Dell XPS T700r
100MHz
256K ram
20G HD
I brought it home and tried booting regularly and in safe mode. There is an administrator login screen (they provided the password). This error appears at the login screen:
"Winlogon.exe - Application Error. The instruction at "numbers that change" referenced memory at "numbers that change". The memory could not be "written".
Sometimes it reads "Winlogon.exe - Application Error. The exception privileged instruction. (0xc00000096) occurred in the application at location (more numbers that change)."
If you click either "OK" or "cancel" you get a Stop error (sorry – didn't write that down).
I also get this error when I try to explore "my computer":
"Windows cannot find '(null)'. Make sure you typed the name correctly, and then try again. To search for a file, click the start button, and then click search."
I get this error and am not sure what initiates it:
"ase Runtime error '35756'; Unable to complete request"
After researching the Winlogon.exe error I saw someone post that one could just move the error window out of the way and proceed into Windows – this works.
I made a copy of UBCD4win using my own XP Home copy and included most of the anti-virus/malware features. After running a few and finding loads of trojans, getting some errors. being unable to delete files anyway, I stopped and started reading more posts on this and other forums.
I started to worry when I found a post from someone (on this forum I believe) with something like 2000+ instances of malware – and the Malware Team member helping stated that sometimes it was not advisable to attempt to clean a machine infected with key-logger trojans or infections that might not be possible to completely eradicate.
Would someone mind taking a look at the following HijackThis and Adsspy logs? I'm going to try to add the Adaware and ClamAV logs as attached files – this post was "too long" when I tried pasting the text. Could you advise me on how to proceed? I did run spybot and let it "fix" things. (I should have been taking notes on what I've been doing, but am trying to squeeze this in and rushed through some things.) I did install ClamAV, but have not yet uninstalled some AV ware they have called "Ban_____" (don't know the name yet).
[Although this couple said they connect to the internet wirelessly (I don't have the adapter), they said that they've never purchased anything online. They only seem to use the machine for playing games, uploading photos and email (yahoo account). I have their permission to add or delete programs as necessary. On the other hand, they don't have money to spend and they don't appear to have licenses for their software (that I know of). Perhaps that will affect how I proceed?]
Sorry – they're very long.
Thanks very much. mcaren
********************************************************************************
********************
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:50:18 AM, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\win3207222-331985.exe
C:\WINDOWS\system32\swinsndv.exe
C:\windows\system32\vdsreg.exe
C:\WINDOWS\bjam.exe
C:\windows\system32\deuceizr.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\ECURIT~1\fast.exe
C:\Program Files\Common Files\S?mantec\rundll.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\malware stuff\HiJackThis_v2.exe
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {1616353F-3F18-4C17-AED5-184F8F7E50AD} - C:\WINDOWS\system32\qoppo.dll
O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - (no file)
O2 - BHO: (no name) - {4CBA54E7-81B5-4D01-98B8-90115257665c} - C:\WINDOWS\system32\hkyeusbw.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {50FE60AD-B13D-46DE-A29F-3AFA5A884ED4} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\fccbbxv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: support - {991EF04C-93CF-469b-A2BE-CC1B3347566F} - C:\Program Files\BHO\plugin1.dll
O2 - BHO: (no name) - {A4026D9D-6EA6-4944-8E72-3838DB2D7CE4} - undefined\homeryt.dll (file missing)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\itkxcyix.dll
O2 - BHO: (no name) - {d24fa86c-717c-4239-a85c-c39859868829} - C:\WINDOWS\system32\c_2ime.dll (file missing)
O2 - BHO: (no name) - {EBAACA78-1A40-4429-9F1B-D8B74E0762C4} - C:\WINDOWS\system32\hkyeusbw.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [D-Link Wireless G WUA-1340] C:\Program Files\D-Link\Wireless G WUA-1340\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [win3207222-331985] C:\WINDOWS\win3207222-331985.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [sys01331985222-] C:\WINDOWS\sys01331985222-.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\swinsndv.exe SKY001
O4 - HKLM\..\Run: [RunOnce2Upd] "C:\WINDOWS\system32\svchost.exe"
O4 - HKLM\..\Run: [{64-4E-EB-BA-ZN}] C:\windows\system32\vdsreg.exe SKY001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Annt] "C:\DOCUME~1\ADMINI~1\APPLIC~1\ECURIT~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Qudmosyy] "C:\Program Files\Common Files\S?mantec\rundll.exe"
O4 - HKCU\..\Run: [DDC] C:\WINDOWS\system32\chidfviu.exe
O4 - HKLM\..\Policies\Explorer\Run: [7H28X9M91L] C:\WINDOWS\winlogon32.exe
O4 - HKCU\..\Policies\Explorer\Run: [{EC364EBA-02BA-1033-0322-000615990001}] "C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe" mc-110-12-0000501
O4 - HKUS\S-1-5-18\..\Run: [Windows update loader] C:\Windows\xpupdate.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.6.8\webbuying.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{EC364EBA-02BA-1033-0322-000615990001}] "C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe" mc-110-12-0000501 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows update loader] C:\Windows\xpupdate.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{EC364EBA-02BA-1033-0322-000615990001}] "C:\Program Files\Common Files\{EC364EBA-02BA-1033-0322-000615990001}\Update.exe" mc-110-12-0000501 (User 'Default user')
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinsndv.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZJxdm128YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\winhealer.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\winhealer.dll
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/insta…FreeInstall.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://cdn.downloadcontrol.com/files/insta…tector-Free.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EC29350-8F42-400E-A2D9-2592BF40DCE4}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{41D59572-D390-4DC4-BBFC-F1B14399EF83}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{5EFCA02F-A4F0-418E-8DF1-68B98D595189}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{6353682F-545B-442A-9C83-DC3B39FA4898}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{652842D8-EFB8-45A9-8829-1B6D2A571EAA}: NameServer = 202.215.242.193
O17 - HKLM\System\CCS\Services\Tcpip\..\{A98B3DA1-F0FF-40B0-8F76-D90BDBE1A7AD}: NameServer = 202.215.242.193
O17 - HKLM\System\CS1\Services\Tcpip\..\{0EC29350-8F42-400E-A2D9-2592BF40DCE4}: NameServer = 202.215.242.193
O17 - HKLM\System\CS2\Services\Tcpip\..\{0EC29350-8F42-400E-A2D9-2592BF40DCE4}: NameServer = 202.215.242.193
O20 - AppInit_DLLs: ???????????
O20 - Winlogon Notify: c_2ime - c_2ime.dll (file missing)
O20 - Winlogon Notify: fccbbxv - C:\WINDOWS\SYSTEM32\fccbbxv.dll
O20 - Winlogon Notify: qoppo - C:\WINDOWS\system32\qoppo.dll
O21 - SSODL: CDRecorder036 - {A3BC5E20-0235-1ABF-9CE1-00AA00512036} - (no file)
O21 - SSODL: otyPts - {EC364EBB-469C-E411-A5BC-0B66BFB12A2F} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
–
End of file - 9652 bytes
********************************************************************************
********************
adsspy.txt
C:\WINDOWS\system32 : lzx32.sys (54218 bytes)
C:\WINDOWS\system32 : lzx32.sys (54218 bytes)
C:\WINDOWS\system32\ws2_32.dll : fork2 (30720 bytes)