Here are the problems:
1. Desktop explorer won't come up when system is starting. The computer keeps
loading but the screen is blue. By doing Alt-Ctrl-Del/ Task Manager/ New Task/
and cmd.exe, I can start explorer.exe.
2. Sometimes I get the following message when the desktop is supposed to appear
An exception has occurred while trying to run "C:\WINNT\System32\
______.dll","UMonitor"
3. The quick launch toolbar shows duplicate icons.
4. The recycle bin will not empty.
5. When shutting down, get message that Fax Monitor will not shut down,
however, Fax Monitor was not an active program prior to shutting down.
I will attach my Finditnt200xp and Hijackthis logs.
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: C:\Documents and Settings\Administrator\My Documents\Computer\Umonitor\Find It NT-2K-XP
------- System Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is 00CB-17C1
Directory of C:\WINNT\System32
01/14/2005 07:12p 222,863 dpauth.dll
01/14/2005 07:09p 225,491 fp8m03l1e.dll
01/11/2005 11:33p 222,863 g0jola131d.dll
01/11/2005 10:59p <DIR> dllcache
01/09/2005 08:01p 222,647 lvp8097ue.dll
01/09/2005 10:38a 225,491 o4480ehueh480.dll
01/09/2005 10:26a 225,491 fpr0039me.dll
01/09/2005 10:02a 225,338 ir0sl5d71.dll
01/08/2005 03:44p 222,722 g440lehm1h4a.dll
01/08/2005 12:14a 223,153 enr8l19u1.dll
01/07/2005 11:21p 225,865 q0rqla951d.dll
01/07/2005 11:16p 225,595 h02olaf31d2.dll
01/06/2005 11:40p 222,552 lv8609lse.dll
01/06/2005 11:03p 225,866 lvro0993e.dll
01/06/2005 09:13p 226,213 f00olad31d0.dll
01/06/2005 09:10p 223,065 irjsl5171.dll
01/06/2005 09:06p 225,537 k4260efseh260.dll
01/06/2005 08:45p 225,174 dn6201joe.dll
01/06/2005 08:37p 223,005 i8lo0i33e8.dll
01/06/2005 08:28p 223,005 doprop.dll
01/06/2005 08:24p 223,108 fp0m03d1e.dll
01/06/2005 08:20p 226,180 ir8ol5l31.dll
01/06/2005 06:52p 226,150 g8400ihme84a0.dll
01/06/2005 06:48p 225,689 lvns0957e.dll
01/06/2005 06:43p 225,689 dlauth.dll
01/06/2005 06:37p 222,875 k044lahq1d4e.dll
01/06/2005 06:33p 222,875 MOGSVC.DLL
01/06/2005 05:30p 224,254 en2ul1f91.dll
01/05/2005 09:34p 224,692 j8l40i3qe8.dll
01/05/2005 09:25p 225,483 mv22l9fo1.dll
01/05/2005 09:15p 223,376 fp4403hqe.dll
01/05/2005 06:42p 224,730 k4nole531h.dll
01/05/2005 06:19p 225,246 m4280efueh280.dll
01/03/2005 04:49p 223,789 fpj4031qe.dll
01/02/2005 04:38p 223,810 fn2021fmg.dll
12/30/2004 11:19p 224,256 e420lefm1h2a.dll
35 File(s) 7,854,138 bytes
1 Dir(s) 33,643,208,704 bytes free
------- Hidden Files in System32 Directory -------
Volume in drive C has no label.
Volume Serial Number is 00CB-17C1
Directory of C:\WINNT\System32
01/14/2005 07:12p 890 vsconfig.xml
01/11/2005 10:59p <DIR> dllcache
01/07/2005 11:12p <DIR> vmss
01/07/2005 11:36a <DIR> wsxsvc
01/06/2005 11:27p 21,692 folder.htt
01/06/2005 11:27p 271 desktop.ini
01/02/2005 07:31p 4,212 zllictbl.dat
10/23/2004 11:52a <DIR> GroupPolicy
4 File(s) 27,065 bytes
4 Dir(s) 33,643,208,704 bytes free
------------ Files Named "Guard" ---------------
Volume in drive C has no label.
Volume Serial Number is 00CB-17C1
Directory of C:\WINNT\System32
------ Temp Files in System32 Directory ------
Volume in drive C has no label.
Volume Serial Number is 00CB-17C1
Directory of C:\WINNT\System32
07/24/2002 06:00a 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 33,643,208,704 bytes free
------------------ User Agent ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{BCF65EE1-3368-4CF8-A78A-E1D36625F190}"=""
------------- Keys Under Notify -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\g0jola131d.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000
------------- Locate.com Results -------------
C:\WINNT\SYSTEM32\
desktop.ini Thu Jan 6 2005 11:27:08p ...H. 271 0.26 K
dlauth.dll Thu Jan 6 2005 6:43:54p A.S.R 225,689 220.40 K
dn6201~1.dll Thu Jan 6 2005 8:45:16p A.S.R 225,174 219.89 K
doprop.dll Thu Jan 6 2005 8:28:22p A.S.R 223,005 217.78 K
dpauth.dll Fri Jan 14 2005 7:12:30p ..S.R 222,863 217.64 K
e420le~1.dll Thu Dec 30 2004 11:19:32p A.S.R 224,256 219.00 K
en2ul1~1.dll Thu Jan 6 2005 5:30:06p A.S.R 224,254 218.99 K
enr8l1~1.dll Sat Jan 8 2005 12:14:12a ..S.R 223,153 217.92 K
f00ola~1.dll Thu Jan 6 2005 9:13:12p A.S.R 226,213 220.91 K
fn2021~1.dll Sun Jan 2 2005 4:38:10p A.S.R 223,810 218.56 K
folder.htt Thu Jan 6 2005 11:27:08p ...H. 21,692 21.18 K
fp0m03~1.dll Thu Jan 6 2005 8:24:04p A.S.R 223,108 217.88 K
fp4403~1.dll Wed Jan 5 2005 9:15:18p A.S.R 223,376 218.14 K
fp8m03~1.dll Fri Jan 14 2005 7:09:38p ..S.R 225,491 220.20 K
fpj403~1.dll Mon Jan 3 2005 4:49:52p A.S.R 223,789 218.54 K
fpr003~1.dll Sun Jan 9 2005 10:26:44a ..S.R 225,491 220.20 K
g0jola~1.dll Tue Jan 11 2005 11:33:12p ..S.R 222,863 217.64 K
g440le~1.dll Sat Jan 8 2005 3:45:00p ..S.R 222,722 217.50 K
g8400i~1.dll Thu Jan 6 2005 6:52:40p A.S.R 226,150 220.85 K
h02ola~1.dll Fri Jan 7 2005 11:16:54p ..S.R 225,595 220.30 K
i8lo0i~1.dll Thu Jan 6 2005 8:37:22p A.S.R 223,005 217.78 K
ir0sl5~1.dll Sun Jan 9 2005 10:02:26a ..S.R 225,338 220.05 K
ir8ol5~1.dll Thu Jan 6 2005 8:20:22p A.S.R 226,180 220.88 K
irjsl5~1.dll Thu Jan 6 2005 9:10:48p A.S.R 223,065 217.84 K
j8l40i~1.dll Wed Jan 5 2005 9:34:02p A.S.R 224,692 219.43 K
k044la~1.dll Thu Jan 6 2005 6:37:26p A.S.R 222,875 217.65 K
k4260e~1.dll Thu Jan 6 2005 9:06:52p A.S.R 225,537 220.25 K
k4nole~1.dll Wed Jan 5 2005 6:42:18p A.S.R 224,730 219.46 K
lv8609~1.dll Thu Jan 6 2005 11:40:02p ..S.R 222,552 217.34 K
lvns09~1.dll Thu Jan 6 2005 6:48:54p A.S.R 225,689 220.40 K
lvp809~1.dll Sun Jan 9 2005 8:01:24p ..S.R 222,647 217.43 K
lvro09~1.dll Thu Jan 6 2005 11:03:26p A.S.R 225,866 220.57 K
m4280e~1.dll Wed Jan 5 2005 6:19:22p A.S.R 225,246 219.96 K
mogsvc.dll Thu Jan 6 2005 6:33:26p A.S.R 222,875 217.65 K
mv22l9~1.dll Wed Jan 5 2005 9:25:44p A.S.R 225,483 220.20 K
o4480e~1.dll Sun Jan 9 2005 10:38:58a ..S.R 225,491 220.20 K
q0rqla~1.dll Fri Jan 7 2005 11:21:08p ..S.R 225,865 220.57 K
vsconfig.xml Fri Jan 14 2005 7:12:24p A..H. 890 0.87 K
zllictbl.dat Sun Jan 2 2005 7:31:06p A..H. 4,212 4.11 K
39 items found: 39 files, 0 directories.
Total of file sizes: 7,881,203 bytes 7.52 M
-------- Strings.exe Qoologic Results --------
C:\WINNT\system32\hlluxm.exe: updates.qoologic.com
--------- Strings.exe Aspack Results ---------
-------------- HKLM Run Key ----------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe /logon"
"zzzHPSETUP"="D:\\Setup.exe"
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"tgcmd"="\"C:\\Program Files\\Support.com\\bin\\tgcmd.exe\" /server /startmonitor /deaf"
"SSRunScript"="\"C:\\Program Files\\Support.com\\Charter\\bin\\SSRunScript.exe\" /script \"C:\\Program Files\\Support.com\\Charter\\vbs\\verifyconnection.vbs\" /args //b startupdelay"
"VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask"
"VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\""
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\McUpdate.exe"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"vcmxin"="C:\\WINNT\\system32\\BW_ActiveX.Stub.exe"
"Dvx"="C:\\WINNT\\System32\\wsxsvc\\wsxsvc.exe"
"gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
"projselector"="\"C:\\Program Files\\Common Files\\Roxio Shared\\Project Selector\\projselector.exe\" -r"
"RoxioEngineUtility"="\"C:\\Program Files\\Common Files\\Roxio Shared\\System\\EngUtil.exe\""
"RoxioDragToDisc"="\"C:\\Program Files\\Roxio\\Easy CD Creator 6\\DragToDisc\\DrgToDsc.exe\""
"RoxioAudioCentral"="\"C:\\Program Files\\Roxio\\Easy CD Creator 6\\AudioCentral\\RxMon.exe\""
"NeroFilterCheck"="C:\\WINNT\\system32\\NeroCheck.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
Logfile of HijackThis v1.98.2
Scan saved at 8:22:53 PM, on 1/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\userinit.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINNT\explorer.exe
C:\WINNT\System32\mdm.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\System32\wsxsvc\wsxsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Roxio Shared\Project Selector\projselector.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Documents and Settings\Administrator\My Documents\Computer\Hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [SSRunScript] "C:\Program Files\Support.com\Charter\bin\SSRunScript.exe" /script "C:\Program Files\Support.com\Charter\vbs\verifyconnection.vbs" /args //b startupdelay
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [vcmxin] C:\WINNT\system32\BW_ActiveX.Stub.exe
O4 - HKLM\..\Run: [Dvx] C:\WINNT\System32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [projselector] "C:\Program Files\Common Files\Roxio Shared\Project Selector\projselector.exe" -r
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\Ahead\data\Xtras\mssysmgr.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....738&clcid=0x409