Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware [RESOLVED]


  • This topic is locked This topic is locked

#1
mill6793

mill6793

    New Member

  • Member
  • Pip
  • 5 posts
Some spyware got by me. Most of the pop-ups are adopt dot something. Please help.

Logfile of HijackThis v1.99.1
Scan saved at 12:36:16 PM, on 08/19/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\OOBE\BLANK.HTM
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} - http://adserver.shar...ver/Install.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...rCabInstall.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 159.238.200.2,159.238.69.2
  • 0

Advertisements


#2
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Hi mill6793, welcome to GeeksToGo

Was that HijackThis scan made in safe mode? It looks a little short. If so, please post the new log after scanning in normal mode and if you have any items disabled from startup please reenable them before the scan.

Please download L2m9xfix here:
http://swandog46.gee...om/l2m9xfix.exe

Save it to the desktop and run it. Extract the files, and then open the l2m9xfix folder you just created and run RunThis.bat.

A window will open, and your desktop will disappear, then reappear. Please be patient until the batch says it is completed.

Then please restart your computer, and post a new HijackThis log as well as the entire text of the log.txt file which should be in the same folder as RunThis.bat.

Regards,

Armodeluxe
  • 0

#3
mill6793

mill6793

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Ran Hijack This and RunThis.bat (not in safe mode)

Logfile of HijackThis v1.99.1
Scan saved at 11:17:57 AM, on 08/22/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\OOBE\BLANK.HTM
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} - http://adserver.shar...ver/Install.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...rCabInstall.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 159.238.200.2,159.238.69.2

Log of L2M9XFix v1

************

Running from directory:
C:\Program Files\l2m9xfix

************

Files found:

C:\WINDOWS\system\aafsipc.dll
C:\WINDOWS\system\aafsipc.dll
C:\WINDOWS\system\aafsipc.dll
C:\WINDOWS\system\aafsipc.dll
C:\WINDOWS\system\AGYCFILT.DLL
C:\WINDOWS\system\AGYCFILT.DLL
C:\WINDOWS\system\AGYCFILT.DLL
C:\WINDOWS\system\AGYCFILT.DLL
C:\WINDOWS\system\AIITVT16.DLL
C:\WINDOWS\system\AIITVT16.DLL
C:\WINDOWS\system\AIITVT16.DLL
C:\WINDOWS\system\AIITVT16.DLL
C:\WINDOWS\system\AOTXPRXY.DLL
C:\WINDOWS\system\AOTXPRXY.DLL
C:\WINDOWS\system\AOTXPRXY.DLL
C:\WINDOWS\system\AOTXPRXY.DLL
C:\WINDOWS\system\AQIVPM16.DLL
C:\WINDOWS\system\AQIVPM16.DLL
C:\WINDOWS\system\AQIVPM16.DLL
C:\WINDOWS\system\AQIVPM16.DLL
C:\WINDOWS\system\AROGLRP9.DLL
C:\WINDOWS\system\AROGLRP9.DLL
C:\WINDOWS\system\AROGLRP9.DLL
C:\WINDOWS\system\AROGLRP9.DLL
C:\WINDOWS\system\AUIDIAG.DLL
C:\WINDOWS\system\AUIDIAG.DLL
C:\WINDOWS\system\AUIDIAG.DLL
C:\WINDOWS\system\AUIDIAG.DLL
C:\WINDOWS\system\CEMCAT.DLL
C:\WINDOWS\system\CEMCAT.DLL
C:\WINDOWS\system\CEMCAT.DLL
C:\WINDOWS\system\CEMCAT.DLL
C:\WINDOWS\system\CETDLL.DLL
C:\WINDOWS\system\CETDLL.DLL
C:\WINDOWS\system\CETDLL.DLL
C:\WINDOWS\system\CETDLL.DLL
C:\WINDOWS\system\CGTDLL.DLL
C:\WINDOWS\system\CGTDLL.DLL
C:\WINDOWS\system\CGTDLL.DLL
C:\WINDOWS\system\CGTDLL.DLL
C:\WINDOWS\system\CTMCTL32.DLL
C:\WINDOWS\system\CTMCTL32.DLL
C:\WINDOWS\system\CTMCTL32.DLL
C:\WINDOWS\system\CTMCTL32.DLL
C:\WINDOWS\system\CVTDLL.DLL
C:\WINDOWS\system\CVTDLL.DLL
C:\WINDOWS\system\CVTDLL.DLL
C:\WINDOWS\system\CVTDLL.DLL
C:\WINDOWS\system\CXCFG32.DLL
C:\WINDOWS\system\CXCFG32.DLL
C:\WINDOWS\system\CXCFG32.DLL
C:\WINDOWS\system\CXCFG32.DLL
C:\WINDOWS\system\CZTDLL.DLL
C:\WINDOWS\system\CZTDLL.DLL
C:\WINDOWS\system\CZTDLL.DLL
C:\WINDOWS\system\CZTDLL.DLL
C:\WINDOWS\system\dfnlobby.dll
C:\WINDOWS\system\dfnlobby.dll
C:\WINDOWS\system\dfnlobby.dll
C:\WINDOWS\system\dfnlobby.dll
C:\WINDOWS\system\DHDXOF.DLL
C:\WINDOWS\system\DHDXOF.DLL
C:\WINDOWS\system\DHDXOF.DLL
C:\WINDOWS\system\DHDXOF.DLL
C:\WINDOWS\system\di8vb.dll
C:\WINDOWS\system\di8vb.dll
C:\WINDOWS\system\di8vb.dll
C:\WINDOWS\system\di8vb.dll
C:\WINDOWS\system\dJd8.dll
C:\WINDOWS\system\dJd8.dll
C:\WINDOWS\system\dJd8.dll
C:\WINDOWS\system\dJd8.dll
C:\WINDOWS\system\dlmclien.dll
C:\WINDOWS\system\dlmclien.dll
C:\WINDOWS\system\dlmclien.dll
C:\WINDOWS\system\dlmclien.dll
C:\WINDOWS\system\DNLAY.DLL
C:\WINDOWS\system\DNLAY.DLL
C:\WINDOWS\system\DNLAY.DLL
C:\WINDOWS\system\DNLAY.DLL
C:\WINDOWS\system\DODXOF.DLL
C:\WINDOWS\system\DODXOF.DLL
C:\WINDOWS\system\DODXOF.DLL
C:\WINDOWS\system\DODXOF.DLL
C:\WINDOWS\system\domssocn.dll
C:\WINDOWS\system\domssocn.dll
C:\WINDOWS\system\domssocn.dll
C:\WINDOWS\system\domssocn.dll
C:\WINDOWS\system\DPAO36.DLL
C:\WINDOWS\system\DPAO36.DLL
C:\WINDOWS\system\DPAO36.DLL
C:\WINDOWS\system\DPAO36.DLL
C:\WINDOWS\system\dudmoprp.dll
C:\WINDOWS\system\dudmoprp.dll
C:\WINDOWS\system\dudmoprp.dll
C:\WINDOWS\system\dudmoprp.dll
C:\WINDOWS\system\dunlobby.dll
C:\WINDOWS\system\dunlobby.dll
C:\WINDOWS\system\dunlobby.dll
C:\WINDOWS\system\dunlobby.dll
C:\WINDOWS\system\dv8vb.dll
C:\WINDOWS\system\dv8vb.dll
C:\WINDOWS\system\dv8vb.dll
C:\WINDOWS\system\dv8vb.dll
C:\WINDOWS\system\DWEML.DLL
C:\WINDOWS\system\DWEML.DLL
C:\WINDOWS\system\DWEML.DLL
C:\WINDOWS\system\DWEML.DLL
C:\WINDOWS\system\dwmstor.dll
C:\WINDOWS\system\dwmstor.dll
C:\WINDOWS\system\dwmstor.dll
C:\WINDOWS\system\dwmstor.dll
C:\WINDOWS\system\DWSTYLE.DLL
C:\WINDOWS\system\DWSTYLE.DLL
C:\WINDOWS\system\DWSTYLE.DLL
C:\WINDOWS\system\DWSTYLE.DLL
C:\WINDOWS\system\EDSHARED.DLL
C:\WINDOWS\system\EDSHARED.DLL
C:\WINDOWS\system\EDSHARED.DLL
C:\WINDOWS\system\EDSHARED.DLL
C:\WINDOWS\system\FS20ENU.DLL
C:\WINDOWS\system\FS20ENU.DLL
C:\WINDOWS\system\FS20ENU.DLL
C:\WINDOWS\system\FS20ENU.DLL
C:\WINDOWS\system\FV20.DLL
C:\WINDOWS\system\FV20.DLL
C:\WINDOWS\system\FV20.DLL
C:\WINDOWS\system\FV20.DLL
C:\WINDOWS\system\FWWPP.DLL
C:\WINDOWS\system\FWWPP.DLL
C:\WINDOWS\system\FWWPP.DLL
C:\WINDOWS\system\FWWPP.DLL
C:\WINDOWS\system\FX20.DLL
C:\WINDOWS\system\FX20.DLL
C:\WINDOWS\system\FX20.DLL
C:\WINDOWS\system\FX20.DLL
C:\WINDOWS\system\FXWPP.DLL
C:\WINDOWS\system\FXWPP.DLL
C:\WINDOWS\system\FXWPP.DLL
C:\WINDOWS\system\FXWPP.DLL
C:\WINDOWS\system\GLDEF.DLL
C:\WINDOWS\system\GLDEF.DLL
C:\WINDOWS\system\GLDEF.DLL
C:\WINDOWS\system\GLDEF.DLL
C:\WINDOWS\system\GRDEF.DLL
C:\WINDOWS\system\GRDEF.DLL
C:\WINDOWS\system\GRDEF.DLL
C:\WINDOWS\system\GRDEF.DLL
C:\WINDOWS\system\GWU32.DLL
C:\WINDOWS\system\GWU32.DLL
C:\WINDOWS\system\GWU32.DLL
C:\WINDOWS\system\GWU32.DLL
C:\WINDOWS\system\HEINK.DLL
C:\WINDOWS\system\HEINK.DLL
C:\WINDOWS\system\HEINK.DLL
C:\WINDOWS\system\HEINK.DLL
C:\WINDOWS\system\HNDCI.DLL
C:\WINDOWS\system\HNDCI.DLL
C:\WINDOWS\system\HNDCI.DLL
C:\WINDOWS\system\HNDCI.DLL
C:\WINDOWS\system\HWD.DLL
C:\WINDOWS\system\HWD.DLL
C:\WINDOWS\system\HWD.DLL
C:\WINDOWS\system\HWD.DLL
C:\WINDOWS\system\HWDCI.DLL
C:\WINDOWS\system\HWDCI.DLL
C:\WINDOWS\system\HWDCI.DLL
C:\WINDOWS\system\HWDCI.DLL
C:\WINDOWS\system\ibctl.dll
C:\WINDOWS\system\ibctl.dll
C:\WINDOWS\system\ibctl.dll
C:\WINDOWS\system\ibctl.dll
C:\WINDOWS\system\IEFRARED.DLL
C:\WINDOWS\system\IEFRARED.DLL
C:\WINDOWS\system\IEFRARED.DLL
C:\WINDOWS\system\IEFRARED.DLL
C:\WINDOWS\system\IJ_NDI.DLL
C:\WINDOWS\system\IJ_NDI.DLL
C:\WINDOWS\system\IJ_NDI.DLL
C:\WINDOWS\system\IJ_NDI.DLL
C:\WINDOWS\system\IKDICDLL.DLL
C:\WINDOWS\system\IKDICDLL.DLL
C:\WINDOWS\system\IKDICDLL.DLL
C:\WINDOWS\system\IKDICDLL.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILM32.DLL
C:\WINDOWS\system\ILROP.DLL
C:\WINDOWS\system\ILROP.DLL
C:\WINDOWS\system\ILROP.DLL
C:\WINDOWS\system\ILROP.DLL
C:\WINDOWS\system\INESHARE.DLL
C:\WINDOWS\system\INESHARE.DLL
C:\WINDOWS\system\INESHARE.DLL
C:\WINDOWS\system\INESHARE.DLL
C:\WINDOWS\system\IOM32.DLL
C:\WINDOWS\system\IOM32.DLL
C:\WINDOWS\system\IOM32.DLL
C:\WINDOWS\system\IOM32.DLL
C:\WINDOWS\system\IP50_32.DLL
C:\WINDOWS\system\IP50_32.DLL
C:\WINDOWS\system\IP50_32.DLL
C:\WINDOWS\system\IP50_32.DLL
C:\WINDOWS\system\IPM32.DLL
C:\WINDOWS\system\IPM32.DLL
C:\WINDOWS\system\IPM32.DLL
C:\WINDOWS\system\IPM32.DLL
C:\WINDOWS\system\IX50_QC.DLL
C:\WINDOWS\system\IX50_QC.DLL
C:\WINDOWS\system\IX50_QC.DLL
C:\WINDOWS\system\IX50_QC.DLL
C:\WINDOWS\system\jfpl400.dll
C:\WINDOWS\system\jfpl400.dll
C:\WINDOWS\system\jfpl400.dll
C:\WINDOWS\system\jfpl400.dll
C:\WINDOWS\system\jiproxy.dll
C:\WINDOWS\system\jiproxy.dll
C:\WINDOWS\system\jiproxy.dll
C:\WINDOWS\system\jiproxy.dll
C:\WINDOWS\system\JRCRIPT.DLL
C:\WINDOWS\system\JRCRIPT.DLL
C:\WINDOWS\system\JRCRIPT.DLL
C:\WINDOWS\system\JRCRIPT.DLL
C:\WINDOWS\system\LHRT.DLL
C:\WINDOWS\system\LHRT.DLL
C:\WINDOWS\system\LHRT.DLL
C:\WINDOWS\system\LHRT.DLL
C:\WINDOWS\system\lkcmgr10.dll
C:\WINDOWS\system\lkcmgr10.dll
C:\WINDOWS\system\lkcmgr10.dll
C:\WINDOWS\system\lkcmgr10.dll
C:\WINDOWS\system\MAHTMLED.DLL
C:\WINDOWS\system\MAHTMLED.DLL
C:\WINDOWS\system\MAHTMLED.DLL
C:\WINDOWS\system\MAHTMLED.DLL
C:\WINDOWS\system\mbrd2x35.dll
C:\WINDOWS\system\mbrd2x35.dll
C:\WINDOWS\system\mbrd2x35.dll
C:\WINDOWS\system\mbrd2x35.dll
C:\WINDOWS\system\mcidntld.dll
C:\WINDOWS\system\mcidntld.dll
C:\WINDOWS\system\mcidntld.dll
C:\WINDOWS\system\mcidntld.dll
C:\WINDOWS\system\MDRTEDIT.DLL
C:\WINDOWS\system\MDRTEDIT.DLL
C:\WINDOWS\system\MDRTEDIT.DLL
C:\WINDOWS\system\MDRTEDIT.DLL
C:\WINDOWS\system\mdvcr71.dll
C:\WINDOWS\system\mdvcr71.dll
C:\WINDOWS\system\mdvcr71.dll
C:\WINDOWS\system\mdvcr71.dll
C:\WINDOWS\system\MEJAVA.DLL
C:\WINDOWS\system\MEJAVA.DLL
C:\WINDOWS\system\MEJAVA.DLL
C:\WINDOWS\system\MEJAVA.DLL
C:\WINDOWS\system\MGWSOSP.DLL
C:\WINDOWS\system\MGWSOSP.DLL
C:\WINDOWS\system\MGWSOSP.DLL
C:\WINDOWS\system\MGWSOSP.DLL
C:\WINDOWS\system\MHTCP.DLL
C:\WINDOWS\system\MHTCP.DLL
C:\WINDOWS\system\MHTCP.DLL
C:\WINDOWS\system\MHTCP.DLL
C:\WINDOWS\system\MIPI.DLL
C:\WINDOWS\system\MIPI.DLL
C:\WINDOWS\system\MIPI.DLL
C:\WINDOWS\system\MIPI.DLL
C:\WINDOWS\system\MJJT3032.DLL
C:\WINDOWS\system\MJJT3032.DLL
C:\WINDOWS\system\MJJT3032.DLL
C:\WINDOWS\system\MJJT3032.DLL
C:\WINDOWS\system\mlisam11.dll
C:\WINDOWS\system\mlisam11.dll
C:\WINDOWS\system\mlisam11.dll
C:\WINDOWS\system\mlisam11.dll
C:\WINDOWS\system\mmg4dmod.dll
C:\WINDOWS\system\mmg4dmod.dll
C:\WINDOWS\system\mmg4dmod.dll
C:\WINDOWS\system\mmg4dmod.dll
C:\WINDOWS\system\MMNET32.DLL
C:\WINDOWS\system\MMNET32.DLL
C:\WINDOWS\system\MMNET32.DLL
C:\WINDOWS\system\MMNET32.DLL
C:\WINDOWS\system\mmuni11.dll
C:\WINDOWS\system\mmuni11.dll
C:\WINDOWS\system\mmuni11.dll
C:\WINDOWS\system\mmuni11.dll
C:\WINDOWS\system\mmxoci.dll
C:\WINDOWS\system\mmxoci.dll
C:\WINDOWS\system\mmxoci.dll
C:\WINDOWS\system\mmxoci.dll
C:\WINDOWS\system\MNHTMLED.DLL
C:\WINDOWS\system\MNHTMLED.DLL
C:\WINDOWS\system\MNHTMLED.DLL
C:\WINDOWS\system\MNHTMLED.DLL
C:\WINDOWS\system\MOC42.DLL
C:\WINDOWS\system\MOC42.DLL
C:\WINDOWS\system\MOC42.DLL
C:\WINDOWS\system\MOC42.DLL
C:\WINDOWS\system\mppatcha.dll
C:\WINDOWS\system\mppatcha.dll
C:\WINDOWS\system\mppatcha.dll
C:\WINDOWS\system\mppatcha.dll
C:\WINDOWS\system\mqjet40.dll
C:\WINDOWS\system\mqjet40.dll
C:\WINDOWS\system\mqjet40.dll
C:\WINDOWS\system\mqjet40.dll
C:\WINDOWS\system\mqrd2x40.dll
C:\WINDOWS\system\mqrd2x40.dll
C:\WINDOWS\system\mqrd2x40.dll
C:\WINDOWS\system\mqrd2x40.dll
C:\WINDOWS\system\MQVCRT.DLL
C:\WINDOWS\system\MQVCRT.DLL
C:\WINDOWS\system\MQVCRT.DLL
C:\WINDOWS\system\MQVCRT.DLL
C:\WINDOWS\system\MRXDM.DLL
C:\WINDOWS\system\MRXDM.DLL
C:\WINDOWS\system\MRXDM.DLL
C:\WINDOWS\system\MRXDM.DLL
C:\WINDOWS\system\MUIEFTP.DLL
C:\WINDOWS\system\MUIEFTP.DLL
C:\WINDOWS\system\MUIEFTP.DLL
C:\WINDOWS\system\MUIEFTP.DLL
C:\WINDOWS\system\MVJET35.DLL
C:\WINDOWS\system\MVJET35.DLL
C:\WINDOWS\system\MVJET35.DLL
C:\WINDOWS\system\MVJET35.DLL
C:\WINDOWS\system\MWRTEDIT.DLL
C:\WINDOWS\system\MWRTEDIT.DLL
C:\WINDOWS\system\MWRTEDIT.DLL
C:\WINDOWS\system\MWRTEDIT.DLL
C:\WINDOWS\system\mzrd2x40.dll
C:\WINDOWS\system\mzrd2x40.dll
C:\WINDOWS\system\mzrd2x40.dll
C:\WINDOWS\system\mzrd2x40.dll
C:\WINDOWS\system\NGture.dll
C:\WINDOWS\system\NGture.dll
C:\WINDOWS\system\NGture.dll
C:\WINDOWS\system\NGture.dll
C:\WINDOWS\system\OBECLI.DLL
C:\WINDOWS\system\OBECLI.DLL
C:\WINDOWS\system\OBECLI.DLL
C:\WINDOWS\system\OBECLI.DLL
C:\WINDOWS\system\ODTLWAB.DLL
C:\WINDOWS\system\ODTLWAB.DLL
C:\WINDOWS\system\ODTLWAB.DLL
C:\WINDOWS\system\ODTLWAB.DLL
C:\WINDOWS\system\ogbccr32.dll
C:\WINDOWS\system\ogbccr32.dll
C:\WINDOWS\system\ogbccr32.dll
C:\WINDOWS\system\ogbccr32.dll
C:\WINDOWS\system\PJSTWPP.DLL
C:\WINDOWS\system\PJSTWPP.DLL
C:\WINDOWS\system\PJSTWPP.DLL
C:\WINDOWS\system\PJSTWPP.DLL
C:\WINDOWS\system\PKSTWPP.DLL
C:\WINDOWS\system\PKSTWPP.DLL
C:\WINDOWS\system\PKSTWPP.DLL
C:\WINDOWS\system\PKSTWPP.DLL
C:\WINDOWS\system\PNSPL.DLL
C:\WINDOWS\system\PNSPL.DLL
C:\WINDOWS\system\PNSPL.DLL
C:\WINDOWS\system\PNSPL.DLL
C:\WINDOWS\system\PQBDLG.DLL
C:\WINDOWS\system\PQBDLG.DLL
C:\WINDOWS\system\PQBDLG.DLL
C:\WINDOWS\system\PQBDLG.DLL
C:\WINDOWS\system\PSFMGR.DLL
C:\WINDOWS\system\PSFMGR.DLL
C:\WINDOWS\system\PSFMGR.DLL
C:\WINDOWS\system\PSFMGR.DLL
C:\WINDOWS\system\PULMON.DLL
C:\WINDOWS\system\PULMON.DLL
C:\WINDOWS\system\PULMON.DLL
C:\WINDOWS\system\PULMON.DLL
C:\WINDOWS\system\RBR20.DLL
C:\WINDOWS\system\RBR20.DLL
C:\WINDOWS\system\RBR20.DLL
C:\WINDOWS\system\RBR20.DLL
C:\WINDOWS\system\RER20.DLL
C:\WINDOWS\system\RER20.DLL
C:\WINDOWS\system\RER20.DLL
C:\WINDOWS\system\RER20.DLL
C:\WINDOWS\system\RGAPH.DLL
C:\WINDOWS\system\RGAPH.DLL
C:\WINDOWS\system\RGAPH.DLL
C:\WINDOWS\system\RGAPH.DLL
C:\WINDOWS\system\RHGWIZC.DLL
C:\WINDOWS\system\RHGWIZC.DLL
C:\WINDOWS\system\RHGWIZC.DLL
C:\WINDOWS\system\RHGWIZC.DLL
C:\WINDOWS\system\ROR20.DLL
C:\WINDOWS\system\ROR20.DLL
C:\WINDOWS\system\ROR20.DLL
C:\WINDOWS\system\ROR20.DLL
C:\WINDOWS\system\RRCLTSPX.DLL
C:\WINDOWS\system\RRCLTSPX.DLL
C:\WINDOWS\system\RRCLTSPX.DLL
C:\WINDOWS\system\RRCLTSPX.DLL
C:\WINDOWS\system\RWCNS4.DLL
C:\WINDOWS\system\RWCNS4.DLL
C:\WINDOWS\system\RWCNS4.DLL
C:\WINDOWS\system\RWCNS4.DLL
C:\WINDOWS\system\RYGWIZC.DLL
C:\WINDOWS\system\RYGWIZC.DLL
C:\WINDOWS\system\RYGWIZC.DLL
C:\WINDOWS\system\RYGWIZC.DLL
C:\WINDOWS\system\RZAPH.DLL
C:\WINDOWS\system\RZAPH.DLL
C:\WINDOWS\system\RZAPH.DLL
C:\WINDOWS\system\RZAPH.DLL
C:\WINDOWS\system\SDLWAPI.DLL
C:\WINDOWS\system\SDLWAPI.DLL
C:\WINDOWS\system\SDLWAPI.DLL
C:\WINDOWS\system\SDLWAPI.DLL
C:\WINDOWS\system\SJDOCLC.DLL
C:\WINDOWS\system\SJDOCLC.DLL
C:\WINDOWS\system\SJDOCLC.DLL
C:\WINDOWS\system\SJDOCLC.DLL
C:\WINDOWS\system\SRMSETUP.DLL
C:\WINDOWS\system\SRMSETUP.DLL
C:\WINDOWS\system\SRMSETUP.DLL
C:\WINDOWS\system\SRMSETUP.DLL
C:\WINDOWS\system\SZCDLL.DLL
C:\WINDOWS\system\SZCDLL.DLL
C:\WINDOWS\system\SZCDLL.DLL
C:\WINDOWS\system\SZCDLL.DLL
C:\WINDOWS\system\Tze Golden Era.dll
C:\WINDOWS\system\Tze Golden Era.dll
C:\WINDOWS\system\Tze Golden Era.dll
C:\WINDOWS\system\Tze Golden Era.dll
C:\WINDOWS\system\UKLMON.DLL
C:\WINDOWS\system\UKLMON.DLL
C:\WINDOWS\system\UKLMON.DLL
C:\WINDOWS\system\UKLMON.DLL
C:\WINDOWS\system\UQDM16.DLL
C:\WINDOWS\system\UQDM16.DLL
C:\WINDOWS\system\UQDM16.DLL
C:\WINDOWS\system\UQDM16.DLL
C:\WINDOWS\system\UZDM16.DLL
C:\WINDOWS\system\UZDM16.DLL
C:\WINDOWS\system\UZDM16.DLL
C:\WINDOWS\system\UZDM16.DLL
C:\WINDOWS\system\VAR.DLL
C:\WINDOWS\system\VAR.DLL
C:\WINDOWS\system\VAR.DLL
C:\WINDOWS\system\VAR.DLL
C:\WINDOWS\system\vtpodbc.dll
C:\WINDOWS\system\vtpodbc.dll
C:\WINDOWS\system\vtpodbc.dll
C:\WINDOWS\system\vtpodbc.dll
C:\WINDOWS\system\vxar332.dll
C:\WINDOWS\system\vxar332.dll
C:\WINDOWS\system\vxar332.dll
C:\WINDOWS\system\vxar332.dll
C:\WINDOWS\system\WA2HELP.DLL
C:\WINDOWS\system\WA2HELP.DLL
C:\WINDOWS\system\WA2HELP.DLL
C:\WINDOWS\system\WA2HELP.DLL
C:\WINDOWS\system\wbv8dmoe.dll
C:\WINDOWS\system\wbv8dmoe.dll
C:\WINDOWS\system\wbv8dmoe.dll
C:\WINDOWS\system\wbv8dmoe.dll
C:\WINDOWS\system\wcspdmoe.dll
C:\WINDOWS\system\wcspdmoe.dll
C:\WINDOWS\system\wcspdmoe.dll
C:\WINDOWS\system\wcspdmoe.dll
C:\WINDOWS\system\wcstream.dll
C:\WINDOWS\system\wcstream.dll
C:\WINDOWS\system\wcstream.dll
C:\WINDOWS\system\wcstream.dll
C:\WINDOWS\system\WK5INF16.DLL
C:\WINDOWS\system\WK5INF16.DLL
C:\WINDOWS\system\WK5INF16.DLL
C:\WINDOWS\system\WK5INF16.DLL
C:\WINDOWS\system\wovdmoe.dll
C:\WINDOWS\system\wovdmoe.dll
C:\WINDOWS\system\wovdmoe.dll
C:\WINDOWS\system\wovdmoe.dll
C:\WINDOWS\system\wupui.dll
C:\WINDOWS\system\wupui.dll
C:\WINDOWS\system\wupui.dll
C:\WINDOWS\system\wupui.dll
C:\WINDOWS\system\XANROLL.DLL
C:\WINDOWS\system\XANROLL.DLL
C:\WINDOWS\system\XANROLL.DLL
C:\WINDOWS\system\XANROLL.DLL

************

Registry entries found:

[HKEY_CLASSES_ROOT\CLSID\{CAE0B3C0-E966-11D9-B835-00105A1F26EA}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\ODTLWAB.DLL"
[HKEY_CLASSES_ROOT\CLSID\{CAE0B3C0-E966-11D9-B835-00105A1F26EA}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\ODTLWAB.DLL"
[HKEY_CLASSES_ROOT\CLSID\{CAE0B3C0-E966-11D9-B835-00105A1F26EA}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\ODTLWAB.DLL"
[HKEY_CLASSES_ROOT\CLSID\{CAE0B3C0-E966-11D9-B835-00105A1F26EA}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\ODTLWAB.DLL"


************

Killing Explorer
Done!

Killing Rundll32
Done!

Removing malicious CLSID(s)
Done!

Restarting Explorer
Done!

Deleting malicious files
Done!


Finished!
  • 0

#4
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Ok, looks like L2MFix did the job.

Open HijackThis and click Scan. Put a check next to these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\OOBE\BLANK.HTM
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} - http://adserver.shar...ver/Install.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...rCabInstall.cab

Close all other windows except HijackThis and click Fix Checked. Reboot.

Then go here and make an online scan, save the results as a text file.

http://www.pandasoft...com/activescan/

When done, post a new log along with the Panda results. Are the popups gone now?
  • 0

#5
mill6793

mill6793

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Yes. Thank you.
  • 0

#6
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Good to hear that :) but please do that Panda scan and post the results. Since L2M is known to download other malware we should check. Panda does a very good job on identifying malware even though it won't remove it. Then it's our job to go after whatever it finds. :tazz:
  • 0

#7
mill6793

mill6793

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
I use AVG Grisoft. Would Panda conflict with that?
  • 0

#8
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
No, not at all..you're not going to download a second antivirus program..to do that would definitely cause conflicts...but this is just an online scan, you'll just download an Active-x to perform the scan..in almost all cases here we like to see an online scan performed and advise users to do one like at least once a month apart from the regular scans with their resident antivirus..it's like getting a second opinion:)
Though it's a good idea to turn off AVG for the course of the scan and reactivate immediately after..
  • 0

#9
mill6793

mill6793

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Downloaded Panda and ran scan. I've no idea how to post it. Everthing seems to be working great though. Thanx.
  • 0

#10
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
If you saved the results, just copy and paste them...
  • 0

#11
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Please take the following into consideration to maintain a clean computer.

Now you should go get a firewall. Don't rely on the Windows firewall as it monitors only incoming traffic. Pick one of these, they are all free.
Kerio
Zonealarm
Sygate

Visit Windows Update regularly to get the latest security updates.You can also enable automatic updates.Your antivirus software and antispyware programs should also be updated regularly. Make a habit of running scans on a timely basis. Be careful about what you download, scan every file before clicking on it.

Additional programs to consider:

Spywareblaster Prevents the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.Blocks spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.Restricts the actions of potentially unwanted sites in Internet Explorer.
Spywareguard An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware!
IE/Spyad
Adds a list of malicious sites to your Restricted Sites Zone.
Firefox An alternate browser safer than IE

A good article to read:
So how did I get infected in the first place?

Regards,

Armodeluxe
  • 0

#12
Armodeluxe

Armodeluxe

    Member 2k

  • Retired Staff
  • 2,744 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP