This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis log, help please

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok The 2 entries for PC Power Scan were: C:\WINDOWS\SYSTEM\intrigue.dll C:\Program Files\Intrigue Learning The only Intrique Learning programs I have installed is the PC Power Scan so I was afraid that if I deleted anything that had to do with Intrique Learning it would mess up the program. I downloaded the VX2Finder9X and ran it like you said. I hope I am still supposed to be using Agent Ransack under these terms????? Start Agent Ransack. [x] check expert user In the text containing field copy/paste this in: (UMonitor|IsProcessorFeaX|NictechNetworks)+ In the Look in field paste in: C:\windows\system [ ] uncheck the box to search sub folders Click Start search Here is my new Agent Ransack file: C:\windows\system\DIMSSOCN.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PWWEROLD.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\IYM32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\RLCRES.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dfdmoprp.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\cJbinet.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\hczpm110.dll (222 KB, 5/11/05 9:30:32 AM) I must say you sure are persistant also! You are sticking in there with me……Thanks a bunch Julia
Thanks for the info on PC Power Scan… Panda was confusing it with PowerScan by IST.

And yes… you are doing the Agent Ransack searches correctly. If I need you to do a different one, I will give specific instructions for it.

OK… lets try this again… little differently this time…

Copy/paste this into notepad or wordpad for reference during the fix.

As before, disconnect from the Internet. Unplug the cable to your modem if need be.

Close all open windows and programs, then start Killbox. Click the radial beside "Replace on Reboot", put a check in the box beside "Use Dummy".

Copy this line in "Full Path of File to Delete" box:

C:\windows\system\DIMSSOCN.DLL

Click the red and white "Delete File" button.
Click "Yes" at the first prompt .
Click "No" at the second.

Repeat those same steps for each of these files one at a time:

C:\windows\system\PWWEROLD.DLL
C:\windows\system\IYM32.DLL
C:\windows\system\RLCRES.dll
C:\windows\system\dlvacm.dll
C:\windows\system\dfdmoprp.dll
C:\windows\system\cJbinet.dll
C:\windows\system\hczpm110.dll


Exit Killbox when done.

Run VX2Finder9x.exe again

Click Find VX2.betterinternet

If any files are found, click make log and post it, if not continue on.

Then click User Agent, dont be alarmed it will restore the proper one.

Click Restore Desktop, (If its not dimmed out)dont be alarmed the desktop will disappear then reappear again

Click Import Reg, then exit the tool.

Reboot Windows normally(you may need to rearrange your taskbar/quicklaunch bar.

Do another Agent Ransack search and post the results please.
Ok here we go again, are we having fun yet??? Here is what was in the box after doing the VX2 finder: VX2 finder results: Files Found— User Agent String— {8B6BAA29-4C7A-400C-E0CF-748146E37055} I also have found a new problem that just cropped up this afternoon…..Like I dont have enough problems??? Haa haa. Anyhow my Outlook Express is acting up. It wont open up any Hyper links now. I tried several different emails none will open up the links in a new browser window……Any idea what caused this or how to fix it…Also on my yahoo pager links wont open either. Like the screen that says you have mail,,,,,you can usually click it and it takes you to your email. It doesnt do anything now……….. Here is the newest Agent Ransack results: C:\windows\system\WXNINET.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\PWWEROLD.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\IYM32.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\RLCRES.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dfdmoprp.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\cJbinet.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\hczpm110.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\mHpistub.dll (222 KB, 5/11/05 9:30:32 AM) Just a question, is there some reason all these results have the same date and time stamp on them???? I wish I knew more about all this stuff…. Julia
This is always fun :)

As for the correllation between the infection and the time stamps on the files…. yes. That is a sign of the infection… as is the fact they are all 222 KB in size.

OK… gotta be something the scans arent showing…

Going to get you to try another tool.

Download FindIt9x/ME
Extract(unzip) the files to a folder. Browse to where you extracted the files and double click on FindIt9xME.bat

Once the scan is done.. notepad should open with log. Copy the contents of that log into your reply.

Also, if you have rebooted since you posted the last Agent Ransack search results… can you do another search and post the results.

Thanks!
Ok I tried the FindIt9xME, I hope I copied what you wanted: Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM 18,470.81 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM FOLDER HTT 13,122 05-21-05 3:24p folder.htt DESKTOP INI 266 05-21-05 3:24p desktop.ini 2 file(s) 13,388 bytes 0 dir(s) 18,470.80 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{8B6BAA29-4C7A-400C-E0CF-748146E37055}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ folder.htt Sat May 21 2005 3:24:10p …H. 13,122 12.81 K desktop.ini Sat May 21 2005 3:24:10p …H. 266 0.26 K 2 items found: 2 files, 0 directories. Total of file sizes: 13,388 bytes 13.07 K ———— Strings.exe Qoologic Results ———— C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] I couldnt figure out how to copy what was in the black screen ( MS Dos )……I hope thats not what you needed. Here is the newest Agent Ransack, I am thinking maybe I should just throw in the towel and surrender???? before I manage to crash my system……. C:\windows\system\WXNINET.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) I do know both of these files are related to the adware Look2me.af , I have deleted them before and they keep returning.GGGGGGGRRRRRR ok i'm about to give up………..Thanks again for all your help and patience. Julia
Don't give up on me now… if Agent Ransack only found thos two files, we may be real close :)

Download the Hoster. Extract(unzip) it to a folder.

Copy/paste this into notepad or wordpad for reference during the fix

Copy/paste the following quotebox into a new notepad document.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{8B6BAA29-4C7A-400C-E0CF-748146E37055}"=-


Save it to your desktop as fixme.reg. Save it File Type "All Files"(not as a plain text document or it won't work).

Disconnect from the net… totally… unplug the cable to your modem.

Start Killbox. Click the radial beside "Replace on Reboot", put a check in the box beside "Use Dummy".

Copy this line in "Full Path of File to Delete" box:

C:\windows\system\WXNINET.DLL

Click the red and white "Delete File" button.
Click "Yes" at the first prompt .
Click "No" at the second.

Repeat those same steps for each of these files one at a time:

C:\windows\system\dlvacm.dll

Exit Killbox when done.

Double click fixme.reg, answer yes to merge it into the registry.

Run the Hoster. Press the "Restore original Hosts File" button. Exit the program.

Reboot.

Run another FindIt scan along with another Agent Ransack scan please. Posts the logs in your reply.
Ok here is the latest Agent Ransack log: C:\windows\system\dknwsock.dll (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) It looks like dlvacm.dll is being a diehard???????? Here is the FindIt9xme log: Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM DLVACM DLL 226,592 05-11-05 9:30a dlvacm.dll 1 file(s) 226,592 bytes 0 dir(s) 18,467.03 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM FOLDER HTT 13,122 05-21-05 3:24p folder.htt DESKTOP INI 266 05-21-05 3:24p desktop.ini 2 file(s) 13,388 bytes 0 dir(s) 18,467.02 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{8B6BAA29-4C7A-400C-E0CF-748146E37055}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ folder.htt Sat May 21 2005 3:24:10p …H. 13,122 12.81 K desktop.ini Sat May 21 2005 3:24:10p …H. 266 0.26 K dlvacm.dll Wed May 11 2005 9:30:32a ..S.R 226,592 221.28 K 3 items found: 3 files, 0 directories. Total of file sizes: 239,980 bytes 234.36 K ———— Strings.exe Qoologic Results ———— C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] I dont know if I did something wrong but I couldnt get the fixme.reg to take. It kept telling me it couldnt do it…….it said it couldnt import it, that the specified file is not a registry script….. ????????? Julia
Any advice on the hyper link problem??? All of the Outlook Express fixes havent fixed it…………..I'm batting 1000….. Julia
Re the regfix… I messed it up… this one should work for you… recopy it please.

Sorry :oops:

REGEDIT 4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{8B6BAA29-4C7A-400C-E0CF-748146E37055}"=-


Save it just like before.

We'll try this again…

Disconnect from the net.

Double click fixme.reg. Answer yes to merge it into the registry.

Start Killbox. Click the radial beside "Replace on Reboot", put a check in the box beside "Use Dummy". Put a check in the box "End Explorer Shell While Killing File".

Copy this line in "Full Path of File to Delete" box:

C:\windows\system\dknwsock.dll

Click the red and white "Delete File" button.
Click "Yes" at the first prompt .
Click "No" at the second.

Repeat those same steps for each of these files one at a time:

C:\windows\system\dlvacm.dll

Exit Killbox when done.

Reboot. Run FindIt and Agent Ransack again and post the logs please.
New Agent Ransack log: C:\windows\system\DT3J.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) I dont think dlvacm.dll wants to leave me……….am I stuck with it for good???? New Findit log: Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM DLVACM DLL 226,592 05-11-05 9:30a dlvacm.dll 1 file(s) 226,592 bytes 0 dir(s) 18,488.66 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM FOLDER HTT 13,122 05-21-05 3:24p folder.htt DESKTOP INI 266 05-21-05 3:24p desktop.ini 2 file(s) 13,388 bytes 0 dir(s) 18,488.64 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{8B6BAA29-4C7A-400C-E0CF-748146E37055}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ folder.htt Sat May 21 2005 3:24:10p …H. 13,122 12.81 K desktop.ini Sat May 21 2005 3:24:10p …H. 266 0.26 K dlvacm.dll Wed May 11 2005 9:30:32a ..S.R 226,592 221.28 K 3 items found: 3 files, 0 directories. Total of file sizes: 239,980 bytes 234.36 K ———— Strings.exe Qoologic Results ———— C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Wow :blink: Think I'm going to have to get another set of eyes on this… I'm missing something, or the scan are, but I'm not sure what… Will reply back as soon as I can. You've done great so far Julia. Hang in there… we will get this cleaned up!
I will be watching for your next post. I very much appreciate all your time and help so far……..BTW the pop ups are very infrequent now. So atleast you did help to clear that up……I think I might have to re install Outlook Express to fix that…….. Julia
Hi Julia…

Got something else for you to try.

Click Start>Run, type in regsvr32 /u DT3J.DLL hit Enter. Click Start>Run, type in regsvr32 /u dlvacm.dll hit Enter.

Run Killbox. Click the radial beside "Replace on Reboot", put a check in the box beside "Use Dummy". Copy this line in "Full Path of File to Delete" box:

C:\windows\system\DT3J.DLL

Click the red and white "Delete File" button.
Click "Yes" at the first prompt .
Click "No" at the second.

Repeat those same steps for each of these files one at a time:

C:\windows\system\dlvacm.dll

Exit Killbox when done.

Reboot. Run FindIt and Agent Ransack again and post the logs please.
Ok doing these steps did nothing, got error messages. Click Start>Run, type in regsvr32 /u DT3J.DLL hit Enter. Click Start>Run, type in regsvr32 /u dlvacm.dll hit Enter. Here is the agent ransack log: C:\windows\system\SESTHUNK.DLL (222 KB, 5/11/05 9:30:32 AM) C:\windows\system\dlvacm.dll (222 KB, 5/11/05 9:30:32 AM) is it normal for new things to keep popping up???? after doing so many scans, I havent seen the SESTHUNK.DLL before and dlvacm.dll is still hanging in there!!!!!! new find it log: Warning! This utility will find legitimate files in addition to malware. Do not remove anything unless you are sure you know what you're doing. ——- System Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM DLVACM DLL 226,592 05-11-05 9:30a dlvacm.dll 1 file(s) 226,592 bytes 0 dir(s) 18,471.88 MB free ——- Hidden Files in System Directory ——- Volume in drive C has no label Volume Serial Number is 0352-1513 Directory of C:\WINDOWS\SYSTEM FOLDER HTT 13,122 05-21-05 3:24p folder.htt DESKTOP INI 266 05-21-05 3:24p desktop.ini 2 file(s) 13,388 bytes 0 dir(s) 18,471.86 MB free —————- User Agent ———— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{8B6BAA29-4C7A-400C-E0CF-748146E37055}"="" —————— Locate.com Results —————— C:\WINDOWS\SYSTEM\ folder.htt Sat May 21 2005 3:24:10p …H. 13,122 12.81 K desktop.ini Sat May 21 2005 3:24:10p …H. 266 0.26 K dlvacm.dll Wed May 11 2005 9:30:32a ..S.R 226,592 221.28 K 3 items found: 3 files, 0 directories. Total of file sizes: 239,980 bytes 234.36 K ———— Strings.exe Qoologic Results ———— C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com ————– Strings.exe Aspack Results ————- —————– HKLM Run Key —————— ————– Strings.exe Umonitor Results ————- REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] Grrrrrrrrrrr Julia
Ok I am about to say the " heck " with it, but I wanted to let you know I did all of these scans with the following results: Spyzooka - says my system is clean Spybot - no threats found Yahoo Anti-Spy - no items found Ad-Aware - 0 new critical objects A Squared - :rant2: :scratch: So with these all saying im clean, what do you think ??? I have been online a few times and for quite a bit of time this morning and havent had even 1 annoying pop up. So I think atleast that part of this was a complete success!!!!!!! Now to fix my Outlook Express and Hpyer link prblem and i'll be a happy camper again……. <_< Julia

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI