This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

About;blank

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After loggging onto the net and selecting a link I get redirected to other sites.
For instance;
66.230.146.2/sms.universe.
privacy defender.com.
threatlevel.com.
When deleting these site I get back to About :blank.Logfile of HijackThis v1.99.0
Scan saved at 09:23:03, on 02/08/2005
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.00 (5.00.2919.6304)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\SURFSIDEKICK 2\SSK.EXE
C:\N20050308.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SURFSIDEKICK 2\SSK.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\SAFE & SOUND\WGLITE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\SAFE & SOUND\BOMB32.EXE
C:\WINDOWS\SYSTEM\MACROMED\SHOCKWAVE\REMOTE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by KZuk.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve.:8080
R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\PROGRAM FILES\SURFSIDEKICK 2\SSKBHO.DLL
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: IEMenuExtension toolbar - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - C:\PROGRAM FILES\IEMENUEXTENSION\TBEXTN.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [AttuneSysTray] C:\PROGRA~1\AVEO\ATTUNE\Bin\Attune_st.exe /boot
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - HKLM\..\Run: [IE Menu Extension toolbar] rundll32.exe "C:\PROGRA~1\IEMENU~1\tbextn.dll" DllShowTB
O4 - HKLM\..\Run: [ntechin] C:\N20050308.EXE
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\RunServices: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
O4 - Startup: Mount Retake Volumes.lnk = C:\Program Files\Network Associates\Safe & Sound\fbmount.exe
O4 - Startup: Image & Restore.lnk = C:\Program Files\Network Associates\Safe & Sound\Image32.exe
O4 - Startup: WinGauge Lite.lnk = C:\Program Files\Network Associates\Safe & Sound\wglite.exe
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .eid: C:\PROGRA~1\INTERN~1\PLUGINS\NPIPRT32.DLL
O12 - Plugin for .php: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .tif: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted IP range: 67.19.185.246
O15 - Trusted IP range: 67.19.185.246 (HKLM)
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://67.19.185.246/i/1/loader2.ocx
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/DnJVQ1XZTdB6sysgyy-g.chm::/on-line.exe
O18 - Filter: text/html - {7FE76521-72F7-11D9-9CAD-4445A6FB421C} - C:\WINDOWS\SYSTEM\DLFG.DLL
O18 - Filter: text/plain - {7FE76521-72F7-11D9-9CAD-4445A6FB421C} - C:\WINDOWS\SYSTEM\DLFG.DLL

Scrubber
Move Hijackthis out of your unzipped folder (extract from zip)into a permanent folder. Example:
c:\program files\hijackthis\hijackthis.exe

This will allow backups to be made and saved By hijackthis in case something goes wrong.

Place a check next to the following entries, then close all open windows except hijackthis and click fix.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\PROGRAM FILES\SURFSIDEKICK 2\SSKBHO.DLL
O4 - HKLM\..\Run: [AttuneSysTray] C:\PROGRA~1\AVEO\ATTUNE\Bin\Attune_st.exe /boot
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - HKLM\..\Run: [IE Menu Extension toolbar] rundll32.exe "C:\PROGRA~1\IEMENU~1\tbextn.dll" DllShowTB
O4 - HKLM\..\Run: [ntechin] C:\N20050308.EXE
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKCU\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\RunServices: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted IP range: 67.19.185.246
O15 - Trusted IP range: 67.19.185.246 (HKLM)
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://67.19.185.246/i/1/loader2.ocx
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/DnJVQ1XZTdB6sysgyy-g.chm::/on-line.exe
O18 - Filter: text/html - {7FE76521-72F7-11D9-9CAD-4445A6FB421C} - C:\WINDOWS\SYSTEM\DLFG.DLL
O18 - Filter: text/plain - {7FE76521-72F7-11D9-9CAD-4445A6FB421C} - C:\WINDOWS\SYSTEM\DLFG.DLL

Then reboot into safe mode and delete these files.
C:\WINDOWS\SYSTEM\twink64.exe
C:\PROGRA~1\IEMENU~1\tbextn.dll
C:\N20050308.EXE

And these folders.
C:\PROGRAM FILES\SURFSIDEKICK 2
C:\PROGRA~1\AVEO\ATTUNE
C:\PROGRA~1\VBOUNCER

You may have to enable hidden files to find all the files.

Then reboot into normal mode.

Download FindIt 9x/ME
http://www.thatcomputerguy.us/downloads/findit9xme.zip

Unzip the contents to a folder, then open the folder and double-click on Find.bat. It will run for a minute, then produce a log. Copy and paste the log here.
Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM DNTIME DLL 222,568 30/01/05 19:56 DNTIME.DLL MLPI32 DLL 222,568 30/01/05 19:56 MLPI32.DLL PEPARSE DLL 222,568 30/01/05 19:56 PEPARSE.DLL ERDMIU01 DLL 222,568 30/01/05 19:56 ERDMIU01.DLL AOVAPI32 DLL 222,568 30/01/05 19:56 AOVAPI32.DLL RHR20 DLL 222,568 30/01/05 19:56 RHR20.DLL MPC250 DLL 222,568 30/01/05 19:56 MPC250.DLL DYDRAMP DLL 222,568 30/01/05 19:56 DYDRAMP.DLL MWVCP60 DLL 222,568 30/01/05 19:56 MWVCP60.DLL EFCVDO DLL 222,568 30/01/05 19:56 efcvdo.dll EAISRA5D DLL 222,568 30/01/05 19:56 EAISRA5D.DLL DVCFRAME DLL 222,568 30/01/05 19:56 dvcframe.dll WJHEXT DLL 222,568 30/01/05 19:56 wjhext.dll UYDMXFRM DLL 222,568 30/01/05 19:56 UYDMXFRM.DLL LMIMG80N DLL 222,568 30/01/05 19:56 lmimg80n.dll DUSTYLE DLL 222,568 30/01/05 19:56 DUSTYLE.DLL BO848DLG DLL 222,568 30/01/05 19:56 BO848DLG.DLL VNSCRIPT DLL 222,568 30/01/05 19:56 vnscript.dll OFTLACCT DLL 222,568 30/01/05 19:56 OFTLACCT.DLL MHOEMAPI DLL 222,568 30/01/05 19:56 mhoemapi.dll 20 file(s) 4,451,360 bytes 0 dir(s) 672,882,688 bytes free ——- Hidden Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM FFASTLOG TXT 23,784 12/02/05 11:47 ffastlog.txt EPIUIE5D GID 10,840 31/07/04 14:19 EPIUIE5D.GID ATI64DEF GID 12,906 12/10/02 14:20 ati64def.GID HPF82T04 GID 8,628 08/11/01 8:59 hpf82t04.GID HPF82H04 GID 8,628 04/11/01 20:38 hpf82h04.GID FOLDER HTT 12,746 07/03/01 9:50 folder.htt DESKTOP INI 266 07/03/01 9:50 desktop.ini HPF82R04 GID 8,628 30/10/00 16:36 HPF82R04.GID EPSTHL8 GID 16,826 27/10/98 10:21 epsthl8.GID 9 file(s) 103,252 bytes 0 dir(s) 672,878,592 bytes free —————- User Agent ———— —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ ffastlog.txt Sat 12 Feb 2005 11:47:24 A..H. 23,784 23.23 K dntime.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mlpi32.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K peparse.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K erdmiu01.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K aovapi32.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K rhr20.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mpc250.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K dydramp.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mwvcp60.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K efcvdo.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K eaisra5d.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K dvcframe.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K wjhext.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K uydmxfrm.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K lmimg80n.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K dustyle.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K bo848dlg.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K vnscript.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K oftlacct.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mhoemapi.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K 21 items found: 21 files, 0 directories. Total of file sizes: 4,475,144 bytes 4.27 M ———— Strings.exe Qoologic Results ———— ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- C:\WINDOWS\SYSTEM\DNTIME.DLL: UMonitor C:\WINDOWS\SYSTEM\MLPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\NATAPI.DLL: UMonitor C:\WINDOWS\SYSTEM\PEPARSE.DLL: UMonitor C:\WINDOWS\SYSTEM\ERDMIU01.DLL: UMonitor C:\WINDOWS\SYSTEM\AOVAPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\RHR20.DLL: UMonitor C:\WINDOWS\SYSTEM\MPC250.DLL: UMonitor C:\WINDOWS\SYSTEM\DYDRAMP.DLL: UMonitor C:\WINDOWS\SYSTEM\MWVCP60.DLL: UMonitor C:\WINDOWS\SYSTEM\efcvdo.dll: UMonitor C:\WINDOWS\SYSTEM\EAISRA5D.DLL: UMonitor C:\WINDOWS\SYSTEM\dvcframe.dll: UMonitor C:\WINDOWS\SYSTEM\wjhext.dll: UMonitor C:\WINDOWS\SYSTEM\UYDMXFRM.DLL: UMonitor C:\WINDOWS\SYSTEM\lmimg80n.dll: UMonitor C:\WINDOWS\SYSTEM\DUSTYLE.DLL: UMonitor C:\WINDOWS\SYSTEM\BO848DLG.DLL: UMonitor C:\WINDOWS\SYSTEM\vnscript.dll: UMonitor C:\WINDOWS\SYSTEM\OFTLACCT.DLL: UMonitor C:\WINDOWS\SYSTEM\mhoemapi.dll: UMonitor REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry"="c:\\windows\\scanregw.exe /autorun" "TaskMonitor"="c:\\windows\\taskmon.exe" "SystemTray"="SysTray.Exe" "AtiCwd32"="Aticwd32.exe" "AtiKey"="Atitask.exe" "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" "StillImageMonitor"="C:\\WINDOWS\\SYSTEM\\STIMON.EXE" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "AVG7_CC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGCC.EXE /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGEMC.EXE" "AVG7_AMSVR"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGAMSVR.EXE" "SurfSideKick 2"="C:\\PROGRAM FILES\\SURFSIDEKICK 2\\Ssk.exe"
Download the killbox from this link:
http://www.downloads.subratam.org/KillBox.exe

create a new folder and save the download to it.

Disconect from the internet while you are following these instructions. If need be print them out for easy reference or you can save them as a text file.

Open killbox.
We are going to use it to delete the files that are causing the infection. It is very important that you do NOT reboot until you have added all the files to be deleted.

You will be adding the files one at a time so you will need to follow these steps for each file. (I will have a file list for you further down this post)

In killbox add a check next to Replace on Reboot

Then copy and paste each full path into the Killbox topmost box.

With the full path to the file name in the topmost textbox, click the option Use Dummy which will create a numbered dummy file instantly for you.

Click the Red X …and for the confirmation message that will appear, you will need to click Yes
A second message will ask to Reboot now? you will need to click No (since you are not finished adding all related files in yet)

Now for the file list. Remember you need to enter the entire path and check the "use dummy" box for each file.

C:\WINDOWS\dntime.dll
C:\WINDOWS\mlpi32.dll
C:\WINDOWS\peparse.dll
C:\WINDOWS\erdmiu01.dll
C:\WINDOWS\aovapi32.dll
C:\WINDOWS\rhr20.dll
C:\WINDOWS\mpc250.dll
C:\WINDOWS\dydramp.dll
C:\WINDOWS\mwvcp60.dll
C:\WINDOWS\efcvdo.dll
C:\WINDOWS\eaisra5d.dll
C:\WINDOWS\dvcframe.dll
C:\WINDOWS\wjhext.dll Sun
C:\WINDOWS\uydmxfrm.dll
C:\WINDOWS\lmimg80n.dll
C:\WINDOWS\dustyle.dll
C:\WINDOWS\bo848dlg.dll
C:\WINDOWS\vnscript.dll
C:\WINDOWS\oftlacct.dll
C:\WINDOWS\mhoemapi.dll
C:\WINDOWS\guard.tmp

When you have added the last file, close all windows and reboot your computer.

Then run Find.bat and post the new log.

Do not reboot your computer till I tell you to. Otherwise new files will be created and we will need to start over.
Unable to find file Find.bat so used the findit9ME. Still getting rouge sites. Scrubber ——- System Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM DNTIME DLL 222,568 30/01/05 19:56 DNTIME.DLL MLPI32 DLL 222,568 30/01/05 19:56 MLPI32.DLL PEPARSE DLL 222,568 30/01/05 19:56 PEPARSE.DLL ERDMIU01 DLL 222,568 30/01/05 19:56 ERDMIU01.DLL AOVAPI32 DLL 222,568 30/01/05 19:56 AOVAPI32.DLL RHR20 DLL 222,568 30/01/05 19:56 RHR20.DLL MPC250 DLL 222,568 30/01/05 19:56 MPC250.DLL DYDRAMP DLL 222,568 30/01/05 19:56 DYDRAMP.DLL MWVCP60 DLL 222,568 30/01/05 19:56 MWVCP60.DLL EFCVDO DLL 222,568 30/01/05 19:56 efcvdo.dll NYTDI DLL 222,568 30/01/05 19:56 NYTDI.DLL DVCFRAME DLL 222,568 30/01/05 19:56 dvcframe.dll WJHEXT DLL 222,568 30/01/05 19:56 wjhext.dll UYDMXFRM DLL 222,568 30/01/05 19:56 UYDMXFRM.DLL LMIMG80N DLL 222,568 30/01/05 19:56 lmimg80n.dll DUSTYLE DLL 222,568 30/01/05 19:56 DUSTYLE.DLL BO848DLG DLL 222,568 30/01/05 19:56 BO848DLG.DLL VNSCRIPT DLL 222,568 30/01/05 19:56 vnscript.dll OFTLACCT DLL 222,568 30/01/05 19:56 OFTLACCT.DLL MHOEMAPI DLL 222,568 30/01/05 19:56 mhoemapi.dll 20 file(s) 4,451,360 bytes 0 dir(s) 725,741,568 bytes free ——- Hidden Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM FFASTLOG TXT 23,912 13/02/05 12:29 ffastlog.txt EPIUIE5D GID 10,840 31/07/04 14:19 EPIUIE5D.GID ATI64DEF GID 12,906 12/10/02 14:20 ati64def.GID HPF82T04 GID 8,628 08/11/01 8:59 hpf82t04.GID HPF82H04 GID 8,628 04/11/01 20:38 hpf82h04.GID FOLDER HTT 12,746 07/03/01 9:50 folder.htt DESKTOP INI 266 07/03/01 9:50 desktop.ini HPF82R04 GID 8,628 30/10/00 16:36 HPF82R04.GID EPSTHL8 GID 16,826 27/10/98 10:21 epsthl8.GID 9 file(s) 103,380 bytes 0 dir(s) 725,737,472 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{054A0321-72F9-11D9-9CAD-444553540000}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ ffastlog.txt Sun 13 Feb 2005 12:29:04 A..H. 23,912 23.35 K dntime.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mlpi32.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K peparse.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K erdmiu01.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K aovapi32.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K rhr20.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mpc250.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K dydramp.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mwvcp60.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K efcvdo.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K nytdi.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K dvcframe.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K wjhext.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K uydmxfrm.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K lmimg80n.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K dustyle.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K bo848dlg.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K vnscript.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K oftlacct.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K mhoemapi.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K 21 items found: 21 files, 0 directories. Total of file sizes: 4,475,272 bytes 4.27 M ———— Strings.exe Qoologic Results ———— ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- C:\WINDOWS\SYSTEM\DNTIME.DLL: UMonitor C:\WINDOWS\SYSTEM\MLPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\NATAPI.DLL: UMonitor C:\WINDOWS\SYSTEM\PEPARSE.DLL: UMonitor C:\WINDOWS\SYSTEM\ERDMIU01.DLL: UMonitor C:\WINDOWS\SYSTEM\AOVAPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\RHR20.DLL: UMonitor C:\WINDOWS\SYSTEM\MPC250.DLL: UMonitor C:\WINDOWS\SYSTEM\DYDRAMP.DLL: UMonitor C:\WINDOWS\SYSTEM\MWVCP60.DLL: UMonitor C:\WINDOWS\SYSTEM\efcvdo.dll: UMonitor C:\WINDOWS\SYSTEM\NYTDI.DLL: UMonitor C:\WINDOWS\SYSTEM\dvcframe.dll: UMonitor C:\WINDOWS\SYSTEM\wjhext.dll: UMonitor C:\WINDOWS\SYSTEM\UYDMXFRM.DLL: UMonitor C:\WINDOWS\SYSTEM\lmimg80n.dll: UMonitor C:\WINDOWS\SYSTEM\DUSTYLE.DLL: UMonitor C:\WINDOWS\SYSTEM\BO848DLG.DLL: UMonitor C:\WINDOWS\SYSTEM\vnscript.dll: UMonitor C:\WINDOWS\SYSTEM\OFTLACCT.DLL: UMonitor C:\WINDOWS\SYSTEM\mhoemapi.dll: UMonitor REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry"="c:\\windows\\scanregw.exe /autorun" "TaskMonitor"="c:\\windows\\taskmon.exe" "SystemTray"="SysTray.Exe" "AtiCwd32"="Aticwd32.exe" "AtiKey"="Atitask.exe" "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" "StillImageMonitor"="C:\\WINDOWS\\SYSTEM\\STIMON.EXE" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "AVG7_CC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGCC.EXE /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGEMC.EXE" "AVG7_AMSVR"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGAMSVR.EXE" "SurfSideKick 2"="C:\\PROGRAM FILES\\SURFSIDEKICK 2\\Ssk.exe" "SheduIer"="C:\\WINDOWS\\winagent.exe /i"
Lets try this again, let me know if you have any trouble.

Disconect from the internet while you are following these instructions. If need be print them out for easy reference or you can save them as a text file.

Open killbox.
We are going to use it to delete the files that are causing the infection. It is very important that you do NOT reboot until you have added all the files to be deleted.

You will be adding the files one at a time so you will need to follow these steps for each file. (I will have a file list for you further down this post)

In killbox add a check next to Replace on Reboot

Then copy and paste each full path into the Killbox topmost box.

With the full path to the file name in the topmost textbox, click the option Use Dummy which will create a numbered dummy file instantly for you.

Click the Red X …and for the confirmation message that will appear, you will need to click Yes
A second message will ask to Reboot now? you will need to click No (since you are not finished adding all related files in yet)

Now for the file list. Remember you need to enter the entire path and check the "use dummy" box for each file.

C:\WINDOWS\SYSTEM\DNTIME.DLL
C:\WINDOWS\SYSTEM\MLPI32.DLL
C:\WINDOWS\SYSTEM\NATAPI.DLL
C:\WINDOWS\SYSTEM\PEPARSE.DLL
C:\WINDOWS\SYSTEM\ERDMIU01.DLL
C:\WINDOWS\SYSTEM\AOVAPI32.DLL
C:\WINDOWS\SYSTEM\RHR20.DLL
C:\WINDOWS\SYSTEM\MPC250.DLL
C:\WINDOWS\SYSTEM\DYDRAMP.DLL
C:\WINDOWS\SYSTEM\MWVCP60.DLL
C:\WINDOWS\SYSTEM\efcvdo.dll
C:\WINDOWS\SYSTEM\NYTDI.DLL
C:\WINDOWS\SYSTEM\dvcframe.dll
C:\WINDOWS\SYSTEM\wjhext.dll
C:\WINDOWS\SYSTEM\UYDMXFRM.DLL
C:\WINDOWS\SYSTEM\lmimg80n.dll
C:\WINDOWS\SYSTEM\DUSTYLE.DLL
C:\WINDOWS\SYSTEM\BO848DLG.DLL
C:\WINDOWS\SYSTEM\vnscript.dll
C:\WINDOWS\SYSTEM\OFTLACCT.DLL
C:\WINDOWS\SYSTEM\mhoemapi.dll
C:\WINDOWS\system\guard.tmp

When you have added the last file, close all windows and reboot your computer.

Then post a new findit log.

Once again do not reboot until I get back to you.
Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM MLPI32 DLL 222,568 30/01/05 19:56 MLPI32.DLL 1 file(s) 222,568 bytes 0 dir(s) 725,098,496 bytes free ——- Hidden Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM FFASTLOG TXT 23,976 14/02/05 9:40 ffastlog.txt EPIUIE5D GID 10,840 31/07/04 14:19 EPIUIE5D.GID ATI64DEF GID 12,906 12/10/02 14:20 ati64def.GID HPF82T04 GID 8,628 08/11/01 8:59 hpf82t04.GID HPF82H04 GID 8,628 04/11/01 20:38 hpf82h04.GID FOLDER HTT 12,746 07/03/01 9:50 folder.htt DESKTOP INI 266 07/03/01 9:50 desktop.ini HPF82R04 GID 8,628 30/10/00 16:36 HPF82R04.GID EPSTHL8 GID 16,826 27/10/98 10:21 epsthl8.GID 9 file(s) 103,444 bytes 0 dir(s) 725,094,400 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{054A0321-72F9-11D9-9CAD-444553540000}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ ffastlog.txt Mon 14 Feb 2005 9:40:06 A..H. 23,976 23.41 K mlpi32.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K 2 items found: 2 files, 0 directories. Total of file sizes: 246,544 bytes 240.77 K ———— Strings.exe Qoologic Results ———— ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- C:\WINDOWS\SYSTEM\DNTIME.DLL: UMonitor C:\WINDOWS\SYSTEM\MLPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\NATAPI.DLL: UMonitor C:\WINDOWS\SYSTEM\PEPARSE.DLL: UMonitor C:\WINDOWS\SYSTEM\ERDMIU01.DLL: UMonitor C:\WINDOWS\SYSTEM\AOVAPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\RHR20.DLL: UMonitor C:\WINDOWS\SYSTEM\MPC250.DLL: UMonitor C:\WINDOWS\SYSTEM\DYDRAMP.DLL: UMonitor C:\WINDOWS\SYSTEM\MWVCP60.DLL: UMonitor C:\WINDOWS\SYSTEM\efcvdo.dll: UMonitor C:\WINDOWS\SYSTEM\Siace.dll: UMonitor C:\WINDOWS\SYSTEM\dvcframe.dll: UMonitor C:\WINDOWS\SYSTEM\wjhext.dll: UMonitor C:\WINDOWS\SYSTEM\UYDMXFRM.DLL: UMonitor C:\WINDOWS\SYSTEM\lmimg80n.dll: UMonitor C:\WINDOWS\SYSTEM\DUSTYLE.DLL: UMonitor C:\WINDOWS\SYSTEM\BO848DLG.DLL: UMonitor C:\WINDOWS\SYSTEM\vnscript.dll: UMonitor C:\WINDOWS\SYSTEM\OFTLACCT.DLL: UMonitor C:\WINDOWS\SYSTEM\mhoemapi.dll: UMonitor REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry"="c:\\windows\\scanregw.exe /autorun" "TaskMonitor"="c:\\windows\\taskmon.exe" "SystemTray"="SysTray.Exe" "AtiCwd32"="Aticwd32.exe" "AtiKey"="Atitask.exe" "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" "StillImageMonitor"="C:\\WINDOWS\\SYSTEM\\STIMON.EXE" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "AVG7_CC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGCC.EXE /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGEMC.EXE" "AVG7_AMSVR"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGAMSVR.EXE" "SurfSideKick 2"="C:\\PROGRAM FILES\\SURFSIDEKICK 2\\Ssk.exe" "SheduIer"="C:\\WINDOWS\\winagent.exe /i"  Scrubber
Delete the following files using killbox and the same method as before.

C:\WINDOWS\SYSTEM\DNTIME.DLL
C:\WINDOWS\SYSTEM\MLPI32.DLL
C:\WINDOWS\SYSTEM\NATAPI.DLL
C:\WINDOWS\SYSTEM\PEPARSE.DLL
C:\WINDOWS\SYSTEM\ERDMIU01.DLL
C:\WINDOWS\SYSTEM\AOVAPI32.DLL
C:\WINDOWS\SYSTEM\RHR20.DLL
C:\WINDOWS\SYSTEM\MPC250.DLL
C:\WINDOWS\SYSTEM\DYDRAMP.DLL
C:\WINDOWS\SYSTEM\MWVCP60.DLL
C:\WINDOWS\SYSTEM\efcvdo.dll
C:\WINDOWS\SYSTEM\Siace.dll
C:\WINDOWS\SYSTEM\dvcframe.dll
C:\WINDOWS\SYSTEM\wjhext.dll
C:\WINDOWS\SYSTEM\UYDMXFRM.DLL
C:\WINDOWS\SYSTEM\lmimg80n.dll
C:\WINDOWS\SYSTEM\DUSTYLE.DLL
C:\WINDOWS\SYSTEM\BO848DLG.DLL
C:\WINDOWS\SYSTEM\vnscript.dll
C:\WINDOWS\SYSTEM\OFTLACCT.DLL
C:\WINDOWS\SYSTEM\mhoemapi.dll

Then reboot and post a new Findit log.

Once again do not reboot until I get back to you.
Pc had been running for 24 hours and when woken-up I got the following;AVGINET caused a general protection fault in module mmsystem.dll @0004:00000db6. In trying to clear this message the pc rebooted.. I still inclose the log. Scrubber. Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM SNTUPAPI DLL 222,568 30/01/05 19:56 SNTUPAPI.DLL CFOOSUSR DLL 222,568 30/01/05 19:56 CFOOSUSR.DLL 2 file(s) 445,136 bytes 0 dir(s) 712,286,208 bytes free ——- Hidden Files in System Directory ——- Volume in drive C is MODEL 75 Volume Serial Number is 377F-11FC Directory of C:\WINDOWS\SYSTEM FFASTLOG TXT 24,008 15/02/05 9:01 ffastlog.txt EPIUIE5D GID 10,840 31/07/04 14:19 EPIUIE5D.GID ATI64DEF GID 12,906 12/10/02 14:20 ati64def.GID HPF82T04 GID 8,628 08/11/01 8:59 hpf82t04.GID HPF82H04 GID 8,628 04/11/01 20:38 hpf82h04.GID FOLDER HTT 12,746 07/03/01 9:50 folder.htt DESKTOP INI 266 07/03/01 9:50 desktop.ini HPF82R04 GID 8,628 30/10/00 16:36 HPF82R04.GID EPSTHL8 GID 16,826 27/10/98 10:21 epsthl8.GID 9 file(s) 103,476 bytes 0 dir(s) 712,282,112 bytes free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{054A0321-72F9-11D9-9CAD-444553540000}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ ffastlog.txt Tue 15 Feb 2005 9:01:06 A..H. 24,008 23.45 K sntupapi.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K cfoosusr.dll Sun 30 Jan 2005 19:56:26 ..S.R 222,568 217.35 K 3 items found: 3 files, 0 directories. Total of file sizes: 469,144 bytes 458.15 K ———— Strings.exe Qoologic Results ———— ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- C:\WINDOWS\SYSTEM\DNTIME.DLL: UMonitor C:\WINDOWS\SYSTEM\MLPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\NATAPI.DLL: UMonitor C:\WINDOWS\SYSTEM\PEPARSE.DLL: UMonitor C:\WINDOWS\SYSTEM\ERDMIU01.DLL: UMonitor C:\WINDOWS\SYSTEM\AOVAPI32.DLL: UMonitor C:\WINDOWS\SYSTEM\RHR20.DLL: UMonitor C:\WINDOWS\SYSTEM\MPC250.DLL: UMonitor C:\WINDOWS\SYSTEM\DYDRAMP.DLL: UMonitor C:\WINDOWS\SYSTEM\MWVCP60.DLL: UMonitor C:\WINDOWS\SYSTEM\efcvdo.dll: UMonitor C:\WINDOWS\SYSTEM\Siace.dll: UMonitor C:\WINDOWS\SYSTEM\dvcframe.dll: UMonitor C:\WINDOWS\SYSTEM\wjhext.dll: UMonitor C:\WINDOWS\SYSTEM\UYDMXFRM.DLL: UMonitor C:\WINDOWS\SYSTEM\lmimg80n.dll: UMonitor C:\WINDOWS\SYSTEM\DUSTYLE.DLL: UMonitor C:\WINDOWS\SYSTEM\BO848DLG.DLL: UMonitor C:\WINDOWS\SYSTEM\vnscript.dll: UMonitor C:\WINDOWS\SYSTEM\OFTLACCT.DLL: UMonitor C:\WINDOWS\SYSTEM\mhoemapi.dll: UMonitor C:\WINDOWS\SYSTEM\SNTUPAPI.DLL: UMonitor C:\WINDOWS\SYSTEM\CFOOSUSR.DLL: UMonitor REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ScanRegistry"="c:\\windows\\scanregw.exe /autorun" "TaskMonitor"="c:\\windows\\taskmon.exe" "SystemTray"="SysTray.Exe" "AtiCwd32"="Aticwd32.exe" "AtiKey"="Atitask.exe" "LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" "StillImageMonitor"="C:\\WINDOWS\\SYSTEM\\STIMON.EXE" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "AVG7_CC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGCC.EXE /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGEMC.EXE" "AVG7_AMSVR"="C:\\PROGRA~1\\GRISOFT\\AVGFRE~1\\AVGAMSVR.EXE" "SurfSideKick 2"="C:\\PROGRAM FILES\\SURFSIDEKICK 2\\Ssk.exe" "SheduIer"="C:\\WINDOWS\\winagent.exe /i" 
Hi Scrubber

Racktracker's away for a couple days

I can help until he returns

I use a differant tool than findit though.


Download and install Agent Ransack a free search tool.
http://www.mythicsoft.com/agentransack/default.aspx
Start the program, start > search > Agent Ransack
[x] check expert user
In the text containing field copy/paste this in
(UMonitor|IsProcessorFeaX|NictechNetworks)+
In the Look in field paste in
C:\windows\system
[ ] uncheck the box to search sub folders
Click Start search

Once its done go file save results (x)clipboard is checked by default,
leave it, BUT uncheck [ ] file contents. Now save, which copies it to your clipboard,
in your next post right-click paste that information back here, dont assume all thats found is a bad thing.

Post a fresh Hijackthis log also
C:\windows\system\SNTUPAPI.DLL (218 KB, 01/30/2005 19:56:26)
C:\windows\system\CFOOSUSR.DLL (218 KB, 01/30/2005 19:56:26)
C:\windows\system\VCFC32.DLL (218 KB, 01/30/2005 19:56:26)
C:\windows\system\lfinf509.dll (218 KB, 01/30/2005 19:56:26)

Logfile of HijackThis v1.99.0
Scan saved at 11:08:00, on 02/17/2005
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v5.00 (5.00.2919.6304)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\WINAGENT.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\CLIPBRD.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MSOFFICE\WINWORD\WINWORD.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by KZuk.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve.:8080
R3 - URLSearchHook: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - C:\PROGRAM FILES\SURFSIDEKICK 2\SSKBHO.DLL (file missing)
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: IEMenuExtension toolbar - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - C:\PROGRAM FILES\IEMENUEXTENSION\TBEXTN.DLL (file missing)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - HKLM\..\Run: [SheduIer] C:\WINDOWS\winagent.exe /i
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SurfSideKick 2] C:\PROGRAM FILES\SURFSIDEKICK 2\Ssk.exe
O4 - Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
O4 - Startup: STRINGS.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .eid: C:\PROGRA~1\INTERN~1\PLUGINS\NPIPRT32.DLL
O12 - Plugin for .php: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .tif: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O15 - Trusted IP range: 67.19.185.246
O15 - Trusted IP range: 67.19.185.246 (HKLM)
Thanks Lonny for stepping in while I was gone.

Ok Scrubber

It looks like agent ransack found a couple files that were not showing up before.

Hopefully removal of them will take care of this.

Open killbox again and remove these files using the same method we did before.

C:\windows\system\SNTUPAPI.DLL
C:\windows\system\CFOOSUSR.DLL
C:\windows\system\VCFC32.DLL
C:\windows\system\lfinf509.dll

Then reboot and post a new agent ransack log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI