This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Fix spyware and Windows won't operate properly

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm having a problem removing a spyware program. This computer has the file, winocx32.exe which is running multiple processes. This program is apparently installed by the PROTORIDE worm.

Using HJT and following directions, I stopped the winocx32 processes running in Task Manager, reran HJT and successfully deleted the entry. Then I located and deleted the winocx32.exe file.

After that, Windows could no longer find and run *any* file on the computer.

I get the error message, "Windows cannot find 'xxx.exe'. Make sure you typed the name correctly…" [where xxx.exe is any program, ie winword.exe, hjt.exe, etc]. The only programs that will run are the connecting software (SBC DSL) and IE.

Rebooting doesn't fix this, nor does safe mode. Windows loads, but it can't load anything else.

Experimenting, I found that restoring winocx32.exe to the directory it came from (…all users\start menu\programs\startup) allows windows to operate normally again. It's like a toggle: remove winocx32 from that directory, nothing can be found/run; put it back, all is normal.

How do I remove this thing from the computer and leave it operating?

A HJT log is below, but it was run with the winocx32 operating, because of course Windows can't find HJT without it.

Thanks,
Ed


Logfile of HijackThis v1.99.1
Scan saved at 12:10:47 PM, on 6/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\Yahoo!\browser\YBrowser.exe
c:\documents and settings\all users\start menu\programs\startup\winocx32.exe
c:\documents and settings\all users\start menu\programs\startup\winocx32.exe
c:\documents and settings\all users\start menu\programs\startup\winocx32.exe
C:\DOCUME~1\Admin\Desktop\ED'SHI~1\HIJACK~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/sbcydsl/defa…hoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/sbcydsl/defa…hoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.platinum-electronics.com/atention.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\WCESCOMM.EXE"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MsUpdate.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: winocx32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097790069171
O17 - HKLM\System\CCS\Services\Tcpip\..\{C441EEC4-C37A-4975-9165-40E0C13EC9BB}: NameServer = 206.13.28.12 206.13.29.12
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Hello Ed, Welcome to TomCoyote. Sorry for the wait, if you are not being helped elsewhere then follow these directions in the posted order.

1) ED'SHI~1 is what you have called the folder where HJT must store the .exe, logs and backups. I have no problem with this just do not store anything but HJT related in that folder. Thanks.

2) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions on the download page so that when I ask you to run it you will know what you are doing.

3) This item reads for CoolWebSearch: http://www.liutilities.com/products/wintas…brary/MSupdate/ Let's run CWShredder to be sure. Download from the following site, updates and click on FIX not scan. Allow it to run and remove anything it locates. Let me know what it finds in your next post.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

4) Ewido trojan scanner: http://www.ewido.net/en/download/
Please download, install, update and scan your system with the free version of Ewido trojan scanner:
  1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  3. From the main ewido screen, click on update in the left menu, then click the Start update button.
  4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack….
  5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  6. When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread.

  7. 5) Open Task Manager then the Processes teb and end process on any instance of this item that is running:
    c:\documents and settings\all users\start menu\programs\startup\winocx32.exe

    6) TeaTimer is a good program, but itll block the HJT fix. Use these instructions to turn it off. Bet sure to active it after the fix for it's realtime protection.
    http://russelltexas.com/malware/teatimer.htm

    7) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rd.yahoo.com/customize/sbcydsl/defa…hoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defa…/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
    O4 - Global Startup: MsUpdate.exe
    O4 - Global Startup: winocx32.exe
    O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll

    Close all programs but HJT and all browser windows, then click on "Fix Checked"

    8) SHOW HIDDEN FILES: Follow the instructions in the link to enable hidden files for your operating system.
    You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
    http://www.xtra.co.nz/help/0,,4155-1916458,00.html

    RIGHT Click on Start then click on Explore. Locate and delete these items:

    You will need to search for this one, might be gone?
    MsUpdate.exe >>> file

    c:\documents and settings\all users\start menu\programs\startup\winocx32.exe >>> file

    Locate C:\Windows\Prefetch folder and open it. Delete the contents of the folder (NOT THE FOLDER) if there are many choose Edit then Select all then Delete. You may not be able to remove them all, don't be concerned unless any have the name of the items we need to remove. Here is some information about the Prefetch for you:
    http://techrepublic.com.com/5100-6270-5165773.html
    http://www.pcmag.com/article2/0,1759,1683520,00.asp

    9) Run CCleaner then restart the computer and post a new HJT log along with the Ewido scan results in this same thread along with any feedback you have. Let us know how you are running.

    Thanks…pskelley
    TomCoyote forum
    Slyware Warrior

    PURGE SYSTEM RESTORE
    When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instructions:
    http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam
Hi, I got your message after I'd already begun working through the Protoride removal. I was successful, but I'm really grateful for your tips; they'll be very handy the next time. FYI, the process went something like this: 1) Using HJT I killed the processes outlined in the last message, then 2) I switched to Safe Mode and renamed the winocx32.exe and MSUpdate files. 3) This put me back in the "windows won't run" situation, but did leave me IE (IE kept working through all this) and access to Trend Micro's scan, which quickly found the still-running protoride worm. Trend could stop it temporarily, but not clean the system. While it was stopped… 4) By this time, I was having more trouble with the two-years-out-of-date McAffee programs, so I deleted them. [Am I the only one who finds McAffee and Norton causing more problems these days than they fix?] 5) Installed AVG anti-virus and ran it, which found 14 (!) copies of Protoride on the system and was able to clean them up. 6) Then to safe mode, where I deleted the winocx32 and MSupdate programs, and re-ran AVG, which found another 10 or so different worms, trojans and viruses on the system (including the Britney Spears!) that had been hidden by the Protoride and was able to kill them. 7) Then back to regular mode, reran HJT, killed every process related to SBC's Yahoo! software except the connection [and the #*& Yahoo Messenger, which has defied my every attempt to remove it], deleted all temp files, deleted all IE saved files, rebooted regularly, reran AVG etc etc etc and finally came up with a clean machine. 8) Ran Registry Cleaner, reinstalled Spybot, set up Zone Alarm, made sure all Windows patches were installed, and HOPEFULLY I am done with that system for a while! :) Wow! Thanks again. If it wasn't for you guys, dealing with this stuff would be impossible. Ed
Hey Ed, That sounds cool…You ever want to learn more about this process there are several free schools including one here at TomCoyote. Just let one of us know. Here is the information I give when a log is clean to help folks stay that way:
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

I would also be glad to look at a last log for you to make sure this is true.
I will leave your thread open for a few days in the event you would like to do this.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Thanks, PSKelley, Yes, I think I'll take the classes you recommend. I'm doing more and more of this: all my friends/family/friends-of, etc etc rely on me (I've been ordered a) never to die; and B) never to go anywhere where I can't be reached, otherwise "who will fix our computers??!" As they say, No Good Deed Goes Unpunished…). I've learned a lot but there's clearly more to go. The cleaned (I hope) HTJ log is below. Thanks again! Ed Logfile of HijackThis v1.99.1 Scan saved at 4:37:08 PM, on 6/30/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\MMKeybd.exe C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe C:\Program Files\Dell\Support\Alert\bin\DAMon.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\MICROS~3\WCESCOMM.EXE C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe C:\Program Files\Netropa\Traymon.exe C:\Program Files\Netropa\OSD.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Grisoft\AVG Free\avgwb.dat C:\Program Files\Grisoft\AVG Free\avgvv.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Documents and Settings\Admin\My Documents\Ed's hijack this folder\HijackThis.exe
Hey Ed, Post the complete log, you cut it in half… :lol: I'll post links to TC Classroom and Malware Removal University shortly.
TomCoyote Classroom: http://forums.tomcoyote.org/index.php?showtopic=1421

Malware Removal University:
This school was started a short while ago by a good friend in the UK. Smaller, so you might get more personal attention? I must say I was in contact with another friend in the UK and she told me that there is a server issue that has several sites down and Malware Removal is one of them. I sure it will be up soon but do not quote me on that. I have to give you the link I use http://www.malwareremoval.com/ since I can't link to anything else right now. When you get in, just look for Malware University link at the top and you will find the information there. Good luck.

Send me that whole log and I'll check it out…Phil
Oops! I only copied half the HJT log before I left that machine. Not there now and won't be for a while (praying to deities now) so I'd say just consider this thread done. Thanks again! Ed
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI