This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help With Log

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

web pages and anything with a scroll bar on the side (even Wiord) still have a mind of their own, but that must be another issue. The last AdAware and Spybot search I ran came up clean. If you have any ideas on the dancing pages, I'd appreciate, but other than that thank you so much for your help.
Thanks for the help. Here is what the scan found. File C:\WINDOWS\iconw.exe infected by "not-a-virus:AdWare.Zestyfind" Virus. Action Taken: No Action Taken. File C:\WINDOWS\knzrl.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\ltiat.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sideb.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\swmfl.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\akcore.dll infected by "not-a-virus:AdWare.Coreak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\akrules.dll infected by "TrojanDownloader.Win32.Agent.bt" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\calsp.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\guard.tmp infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\Temp\temp.frA4C2\PIB.exe infected by "not-a-virus:AdWare.WebSearch.h" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\Content.IE5\5GWCKDXZ\AppWrap[1].exe infected by "Trojan-Dropper.Win32.Small.of" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\Content.IE5\5GWCKDXZ\Installer[1].exe infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\Content.IE5\QA5ZZ0VG\AppWrap[2].exe infected by "Trojan-Dropper.Win32.Small.of" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\Content.IE5\QA5ZZ0VG\inst201[1].exe infected by "TrojanDownloader.Win32.Small.wj" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\Content.IE5\QI6KI4GV\AppWrap[1].exe infected by "not-a-virus:AdWare.Zestyfind" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\Content.IE5\VZO7T4MQ\AppWrap[3].exe infected by "Trojan-Dropper.Win32.Small.of" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users\Application Data\AOL Downloads\updateni_setup90\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL Downloads\lpitunes_setupSTUS\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\GC\Local Settings\Temp\NoAdwareBackup\WinTools\WSup.exe infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\GC\Local Settings\Temp\NoAdwareBackup\WinTools\WToolsA.exe infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\GC\Local Settings\Temp\NoAdwareBackup\WSup.exe infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\GC\Local Settings\Temp\NoAdwareBackup\WToolsA.exe infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\GC\Local Settings\Temp\temp.frC599\WSup.exe infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\GC\Local Settings\Temp\temp.frC599\WToolsA.exe infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temp\temp.frA4C2\PIB.exe infected by "not-a-virus:AdWare.WebSearch.h" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\5GWCKDXZ\AppWrap[1].exe infected by "Trojan-Dropper.Win32.Small.of" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\5GWCKDXZ\Installer[1].exe infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QA5ZZ0VG\AppWrap[2].exe infected by "Trojan-Dropper.Win32.Small.of" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QA5ZZ0VG\inst201[1].exe infected by "TrojanDownloader.Win32.Small.wj" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QI6KI4GV\AppWrap[1].exe infected by "not-a-virus:AdWare.Zestyfind" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VZO7T4MQ\AppWrap[3].exe infected by "Trojan-Dropper.Win32.Small.of" Virus. Action Taken: No Action Taken. File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\America Online 9.0a\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\America Online 9.0b\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\America Online 9.0c\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\America Online 9.0d\backup\restore\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\America Online 9.0d\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Common Files\aolback\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Internet Explorer\twnloa.exe infected by "Trojan-Downloader.Win32.Harnig.am" Virus. Action Taken: No Action Taken. File C:\Program Files\Internet Explorer\ymwitwbb.exe infected by "Trojan-Downloader.Win32.Harnig.am" Virus. Action Taken: No Action Taken. File C:\Program Files\Windows Media Player\wmplayer.exe.tmp infected by "TrojanDownloader.Win32.Small.wj" Virus. Action Taken: No Action Taken. File C:\sidebDD.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\open.exe infected by "TrojanDownloader.Win32.WinShow.am" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\sl.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\WINDOWS\iconw.exe infected by "not-a-virus:AdWare.Zestyfind" Virus. Action Taken: No Action Taken. File C:\WINDOWS\knzrl.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\ltiat.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\occache\WEBInstaller.dll infected by "not-a-virus:AdWare.Sahat.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sideb.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\swmfl.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\akcore.dll infected by "not-a-virus:AdWare.Coreak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\akrules.dll infected by "TrojanDownloader.Win32.Agent.bt" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\calsp.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\guard.tmp infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\2.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\39.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\4.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\56.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\69.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\6A.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\7.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\A.tmp infected by "Trojan.Win32.HideProc.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\akcore.dll infected by "not-a-virus:AdWare.Coreak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\akrules.dll infected by "TrojanDownloader.Win32.Agent.bt" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\f12123421.exe infected by "not-a-virus:AdWare.Sahat.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\nsdtmp09.dll infected by "not-a-virus:AdWare.MetaDirect.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\0Q9Z1Q91\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\Y1FCEP18\sideb[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken.
I also clicked on the view log button and it looks like it gave me a log of the entire scan. Since it is so long, I didn't post it, but if that is what I need to post just let me know.
New hijack this log

Logfile of HijackThis v1.99.0
Scan saved at 10:23:54 PM, on 1/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\COMMON~1\AOL\110196~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110196~1\EE\AOLServiceHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\mwavscan.com
C:\DOCUME~1\Owner\LOCALS~1\Temp\kavss.exe
C:\Hijack This\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: (HKLM)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1101282315953
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://firepass.mossadams.com/vdesk/termin…ion=2004,7,12,1
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://firepass.mossadams.com/vdesk/terminal/urxshost.cab
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://firepass.mossadams.com/vdesk/termin…ion=2004,7,12,1
O23 - Service: AOL Connectivity Service - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service - Unknown - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Find_It log Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. Find.bat is running from: C:\Documents and Settings\[removed]\Desktop\Find It NT-2K-XP\Find It NT-2K-XP ——- System Files in System32 Directory ——- Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 12/30/2004 04:57 PM DLLCACHE 12/04/2003 12:26 PM Microsoft 0 File(s) 0 bytes 2 Dir(s) 29,800,525,824 bytes free ——- Hidden Files in System32 Directory ——- Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 12/30/2004 04:57 PM DLLCACHE 11/15/2004 03:41 PM 488 logonui.exe.manifest 11/15/2004 03:41 PM 488 WindowsLogon.manifest 11/15/2004 03:41 PM 749 nwc.cpl.manifest 11/15/2004 03:41 PM 749 sapi.cpl.manifest 11/15/2004 03:41 PM 749 ncpa.cpl.manifest 11/15/2004 03:41 PM 749 wuaucpl.cpl.manifest 11/15/2004 03:41 PM 749 cdplayer.exe.manifest 7 File(s) 4,721 bytes 1 Dir(s) 29,800,525,824 bytes free ———- Files Named "Guard" ————- Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 01/01/2005 06:07 PM 223,203 guard.tmp 1 File(s) 223,203 bytes 0 Dir(s) 29,800,525,824 bytes free ——— Temp Files in System32 Directory ——– Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 01/01/2005 06:07 PM 223,203 guard.tmp 07/16/2003 12:25 PM 2,577 CONFIG.TMP 06/19/2002 05:39 PM 384 ~GLH001a.TMP 06/19/2002 03:39 PM 25,088 ~GLH001b.TMP 4 File(s) 251,252 bytes 0 Dir(s) 29,800,521,728 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{0F34C91C-904E-436F-A518-A1D52A47968C}"="" ———— Keys Under Notify ———— REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] @="" "DLLName"="igfxsrvc.dll" "Asynchronous"=dword:00000001 "Impersonate"=dword:00000001 "Unlock"="WinlogonUnlockEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WindowsUpdate] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\gp4ol3h31.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 —————— Locate.com Results —————— C:\WINDOWS\SYSTEM32\ cdplay~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K logonu~1.man Mon Nov 15 2004 3:41:42p A..HR 488 0.48 K ncpacp~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K nwccpl~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K sapicp~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K window~1.man Mon Nov 15 2004 3:41:42p A..HR 488 0.48 K wuaucp~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K 7 items found: 7 files, 0 directories. Total of file sizes: 4,721 bytes 4.61 K ———— Strings.exe Qoologic Results ———— ————– Strings.exe Aspack Results ————- C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack —————– HKLM Run Key —————— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mmtask"="c:\\Program Files\\MusicMatch\\MusicMatch Jukebox\\mmtask.exe" "Logitech Utility"="Logi_MwX.Exe" "IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe" "AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\"" "AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe" "DIGStream"="C:\\Program Files\\DIGStream\\digstream.exe" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask" "VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\"" "MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe" "MCUpdateExe"="C:\\PROGRA~1\\McAfee.com\\Agent\\mcupdate.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" 
First, Disconnect from the Internet!!

(Please copy these instructions to NotePad for copy/paste use, since you will be off the Internet.)

Next, launch Notepad, and copy/paste all the blue REGEDIT below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{0F34C91C-904E-436F-A518-A1D52A47968C}"=""

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WindowsUpdate]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""

  • Download the Pocket Killbox.
  • Unzip the contents of KillBox.zip to a convenient location.
  • Double-click on KillBox.exe.
  • Click "Replace on Reboot" and check the "Use Dummy" box.
  • Paste this file into the top "Full Path of File to Delete" box.
    • C:\\WINDOWS\\system32\\gp4ol3h31.dll
  • Click the "Delete File" button which looks like a stop sign.
  • Click "Yes" at the Replace on Reboot prompt.
  • Click "No" at the Pending Operations prompt.
  • Click "Replace on Reboot" and check the "Use Dummy" box.
  • Paste this file into the top "Full Path of File to Delete" box.
    • C:\WINDOWS\System32\Guard.tmp
  • Click the "Delete File" button which looks like a stop sign.
  • Click "Yes" at the Replace on Reboot prompt.
  • Click "Yes" at the Pending Operations prompt to restart your computer.
  • Double-click on find.bat and post the new output.txt.
Not a problem at all. That isn't a bad idea. Here is the new Find_It log. Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. Find.bat is running from: C:\Documents and Settings\[removed]\Desktop\Find It NT-2K-XP\Find It NT-2K-XP ——- System Files in System32 Directory ——- Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 12/30/2004 04:57 PM DLLCACHE 12/04/2003 12:26 PM Microsoft 0 File(s) 0 bytes 2 Dir(s) 29,804,638,208 bytes free ——- Hidden Files in System32 Directory ——- Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 12/30/2004 04:57 PM DLLCACHE 11/15/2004 03:41 PM 488 logonui.exe.manifest 11/15/2004 03:41 PM 488 WindowsLogon.manifest 11/15/2004 03:41 PM 749 nwc.cpl.manifest 11/15/2004 03:41 PM 749 sapi.cpl.manifest 11/15/2004 03:41 PM 749 ncpa.cpl.manifest 11/15/2004 03:41 PM 749 wuaucpl.cpl.manifest 11/15/2004 03:41 PM 749 cdplayer.exe.manifest 7 File(s) 4,721 bytes 1 Dir(s) 29,804,638,208 bytes free ———- Files Named "Guard" ————- Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 01/02/2005 10:52 PM 56 Guard.tmp 1 File(s) 56 bytes 0 Dir(s) 29,804,638,208 bytes free ——— Temp Files in System32 Directory ——– Volume in drive C has no label. Volume Serial Number is 5C27-CD3B Directory of C:\WINDOWS\System32 01/02/2005 10:52 PM 56 Guard.tmp 07/16/2003 12:25 PM 2,577 CONFIG.TMP 06/19/2002 05:39 PM 384 ~GLH001a.TMP 06/19/2002 03:39 PM 25,088 ~GLH001b.TMP 4 File(s) 28,105 bytes 0 Dir(s) 29,804,634,112 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{0F34C91C-904E-436F-A518-A1D52A47968C}"="" ———— Keys Under Notify ———— REGEDIT4 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] @="" "DLLName"="igfxsrvc.dll" "Asynchronous"=dword:00000001 "Impersonate"=dword:00000001 "Unlock"="WinlogonUnlockEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp] "DLLName"="wlnotify.dll" "Logon"="SCardStartCertProp" "Logoff"="SCardStopCertProp" "Lock"="SCardSuspendCertProp" "Unlock"="SCardResumeCertProp" "Enabled"=dword:00000001 "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "StartShell"="SchedStartShell" "Logoff"="SchedEventLogOff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy] "Logoff"="WLEventLogoff" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn] "DLLName"="WlNotify.dll" "Lock"="SensLockEvent" "Logon"="SensLogonEvent" "Logoff"="SensLogoffEvent" "Safe"=dword:00000001 "MaxWait"=dword:00000258 "StartScreenSaver"="SensStartScreenSaverEvent" "StopScreenSaver"="SensStopScreenSaverEvent" "Startup"="SensStartupEvent" "Shutdown"="SensShutdownEvent" "StartShell"="SensStartShellEvent" "PostShell"="SensPostShellEvent" "Disconnect"="SensDisconnectEvent" "Reconnect"="SensReconnectEvent" "Unlock"="SensUnlockEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv] "Asynchronous"=dword:00000000 "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00 "Impersonate"=dword:00000000 "Logoff"="TSEventLogoff" "Logon"="TSEventLogon" "PostShell"="TSEventPostShell" "Shutdown"="TSEventShutdown" "StartShell"="TSEventStartShell" "Startup"="TSEventStartup" "MaxWait"=dword:00000258 "Reconnect"="TSEventReconnect" "Disconnect"="TSEventDisconnect" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WindowsUpdate] "Asynchronous"=dword:00000000 "DllName"="C:\\WINDOWS\\system32\\gp4ol3h31.dll" "Impersonate"=dword:00000000 "Logon"="WinLogon" "Logoff"="WinLogoff" "Shutdown"="WinShutdown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon] "DLLName"="wlnotify.dll" "Logon"="RegisterTicketExpiredNotificationEvent" "Logoff"="UnregisterTicketExpiredNotificationEvent" "Impersonate"=dword:00000001 "Asynchronous"=dword:00000001 —————— Locate.com Results —————— C:\WINDOWS\SYSTEM32\ cdplay~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K logonu~1.man Mon Nov 15 2004 3:41:42p A..HR 488 0.48 K ncpacp~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K nwccpl~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K sapicp~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K window~1.man Mon Nov 15 2004 3:41:42p A..HR 488 0.48 K wuaucp~1.man Mon Nov 15 2004 3:41:32p A..HR 749 0.73 K 7 items found: 7 files, 0 directories. Total of file sizes: 4,721 bytes 4.61 K ———— Strings.exe Qoologic Results ———— ————– Strings.exe Aspack Results ————- C:\WINDOWS\SYSTEM32\ntdll.dll: .aspack —————– HKLM Run Key —————— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mmtask"="c:\\Program Files\\MusicMatch\\MusicMatch Jukebox\\mmtask.exe" "Logitech Utility"="Logi_MwX.Exe" "IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe" "AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\"" "AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe" "DIGStream"="C:\\Program Files\\DIGStream\\digstream.exe" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask" "VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\"" "MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe" "MCUpdateExe"="C:\\PROGRA~1\\McAfee.com\\Agent\\mcupdate.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" 
I have to head of to work, but I'll check this evening to see if you've had a chance to look at the new log. If not, I'll check again tomorrow morning. Thanks for all your help.
Use killbox to delete these files. Then do antoerh scan at microworld and post. C:\WINDOWS\iconw.exe C:\WINDOWS\knzrl.dll C:\WINDOWS\ltiat.dll C:\WINDOWS\sideb.exe C:\WINDOWS\swmfl.dll C:\WINDOWS\system32\akcore.dll C:\WINDOWS\system32\aklsp.dll infected C:\WINDOWS\system32\akrules.dll C:\WINDOWS\system32\calsp.dll C:\WINDOWS\system32\guard.tmp C:\WINDOWS\system32\netut80ex.vxd C:\sidebDD.exe C:\WINDOWS\Downloaded Program Files\open.exe C:\WINDOWS\Downloaded Program Files\sl.ocx C:\WINDOWS\iconw.exe C:\WINDOWS\knzrl.dll C:\WINDOWS\ltiat.dll C:\WINDOWS\occache\WEBInstaller.dll C:\WINDOWS\sideb.exe C:\WINDOWS\swmfl.dll C:\WINDOWS\SYSTEM32\akcore.dll C:\WINDOWS\SYSTEM32\aklsp.dll C:\WINDOWS\SYSTEM32\akrules.dll C:\WINDOWS\SYSTEM32\calsp.dll C:\WINDOWS\SYSTEM32\guard.tmp

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI