exe file on your desktop and double-click on it to start the program.
  • Click on the Click to find VX2.BetterInternet button.
  • When the scan is done click the Make Log button.
Notepad should open up with the information in it. Please copy/paste that information back here and I will review it when it comes in.

DO NOT click any of the other buttons until I have had a chance to review the information and instruct you to do so. Doing so can harm your computer and cause it to quit functioning.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#12 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 06 May 2005 - 02:59 PM

When pressing Make Log It automatically direct to a bittorrent downloader saying that its an invalid torrent file (yes, of course). Now that I uninstall it yet it's still looking for btdownloadgui.exe.

Posted Image

Before, when saving log in HijackThis, I also encountered the same problem above so I just put .txt after the file name so it will be saved in notepad. What should I do now? Thanks for being patient.

:thumbsup:

#13 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:24 AM

Posted 06 May 2005 - 05:25 PM

Hi henryx. What that message means is that you have associated the .log file extension with that particular program. Is that program something that you use? To resolve that message you will need to associate the .log file extension back to the default of Notepad. to do that open My Computer and click the Tools>Folder Options menus. click on the File Types tab and scroll down the list of registerd file types to find the entry for Log. Then click teh Change button and browse to Notepad.exe. This shoud be either in the c:\windows or c:\windows\system folder. Ok your way out of the dialog box and My Computer and then repeat the steps in my previous post.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#14 henryx

henryx
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:09:24 AM

Posted 06 May 2005 - 05:59 PM

Ooops! now I'm lost. I see the LOG file with the icon of btdownload.exe but i Remove it. I thought that the original(notepad.exe) setting will come back if I removed it. Should I click the New Type... to add the LOG with my setting as notepad, how? I dont know what to fill in...

I try the VX2Finder9x(126).exe again and when i press the [Make Log] nothing happens.

Posted Image

I dont use the btdownload.exe (Bittorent) anymore so I uninstall it anyway.


Thanks again.

Edited by henryx, 06 May 2005 - 06:06 PM.


#15 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:24 AM

Posted 06 May 2005 - 07:08 PM

Hey henryx. Just double-click on a log file and from the Open with dialog choose Notepad and check Always use this program to open this file. Click the Ok button and you're done.

Re-run the steps in my previous post and post the log file back here.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users