This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Daemon, Take Care Of Me

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi There!!

You have taken care of me in the past and I'm looking for more advice on this tough hijack. I keep getting the About Blank page and redirected to the cool search site. I've read a bit of what you've done for Genemash, but would like some specific help.

After running Spybot, Hijack This, CWS, and Ad-Aware, I've had no luck in clearing this one out. I'm pasting my latest Hijack This Log plus a FindNFix Log if it helps.

Your help is greatly appreciated. Thanks.

Logfile of HijackThis v1.98.0
Scan saved at 6:25:30 PM, on 7/5/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
————————————————————————————
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\hector\Desktop\GoogleToolbarInstaller.exe
C:\Documents and Settings\hector\Desktop\GoogleToolbarInstaller.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\hector\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\hector\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\hector\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\hector\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\hector\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\hector\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\hijackthis\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {807F7A0C-DEAF-43C0-A83A-DD1D6C62051E} - C:\WINNT\system32\ijn.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O18 - Filter: text/html - {ACC849A6-86C7-4834-B44A-C4F51AC7ABA4} - C:\WINNT\system32\ijn.dll
O18 - Filter: text/plain - {ACC849A6-86C7-4834-B44A-C4F51AC7ABA4} - C:\WINNT\system32\ijn.dll

————————————————————————————
FindNFix Log:

»»»»»»»»»»»»»»»»»»*** freeatlast100.100free.com ***»»»»»»»»»»»»»»»»

Microsoft Windows 2000 [Version 5.00.2195]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q822925-Q330994-Q832894-Q831167
The type of the file system is NTFS.
C: is not dirty.

Mon 07/05/2004
2:49pm up 0 days, 1:42

»»»»»»»»»»»»»»»»»»***LOG!***»»»»»»»»»»»»»»»»

Scanning for file(s)…
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»» (*1*) »»»»» ………
»»Locked or 'Suspect' file(s) found…

C:\WINNT\System32\MSFDON.DLL +++ File read error
\\?\C:\WINNT\System32\MSFDON.DLL +++ File read error

»»»»» (*2*) »»»»»……..
**File C:\FINDnFIX\LIST.TXT
MSFDON.DLL Can't Open!

»»»»» (*3*) »»»»»……..

C:\WINNT\SYSTEM32\
msfdon.dll Sun Jul 4 2004 8:52:06p A…R 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

unknown/hidden files…

No matches found.

»»»»» (*4*) »»»»»………
Sniffing……….
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINNT\SYSTEM32\MSFDON.DLL


»»»»»(*5*)»»»»»
**File C:\WINNT\SYSTEM32\DLLXXX.TXT
¯ Access denied ® ………………… MSFDON.DLL …..57344 04.07.2004

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»

»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512…)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448

»»Dumping Values……..
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***)

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(NI) ALLOW Read BUILTIN\Users
(IO) ALLOW Read BUILTIN\Users
(NI) ALLOW Read BUILTIN\Power Users
(IO) ALLOW Read BUILTIN\Power Users
(NI) ALLOW Full access BUILTIN\Administrators
(IO) ALLOW Full access BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access BUILTIN\Administrators
(IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Read BUILTIN\Power Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM


»»Member of…: (Admin logon required!)
User is a member of group HCU_PD\Domain Users.
User is a member of group \Everyone.
User is a member of group BUILTIN\Administrators.
User is a member of group BUILTIN\Users.
User is a member of group NT AUTHORITY\INTERACTIVE.
User is a member of group NT AUTHORITY\Authenticated Users.
User is a member of group \LOCAL.

»» Service search:(different variant) '"Network Security Service","__NS_Service_3"…

[SC] GetServiceKeyName FAILED 1060:

The specified service does not exist as an installed service.

[SC] GetServiceDisplayName FAILED 1060:

The specified service does not exist as an installed service.


»»Notepad check….

C:\WINNT\
notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K

1 item found: 1 file, 0 directories.
Total of file sizes: 50,960 bytes 49.77 K

C:\WINNT\SYSTEM32\
notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K

1 item found: 1 file, 0 directories.
Total of file sizes: 50,960 bytes 49.77 K

C:\WINNT\SYSTEM32\DLLCACHE\
notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K

1 item found: 1 file, 0 directories.
Total of file sizes: 50,960 bytes 49.77 K
–a– W32i APP ENU 5.0.2140.1 shp 50,960 05-08-2001 notepad.exe
Language 0x0409 (English (United States))
CharSet 0x04b0 Unicode
OleSelfRegister Disabled
CompanyName Microsoft Corporation
FileDescription Notepad
InternalName Notepad
OriginalFilenam NOTEPAD.EXE
ProductName Microsoft® Windows ® 2000 Operating System
ProductVersion 5.00.2140.1
FileVersion 5.00.2140.1
LegalCopyright Copyright © Microsoft Corp. 1981-1999

VS_FIXEDFILEINFO:
Signature: feef04bd
Struc Ver: 00010000
FileVer: 00050000:085c0001 (5.0:2140.1)
ProdVer: 00050000:085c0001 (5.0:2140.1)
FlagMask: 0000003f
Flags: 00000000
OS: 00040004 NT Win32
FileType: 00000001 App
SubType: 00000000
FileDate: 00000000:00000000

»»Dir 'junkxxx' was created with the following permissions…
(FAT32=NA)
Directory "C:\junkxxx"
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone

Owner: BUILTIN\Administrators

Primary Group: HCU_PD\Domain Users



»»»»»»Backups created…»»»»»»
2:49pm up 0 days, 1:43
Mon 07/05/2004

A C:\FINDnFIX\winBack.hiv
–a– - - - - - 8,192 07-05-2004 winback.hiv
A C:\FINDnFIX\keys1\winkey.reg
–a– - - - - - 287 07-05-2004 winkey.reg

»»Performing string scan….
00001150: ?
00001190: H x
000011D0: vk e DeviceNotSelectedTimeout 1 5
00001210: vk ' , GDIProcessHandleQuota " vk
00001250: h m Spooler y e s O F vk
00001290:swapdisk vk o TransmissionRetryTimeout 9 0
000012D0: vk ' c USERProcessHandleQuotaK vk
00001310:: 0 ogAppInit_DLLsCLSI C : \ W I N N T \ s y s t e
00001350:m 3 2 \ m s f d o n . d l l
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:

———- WIN.TXT
ogAppInit_DLLsCLSIÀÿÿÿC
————–
yes
C:\WINNT\system32\msfdon.dll
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"=""


**File C:\FINDnFIX\WIN.TXT
        àÿÿÿÐ  H x ˜ Ø  Ðÿÿÿvk     e DeviceNotSelectedTimeoutèÿÿÿ1 5  ˆ Ø  Ðÿÿÿvk  €'   , GDIProcessHandleQuota " àÿÿÿvk  h   m Spooler ðÿÿÿy e s O F àÿÿÿvk  €   swapdiskÐÿÿÿvk  È   o TransmissionRetryTimeoutðÿÿÿ9 0  ˆ Ðÿÿÿvk  €'   c USERProcessHandleQuotaK Øÿÿÿvk : 0   ogAppInit_DLLsCLSIÀÿÿÿC : \ W I N N T \ s y s t e m 3 2 \ m s f d o n . d l l ¸  ÿÿÿÿ

Open the FINDnFIX folder and then open the keys1 folder. Right-click on the MOVEit.bat file and select 'edit'. That will open the file as an empty text file - copy and paste this line into the blank file:

move %WinDir%\System32\MSFDON.DLL %SystemDrive%\junkxxx\MSFDON.DLL

Save the file and close. The next step will cause a restart. Still in the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot.

On restart, open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log1.txt - post it's contents in your next reply.



Occasionally when trying to edit the MOVEit.bat file the following error occurs: "Windows cannot find "C:FINDnFIX\keys1\MOVEit.bat. Make sure you typed the name correctly then try again."

If that happens, skip that step and proceed this way instead. In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the MSFDON.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder…

Select C:\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log1.txt - post it's contents in your next reply.
Daemon, I ran the FindNFix steps as you instructed and you'll see the log attached. I'm not sure how to read this log, but my guess is it didn't take care of it. I hope I'm wrong. I also copied the line you gave me to paste in italics and you'll see a second log attached to this as well. Let me know what you think. Thanks, hecrodfnp »»»»»»»»»»»»»»»»»»*** freeatlast100.100free.com ***»»»»»»»»»»»»»»»» Thu 07/08/2004 8:40am up 0 days, 0:03 Microsoft Windows 2000 [Version 5.00.2195] »»»IE build and last SP(s) 6.0.2800.1106 SP1-Q822925-Q330994-Q832894-Q831167 The type of the file system is NTFS. C: is not dirty. »»»»»»»»»»»»»»»»»»***LOG1!***»»»»»»»»»»»»»»»» Scanning for file(s) in System32… »»»»»»» (1) »»»»»»» \\?\C:\WINNT\System32\MSFDON.DLL +++ File read error C:\WINNT\System32\MSFDON.DLL +++ File read error »»»»»»» (2) »»»»»»» **File C:\FINDnFIX\LIST.TXT MSFDON.DLL Can't Open! »»»»»»» (3) »»»»»»» C:\WINNT\SYSTEM32\ msfdon.dll Sun Jul 4 2004 8:52:06p A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. »»»»»»» (4) »»»»»»» Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINNT\SYSTEM32\MSFDON.DLL »»»»»(5)»»»»» **File C:\WINNT\SYSTEM32\DLLXXX.TXT ¯ Access denied ® ………………… MSFDON.DLL …..57344 04.07.2004 »»»*»»» Scanning for moved file… »»»*»»» No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. fgrep: no files found for C:\JUNKXXX\*.* rem replace this entire line with your given command… File not found - C:\junkxxx\*.* »»Permissions: There are no more files. Directory "C:\junkxxx\." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone Allow 00000003 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators Owner: BUILTIN\Administrators Primary Group: HCU_PD\Domain Users Directory "C:\junkxxx\.." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone Owner: BUILTIN\Administrators Primary Group: BUILTIN\Administrators »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Dumping Values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ C:\\WINNT\\system32\\msfdon.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = C:\WINNT\system32\msfdon.dll »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Read BUILTIN\Power Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM »»Notepad check…. C:\WINNT\ notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\ notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\DLLCACHE\ notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K –a– W32i APP ENU 5.0.2140.1 shp 50,960 05-08-2001 notepad.exe Language 0x0409 (English (United States)) CharSet 0x04b0 Unicode OleSelfRegister Disabled CompanyName Microsoft Corporation FileDescription Notepad InternalName Notepad OriginalFilenam NOTEPAD.EXE ProductName Microsoft® Windows ® 2000 Operating System ProductVersion 5.00.2140.1 FileVersion 5.00.2140.1 LegalCopyright Copyright © Microsoft Corp. 1981-1999 VS_FIXEDFILEINFO: Signature: feef04bd Struc Ver: 00010000 FileVer: 00050000:085c0001 (5.0:2140.1) ProdVer: 00050000:085c0001 (5.0:2140.1) FlagMask: 0000003f Flags: 00000000 OS: 00040004 NT Win32 FileType: 00000001 App SubType: 00000000 FileDate: 00000000:00000000 00001150: ? 00001190: H x 000011D0: vk e DeviceNotSelectedTimeout 1 5 00001210: vk ' , GDIProcessHandleQuota " vk 00001250: h m Spooler y e s O F vk 00001290:swapdisk vk o TransmissionRetryTimeout 9 0 000012D0: vk ' c USERProcessHandleQuotaK vk 00001310:: 0 a AppInit_DLLss C : \ W I N N T \ s y s t e 00001350:m 3 2 \ m s f d o n . d l l 00001390: 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: ———- WIN.TXT ogAppInit_DLLsCLSIÀÿÿÿC ———- NEWWIN.TXT AppInit_DLLss ————– yes C:\WINNT\system32\msfdon.dll **File C:\FINDnFIX\NEWWIN.TXT         **File C:\FINDnFIX\NEWWIN.TXT 00001320: 01 00 00 00 01 00 61 00 . 5F 44 4C 4C 73 73 00 00 ……a. _DLLss.. **File C:\FINDnFIX\NEWWIN.TXT         àÿÿÿÐ  H x ˜ Ø  Ðÿÿÿvk     e DeviceNotSelectedTimeoutèÿÿÿ1 5  ˆ Ø  Ðÿÿÿvk  €'   , GDIProcessHandleQuota " àÿÿÿvk  h   m Spooler ðÿÿÿy e s O F àÿÿÿvk  €   swapdiskÐÿÿÿvk  È   o TransmissionRetryTimeoutðÿÿÿ9 0  ˆ Ðÿÿÿvk  €'   c USERProcessHandleQuotaK Øÿÿÿvk : 0   a AppInit_DLLss ÀÿÿÿC : \ W I N N T \ s y s t e m 3 2 \ m s f d o n . d l l ¸  ÿÿÿÿ ————————————————————————————— » Log with line in italics: »»»»»»»»»»»»»»»»»*** freeatlast100.100free.com ***»»»»»»»»»»»»»»»» Thu 07/08/2004 9:02am up 0 days, 0:07 Microsoft Windows 2000 [Version 5.00.2195] »»»IE build and last SP(s) 6.0.2800.1106 SP1-Q822925-Q330994-Q832894-Q831167 The type of the file system is NTFS. C: is not dirty. »»»»»»»»»»»»»»»»»»***LOG1!***»»»»»»»»»»»»»»»» Scanning for file(s) in System32… »»»»»»» (1) »»»»»»» \\?\C:\WINNT\System32\MSFDON.DLL +++ File read error C:\WINNT\System32\MSFDON.DLL +++ File read error »»»»»»» (2) »»»»»»» **File C:\FINDnFIX\LIST.TXT MSFDON.DLL Can't Open! »»»»»»» (3) »»»»»»» C:\WINNT\SYSTEM32\ msfdon.dll Sun Jul 4 2004 8:52:06p A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. »»»»»»» (4) »»»»»»» Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINNT\SYSTEM32\MSFDON.DLL »»»»»(5)»»»»» **File C:\WINNT\SYSTEM32\DLLXXX.TXT ¯ Access denied ® ………………… MSFDON.DLL …..57344 04.07.2004 »»»*»»» Scanning for moved file… »»»*»»» No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. fgrep: no files found for C:\JUNKXXX\*.* rem replace this entire line with your given command… File not found - C:\junkxxx\*.* »»Permissions: There are no more files. Directory "C:\junkxxx\." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone Allow 00000003 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators Owner: BUILTIN\Administrators Primary Group: HCU_PD\Domain Users Directory "C:\junkxxx\.." Permissions: Type Flags Inh. Mask Gen. Std. File Group or User ======= ======== ==== ======== ==== ==== ==== ================ Allow 00000003 tco- 001F01FF —- DSPO rw+x \Everyone Owner: BUILTIN\Administrators Primary Group: BUILTIN\Administrators »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Dumping Values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ C:\\WINNT\\system32\\msfdon.dll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 AppInit_DLLs = C:\WINNT\system32\msfdon.dll »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (NI) ALLOW Read BUILTIN\Users (IO) ALLOW Read BUILTIN\Users (NI) ALLOW Read BUILTIN\Power Users (IO) ALLOW Read BUILTIN\Power Users (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access BUILTIN\Administrators (NI) ALLOW Full access NT AUTHORITY\SYSTEM (IO) ALLOW Full access NT AUTHORITY\SYSTEM (NI) ALLOW Full access BUILTIN\Administrators (IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Read BUILTIN\Power Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM »»Notepad check…. C:\WINNT\ notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\ notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K C:\WINNT\SYSTEM32\DLLCACHE\ notepad.exe Tue May 8 2001 8:00:00a A…. 50,960 49.77 K 1 item found: 1 file, 0 directories. Total of file sizes: 50,960 bytes 49.77 K –a– W32i APP ENU 5.0.2140.1 shp 50,960 05-08-2001 notepad.exe Language 0x0409 (English (United States)) CharSet 0x04b0 Unicode OleSelfRegister Disabled CompanyName Microsoft Corporation FileDescription Notepad InternalName Notepad OriginalFilenam NOTEPAD.EXE ProductName Microsoft® Windows ® 2000 Operating System ProductVersion 5.00.2140.1 FileVersion 5.00.2140.1 LegalCopyright Copyright © Microsoft Corp. 1981-1999 VS_FIXEDFILEINFO: Signature: feef04bd Struc Ver: 00010000 FileVer: 00050000:085c0001 (5.0:2140.1) ProdVer: 00050000:085c0001 (5.0:2140.1) FlagMask: 0000003f Flags: 00000000 OS: 00040004 NT Win32 FileType: 00000001 App SubType: 00000000 FileDate: 00000000:00000000 00001150: ? 00001190: W| X 000011D0: vk e DeviceNotSelectedTimeout 1 5 00001210: vk ' , GDIProcessHandleQuota " 00001250:edd O vk x m Spooler y e s O F vk 00001290: swapdisk vk o TransmissionRetr 000012D0:yTimeout 9 0 vk ' c USERProcessHandl 00001310:eQuotaK vk : @ ogAppInit_DLLsCLSI C : \ W I N 00001350:N T \ s y s t e m 3 2 \ m s f d o n . d l l o@ w& w 00001390: k w < w ; w p wq8 w 8 w j w 6 w < w w x w w ) weS w m w(T w 000013D0: , w { wh w _ w9K w P w a we9 w | w w p w w wwo wFq w5g w 00001410: w ~ w w&H w & wm who w w 4 w:7 w 0 w;. w | wb3 wJ' w` w 00001450: w ^ w w w w, w^. w S wAM wfy w 6 w w, wq; wud w0 w 00001490: w 7 w R w K w I wAo w V w U SV u W " j 000014D0: u V u ; _^[ U V3 9u W $ 9u u 9u $ u 00001510: u u u u u u _^] T$ . 8 T$ . 00001550:T ———- WIN.TXT ogAppInit_DLLsCLSIÀÿÿÿC ———- NEWWIN.TXT ogAppInit_DLLsCLSIÀÿÿÿC ————– yes C:\WINNT\system32\msfdon.dll **File C:\FINDnFIX\NEWWIN.TXT **File C:\FINDnFIX\NEWWIN.TXT 00001330: 01 00 00 00 01 00 6F 67 . 5F 44 4C 4C 73 43 4C 53 ……og _DLLsCLS **File C:\FINDnFIX\NEWWIN.TXT         ÿ­W|àÿÿÿØ  X ˆ ¨ è  Ðÿÿÿvk     e DeviceNotSelectedTimeoutèÿÿÿ1 5  ˆ Ø  Èÿÿÿvk  €'   , GDIProcessHandleQuota " edd ð˜O àÿÿÿvk  x   m Spooler ðÿÿÿy e s O F àÿÿÿvk  €   swapdiskÐÿÿÿvk  Ø   o TransmissionRetryTimeoutðÿÿÿ9 0  ˆ Ðÿÿÿvk  €'   c USERProcessHandleQuotaK Øÿÿÿvk : @   ogAppInit_DLLsCLSIÀÿÿÿC : \ W I N N T \ s y s t e m 3 2 \ m s f d o n . d l l ¸ € ÿÿÿÿo@ôw& öwþkôwÎ<ôw;ôwÓpôwq8ôwò8ôwàjôw 6ôw <ôwÕôwÍxõw¨‚ôw¸)ôweSôwömôw(Tôwæ,ôw{ôwh„ôwö_ôw9KôwÈPôw
Daemon, When you say to try the approach in italics you're meaning for me to copy and paste the line and change the text to italic format, correct? If that's the case, I've tried it that way already. I've noticed that the other forum members you've helped have had similar problems, but their bad file was in Windows and not WINNT. Plus in reviewing their FindNFix It logs, theirs did not show a #5 (Access Denied). I don't know if that means anything. Let me know about the italic approach and if I did it right, what you think my next step should be. I appreciate it and thanks for working so fast on helping all of us out. hecrodfnp
I meant do this:

Occasionally when trying to edit the MOVEit.bat file the following error occurs: "Windows cannot find "C:FINDnFIX\keys1\MOVEit.bat. Make sure you typed the name correctly then try again."

If that happens, skip that step and proceed this way instead. In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the MSFDON.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder…

Select C:\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log1.txt - post it's contents in your next reply.


Daemon,

I followed the advice in performing it in italics and performed the final steps to FixNFind, including ZipZap and dragging the junkxxx file to e-mail, but it appears our server was down at the time and it didn't e-mail it.

I've attached the last HJT log for your review…it looks clean, but you let me know.

Now that I've got your expertise…I wrote to the Spybot Forum regarding some glitches with the updated Spybot 1.3. I downloaded and integrated it over 1.2, but when it tries to fix the found problems it doesn't complete the fix and continually pops up error windows indicating I'm missing components. Their advice was to completely uninstall Spybot 1.2 and 1.3 from my system and re-download the 1.3 version. Do you think this MUST be done or is there another easy fix that you know of?

Hey, Daemon, I really appreciate your help and smooth expertise. You have very effectively taken care of my issues. KUDOS!

hecrodfnp

—————————————————————————
Logfile of HijackThis v1.98.0
Scan saved at 4:16:18 PM, on 7/8/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\hijackthis\HijackThis.exe
C:\WINNT\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://business.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\hijackthis\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
Daemon may be away for a few days, but I would say that if the folks in the Spybot forum have recommended complete uninstall and re-install then that is the way to go!! Your log looks ok to! :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI