This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Log.

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my log. I ran Spybot S&D/Adaware and found/fixed a few things. I rebooted and ran HijackThis. What can/should I get rid of?

Logfile of HijackThis v1.99.1
Scan saved at 3:15:58 AM, on 4/28/2005
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\system32\Brmfrmps.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
C:\WINNT\Logi_MwX.Exe
C:\WINNT\System32\carpserv.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://realsearch.cc/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://realsearch.cc/?a=2
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: ActiveX Control - {6FA7E10C-89A0-484F-8FD2-1BA6532C7107} - C:\WINNT\System32\msdgi.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ConferenceRoom Java Client - http://chat.ar15.com/java/cr.cab
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://ftp.newaol.com/pub/sr-test/streetnoagent7.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {886DDE35-E955-11D0-A707-000000521958} - http://69.56.176.78/webplugin.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINNT\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
Hi amtekco, Welcome to TomCoyote forum. You do have some nasties onboard, if you want my help, follow these directions:

1) My scan show a strong possibility you have a CoolWebSearch infection. Download CWShredder from the following link, update it first then choose FIX not scan. Allow it to run and remove anything it locates and let me know what it found in your next post.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

2) Download CCleaner from this link: http://www.ccleaner.com/ Take the time to review the instructions on the download page so that when I ask you to run it you will know what you are doing.

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://realsearch.cc/?a=2
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://realsearch.cc/?a=2
O2 - BHO: ActiveX Control - {6FA7E10C-89A0-484F-8FD2-1BA6532C7107} - C:\WINNT\System32\msdgi.dll
Trojan.Eman
O16 - DPF: {886DDE35-E955-11D0-A707-000000521958} - http://69.56.176.78/webplugin.cab
IEPlugin Websearch

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Let's check for trojans to make sure none are hiding, run this free online scan, scan the whole system and set it to clean or fix anything it locates. Let me know what it finds and the exact name and location of anything it locates but can't remove. You may be asked to install an ActiveX, please do so as this program is safe and it can not run without it.
http://www.windowsecurity.com/trojanscan/

Run CCleaner then restart the computer and post a new log in this same thread along with any feedback you have. Let us know how you are running.

Thanks…pskelley
TomCoyote forum
Slyware Warrior

PURGE SYSTEM RESTORE
When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instruction:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam
pskelley, thank you for helping me.

1. CWShredder found nothing.

2. Fixed items in HijackThis.

3. WindowSecurity.com found and fixed these:
C:\WINT\Downloaded Program Files\CONFLICT.1\deaGB187.exe
C:\WINT\Downloaded Program Files\CONFLICT.2\deaGB187.exe
C:\WINT\Downloaded Program Files\deaGB187.exe
C:\WINT\Downloaded Program Files\extract.exe
C:\WINT\Downloaded Program Files\ssk.exe
C:\WINT\Downloaded Program Files\system32\lbaccrow.dll

4. Ran CCleaner then restarted the computer.

5. My new log:

Logfile of HijackThis v1.99.1
Scan saved at 6:01:20 AM, on 5/3/2005
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\system32\Brmfrmps.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
C:\WINNT\Logi_MwX.Exe
C:\WINNT\System32\carpserv.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.63.219.181.7
O16 - DPF: ConferenceRoom Java Client - http://chat.ar15.com/java/cr.cab
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://ftp.newaol.com/pub/sr-test/streetnoagent7.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINNT\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe


No problems in 15 minutes since I restarted computer. How does my log look?
Thank you, amtekco.
Hi again amtekco, Thanks for the information…it does help. Sorry about CWShredder not locating anything but I wanted to be sure. CWS is a nasty infection and getting it quick can save a lot of work. My scan said maybe and I thought better safe than sorry. Tool is free, update and tuck it away on C:\ in case you ever need it.
Your log is looking much better :thumbup: but it looks like I missed one item: :( O15 - Trusted Zone: http://*.63.219.181.7. Unless you personally put this in your trusted zone you should use HJT to remove it. I get this when I scan the address with SamSpade: Beyond The Network America, Inc. I will also mention that you have programs (look at the 04 Run items) that start everytime you boot your computer. You might want to consider turning them off in msconfig and starting the manually via Start/All Programs when you need them to save you some resources. Your call.

Scan with HJT aand check these items:
If you did not set this restriction you can remove it:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted Zone: http://*.63.219.181.7

Close all programs and click "Fix Checked"

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Safe surfing
Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
pskelley, thanks again. I have been on computer a couple of hours now without any more problems. I was going to ask you about O15 - Trusted Zone: http://*.63.219.181.7 but forgot. I had tried to remove it with HJT before but it doesn't. I just tried 5 times. When I scan again it is still there. How do I get rid of it? As for the programs that start I would love to stop as many as I can but I don't know how or what they even are to begin with. Someone told me to do the msconfig thing but I get an error message (cannot find 'msconfig'….) when I try to run it. I was then told that was because I have Windows 2000. In task manager I always have around 30 things running and it really slows my old computer down. I don't know what to do. Thanks again, amtekco.
Hello amtekco, The more I look at that item the less I like it. It will not remove because this in the item (*) means it is running as soon as the computer starts. If you know how to take your computer to safe mode, do so and use HJT to remove in there. If you need instructions for entering Safe mode, they are here: http://www.bleepingcomputer.com/forums/tutorial61.html
Make sure you choose the instructions for your Operating System.
Once this item is removed, please post a new log so I can make sure all is well.

Here is information about MSCONFIG: http://netsquirrel.com/msconfig/
I found this information, I do not work with Windows2000 often:
What about Windows 95, NT, and 2000?
MSCONFIG is not (quite) available for Windows 95, NT, or 2000. But don't panic. The free "Startup Control Panel" program at http://www.mlin.net/StartupCPL.shtml will work just as well. And if you have Windows NT or 2000, you can also download the official, Windows XP version of MSCONFIG at http://www.thetechguide.com/downloads.html
I would suggest you use the official WindowsXp version.
This is the Microsoft Configuration Utility You can make a list and I will tell you which ones to uncheck. There is no need to list items link Antivirus, firewall, and security programs or anything you know must run at Startup.
Thanks…Phil
pskelley.

I rebooted in safe mode and tried to remove O15 - Trusted Zone: http://*.63.219.181.7 with HJT. I did it several times. Same thing, I rescan and it is still there.

I am going to check out the msconfig info you gave me now.

Here is my new scan but I think it is the same.

Logfile of HijackThis v1.99.1
Scan saved at 9:07:43 PM, on 5/3/2005
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\system32\Brmfrmps.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
C:\WINNT\Logi_MwX.Exe
C:\WINNT\System32\carpserv.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Microsoft IntelliType Pro] "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zapro.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.63.219.181.7
O16 - DPF: ConferenceRoom Java Client - http://chat.ar15.com/java/cr.cab
O16 - DPF: {0B72CCA4-5F11-11D0-9CB5-0000C0EC9FDB} (Street Technologies ActiveX Control Object) - http://ftp.newaol.com/pub/sr-test/streetnoagent7.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINNT\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
Hello amtekco, My research on this item: O15 - Trusted Zone: http://*.63.219.181.7 Indicates it may be a RootKit infection. I am trying to get more information. As soon as I have something solid, I will post it for you. Thanks…pskelley
This is indeed a nasty varity of a rootkit infection. Experts have created this fix, please follow the directions carefully.

Download remv3.zip from here:

http://forums.skads.org/index.php?act=Atta…ype=post&id=115

and save it on your desktop. Then extract the zip file to c:\ms4hd.

Boot your computer into Safe Mode. Instructions on how to do this can be found here:

How to boot Windows into Safe Mode

Navigate to c:\ms4hd and double-click on the remv3.bat file. When it is done it will open a log file of what it found. This log file is saved in c:\log.txt.

Reboot your computer back to normal mode and post the contents of c:\log.txt. To open it, click on start, then run, and type notepad c:\log.txt and press the OK button.

A notepad will open up. Please create a reply to this message and post the contents of that notepad along with a new hijackthis log.

pskelley
I am having a problem downloading things. I could not get my startup list because I couldn't download either of the msconfig deals you provided me. Now I can't download remv3.zip either. I keep getting this error message. Critical Error The module C:\Documents and Settings\Desktop\remv3.zip is incomplete – probably due to an incomplete or failed download History: USetupDefinition::Init<-WFilerWizard<-Setup
Hello amtekco, I suggest you concern yourself with the instructions for removing the rootkit infection. I would not be concerned with Startup items at this point. Try the download again, it might have been corrupted the first time. Work on the last instructions I gave you. Thanks…
That is what I am trying to do. I was just letting you know it is not just this file I can't download. I tried this like 20 times. I try to save on desktop and it says it is done in 1 second. When I hit open I get the above message. Thanks.
Hello amtekco, Here are a couple of ways you can try to get the information about this infection if you have still not resolved the issue:
__________________________________________________________________

1) Download rkfiles.zip from here
UNZIP the contents to a permanent folder

Reboot in SAFE MODE !! Important !!
°To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key

Please set your system to show all files.
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Doubleclick rkfiles.bat
It will scan for a while, so please be patient.
Wait till the doswindow closes and reboot back to normal mode.

Post the contents of C:\log.txt in your next reply.

___________________________________________________________________

2) Download unzip then scan RootkitRevealer.exe
http://www.sysinternals.com/ntw2k/freeware…kitreveal.shtml
when its done go file > save
attach the log back here in your next reply
Not to worry, normal there are alot of items.
Its an intensive scan, I suggest you disconnect from the internet and leave the PC alone until its finished.

Because the log can be very large please edit out items in C:\RECYCLER\NPROTECT if there.
And C:\System Volume Information, before posting


___________________________________________________________________

If you have mananged to resolved this issue in some other way, please post to let me know so I can stop looking for a solution.
Thanks…pskelley

1)  Download rkfiles.zip from here
UNZIP the contents to a permanent folder


I can't download anything now. I get the same error message as above when I try to download rkfiles.zip.

Critical Error
The module C:\Documents and Settings\local settings\Temporary Internet Files\content.IE5\4FA9UR4D\rkfiles[1].zip is incomplete – probably due to an incomplete or failed download

History: USetupDefinition::Init<-WFilerWizard<-Setup



___________________________________________________________________

If you have mananged to resolved this issue in some other way, please post to let me know so I can stop looking for a solution.
Thanks…pskelley

162874


No, I haven't. I have been trying everything you give me but I can't download anything now, I get that critical error message. I don't know what to do.

Sorry my response took a couple days. I have spent a couple days outside doing lawn work.

Thanks for your help, I really appreciate it.
Hello amtekco, I wish you to know that I just downloaded RKFiles to my computer so it is not the download site.

I can't download anything now. I get the same error message as above when I try to download rkfiles.zip.

I would like you not to refer back, but rather to post the error message completely in the post we are working with to keep us from having to look back to see what you said. Thanks.
What I would like you to do is to describe any and all symptoms you are experiencing on the computer right now.

I wish to say that it is very important that your read and follow the directions. In this case the instructions clearly indicate that RKFiles must be:
1) Download rkfiles.zip from here
UNZIP the contents to a permanent folder
But you have downloaded RKFiles to here: C:\Documents and Settings\local settings\Temporary Internet Files\content.IE5\4FA9UR4D\rkfiles[1].zip
I want you to locate C:\Documents and Settings\local settings\Temporary Internet Files\content.IE5\4FA9UR4D\rkfiles[1].zip and delete it from the computer. Search for RKFiles and delete any instance of it you find. Then I want you to open your C:\ drive and point your mouse at a blank spot and create a new folder. Call this folder RKFiles. Then using this download site: http://skads.org/special/rkfiles.zip Save the download into that new RKFiles folder you have created. Do not let it save any where else. Once this is complete, then attempt to follow these directions:

UNZIP the contents to a permanent folder (it will be in one, double click) Once the file is unzipped proceed to the balance of these directions.

Reboot in SAFE MODE !! Important !!
°To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key

Please set your system to show all files.
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Doubleclick rkfiles.bat
It will scan for a while, so please be patient.
Wait till the doswindow closes and reboot back to normal mode.

Post the contents of C:\log.txt in your next reply.

Take your time, follow the directions exactly. If any error messages occur, post them in your next post exactly as the appear.
Each time you post I want you to post a new copy of your HJT log so I can watch for any changes that may occur. Thanks…pskelley

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI