This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Please Analyze Hijack This Log!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Could someone please look this log over for me - please! Also, if you can suggest anyways to remove junk that wold be good to. I know my way around the Registry and my HD if that makes things easier. I'm just not that familiar with nasty signtures (-:

Problems:

1.Continued Browser Hijack
2. Unexplained System shutdowns

Thank You Ahead of Time for YOUR time and expertise!
Mike D

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:09 PM, on 5/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\taskswitch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\Program Files\RAM Idle LE\RAM_XP.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Executor\executor.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\WINDOWS\system32\wscntfy.exe
\?\globalroot\C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: Onfolio - {1fea1109-9f65-4fdc-aec5-033f6cc60641} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - D:\PROGRA~1\TEXTAL~1\TAForIE.dll
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R320 Series on ADDIE21] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9XE.EXE" /P46 "Auto EPSON Stylus Photo R320 Series on ADDIE21" /O18 "\\ADDIE21\EPSONSty" /M "Stylus Photo R320"
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PDF3 Registry Controller] "D:\Program Files\ScanSoft\PDF Converter 3.0\\RegistryController.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Everything] "C:\Program Files\Everything\Everything.exe" -startup
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Executor] "C:\Program Files\Executor\executor.exe" -s
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOCUME~1\User\protect.dll,_IWMPEvents@16
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'Default user')
O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User 'Default user')
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: RegVac.lnk = C:\Program Files\RegVac Registry Cleaner\regvac.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Capture &Image To Onfolio… - res://D:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: Capture &Page To Onfolio… - res://D:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddLinkEntryFromDocument.html
O8 - Extra context menu item: Capture &Snippet To Onfolio… - res://D:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentSelection.html
O8 - Extra context menu item: Capture &Target To Onfolio… - res://D:\Program Files\Onfolio\Onfolio.WindowsResources.dll/AddEntryFromDocumentElement.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\Program Files\ScanSoft\PDF Converter 3.0\IEShellExt.dll /100
O8 - Extra context menu item: Summarize! 2.0 - D:\Program Files\Corpora\Summarize! 2.0\IEIntegration\IEAddin.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - D:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - D:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2fc2f9a4-c43e-42c0-9490-19d6be8b1726} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Onfolio Capture… - {2fc2f9a4-c43e-42c0-9490-19d6be8b1726} - mscoree.dll (file missing)
O9 - Extra button: Onfolio - {30e2a68b-20f5-419d-bbb9-dce92edc4e67} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Onfolio Collection Explorer - {30e2a68b-20f5-419d-bbb9-dce92edc4e67} - mscoree.dll (file missing)
O9 - Extra button: Summarize! 2.0 - {CC9F8C6E-6202-4f6e-8E14-83A16E3F05EF} - D:\Program Files\Corpora\Summarize! 2.0\IEIntegration\IEAddin.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ComcastHSI - {5D4D961C-63F7-483F-8CAB-E473C9F975C8} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Support - {C668B79A-D2CE-4483-A7B9-6789B6FF40EE} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: Help - {DB83B641-F855-444D-B92B-0063F31523B8} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {3347F40E-62E6-483B-93EC-ADBE71A5AFA8} - http://www.mediamachines.com/flux2/setup.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/19b2f10dd378337aa203/…ip/RdxIE601.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\vamegeye.dll,C:\WINDOWS\system32\yatevipi.dll,
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: RegVac Registry Service (RegVacService) - Super Win Software, Inc. - C:\Program Files\RegVac Registry Cleaner\RegVserv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Acronis - (no file)
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Cryptainer service (ssoftservice) - Cypherix - C:\WINDOWS\SYSTEM32\ssoftsrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O24 - Desktop Component 0: (no name) - http://grooveradio.com/np/btn_wmp2.jpg

–
End of file - 11418 bytes
Hi curio50, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Open hijackthis, do a system scan only and checkmark these lines, if present

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O3 - Toolbar: Onfolio - {1fea1109-9f65-4fdc-aec5-033f6cc60641} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOCUME~1\User\protect.dll,_IWMPEvents@16
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'Default user')
O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User 'Default user')
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/19b2f10dd378337aa203/…ip/RdxIE601.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\vamegeye.dll,C:\WINDOWS\system32\yatevipi.dll,


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



Download OTListIt2 to your desktop.

Next, Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTLI
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)

:Files
C:\WINDOWS\system32\vamegeye.dll
C:\WINDOWS\system32\yatevipi.dll
C:\WINDOWS\system32\autochk.dll
C:\DOCUME~1\LOCALS~1\protect.dll
C:\DOCUME~1\User\protect.dll

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.


Next
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • OTLISTIT2 log
  • combofix log
  • new HJT log taken last
How is the computer?

Thanks
Hello Oldtimer, I really really appreciate your help, both time and expertise! Here is the log result from OTList: ========== OTLISTIT ========== Process Explorer.EXE killed successfully! ========== FILES ========== File\Folder C:\WINDOWS\system32\vamegeye.dll not found. File\Folder C:\WINDOWS\system32\yatevipi.dll not found. DllUnregisterServer procedure not found in C:\WINDOWS\system32\autochk.dll C:\WINDOWS\system32\autochk.dll NOT unregistered. C:\WINDOWS\system32\autochk.dll moved successfully. File\Folder C:\DOCUME~1\LOCALS~1\protect.dll not found. DllUnregisterServer procedure not found in C:\DOCUME~1\User\protect.dll C:\DOCUME~1\User\protect.dll NOT unregistered. C:\DOCUME~1\User\protect.dll moved successfully. ========== COMMANDS ========== File delete failed. C:\Documents and Settings\User\Local Settings\Temp\etilqs_mlpFVBT5HVI9BwOrUOC0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_5f4.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_f18.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_f20.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\User\Local Settings\Temp\WCESLog.log scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\msb.dll scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\nsrbgxod.bak scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05192009_125501 Files moved on Reboot… File C:\Documents and Settings\User\Local Settings\Temp\etilqs_mlpFVBT5HVI9BwOrUOC0 not found! File C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_474.dat not found! File C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_5f4.dat not found! File C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_f18.dat not found! File C:\Documents and Settings\User\Local Settings\Temp\Perflib_Perfdata_f20.dat not found! C:\Documents and Settings\User\Local Settings\Temp\WCESLog.log moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\temp\msb.dll C:\WINDOWS\temp\msb.dll NOT unregistered. C:\WINDOWS\temp\msb.dll moved successfully. C:\WINDOWS\temp\nsrbgxod.bak moved successfully. Registry entries deleted on Reboot… I am going to proceed to downloading the ComboFix program and will post requested logs Thanks Again, Mike D
Problem! - As I began running ComboFix I got the following:

A blue DOS window, so far so good! but with the message:

"NIRCMDC not recognized as internal or external command, program, or batch file"

In addtion, although my system boots to desktop, I cannot run any programs, including an attempt to run ComboFix again by clicking on its execution file. I click and click but nothing. I also tried right click/run, nothing.

In a worse case scenario, I did an entire system backup (OS and all) a few months ago using Acronis. However, if my system is reasonably salvagable I'd rather spend a little more time. How in the world did I get such a nasty infection? I've been fairly careful where I go and what I click on.

Thanks,
Mike D
Hi curio50,

Is that a typo in the error message?

NIRCMDC

Is it supposed to be NIRCMD

Did combofix run at all?

Thanks
Hi curio50,

Please have a look for the combfix log at one of these locations


  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program…
  • Click on Notepad

If it's not there have a look in these folders

b]C:\Combofix\ or C:\qoobox\

Thanks
Hi, I double checked, it reads "NIRCMDC." The problem began when I got to the Combofix part. I downloaded Combofix, and when I clicked on the exe file to run, I got the DOS screen which appeared to indicate it was beginning to run, then it said something about needing to reboot, which it didn't do even after two or three minutes, I had to do this manually via the task manager. When the machine came back on I end up with this blue DOS screen, with the aforementioned message along with all desktop icons, but none will execute when I click on them. Like I said, if I have to, I'll reformat and use my old acronis backup if this is going to turn into a nightmare. But, I am willing to put in somemore effort if you have any ideas (-: Thanks, Mike D The blue screen looks like the attachment, it shows multi windows b/c I clicked on twice to try and get more info, but the message is the one I mentioned above.

Attachments:

I got a look inside combofix.txt and its blank. I deleted combofix as the trouble seemed to start there, but after I rebooted I got the same blue DOS windows and message! So, must be a system thing? ALSO, I got another message pev.exe problem…must close Should I use my XP system repair disc? maybe some important sys file was accidentally deleted. I am still having trouble running programs, for example my browser wont open, etc. What do you think? mike
Hi Mike, Just hang tough for a bit, don't make any more changes. We don't want to make think worse. I don't think any important system files where removed. pev.exe isn't a windows file. We have a call out to the author and others are looking at this also. Can you recall anything about the reason combofix said it was going to reboot? Are you using another computer to post here? Thanks
Ok, yes I am using another PC to post. No, I can't recall anything specific about why ComboFix said it was going to reboot - I thought it was done doing its thing and reboot was normal. In a worse case scenario, I suppose I could download again and run, and make more careful observations. Would it help if I ran OTlist for a more recent log report? Also, I had literally every single Registry entry listed in bold below, which I ran "fix" on. However, I'll follow your suggestion and wait and see what other input comes my way. Thanks Again, Mike These maleware writers are real bastards!
Hi Mike,

These maleware writers are real bastards!

Agreed.

I'm willing to put in as much time as you are.

Combofix will notify you it wants a reboot if it finds a rootkit or when it's finished scanning.

This may explain what happened

Also, I had literally every single Registry entry listed in bold below, which I ran "fix" on

The reg entries you saw were most likely the registry entries combofix was removing. What were you fixing them with?

Heard back. This looks like the problem you enountered.

WebRoot may have been active and may have killed some of combofix's files. Please make certain that this program is disabled and not allowed to run on reboot.

For Windows NT, Windows 2000, and Windows XP systems:

Disable Webroot Spy Sweeper by:
-Right-mouse click (right-click) the Webroot Spy Sweeper icon located in the system tray.
-Select Shut Down from the shortcut menu. Click the Shut Down button to confirm.
-Next, click Start > Settings > Control Panel.
-Double-click Administrative Tools and then double-click Services.
-Find and double-click Webroot Spy Sweeper Engine listed under the Name column.
-Click the Stop button to stop the Webroot service.
-Click OK to close the Webroot Spy Sweeper Engine properties.

For the antivirus portion

"In order to disable the Anti-Virus components of Webroot Anti-Virus you must go to two separate sections:

Anti-Virus Shield Disabling

1. Click on the Options button on the left hand side of Webroot Anti-Virus

2. Go to the Shields tab of the Options Menu

3. Under the section labeled Anti-Virus Protection, take the checkmark out of the Protect against Viruses box.

"Anti-Virus Shields have successfully been turned off."

Anti-Virus Sweep Disabling

1. Click on the Options button on the left hand side of Webroot Anti-Virus

2. On the Sweep tab, put the dot into Custom Sweep (please note you can only disable Anti-Virus Sweeps by using the Custom Sweep option)

3. Under the section labeled Sweep Settings Summary, click the Change Settings link which is next to Custom Sweep Settings

4. A Custom Sweep box will appear with various sections to click on. Click on the What To Sweep button on the left side of this Custom Sweep box.

5. On this screen, take the checkmark out of Sweep for Viruses under the Viruses section.

6. Click the OK button at the bottom of this screen and you will be returned to the Sweep tab. (Again please note that you can only disable Anti-Virus Sweeps by using the Custom Sweep Option which will now be selected)

"Anti-Virus Sweeps have successfully been turned off."



Let's give combofix another go

These are typically the screens you will see, with the exception of the rootkit warning screen.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the ombofix log and a new HJT log.

Thanks
Thanks Oldman! Yes, I'll give the new set of instructions a shot. I hate to let these creeps force me to reformat and backup unless I run out of time - not there yet. Mike D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI