Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

BYXOEDAT.DLL [Solved]


  • This topic is locked This topic is locked

#31
drpepper23

drpepper23

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
sorry for the delay.

Runscanner logfile http://www.runscanner.net

* = signed file
- = file not found

General info
------------
Computer name : MYCOMPUTER
Creation time : 2009-01-17 10:57:22 PM
Hosts <> 127.0.0.1 : 0
Hosts file location : %SystemRoot%\System32\drivers\etc
IE version : 6.0.2900.5512
OS : Microsoft Windows XP
OS Build : 2600
OS SP : Service Pack 3
RunScanner Version : 1.7.0.0
User Language : English (United States)
User rights : Administrator
Windows folder : C:\WINDOWS

Running processes
-----------------
* C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft)
* C:\Program Files\AIM\aim.exe (America Online, Inc.)
* C:\WINDOWS\System32\alg.exe (Microsoft Corporation)
* C:\WINDOWS\system32\csrss.exe (Microsoft Corporation)
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe (Network Associates, Inc.)
* C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
* C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (Network Associates, Inc.)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\System32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
* C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
* C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
* C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
* C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
* C:\WINDOWS\system32\lsass.exe (Microsoft Corporation)
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe (Network Associates, Inc.)
* C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
* C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
C:\Program Files\Network Associates\VirusScan\mcshield.exe (Network Associates, Inc.)
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE (Network Associates, Inc.)
* C:\DOCUME~1\ILYASH~1.ICO\LOCALS~1\Temp\Rar$EX02.984\RunScanner.exe (Runscanner.net)
* C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
* C:\WINDOWS\system32\services.exe (Microsoft Corporation)
* C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation)
C:\PROGRAM FILES\COMMON FILES\NETWORK ASSOCIATES\TALKBACK\TBMON.EXE (Network Associates, Inc.)
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe (Network Associates, Inc.)
* C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
* C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation)
* c:\windows\System32\smss.exe (Microsoft Corporation)
* C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
C:\Program Files\WinRAR\WinRAR.exe
* C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)

Unrated items
-------------
002 C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe (Network Associates, Inc.)
002 C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE (Network Associates, Inc.)
002 * C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
005 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
010 C:\Program Files\Ares\chatServer.exe (Ares Chatroom server)
010 C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (InstallDriver Table Manager)
010 C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel NCS NetService)
010 * C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Network Connect Service)
010 C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (McAfee Framework Service)
010 C:\Program Files\Network Associates\VirusScan\mcshield.exe (Network Associates McShield)
010 C:\Program Files\Network Associates\VirusScan\vstskmgr.exe (Network Associates Task Manager)
011 C:\WINDOWS\system32\DRIVERS\eacfilt.sys (Eacfilt Miniport)
011 C:\WINDOWS\system32\drivers\EntDrv51.sys (EntDrv51)
011 * C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEARAspiWDM)
011 c:\windows\System32\drivers\HPFECP13.SYS (HPFECP13)
011 C:\WINDOWS\system32\drivers\MxlW2k.sys (MxlW2k)
011 C:\WINDOWS\system32\drivers\naiavf5x.sys (NaiAvFilter1)
011 C:\WINDOWS\system32\drivers\mvstdi5x.sys (NaiAvTdi1)
011 C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys (Nortel Extranet Access Protocol)
011 C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys (Nortel IPSECSHM Adapter)
011 c:\windows\SYSTEM32\DRIVERS\OMCI.SYS (OMCI)
011 C:\WINDOWS\system32\drivers\tbhsd.sys (Tunebite High-Speed Dubbing)
011 C:\Program Files\Unlocker\UnlockerDriver5.sys (UnlockerDriver5)
011 C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software pcouffin)
045 C:\Program Files\AIM Toolbar\AIMBar.dll (America Online, Inc) {40D41A8B-D79B-43D7-99A7-9EE0F344C385}
052 C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) {DBC80044-A445-435b-BC74-9C25C1C588A9}
052 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
061 C:\Program Files\Sonic\RecordNow!\shlext.dll (Sonic Solutions) {DEE12703-6333-4D4E-8F34-738C4DCC2E04}
061 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
062 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc.) {F9DB5320-233E-11D1-9F84-707F02C10627}
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
068 C:\WINDOWS\System32\mclsp.dll (Networks Associates Technology, Inc)
069 C:\WINDOWS\system32\HPFlpm13.dll
069 C:\WINDOWS\system32\mdimon.dll (Microsoft Corporation)
069 C:\WINDOWS\system32\pdfcmnnt.dll
100 SearchUrl HKCU : http://home.microsof...search.asp?p=%s
102 GUID / CLSID not found {32683183-48a0-441b-a342-7c2a440a9478}
104 * C:\WINDOWS\Downloaded Program Files\PCPitstop.dll (PC Pitstop) {0E5F0222-96B9-11D3-8997-00104BD12D94}
104 GUID / CLSID not found {362C56AA-6E4F-40C7-A0B5-85501DBDAD77}
104 C:\WINDOWS\Downloaded Program Files\fscax.dll (F-Secure Corporation) {B9F79165-A264-4C4A-A211-133A5E8D647F}
104 C:\WINDOWS\Downloaded Program Files\CONFLICT.1\fscax.dll (F-Secure Corporation) {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876}
104 * C:\WINDOWS\SYSTEM32\FlashAX\FlashAX.ocx (Microgaming Systems) {D8089245-3211-40F6-819B-9E5E92CD61A2}
104 * C:\WINDOWS\DOWNLO~1\JuniperSetup.ocx (Juniper Networks) {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
104 C:\WINDOWS\McAfee.com\FreeScan\mcfscan.dll (Networks Associates Technology, Inc) {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
104 C:\Program Files\Common Files\Nullsoft\ActiveX\2.0\AmpX.dll {FA3662C3-B8E8-11D6-A667-0010B556D978}
105 &AIM Search :
105 &AOL Toolbar search :
105 &Download with &DAP :
105 &Yahoo! Search :
105 E&xport to Microsoft Excel :
105 Yahoo! &Dictionary :
105 Yahoo! &Maps :
105 Yahoo! &SMS :
107 C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
173 GUID / CLSID not found
173 C:\Program Files\Network Associates\VirusScan\shext.dll (Network Associates, Inc.) {cda2863e-2497-4c49-9b89-06840e070a87}
173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
221 GUID / CLSID not found
221 C:\Program Files\Network Associates\VirusScan\shext.dll (Network Associates, Inc.) {cda2863e-2497-4c49-9b89-06840e070a87}
221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
223 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\Unlocker\UnlockerCOM.dll {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}
225 C:\Program Files\Network Associates\VirusScan\shext.dll (Network Associates, Inc.) {cda2863e-2497-4c49-9b89-06840e070a87}
225 C:\Program Files\Network Associates\VirusScan\shext.dll (Network Associates, Inc.) {cda2863e-2497-4c49-9b89-06840e070a87}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
227 GUID / CLSID not found
227 C:\Program Files\WordPerfect Office 11\Programs\PFSE110.DLL (Novell, Inc., c/o Corel Corporation Limited) {C0E10002-0028-0004-C0E1-C0E1C0E1C0E1}
227 C:\Program Files\Network Associates\VirusScan\shext.dll (Network Associates, Inc.) {cda2863e-2497-4c49-9b89-06840e070a87}
227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA}
231 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc.) PDF Column Info

Missing files
-------------
010 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
011 C:\WINDOWS\system32\drivers\Abiosdsk.sys
011 C:\WINDOWS\system32\drivers\abp480n5.sys
011 C:\WINDOWS\system32\drivers\adpu160m.sys
011 C:\WINDOWS\system32\drivers\Aha154x.sys
011 C:\WINDOWS\system32\drivers\aic78u2.sys
011 C:\WINDOWS\system32\drivers\aic78xx.sys
011 C:\WINDOWS\system32\drivers\AliIde.sys
011 C:\WINDOWS\system32\drivers\amsint.sys
011 C:\WINDOWS\system32\drivers\asc.sys
011 C:\WINDOWS\system32\drivers\asc3350p.sys
011 C:\WINDOWS\system32\drivers\asc3550.sys
011 C:\WINDOWS\system32\drivers\ASPI32.sys
011 C:\WINDOWS\system32\drivers\Atdisk.sys
011 C:\WINDOWS\system32\drivers\Beep.sys
011 C:\WINDOWS\system32\drivers\cd20xrnt.sys
011 C:\WINDOWS\system32\drivers\Changer.sys
011 C:\WINDOWS\system32\drivers\CmdIde.sys
011 C:\WINDOWS\system32\drivers\Cpqarray.sys
011 C:\WINDOWS\system32\drivers\dac2w2k.sys
011 C:\WINDOWS\system32\drivers\dac960nt.sys
011 C:\WINDOWS\system32\drivers\dpti2o.sys
011 C:\WINDOWS\system32\drivers\hpn.sys
011 C:\WINDOWS\system32\drivers\i2omgmt.sys
011 C:\WINDOWS\system32\drivers\i2omp.sys
011 C:\WINDOWS\system32\drivers\ini910u.sys
011 C:\WINDOWS\system32\drivers\IntelIde.sys
011 C:\WINDOWS\system32\drivers\lbrtfdc.sys
011 C:\WINDOWS\system32\drivers\mraid35x.sys
011 C:\WINDOWS\system32\drivers\PCIDump.sys
011 C:\WINDOWS\system32\drivers\PDCOMP.sys
011 C:\WINDOWS\system32\drivers\PDFRAME.sys
011 C:\WINDOWS\system32\drivers\PDRELI.sys
011 C:\WINDOWS\system32\drivers\PDRFRAME.sys
011 C:\WINDOWS\system32\drivers\perc2.sys
011 C:\WINDOWS\system32\drivers\perc2hib.sys
011 System32\Drivers\PortTalk.sys
011 C:\WINDOWS\system32\drivers\ql1080.sys
011 C:\WINDOWS\system32\drivers\Ql10wnt.sys
011 C:\WINDOWS\system32\drivers\ql12160.sys
011 C:\WINDOWS\system32\drivers\ql1240.sys
011 C:\WINDOWS\system32\drivers\ql1280.sys
011 C:\WINDOWS\system32\drivers\Simbad.sys
011 C:\WINDOWS\system32\drivers\Sparrow.sys
011 C:\WINDOWS\system32\drivers\sym_hi.sys
011 C:\WINDOWS\system32\drivers\sym_u3.sys
011 C:\WINDOWS\system32\drivers\symc810.sys
011 C:\WINDOWS\system32\drivers\symc8xx.sys
011 C:\WINDOWS\system32\drivers\TosIde.sys
011 C:\WINDOWS\system32\drivers\ultra.sys
011 C:\WINDOWS\system32\drivers\ViaIde.sys
011 C:\WINDOWS\system32\drivers\WDICA.sys
061 deskpan.dll
061 C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
061 C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
062 C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
067
104 C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
173 C:\Program Files\LitexMedia\Advanced WMA Workshop\awmaw_shellext.dll
221 C:\Program Files\LitexMedia\Advanced WMA Workshop\awmaw_shellext.dll
227 C:\Program Files\LitexMedia\Advanced WMA Workshop\awmaw_shellext.dll
231 C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll

Attached Files


  • 0

Advertisements


#32
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello drpepper23,

Could you please upload the .run file again, for some reason it is not letting me download it.
  • 0

#33
drpepper23

drpepper23

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
sure.

Attached Files


  • 0

#34
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello drpepper23,

Thanks for uploading the .run file again, I was able to download it this time. :)


That log look clean as well, is your Mcafee still not working right?

Edited by Jimmy2012, 19 January 2009 - 06:06 PM.

  • 0

#35
drpepper23

drpepper23

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
no sir.
  • 0

#36
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello drpepper23,
I am not sure why Mcafee is not starting right, but it does not look to be caused by malware since all of your logs look clean. I recommend that you start a new topic over in the Applications forum, someone over there should have some more ideas on how to fix that. :)


Lets go ahead and remove the tools used and update a few programs.





Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.






You are using a old version of Adobe Acrobat Reader, please update it here.








Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    Posted Image








Please download OTCleanIt and save it to your Desktop.
  • Double-click OTCleanIt.exe
  • Click the CleanUp! button to begin removing tools used to clean your computer
  • If you are prompted to Reboot during the cleanup, please select Yes

Please remove any leftover tools used to clean your computer.









The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

1. Spywareguard: Is realtime protection from spyware.

2. Spywareblaster: Helps protect against any bad ActiveX from installing on your computer.

3. SuperAntiSpyware: Use this program to help remove any spyware that may have gotten on your computer.

4. FireFox: This is a great alternate browser over Internet Explorer. Firefox is much more secure then Internet Explorer and also has a bulilt in pop up blocker.

5. ATF Cleaner: This program cleans out your temporary files. This is a great tool that can help speed your computer up.

6. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

7. Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • 0

#37
drpepper23

drpepper23

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
which of the following folders from my c drive can i delete?

1. quarantine
2. rsit
3. !FixIEDef
4. ERDNT
5. _OTMoveIt

thanks again.
  • 0

#38
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello drpepper23,
You can delete all 5 of them. :)
  • 0

#39
drpepper23

drpepper23

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
hmm people in the application forum are suggesting it might be a virus lol.
  • 0

#40
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello drpepper23,

It does not look to be caused from any virus or any malware, all of your logs look clean. :)

Edited by Jimmy2012, 23 January 2009 - 09:50 PM.

  • 0

Advertisements


#41
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP