This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ad-w-a-r-e Hijack

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Those files could not be deleted, they don't exist anymore. Everytime I reboot, they change to a new name. I tried to delete them by thier new names in safemode but it said that the files were unable to be deleted. DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINNT\SYSTEM32\cbonts.dll Sun Apr 10 2005 3:24:56p ..S.R 234,724 229.22 K C:\WINNT\SYSTEM32\n0p4la~1.dll Sun Apr 10 2005 3:23:24p ..S.R 236,295 230.75 K C:\WINNT\SYSTEM32\r0r60a~1.dll Sun Apr 10 2005 12:59:12a ..S.R 234,724 229.22 K ________________________________________________ 1,087 items found: 1,087 files (3 H/S), 0 directories. Total of file sizes: 235,894,133 bytes 224.96 M Administrator Account = True ——————–End log———————
Lets try it this way.


Click HERE to download DllCompare. Start the Program with and click the Run Locate.com - be sure the \Windows\System32 directory is in the box and wait until the the blue text says it has 'completed the scan'.

Click the Compare button to start the next process. The results appear in two panes - files in the upper pane have been verified to 'exist', files in the lower pane were 'not able to be accessed'. Very few files should be listed in the lower pane when the Compare scan is complete. Click on each of the listed entries in the lower pane to select them. Right-click on the file and use the option Rescan. This will cause Windows Find to see if the file does exist, and then if so it will be removed from the list to reduce the number of identified files.

Click the Make a Log of what was found button and post the log here in this thread and wait for further instructions.
DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found :)" ________________________________________________ 1,087 items found: 1,087 files (3 H/S), 0 directories. Total of file sizes: 235,894,200 bytes 224.96 M Administrator Account = True ——————–End log——————— All of the files originally in the lower pane came back as 0 files with 0 bytes, but when I rescaned, they came back as being found and were added to the upper pane
DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINNT\SYSTEM32\n0p4la~1.dll Sun Apr 10 2005 3:23:24p ..S.R 236,295 230.75 K ________________________________________________ 1,087 items found: 1,087 files (3 H/S), 0 directories. Total of file sizes: 235,894,200 bytes 224.96 M Administrator Account = True ——————–End log——————— ok I tried it again, and this time one file would not be found and never went to the upper pane
Start Killbox place a tick next to [x]delete on reboot.
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINNT\SYSTEM32\cbonts.dll
C:\WINNT\SYSTEM32\n0p4la~1.dll
C:\WINNT\SYSTEM32\r0r60a~1.dll
C:\WINNT\system32\ir02l5do1.dll
C:\WINNT\system32\o4nsle571h.dll
C:\WINNT\SYSTEM32\ibwdial.dll
C:\WINNT\SYSTEM32\jt2607~1.dll
C:\WINNT\SYSTEM32\jt4q07~1.dll
C:\WINNT\SYSTEM32\k2pmlc~1.dll
C:\WINNT\SYSTEM32\mv48l9~1.dll
C:\WINNT\SYSTEM32\ndrsesm.dll
C:\WINNT\SYSTEM32\wqw32.dll
C:\WINNT\SYSTEM32\k8260i~1.dll
C:\WINNT\system32\jt2607fse.dll
C:\WINNT\SYSTEM32\r0r60a~1.dll
C:\WINNT\SYSTEM32\sqrrun.dll
C:\WINNT\system32\k8260ifse8260.dll



Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.


"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINNT\SYSTEM32\aimlib.dll Wed Apr 13 2005 2:07:54a ..S.R 234,724 229.22 K
C:\WINNT\SYSTEM32\dn4m01~1.dll Wed Apr 13 2005 2:07:52a ..S.R 234,865 229.36 K
C:\WINNT\SYSTEM32\fpl003~1.dll Tue Apr 12 2005 4:21:56a ..S.R 234,724 229.22 K
________________________________________________

1,087 items found: 1,087 files (3 H/S), 0 directories.
Total of file sizes: 235,891,199 bytes 224.96 M

Administrator Account = True

——————–End log———————


file of HijackThis v1.99.1
Scan saved at 2:14:56 AM, on 4/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINNT\system32\RUNDLL32.EXE
D:\Program Files\AIM\aim.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O20 - Winlogon Notify: ModuleUsage - C:\WINNT\system32\fpl0033me.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe




No change in computer, different websites are now popping up, IE opens to ebay auctions for shady software programs such as spyware removers and Micosoft certified tech secrets and junk like that
Launch Notepad, and copy/paste the box below into a new text file. Save it as FindDLL.bat and save it on your Desktop.


dir C:\WINDOWS\System32\*.dll.dll > BadDLL.txt
notepad BadDLL.txt


Locate FindDLL.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the text here.
It opens up a black window titled, C:\WINNT\system32.exe The window then says C:\Documents and Settings\Administrator\Desktop>dir C:\WINDOWS\System32\*.dll.dll 1>BadDLL.txt The system cannot find the path specified C:\Documents and Settings\Administrator\Desktop>notepad BadDLL.txt Notepad also opens up but is blank
well I was hoping we could use a shortcut but, it doesn't look like it.

Start Killbox place a tick next to [x]delete on reboot.
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINNT\SYSTEM32\aimlib.dll
C:\WINNT\SYSTEM32\dn4m01~1.dll
C:\WINNT\SYSTEM32\fpl003~1.dll
C:\WINNT\system32\fpl0033me.dll



Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox.


Run Hijack This again and put a check by these.

O20 - Winlogon Notify: ModuleUsage - C:\WINNT\system32\fpl0033me.dll


Close ALL windows and browsers except HijackThis and click "Fix checked"





"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 3:30:57 AM, on 4/15/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O20 - Winlogon Notify: IPConfMSP - C:\WINNT\system32\f2l00c3mef.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe



* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINNT\SYSTEM32\f2l00c~1.dll Thu Apr 14 2005 12:38:54p ..S.R 234,724 229.22 K
C:\WINNT\SYSTEM32\igakui.dll Fri Apr 15 2005 3:24:10a ..S.R 234,724 229.22 K
C:\WINNT\SYSTEM32\o2nslc~1.dll Fri Apr 15 2005 3:22:46a ..S.R 234,865 229.36 K
________________________________________________

1,087 items found: 1,087 files (3 H/S), 0 directories.
Total of file sizes: 235,891,199 bytes 224.96 M

Administrator Account = True

——————–End log———————


Still no change in computer
Do you see the Date and Size of these files we're killing? Do you know how to view a folder by file type?

C:\WINNT\SYSTEM32\f2l00c~1.dll Thu Apr 14 2005 12:38:54p ..S.R 234,724 229.22 K
C:\WINNT\SYSTEM32\igakui.dll Fri Apr 15 2005 3:24:10a ..S.R 234,724 229.22 K
C:\WINNT\SYSTEM32\o2nslc~1.dll Fri Apr 15 2005 3:22:46a ..S.R 234,865 229.36 K



Start Killbox place a tick next to [x]delete on reboot.
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINNT\SYSTEM32\f2l00c~1.dll
C:\WINNT\SYSTEM32\igakui.dll
C:\WINNT\SYSTEM32\o2nslc~1.dll
C:\WINNT\system32\f2l00c3mef.dll



Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox.


Run Hijack This again and put a check by these.

O20 - Winlogon Notify: IPConfMSP - C:\WINNT\system32\f2l00c3mef.dll


Close ALL windows and browsers except HijackThis and click "Fix checked"





"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.

153924

I can see the date and size of the files we are killing from the posts and logs, I do not know how to view a folder by type. So far nothing has changed, IE is still opening and seems to be doing it more frequently. The files just seem to be coming back with different names everytime I delete them, or just come back as not being able to be deleted. Should I just wipe out everything on my computer and start fresh, or do you think that it is something that I will be able to remove ?

Logfile of HijackThis v1.99.1
Scan saved at 4:29:27 AM, on 4/18/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINNT\system32\RUNDLL32.EXE
D:\Program Files\AIM\aim.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe

O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HijackThis\HijackThis.exe /startupscan
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O20 - Winlogon Notify: H323TSP - C:\WINNT\system32\m2820cloefqc0.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe


* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINNT\SYSTEM32\m2820c~1.dll Sun Apr 17 2005 4:17:08p ..S.R 235,147 229.63 K
C:\WINNT\SYSTEM32\mvj2l9~1.dll Mon Apr 18 2005 4:19:10a ..S.R 234,865 229.36 K
C:\WINNT\SYSTEM32\mzcsubs.dll Mon Apr 18 2005 4:20:54a ..S.R 235,147 229.63 K
________________________________________________

1,087 items found: 1,087 files (3 H/S), 0 directories.
Total of file sizes: 235,892,045 bytes 224.96 M

Administrator Account = True

——————–End log———————
Start Killbox place a tick next to [x]delete on reboot.
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINNT\SYSTEM32\m2820cloefqc0.dll
C:\WINNT\SYSTEM32\m2820c~1.dll
C:\WINNT\SYSTEM32\mvj2l9~1.dll
C:\WINNT\system32\mzcsubs.dll



Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox.


Run Hijack This again and put a check by these.

O20 - Winlogon Notify: IPConfMSP - C:\WINNT\system32\m2820cloefqc0.dll

Close ALL windows and browsers except HijackThis and click "Fix checked"



Please download this tool called 'About:Buster':

http://www.downloads.subratam.org/AboutBuster.zip

Unzip it to your desktop.

DO NOT relaunch Internet Explorer at any point during this.

Now, boot in to safe mode. Instructions on how to do so are in the following link:

http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

(Follow the instructions revelant to your operating system. In this case it is either Windows 2000 or XP)

Once in safe mode, Launch the About:Buster program you had earlier downloaded. Click 'OK' to the first prompt you get upon launching the program. That message is simply a breif explaination on what the program is and what it does. First of all you must get the latest update for About:Buster. About:Buster uses a file for the detection references, in a similiar way to Ad-aware. So, click the 'Update' button. On the next window, click 'Check for Updates'. If there is a new detection update available, it will say so and the 'Download Update' button will become enabled. Click it and it will download the update. This will take literally a few seconds. Once completed, it will say the update has been complete. Click the 'X' to get rid of that screen.

(If there was no update available and you have the latest it will tell you and automatically close the Update screen)

Now, click the 'Start' button. Click the 'OK' button you now see. Leave it to scan (the scan time can take some time to complete, so leave it scanning.). Once the first scanhas completed, it will ask you if you wish for About:Buster to scan once more. Answer yes and leave it scanning a second time. Once the second scan has finished, then copy/paste it's report somewhere. To copy/paste it all, please select (highlight) with your mouse ALL of the text in the white box (in About:Buster). Right-click with your mouse and select 'Copy'.

Now, launch Notepad (click Start > Run > type in and press enter: notepad.exe) and RIGHT-click in the empty space. Select 'Paste'. Now the logfile from About:Buster will have been copied into Notepad. Click 'File' (in the menus…) > 'Save As'. Save it in C:\ and as Log.txt.

Now, restart the computer as normal and you'll return into Windows 'Normal' mode.Once back in 'Normal' mode, re-scan with About:Buster once more. Answer no to a second scan this time. As before, do the exact same to copy/paste it's logfile. (This time save the file as Log2.txt). Now, with both log files (Log.txt from safe mode and Log2.txt from 'Normal' mode) we can see how things have changed in HijackThis. Launch HijackThis and press the 'Scan' button. Save that new logfile (from HijackThis). Now you have three logfiles to post: Log.txt which is the About:Buster logfile/report in Safe mode, Log2.txt is a new scan in 'Normal' mode with A:B and the HijackThis logfiles. Post all three logfiles, in this topic, seperating each one so I can see which is which.
– Scan 1 ————————— About:Buster Version 4.0 Reference List : 26 No ADS found on system Attempted Clean Of Temp folder. Pages Reset… Done! – Scan 2 ————————— About:Buster Version 4.0 Reference List : 26 No ADS found on system Attempted Clean Of Temp folder. Pages Reset… Done!
– Scan 1 ————————— About:Buster Version 4.0 Reference List : 26 No ADS found on system Attempted Clean Of Temp folder. Pages Reset… Done!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI