This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer Is All Screwed Up, Someone Please Look At Log F

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm trying to fix several problems on my parents computer, which is completely a mess. There are all kinds of viruses and spyware on this thing, and when I first boot up I get an error message titled RUNDLL saying "Error Loading C:\WINNT\System32\qgmkxsc.dll The specified module could not be found." Also, when I try to run Ad-Aware, the computer suddenly turns off and restarts after the program has been scanning for a minute or so. This is probably related to one of several viruses I'm sure this computer has, but I can't figure out a way around it. Here is the logfile from HiJackThis, any help on any of these issues would be much appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 7:43:47 PM, on 6/18/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\WINNT\System32\rundll32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\winnt\system32\drivers\uzcx.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\wdfmgr.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://mww.metlife.com
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {040FA520-78C6-41ce-81D0-9E733ABC1A29} - (no file)
O2 - BHO: (no name) - {619E74DB-8513-EDC7-1977-070178CEBFB7} - C:\WINNT\System32\ueheokj.dll (file missing)
O2 - BHO: Hook Class - {6E3D2E1D-7B23-41c8-8A6C-13012A889F99} - C:\WINNT\System32\rasda2.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_02\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: Hgni_BHO - {888826A1-3C63-4687-8696-482FDBB129DF} - C:\WINNT\System32\hgni_ecol.dll
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINNT\webdir.dll
O2 - BHO: (no name) - {D15ED657-BA6D-41B3-82FE-1C54F28D3C8F} - C:\WINNT\System32\cbayy.dll (file missing)
O2 - BHO: Hook Class - {DBA0F35F-BCD6-4602-863A-96893E4DE018} - C:\WINNT\System32\repl.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\System32\wintask.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [qgmkxsc.dll] C:\WINNT\System32\rundll32.exe C:\WINNT\System32\qgmkxsc.dll,hjfxco
O4 - HKLM\..\Run: [winsync] C:\WINNT\System32\pwrkic.exe reg_run
O4 - HKLM\..\Run: [yvqvgpcb] yvqvgpcb.dll,Check
O4 - HKLM\..\Run: [Alexa bridge] C:\WINNT\System32\wbcdubwn.exe
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINNT\System32\svchost.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iut75] c:\winnt\system32\drivers\uzcx.exe
O4 - HKLM\..\Run: [System] C:\WINNT\System32\kernels32.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [cbfac659.exe] C:\Documents and Settings\Ellen.METLIFE-LD9RZ5I\Local Settings\Application Data\cbfac659.exe
O4 - HKCU\..\Run: [WinSecureDisc] "C:\Program Files\WinSecureDisc\App.exe"
O4 - HKCU\..\Run: [Ultimate Defender.install] "C:\Documents and Settings\Ellen.METLIFE-LD9RZ5I\Local Settings\Temporary Internet Files\Content.IE5\WHQVO56R\udefender_QgaHo26bYG[1].exe" continue
O4 - HKCU\..\RunOnce: [gi1194959841] "C:\DOCUME~1\ELLEN~1.MET\LOCALS~1\Temp\giM389KF.exe" /resume:"C:\DOCUME~1\ELLEN~1.MET\LOCALS~1\Temp\2CM388NU" /exename:"C:\Documents and Settings\Ellen.METLIFE-LD9RZ5I\Local Settings\Temporary Internet Files\Content.IE5\CL2JODER\Super_Text_Twist_msgh-setup[1].exe"
O4 - Startup: .protected
O4 - Global Startup: .protected
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://mww.metlife.com
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{54A70802-162F-4088-9E89-706B550EADEF}: NameServer = 85.255.114.28,85.255.112.99
O17 - HKLM\System\CCS\Services\Tcpip\..\{55955E18-2F92-434A-A3A8-A29F1B9C5879}: Domain = metlife.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{55955E18-2F92-434A-A3A8-A29F1B9C5879}: NameServer = 85.255.114.28,85.255.112.99
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O20 - Winlogon Notify: cbayy - C:\WINNT\System32\cbayy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winidp32 - winidp32.dll (file missing)
O21 - SSODL: cholecyst - {ee2975b6-e8d5-405e-8448-8fe9590f6cfb} - C:\WINNT\System32\mzoeut.dll (file missing)
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINNT\System32\pmnqguh.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
Hi GaryL727 Welcome to the TomCoyote Forums My name is mschroe919 and I am going to read your log. I would like to help you So if you would…. Please be patient and I will be back as soon as possible. A fast look shows there is a lot of bad things on your pc. I will be back as soon as possible. There will be a lot of posting back and forth here. But the good news is we are going to start. mschroe919
. Hi GaryL727
You may want to print out these instructions for reference, since you will have to restart your computer during the fix.
NOTE DO NOT DELETE ANYTHING TILL ASKEDTO DO SO

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts. Afterwards, Hijack This will launch. Close Hijack This, and click OK to proceed. )
NEXT:
Run HijackThis and Scan.
Check box for:
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: (no name) - {040FA520-78C6-41ce-81D0-9E733ABC1A29} - (no file)
O2 - BHO: (no name) - {619E74DB-8513-EDC7-1977-070178CEBFB7} - C:\WINNT\System32\ueheokj.dll (file missing)
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\System32\wintask.exe
O4 - HKLM\..\Run: [qgmkxsc.dll] C:\WINNT\System32\rundll32.exe C:\WINNT\System32\qgmkxsc.dll,hjfxco
O17 - HKLM\System\CCS\Services\Tcpip\..\{54A70802-162F-4088-9E89-706B550EADEF}: NameServer = 85.255.114.28,85.255.112.99
O17 - HKLM\System\CCS\Services\Tcpip\..\{55955E18-2F92-434A-A3A8-A29F1B9C5879}: Domain = metlife.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{55955E18-2F92-434A-A3A8-A29F1B9C5879}: NameServer = 85.255.114.28,85.255.112.99
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.28 85.255.112.99

Please remember to close all other windows, including browsers then click Fix checked
NEXT:
we want to show hidden files here is how:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
NEXT:
Please download ATF Cleaner by Atribune.

Download Here:
http://www.atribune.org/ccount/click.php?id=1

This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
NEXT:
Using Windows Explorer, locate the following files/folders, and delete the folders inRED
Not to worry if not there.
C:\WINNT\System32\ueheokj.dll
C:\WINNT\System32\wintask.exe
C:\WINNT\System32\qgmkxsc.dll

Finally, please post a fresh HijackThis log, along with the contents of the logfile C:\fixwareout\report.txt
At the end of the fix, you may need to restart your computer again.

Now lets check some settings on your system.
(2000/XP) Only
In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)
There will be more when we see the new logs
This is quite a lot to do now.
Good luck mschroe919
Thanks mschroe919
I did everything you said. None of those files you asked me to delete were in the system32 folder. Also some of the hijackthis items you told me to select were gone when I ran it this time. I think it's because I disabled some startup items in msconfig yesterday that I knew to be malware. Let me know if I should have done something differently or if this is ok. Here are the new logs. Thanks in advance for your help.



Logfile of HijackThis v1.99.1
Scan saved at 3:56:41 PM, on 6/19/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\winnt\system32\drivers\uzcx.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yankees.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://mww.metlife.com
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Hook Class - {6E3D2E1D-7B23-41c8-8A6C-13012A889F99} - C:\WINNT\System32\rasda2.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_02\bin\ssv.dll (file missing)
O2 - BHO: Hgni_BHO - {888826A1-3C63-4687-8696-482FDBB129DF} - C:\WINNT\System32\hgni_ecol.dll
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINNT\webdir.dll
O2 - BHO: (no name) - {D15ED657-BA6D-41B3-82FE-1C54F28D3C8F} - C:\WINNT\System32\cbayy.dll (file missing)
O2 - BHO: Hook Class - {DBA0F35F-BCD6-4602-863A-96893E4DE018} - C:\WINNT\System32\repl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [winsync] C:\WINNT\System32\pwrkic.exe reg_run
O4 - HKLM\..\Run: [yvqvgpcb] yvqvgpcb.dll,Check
O4 - HKLM\..\Run: [Alexa bridge] C:\WINNT\System32\wbcdubwn.exe
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINNT\System32\svchost.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iut75] c:\winnt\system32\drivers\uzcx.exe
O4 - HKCU\..\Run: [cbfac659.exe] C:\Documents and Settings\Jerry\Local Settings\Application Data\cbfac659.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Add to AD Black List - C:\PROGRA~1\AVANTB~1\AddToADBlackList.htm
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Block All Images from the Same Server - C:\PROGRA~1\AVANTB~1\AddAllToADBlackList.htm
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Download all by Net Transport - E:\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - E:\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Highlight - C:\PROGRA~1\AVANTB~1\Highlight.htm
O8 - Extra context menu item: Open All Links in This Page… - C:\PROGRA~1\AVANTB~1\OpenAllLinks.htm
O8 - Extra context menu item: Open In New Avant Browser - C:\PROGRA~1\AVANTB~1\OpenInNewBrowser.htm
O8 - Extra context menu item: Search - C:\PROGRA~1\AVANTB~1\Search.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://mww.metlife.com
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O20 - Winlogon Notify: cbayy - C:\WINNT\System32\cbayy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winidp32 - winidp32.dll (file missing)
O21 - SSODL: cholecyst - {ee2975b6-e8d5-405e-8448-8fe9590f6cfb} - C:\WINNT\System32\mzoeut.dll (file missing)
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINNT\System32\pmnqguh.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)



Fixwareout Last edited 5/15/2007
Post this report in the forums please
…
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kddgx.exe"

»»»»»

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
….
»»»»» Misc files.
….
»»»»» Checking for older varients.
….

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.


Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other
C:\WINNT\Temp\kddgx.ren 0 06/19/2003

»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"
"WinTask driver"="C:\\WINNT\\System32\\wintask.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"winsync"="C:\\WINNT\\System32\\pwrkic.exe reg_run"
"yvqvgpcb"="yvqvgpcb.dll,Check"
"Alexa bridge"="C:\\WINNT\\System32\\wbcdubwn.exe"
"RunOnce2Upd"="\"C:\\WINNT\\System32\\svchost.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iut75"="c:\\winnt\\system32\\drivers\\uzcx.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cbfac659.exe"="C:\\Documents and Settings\\Jerry\\Local Settings\\Application Data\\cbfac659.exe"
"HXIPCMAE"=""
"micore"=""
"IPConfig"=""
"wcheckup"=""
….
Hosts file was reset, If you use a custom hosts file please replace it
C:\WINNT\System32\AUTOEXEC.NT missing
»»»»» End report »»»»»
Hi GaryL727
Sorry about the delay in getting back to you. Wanted to research a little'
Double click "My Computer" then your hard drive (probably C drive) and open the C:\WINDOWS folder.

Go down to the "Repair" folder and double click. You should find "autoexec.nt" and "config.nt" in there. Copy these files (Ctrl+C) then go back to C:\Windows\SYSTEM32 and paste them there (Ctrl+V). It will ask you if you want to replace the old one—click "Yes".

NEXT:

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

Next:

Launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: * files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinTask driver"=-
"yvqvgpcb"=-
"winsync"=-
"Alexa bridge"=-
"iut75"=-


Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like this: [external image: Posted Image]
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
(In case you are unsure how to create a reg file, take a look here with screenshots.)

NEXT:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Hook Class - {6E3D2E1D-7B23-41c8-8A6C-13012A889F99} - C:\WINNT\System32\rasda2.dll
O2 - BHO: Hgni_BHO - {888826A1-3C63-4687-8696-482FDBB129DF} - C:\WINNT\System32\hgni_ecol.dll
O2 - BHO: CWebDirObj Object - {C003C49F-53E4-4A72-B7D6-0B2B9997392F} - C:\WINNT\webdir.dll
O2 - BHO: (no name) - {D15ED657-BA6D-41B3-82FE-1C54F28D3C8F} - C:\WINNT\System32\cbayy.dll (file missing)
O2 - BHO: Hook Class - {DBA0F35F-BCD6-4602-863A-96893E4DE018} - C:\WINNT\System32\repl.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [winsync] C:\WINNT\System32\pwrkic.exe reg_run
O4 - HKLM\..\Run: [yvqvgpcb] yvqvgpcb.dll,Check
O4 - HKLM\..\Run: [Alexa bridge] C:\WINNT\System32\wbcdubwn.exe
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINNT\System32\svchost.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iut75] c:\winnt\system32\drivers\uzcx.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O20 - Winlogon Notify: cbayy - C:\WINNT\System32\cbayy.dll (file missing)
O20 - Winlogon Notify: winidp32 - winidp32.dll (file missing)
O21 - SSODL: cholecyst - {ee2975b6-e8d5-405e-8448-8fe9590f6cfb} - C:\WINNT\System32\mzoeut.dll (file missing)
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINNT\System32\pmnqguh.dll (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"

Delete these Files if listed:
C:\WINNT\System32\rasda2.dll
C:\WINNT\System32\hgni_ecol.dll
C:\WINNT\webdir.dll
C:\WINNT\System32\cbayy.dll
C:\WINNT\System32\repl.dll
c:\winnt\system32\drivers\uzcx.exe
C:\WINNT\System32\cbayy.dll

Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment
good luck mschroe919

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI