This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis log, help please

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I will do these last steps and Killbox tomorrow. I did realize today that I had not updated my Spybot in a long time, so I did that and it picked up 24 things. I also didnt have AdAware so I downloaded that and have ran it and corrected what it found. I dont know if this will help or not but I will know before too long. I will repost tomorrow after doing everything you mentioned. Thanks again for ALL your help. Julia
Ok I got the time to do all that tonight. I hope I did it right. I have only been online about 5 mins and still getting the pop ups. They are new browser windows that open up on their own. Anyhow here are my new log files for HijackThis and Scan.bat

Logfile of HijackThis v1.99.1
Scan saved at 6:50:40 PM, on 6/7/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\NSVSVC\NSVSVC.EXE
C:\WINDOWS\SYSTEM\PICSVR\PICSVR.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN1\YT.DLL
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\SYSTEM\PICSVR\PICSVR.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .PDF: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab


I did uninstall Weather Bug but I see there are still a couple things listed related to that program…..Should i check those on the next run of HijackThis and delete them?????

Here is my Scan.bat file

»»»»»»»»»»»»»»»»»»***LOG!***»»»»»»»»»»»»»»»»

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Nsv SZ C:\\WINDOWS\\SYSTEM\\nsvsvc\\nsvsvc.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\picsvr SZ C:\\WINDOWS\\SYSTEM\\PICSVR\\PICSVR.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ NONE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ NONE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ NONE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\ NONE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce\ NONE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\ NONE


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices-\LoadPowerProfile SZ Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices-\SchedulingAgent SZ C:\\WINDOWS\\SYSTEM\\mstask.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices-\KB891711 SZ C:\\WINDOWS\\SYSTEM\\KB891711\\KB891711.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\TaskMonitor SZ C:\\WINDOWS\\taskmon.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\LoadPowerProfile SZ Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\LoadQM SZ loadqm.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\HPDJ Taskbar Utility SZ C:\\WINDOWS\\SYSTEM\\hpztsb10.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\HP Component Manager SZ "C:\\PROGRAM FILES\\HP\\HPCORETECH\\HPCMPMGR.EXE"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\HP Software Update SZ "C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\ScanRegistry SZ C:\\WINDOWS\\scanregw.exe /autorun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-\SystemTray SZ SysTray.Exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-\Sero SZ C:\\WINDOWS\\Application Data\\ldcs.exe

I hope once we get this all figured out I can manage to keep anything new from attacking me????? What a PAIN !!! Thanks again
Thanks for posting the logs… looking better :)

Copy/Paste this into notepad or wordpad for reference during the fix.

Run and scan with HiajckThis. With all browsers and windows closed, place a check beside the following and fix:

O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\SYSTEM\PICSVR\PICSVR.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?


Boot into Safe Mode. Delete these folders:

C:\WINDOWS\SYSTEM\nsvsvc
C:\WINDOWS\SYSTEM\PICSVR

Delete this file:

C:\WINDOWS\Application Data\ldcs.exe

Emtpy your Recycle Bin. Run CCleaner.

Reboot Windows normally and post a new HijackThis log please.
Ooook here we go again. I booted into safe mode and deleted the file ldcs.exe, but I could not locate the 2 folders in C:\windows\system\nsvsvc & C:\windows\system\PICSVR. They just werent there???? I then did the other steps and here is the new Hijackthis log. BTW I am still getting the automatic opening to sites in IE……

Logfile of HijackThis v1.99.1
Scan saved at 9:08:39 PM, on 6/7/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SLRUNDLL.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN1\YT.DLL
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .PDF: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
Persistant :)

I'd like you to do an online scan for me please…. PandaActiveScan. Set it to fix anything it finds. Once the scan starts… close Internet Explorer but keep the scanning window open, this is to ensure that the scan won't quit on you. Post the log here please. You will need to reconnect to the net to get the log results.

Download and install Agent Ransack.

Start Agent Ransack.

[x] check expert user

In the text containing field copy/paste this in:

(UMonitor|IsProcessorFeaX|NictechNetworks)+

In the Look in field paste in:

C:\windows\system

[ ] uncheck the box to search sub folders

Click Start search

Once its done go file save results (x)clipboard is checked by default, leave it, BUT uncheck [ ] file contents. Now save, which copies it to your clipboard, in your next post right-click paste that information back here please.

Also, I'm going to ask you not to reboot, log off, or turn off your computer(unless I instruct it) once you have posted the logs.

Thanks!
Yes I am very persistant when things dont go right and are SOOOO very annoying that you cant even enjoy the online time. Ok I did the Panda Active Scan and it doesnt look so good to me but I am far from knowledgable in this so here are the results. Incident Status Location Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DLVACM.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WA5INF16.DLL Adware:Adware/SaveNow No disinfected Windows Registry Adware:Adware/PowerScan No disinfected C:\Program Files\Intrigue Learning Adware:Adware/SAHAgent No disinfected C:\WINDOWS\seeve.exe Adware:Adware/AdDestroyer No disinfected C:\WINDOWS\All Users\Application Data\AdDestroyer Adware:Adware/VirtualBouncer No disinfected C:\WINDOWS\All Users\Application Data\VBouncer Adware:Adware/DelFinMedia No disinfected Windows Registry Adware:Adware/ISearch No disinfected C:\WINDOWS\deskbar.ini Adware:Adware/Midaddle No disinfected C:\WINDOWS\TEMP\uppicsvr.exe Adware:Adware/AzeSearch No disinfected Windows Registry Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RDAPH.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OREXL32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WFNMM.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\JLEG1X32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PLPWRENU.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WNNMM.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PQBASE.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RZCLTSPX.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CYPBK32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MUVBVM50.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\in50_qcx.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OOCACHE.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ORPDX32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PKTOREC.DLL Adware:Adware/ISearch No disinfected C:\WINDOWS\SYSTEM\HLInstaller1.exe Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ckmintfs.dll Adware:Adware/PortalScan No disinfected C:\WINDOWS\SYSTEM\HyperLinker1.exe Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\Tyain.dll Spyware:Spyware/Virtumonde No disinfected C:\WINDOWS\SYSTEM\wincoreak.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\JREG1X32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DONDI.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wA5inf16.dll Spyware:Spyware/Virtumonde No disinfected C:\WINDOWS\SYSTEM\winrulesak.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HVDCI.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RLCRES.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MTXML4r.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\Aol.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ixtrigue.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OKEACC.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AMIFILE.DLL Adware:Adware/PowerScan No disinfected C:\WINDOWS\SYSTEM\intrigue.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wav8dmoe.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OTEPRO32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MMXMLR.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\qNsf.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\qudit.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CRPBK32.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\tUembed.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\irctl.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dlvacm.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\LKNKINFO.DLL Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\lzclr13n.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PxpOops.dll Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dq8vb.dll Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\TEMP\tsvcin.exe Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\TEMP\uppicsvr.exe Virus:Trj/Downloader.AUP Disinfected C:\WINDOWS\VT17.exe Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts Adware:Adware/ISearch No disinfected C:\WINDOWS\deskbar.ini Spyware:Spyware/Media-motor No disinfected C:\WINDOWS\seeve.exe Adware:Adware/ImGiant No disinfected C:\WINDOWS\myurlff.exe Adware:Adware/DelFinMedia No disinfected C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe Spyware:Spyware/Media-motor No disinfected C:\Program Files\backups\backup-20050605-162607-874.inf Adware:Adware/VirtualBouncer No disinfected C:\WrapperOuter.exe I went to the website for Agent Ransack and I didnt download it because I dont see where it supports Windows 98 SE, did I take that wrong or was I right in not trying to use the program??? Thanks alot! anxiously awaiting your advice………. Julia
Agent Ransack works fine on Win98… please download it and post the results of the search I specified in my previous post. I need that information. Thanks!
Ok I downloaded and ran Agent Ransack, but I am having trouble copying the results, I didnt have the clipboard viewer installed, I did that but it looks like a bunch of encrypted carp**, can you help me with this???? Julia
After you have copied the search results to the clipboard… all you should need to do is right click and paste it into a reply here. No need to view it with a viewer. Just paste it into your reply. Thanks!
C:\windows\system\RDAPH.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\OREXL32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\WFNMM.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\JLEG1X32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PLPWRENU.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\WNNMM.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PQBASE.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\RZCLTSPX.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\CYPBK32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\MUVBVM50.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\in50_qcx.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\OOCACHE.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\ORPDX32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PKTOREC.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\ckmintfs.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\OSTWA400.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\Tyain.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\JREG1X32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\DONDI.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\wA5inf16.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\HVDCI.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\RLCRES.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\MTXML4r.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\Aol.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\ixtrigue.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\OKEACC.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\AMIFILE.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\wav8dmoe.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\OTEPRO32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\MMXMLR.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\qNsf.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\qudit.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\CRPBK32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\tUembed.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\irctl.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\LKNKINFO.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\lzclr13n.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PxpOops.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dq8vb.dll (222 KB, 5/11/05 9:30:32 AM)
OK… we got quite a list to go through…. take your time… make sure you've gotten all the files…

Copy/paste this into notepad or wordpad for reference during the fix.

Disconnect from the Internet. Unplug the cable to your modem if need be.

Close all open windows and programs, then start Killbox. Click the radial beside "Replace on Reboot", put a check in the box beside "Use Dummy".

Copy this line in "Full Path of File to Delete" box:
C:\windows\system\RDAPH.DLL

Click the red and white "Delete File" button.
Click "Yes" at the first prompt .
Click "No" at the second.

Repeat those same steps for each of these files one at a time:

C:\windows\system\OREXL32.DLL
C:\windows\system\WFNMM.DLL
C:\windows\system\JLEG1X32.DLL
C:\windows\system\PLPWRENU.DLL
C:\windows\system\WNNMM.DLL
C:\windows\system\PQBASE.DLL
C:\windows\system\RZCLTSPX.DLL
C:\windows\system\CYPBK32.DLL
C:\windows\system\MUVBVM50.DLL
C:\windows\system\in50_qcx.dll
C:\windows\system\OOCACHE.DLL
C:\windows\system\ORPDX32.DLL
C:\windows\system\PKTOREC.DLL
C:\windows\system\ckmintfs.dll
C:\windows\system\OSTWA400.DLL
C:\windows\system\Tyain.dll
C:\windows\system\JREG1X32.DLL
C:\windows\system\DONDI.DLL
C:\windows\system\wA5inf16.dll
C:\windows\system\HVDCI.DLL
C:\windows\system\RLCRES.dl
C:\windows\system\MTXML4r.dll
C:\windows\system\Aol.dll
C:\windows\system\ixtrigue.dll
C:\windows\system\OKEACC.DLL
C:\windows\system\AMIFILE.DLL
C:\windows\system\wav8dmoe.dll
C:\windows\system\OTEPRO32.DLL
C:\windows\system\MMXMLR.DLL
C:\windows\system\qNsf.dll
C:\windows\system\qudit.dll
C:\windows\system\CRPBK32.DLL
C:\windows\system\tUembed.dll
C:\windows\system\irctl.dll
C:\windows\system\dlvacm.dll
C:\windows\system\LKNKINFO.DLL
C:\windows\system\lzclr13n.dll
C:\windows\system\PxpOops.dll
C:\windows\system\dq8vb.dll
C:\WINDOWS\seeve.exe
C:\WINDOWS\deskbar.ini
C:\WINDOWS\VT17.exe
C:\WINDOWS\myurlff.exe
C:\WINDOWS\SYSTEM\HLInstaller1.exe
C:\WINDOWS\SYSTEM\HyperLinker1.exe
C:\WINDOWS\SYSTEM\wincoreak.dll
C:\WINDOWS\SYSTEM\winrulesak.dll
C:\WINDOWS\SYSTEM\intrigue.dll
C:\WINDOWS\TEMP\tsvcin.exe
C:\WINDOWS\TEMP\uppicsvr.exe
C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe
C:\Program Files\backups\backup-20050605-162607-874.inf
C:\WrapperOuter.exe
C:\Program Files\Intrigue Learning
C:\WINDOWS\All Users\Application Data\AdDestroyer
C:\WINDOWS\All Users\Application Data\VBouncer


Exit Killbox when done.

Reboot Windows normally. Run Agent Ransack like you did before and post the new log please. With the amount of files in there, we may need to take a few cracks at this.
Ok I got that done and most of them seem to have been deleted. There were maybe 5-7 of them that said " file does not seem to exsist " I think all of them were things I manually deleted yesterday. Anyhow there were 1-2 of them that said " file could not be deleted " Also I left 2 of the listings there because they are related to a program I use called PC Power Scan, I didnt want the program to become unusuable since it is a paid program. The list this time around is much, much shorter though, I hope this is a GOOD sign????? Here are the Agent Ransack results: C:\windows\system\COSEQCHK.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PWWEROLD.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\IYM32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\RLCRES.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dfdmoprp.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\cJbinet.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\hczpm110.dll (222 KB, 5/11/05 9:30:32 AM) Thanks! Julia
I have another question. I use the Yahoo Anti-Spy tool and it keeps detecting the IST bar. It was coming up with 99 objects and I always hit remove, but it keeps coming back. Now I just did another scan and its there again but with 17 objects. I have tried to find a removal tool online for this but no success. Do you know how to zap it for good?? Julia
Can you let me know which of the entries you felt were related to PCPowerScan? By my research and the logs you posted… all on that list should have been deleted.

Not sure.. but the Yahoo bar might be incorrectly detecting L2M(the infection we're trying to squish on your machine right now). Seems likely as it has gone from 90+ entries down to 17 after the last fix steps. I have not seen anything else in your logs that suggest ISTBar.

Download VX2Finder(126). Don't run it yet.

Copy/Paste this into notepad or wordpad for reference during the fix.

As before, disconnect from the Internet. Unplug the cable to your modem if need be.

Close all open windows and programs, then start Killbox. Click the radial beside "Replace on Reboot", put a check in the box beside "Use Dummy".

Copy this line in "Full Path of File to Delete" box:

C:\windows\system\COSEQCHK.DLL

Click the red and white "Delete File" button.
Click "Yes" at the first prompt .
Click "No" at the second.

Repeat those same steps for each of these files one at a time:

C:\windows\system\PWWEROLD.DLL
C:\windows\system\IYM32.DLL
C:\windows\system\RLCRES.dll
C:\windows\system\dlvacm.dll
C:\windows\system\dfdmoprp.dll
C:\windows\system\cJbinet.dll
C:\windows\system\hczpm110.dll


Exit Killbox when done.

Reboot Windows normally.

Run VX2Finder and click the following button:

Click to Find VX2.BetterInternet

Then click the User Agent button. When asked if you want to delete the file, click "yes" or OK.

Do another search with Agent Ransack, just like before, and post the log please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI