This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Very infected PC; Clean or Reformat?

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I offered to take a look at a couple's computer – they weren't sure of the problem, but couldn't use it for three months. (I don't know this couple (just volunteered), but as I understand it they purchased an old Dell that had been "put together" by some geek they know. He promised to service it if needed, but won't return their calls…). It is running XP Professional (they received no disks with the machine).

Dell XPS T700r
100MHz
256K ram
20G HD

I brought it home and tried booting regularly and in safe mode. There is an administrator login screen (they provided the password). This error appears at the login screen:

"Winlogon.exe - Application Error. The instruction at "numbers that change" referenced memory at "numbers that change". The memory could not be "written".

Sometimes it reads "Winlogon.exe - Application Error. The exception privileged instruction. (0xc00000096) occurred in the application at location (more numbers that change)."


If you click either "OK" or "cancel" you get a Stop error (sorry – didn't write that down).

I also get this error when I try to explore "my computer":

"Windows cannot find '(null)'. Make sure you typed the name correctly, and then try again. To search for a file, click the start button, and then click search."


I get this error and am not sure what initiates it:


"ase Runtime error '35756'; Unable to complete request"


After researching the Winlogon.exe error I saw someone post that one could just move the error window out of the way and proceed into Windows – this works.

I made a copy of UBCD4win using my own XP Home copy and included most of the anti-virus/malware features. After running a few and finding loads of trojans, getting some errors. being unable to delete files anyway, I stopped and started reading more posts on this and other forums.

I started to worry when I found a post from someone (on this forum I believe) with something like 2000+ instances of malware – and the Malware Team member helping stated that sometimes it was not advisable to attempt to clean a machine infected with key-logger trojans or infections that might not be possible to completely eradicate.

Would someone mind taking a look at the following HijackThis and Adsspy logs? I'm going to try to add the Adaware and ClamAV logs as attached files – this post was "too long" when I tried pasting the text. Could you advise me on how to proceed? I did run spybot and let it "fix" things. (I should have been taking notes on what I've been doing, but am trying to squeeze this in and rushed through some things.) I did install ClamAV, but have not yet uninstalled some AV ware they have called "Ban_____" (don't know the name yet).

[Although this couple said they connect to the internet wirelessly (I don't have the adapter), they said that they've never purchased anything online. They only seem to use the machine for playing games, uploading photos and email (yahoo account). I have their permission to add or delete programs as necessary. On the other hand, they don't have money to spend and they don't appear to have licenses for their software (that I know of). Perhaps that will affect how I proceed?]

Sorry – they're very long.

Thanks very much. mcaren

********************************************************************************
********************
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:50:18 AM, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\win3207222-331985.exe
C:\WINDOWS\system32\swinsndv.exe
C:\windows\system32\vdsreg.exe
C:\WINDOWS\bjam.exe
C:\windows\system32\deuceizr.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\ECURIT~1\fast.exe
C:\Program Files\Common Files\S?mantec\rundll.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\malware stuff\HiJackThis_v2.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1616353F-3F18-4C17-AED5-184F8F7E50AD} - C:\WINDOWS\system32\qoppo.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - (no file)
O2 - BHO: (no name) - {4CBA54E7-81B5-4D01-98B8-90115257665c} - C:\WINDOWS\system32\hkyeusbw.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {50FE60AD-B13D-46DE-A29F-3AFA5A884ED4} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\fccbbxv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: support - {991EF04C-93CF-469b-A2BE-CC1B3347566F} - C:\Program Files\BHO\plugin1.dll
O2 - BHO: (no name) - {A4026D9D-6EA6-4944-8E72-3838DB2D7CE4} - undefined\homeryt.dll (file missing)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\itkxcyix.dll
O2 - BHO: (no name) - {d24fa86c-717c-4239-a85c-c39859868829} - C:\WINDOWS\system32\c_2ime.dll (file missing)
O2 - BHO: (no name) - {EBAACA78-1A40-4429-9F1B-D8B74E0762C4} - C:\WINDOWS\system32\hkyeusbw.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [D-Link Wireless G WUA-1340] C:\Program Files\D-Link\Wireless G WUA-1340\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [win3207222-331985] C:\WINDOWS\win3207222-331985.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [sys01331985222-] C:\WINDOWS\sys01331985222-.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\swinsndv.exe SKY001
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINDOWS\system32\svchost.exe"
O4 - HKLM\..\Run: [{64-4E-EB-BA-ZN}] C:\windows\system32\vdsreg.exe SKY001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Annt] "C:\DOCUME~1\ADMINI~1\APPLIC~1\ECURIT~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Qudmosyy] "C:\Program Files\Common Files\S?mantec\rundll.exe"
O4 - HKCU\..\Run: [DDC] C:\WINDOWS\system32\chidfviu.exe
O4 - HKLM\..\Policies\Explorer\Run: [7H28X9M91L] C:\WINDOWS\winlogon32.exe
O4 - HKCU\..\Policies\Explorer\Run: [{EC364EBA-02BA-1033-0322-000615990001}] "C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe" mc-110-12-0000501
O4 - HKUS\S-1-5-18\..\Run: [Windows update loader] C:\Windows\xpupdate.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.6.8\webbuying.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{EC364EBA-02BA-1033-0322-000615990001}] "C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe" mc-110-12-0000501 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows update loader] C:\Windows\xpupdate.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{EC364EBA-02BA-1033-0322-000615990001}] "C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe" mc-110-12-0000501 (User 'Default user')
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinsndv.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZJxdm128YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\winhealer.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\winhealer.dll
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/insta…FreeInstall.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://cdn.downloadcontrol.com/files/insta…tector-Free.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EC29350-8F42-400E-A2D9-2592BF40DCE4}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{41D59572-D390-4DC4-BBFC-F1B14399EF83}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{5EFCA02F-A4F0-418E-8DF1-68B98D595189}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{6353682F-545B-442A-9C83-DC3B39FA4898}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{652842D8-EFB8-45A9-8829-1B6D2A571EAA}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{A98B3DA1-F0FF-40B0-8F76-D90BDBE1A7AD}: NameServer = 202.215.242.193
O17 - HKLM\System\CS1\Services\Tcpip\..\{0EC29350-8F42-400E-A2D9-2592BF40DCE4}: NameServer = 202.215.242.193
O17 - HKLM\System\CS2\Services\Tcpip\..\{0EC29350-8F42-400E-A2D9-2592BF40DCE4}: NameServer = 202.215.242.193
O20 - AppInit_DLLs: ???????????
O20 - Winlogon Notify: c_2ime - c_2ime.dll (file missing)
O20 - Winlogon Notify: fccbbxv - C:\WINDOWS\SYSTEM32\fccbbxv.dll
O20 - Winlogon Notify: qoppo - C:\WINDOWS\system32\qoppo.dll
O21 - SSODL: CDRecorder036 - {A3BC5E20-0235-1ABF-9CE1-00AA00512036} - (no file)
O21 - SSODL: otyPts - {EC364EBB-469C-E411-A5BC-0B66BFB12A2F} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

–
End of file - 9652 bytes

********************************************************************************
********************

adsspy.txt

C:\WINDOWS\system32 : lzx32.sys (54218 bytes)
C:\WINDOWS\system32 : lzx32.sys (54218 bytes)
C:\WINDOWS\system32\ws2_32.dll : fork2 (30720 bytes)
mcaren, That surely is one of the most infected machines I've ever seen. It's very advisable to take the reformat route. All passwords should be changed.
Thank you Blade81 for your reply. Could you please give me some advice concerning files they'd like to save? The most important thing they'd like to keep are photos (their screensaver is a photo slide show – we're talking about their wedding and baby photos – it would be a big deal not to be able to keep them!). I had begun to copy onto CDs, but am a bit puzzled by the format – they're showing up as some type of Kodak album in Windows explorer – (sort of the way a zip file will show up instead of showing the contents). I'd copied these Kodak files onto a CD, but now wonder if they could contain some type of compression or other software… If you have time to answer some additional questions, I could use some advice: 1. What file types do you have to worry about? If I can use the existing software on their machine to expand the files (or whatever the software does) into .jpg or other recognizable format, would it be safe to put those on a CD for later use? (does a file have to be able to contain a program in order to be infected?) 2. If some types of files are considered safe, could you tell me where I could find a list of these file types? 3. When you suggest the "reformat route," are you talking about simply reformatting the drive or using some sort of super-duper wiping/erasing software? 4. If their photo files could be compromised, but they choose to risk saving them (I would if they were mine!), any suggestions for the most probably way to disinfect them? Thanks very much. I have to admit that I was floored when I saw the scan reports – I was expecting viruses & malware, but nothing on this scale. I certainly appreciate this forum and your efforts to help! mcaren
Hi

The most important thing they'd like to keep are photos (their screensaver is a photo slide show – we're talking about their wedding and baby photos – it would be a big deal not to be able to keep them!). I had begun to copy onto CDs, but am a bit puzzled by the format – they're showing up as some type of Kodak album in Windows explorer – (sort of the way a zip file will show up instead of showing the contents). I'd copied these Kodak files onto a CD, but now wonder if they could contain some type of compression or other software…

I'm not familiar with Kodak format but you might want to test by installing Kodak software to other computer (if possible) and then try to open those Kodak files there.

2. If some types of files are considered safe, could you tell me where I could find a list of these file types?

Unfortunately don't know any list of those but basically photos & videos should be safe to backup.

3. When you suggest the "reformat route," are you talking about simply reformatting the drive or using some sort of super-duper wiping/erasing software?

Check this great tutorial about reformatting made by wng_z3r0.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI