PDA

View Full Version : Explorer Errors



Damnatory
06-28-2004, 10:01 PM
I'm trying to get a friend's Laptop working again...

It's running on WinME, and "suddenly" she said that it stopped working. ( WinME -suprise, suprise) So about 3 minutes into starting windows an error occurs:


Explorer has caused an Error in
~7771777177.tmp
Explorer will now close.

After clicking close, your left with a blank screen and the only thing available is the ctrl-alt-del task manager.

I've tried to do a system restore, but no dates were availiable. I also thought that the problem might have been a P2P program she was using: "Ares" Which for some reason I couldn't keep from loading at start up so I used "msconfig" to stop all startup groups from loading. Now the explorer will allow me to navigate for about 5 minutes and actually open folders.

I also attempted to upgrade her OS, just to get rid of this shitty WinME. It won't boot from the CD, and its not accessable within SafeMode. I finally got the CD to open before the Explorer Err and was presented with another Err. Though the ~7771777177.tmp error still occurs...


The option to upgrtade will not be availiable at this time because Setup was unable to load the file:
C:\WINDOWS\UpdDlls\w95upg.dll\WIN9XUPG\W95UPG.DLL.

The system cannot find the file specified.

So i'm potentially able to install Win2K, but I would have to do a new copy rather than an upgrade. Will this wipe her personal files from the harddrive??? She's got close to 2GB of music that I'd like to save, but I can't move it off the harddrive... Anyone know of what could be causing the problem, and anyway to make the Upgrade available??? :helpsmile:

Chewie
06-28-2004, 11:31 PM
Download and run HijackThis, perform a scan, then post the results here.

EDIT
DIRECT DOWNLOAD (http://www.spywareinfo.com/~merijn/files/hijackthis.zip)
HijackThis will fit on a floppy (so use your computer to download it), leave room for a log file and be quick enough for you to accomplish this feat and post from your own computer.

Damnatory
06-29-2004, 12:07 AM
Well. The Laptop doesn't have a floppy drive... Just a DVD-rom... I could put it on CD but, I can't think of any way to transfer the findings back...

I would try and email them real quick, but the laptop only has a port for a modem, no network adapter, and I have a cable connection... <_<

Damnatory
06-29-2004, 12:56 AM
Ok, I was able to log into her AOL account... lol

Here&#39;s the log file:

Logfile of HijackThis v1.97.7
Scan saved at 6&#58;40&#58;18 PM, on 6/28/2004
Platform&#58; Windows ME &#40;Win9x 4.90.3000&#41;
MSIE&#58; Internet Explorer v5.51 SP2 &#40;5.51.4807.2300&#41;
Running processes&#58;
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;KERNEL32.DLL
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSGSRV32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SPOOL32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MPREXE.EXE
C&#58;&#092;PROGRAM FILES&#092;COMMON FILES&#092;WINTOOLS&#092;WTOOLSA.EXE
C&#58;&#092;WINDOWS&#092;MWW32&#092;MANAGER&#092;MWSSW32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;mmtask.tsk
C&#58;&#092;PROGRAM FILES&#092;COMMON FILES&#092;WINTOOLS&#092;WSUP.EXE
C&#58;&#092;WINDOWS&#092;EXPLORER.EXE
C&#58;&#092;WINDOWS&#092;DHSVR.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
D&#58;&#092;HIJACKTHIS.EXE
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http&#58;//server224.smartbotpro.net/7search/?hkcu
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http&#58;//www.yahoo.com
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//www.mallmonkeys.com/forum/index.php
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//default-homepage-network.com/start.cgi?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http&#58;//server224.smartbotpro.net/7search/?hklm
R1 - HKLM&#092;Softwar&#33; e&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http&#58;//www.yahoo.com
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http&#58;//my.yahoo.com
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http&#58;//www.yahoo.com
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;SearchURL,&#40;Default&#41; = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http&#58;//w&#33; ww.yahoo.com
O2 - BHO&#58; &#40;no name&#41; - {0000CC75-ACF3-4cac-A0A9-DD3 868E06852} - C&#58;&#092;PROGRAM FILES&#092;DAP&#092;DAPBHO.DLL
O2 - BHO&#58; &#40;no name&#41; - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSNKMI.DLL
O2 - BHO&#58; &#40;no name&#41; - {00A0A40C-F432-4C59-BA11-B25D142C7AB7} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSKCEO.DLL
O2 - BHO&#58; &#40;no name&#41; - {CC916B4B-BE44-4026-A19D-8C74BBD23361} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSEDAH.DLL
O2 - BHO&#58; &#40;no name&#41; - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSKHHE.DLL
O2 - BHO&#58; &#40;no name&#41; - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C&#58;&#092;PROGRAM FILES&#092;LYCOS&#092;SIDESEARCH&#092;SIDESEARCH1400.DLL &#40;file missing&#41;
O2 - BHO&#58; &#40;no name&#41; - {0BA1C6EB-D062-4E37-9DB5-B07743276324} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSDAIM.DLL
O2 - BHO&#58; &#40;no name&#41; - {94927A13-4AAA-476A-989D-392456427688} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSJFBL.DLL
O2 - BHO&#58; &#40;no name&#41; - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSIBKD.DLL
O2 - BHO&#58; &#40;no name&#41; - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C&#58;&#092;WINDOWS&#092;DEALHLPR.DLL
O2 - BHO&#58; &#40;no name&#41; - {87766247-311C-43B4-8499-3D5FE&#33; C94A183} - C&#58;&#092;PROGRA~1&#092;COMMON~1&#092;WINTOOLS&#092;WTOOLSB.DLL
O3 - Toolbar&#58; DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C&#58;&#092;PROGRAM FILES&#092;DAP&#092;DAPIEBAR.DLL
O3 - Toolbar&#58; @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSDXM.OCX
O3 - Toolbar&#58; Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C&#58;&#092;WINDOWS&#092;DEALHLPR.DLL
O3 - Toolbar&#58; zSearch Bar - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;zSearch.dll
O4 - HKLM&#092;..&#092;Run&#58; &#91;MSConfigReminder&#93; C&#58;&#092;WINDOWS&#092;SYSTEM&#092;msconfig.exe /reminder
O4 - HKLM&#092;..&#092;Run&#58; &#91;zSearch&#93; C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;ZSTB.EXE
O4 - HKLM&#092;..&#092;Run&#58; &#91;WinTools&#93; C&#58;&#092;Program Files&#092;Common files&#092;WinTools&#092;WToolsA.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;WinTools&#93; C&#58;&#092;Program Files&#092;Common files&#092;WinTools&#092;WToolsA.exe
O4 - HKCU&#092;..&#092;Run&#58; &#91;ares&#93; &#34;C&#58;&#092;PROGRAM FILES&#092;ARES&#092;ARES.EXE&#34; -h
O4 - HKCU&#092;..&#092;Run&#58; &#91;msmc&#93; C&#58;&#092;WINDOWS&#092;SYSTEM&#092;msmc.exe
O4 - HKCU&#092;..&#092;Run&#58; &#91;zSearch&#93; C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;ZSTB.EXE
O8&#33; - Extra context menu item&#58; &Download with &DAP - C&#58;&#092;PROGRA~1&#092; DAP&#092;dapextie.htm
O8 - Extra context menu item&#58; Download &all with DAP - C&#58;&#092;PROGRA~1&#092;DAP&#092;dapextie2.htm
O8 - Extra context menu item&#58; Yahoo&#33; Search - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycsrch.htm
O8 - Extra context menu item&#58; Yahoo&#33; Dictionary - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycdict.htm
O9 - Extra button&#58; Run DAP &#40;HKLM&#41;
O9 - Extra button&#58; AIM &#40;HKLM&#41;
O9 - Extra button&#58; Sidesearch &#40;HKLM&#41;
O16 - DPF&#58; {1D6711C8-7154-40BB-8380-3DEA45B69CBF} &#40;Web P2P Installer&#41; -
O16 - DPF&#58; {D27CDB6E-AE6D-11CF-96B8-444553540000} &#40;Shockwave Flash Object&#41; - http&#58;//download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF&#58; Yahoo&#33; Literati - http&#58;//download.games.yahoo.com/games/clients/y/tt2_x.cab

Jg427
06-29-2004, 02:43 AM
You have lots of stuff happening in that log.
I think it&#39;s msmc.exe that&#39;s causing explorer to shut down. TROJ_SMALL.XC (http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_SMALL.XC&VSect=T)

Since you have little time before windows shuts down, download and burn to cd for the laptop: Adaware, process explorer and stinger.

If you could shut down that running process, msmc, you might have time for a more complete fix. I don&#39;t think windows ME has a task manager that will end processes, but you can download Process explorer (http://www.sysinternals.com/ntw2k/freeware/procexp.shtml) that works on ME. It will allow you to right click msmc and end process.

Download AdAware (http://www.lavasoftusa.com/), install and update before you run it.
On the lavasoft page you can download the latest reference file separately and update adaware after you install. Go to C:&#092;Program Files&#092;Lavasoft&#092;Ad-aware 6 and replace the reflist.ref file with the new one.

While your at it, download Stinger (http://vil.nai.com/vil/stinger/), a virus scanner, and put it on the cd .

Check in add/remove programs for wintools and uninstall, if it&#39;s listed. Also uninstall Download accelerator plus if you can.

Post a new log.

Damnatory
06-29-2004, 09:57 PM
Ok, so I followed the instructions to remove the msmc.exe, but somehow, it&#39;s still there, though now it doesn&#39;t kill the explorer. The registry key I deleted from it keeps coming back... <_< So no explorer errors, but now the laptop suffers massive hang time... Sure its a slow processor, but not so slow that it takes like 2 minutes to load "my computer". I was able to install Adaware, Ultra Win cleaner, and Diskeeper 8 to try and speed things up a bit, but I wasn&#39;t able to install Process Explorer... I used the Stinger program, and it ran for like 45 minutes and crashed. Ultra Win Cleaner crashes, Diskeeper 8 Hangs and never performs the defrag, but Adaware works like a champ. (508 removed spyware... god I love Adaware )

Download Excellerator plus is gone now too.
I&#39;m getting ready to go back over there and swipe her laptop again, so I&#39;ll post another Hijackthis log when I get there.

Thanks for the help so far&#33;

Damnatory
06-30-2004, 06:59 AM
Alright, Here&#39;s the new Hijackthis.log
The odd thing is, it looks as if there is more things going on now than before. Of course now I&#39;m starting up with the startup groups that I had turned off before. I&#39;ve still got remnents of alot of the programs that I have removed from the computer too... (i.e. Dealhelper, zSearch, Ares... etc. )


Logfile of HijackThis v1.97.7
Scan saved at 12&#58;51&#58;08 AM, on 6/30/2004
Platform&#58; Windows ME &#40;Win9x 4.90.3000&#41;
MSIE&#58; Internet Explorer v5.51 SP2 &#40;5.51.4807.2300&#41;

Running processes&#58;
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;KERNEL32.DLL
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSGSRV32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;mmtask.tsk
C&#58;&#092;WINDOWS&#092;MWW32&#092;MANAGER&#092;MWSSW32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MPREXE.EXE
C&#58;&#092;PROGRAM FILES&#092;COMMON FILES&#092;WINTOOLS&#092;WTOOLSA.EXE
C&#58;&#092;PROGRAM FILES&#092;DISKEEPER&#092;DKSERVICE.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSTASK.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;CMD32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;RPCSS.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;RESTORE&#092;STMGR.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SPOOL32.EXE
C&#58;&#092;PROGRAM FILES&#092;COMMON FILES&#092;WINTOOLS&#092;WSUP.EXE
C&#58;&#092;WINDOWS&#092;EXPLORER.EXE
C&#58;&#092;WINDOWS&#092;TASKMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SYSTRAY.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;IRMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;WMIEXE.EXE
C&#58;&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER&#092;DPPS2.EXE
C&#58;&#092;WINDOWS&#092;LOADQM.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE
C&#58;&#092;WINDOWS&#092;DHUPDT.EXE
C&#58;&#092;WINDOWS&#092;DHBRWSR.EXE
C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.EXE
C&#58;&#092;WINDOWS&#092;DHSVR.EXE
C&#58;&#092;WINDOWS&#092;DESKTOP&#092;HIJACKTHIS.EXE

R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http&#58;//server224.smartbotpro.net/7search/?hkcu
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http&#58;//www.yahoo.com
R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//www.mallmonkeys.com/forum/index.php
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//default-homepage-network.com/start.cgi?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http&#58;//server224.smartbotpro.net/7search/?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http&#58;//www.yahoo.com
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http&#58;//my.yahoo.com
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http&#58;//www.yahoo.com
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;SearchURL,&#40;Default&#41; = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http&#58;//www.yahoo.com
O2 - BHO&#58; &#40;no name&#41; - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSNKMI.DLL
O2 - BHO&#58; &#40;no name&#41; - {00A0A40C-F432-4C59-BA11-B25D142C7AB7} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSKCEO.DLL
O2 - BHO&#58; &#40;no name&#41; - {CC916B4B-BE44-4026-A19D-8C74BBD23361} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSEDAH.DLL
O2 - BHO&#58; &#40;no name&#41; - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSKHHE.DLL
O2 - BHO&#58; &#40;no name&#41; - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C&#58;&#092;PROGRAM FILES&#092;LYCOS&#092;SIDESEARCH&#092;SIDESEARCH1400.DLL &#40;file missing&#41;
O2 - BHO&#58; &#40;no name&#41; - {0BA1C6EB-D062-4E37-9DB5-B07743276324} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSDAIM.DLL
O2 - BHO&#58; &#40;no name&#41; - {94927A13-4AAA-476A-989D-392456427688} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSJFBL.DLL
O2 - BHO&#58; &#40;no name&#41; - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSIBKD.DLL
O2 - BHO&#58; &#40;no name&#41; - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C&#58;&#092;WINDOWS&#092;DEALHLPR.DLL
O2 - BHO&#58; &#40;no name&#41; - {87766247-311C-43B4-8499-3D5FEC94A183} - C&#58;&#092;PROGRA~1&#092;COMMON~1&#092;WINTOOLS&#092;WTOOLSB.DLL
O2 - BHO&#58; &#40;no name&#41; - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;zSearch.dll &#40;file missing&#41;
O3 - Toolbar&#58; @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSDXM.OCX
O3 - Toolbar&#58; Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C&#58;&#092;WINDOWS&#092;DEALHLPR.DLL
O4 - HKLM&#092;..&#092;Run&#58; &#91;zSearch&#93; C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;ZSTB.EXE
O4 - HKLM&#092;..&#092;Run&#58; &#91;ScanRegistry&#93; C&#58;&#092;WINDOWS&#092;scanregw.exe /autorun
O4 - HKLM&#092;..&#092;Run&#58; &#91;TaskMonitor&#93; C&#58;&#092;WINDOWS&#092;taskmon.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;SystemTray&#93; SysTray.Exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;IrMon&#93; irmon.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;PCHealth&#93; C&#58;&#092;WINDOWS&#092;PCHealth&#092;Support&#092;PCHSchd.exe -s
O4 - HKLM&#092;..&#092;Run&#58; &#91;LoadPowerProfile&#93; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM&#092;..&#092;Run&#58; &#91;SoundFusion&#93; RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM&#092;..&#092;Run&#58; &#91;Modem Update Reminder&#93; C&#58;&#092;WINDOWS&#092;MWW32&#092;manager&#092;mwremind.exe autorun
O4 - HKLM&#092;..&#092;Run&#58; &#91;Pop-Up Stopper&#93; &#34;C&#58;&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER&#092;DPPS2.EXE&#34;
O4 - HKLM&#092;..&#092;Run&#58; &#91;LoadQM&#93; loadqm.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;Gtwatch&#93; C&#58;&#092;WINDOWS&#092;gtwatch.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;CMD&#93; cmd32.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;QuickTime Task&#93; &#34;C&#58;&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE&#34; -atboottime
O4 - HKLM&#092;..&#092;Run&#58; &#91;ClrSchLoader&#93; &#092;Program Files&#092;ClearSearch&#092;Loader.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;DealHelperUpdate&#93; C&#58;&#092;WINDOWS&#092;DHUpdt.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;DealHelperBrwsr&#93; C&#58;&#092;WINDOWS&#092;dhbrwsr.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;WinTools&#93; C&#58;&#092;Program Files&#092;Common files&#092;WinTools&#092;WToolsA.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;WinTools&#93; C&#58;&#092;Program Files&#092;Common files&#092;WinTools&#092;WToolsA.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;DkService&#93; C&#58;&#092;Program Files&#092;Diskeeper&#092;DkService.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;LoadPowerProfile&#93; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;SchedulingAgent&#93; mstask.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;*StateMgr&#93; C&#58;&#092;WINDOWS&#092;System&#092;Restore&#092;StateMgr.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;StillImageMonitor&#93; C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;CMD&#93; cmd32.exe
O4 - HKCU&#092;..&#092;Run&#58; &#91;ares&#93; &#34;C&#58;&#092;PROGRAM FILES&#092;ARES&#092;ARES.EXE&#34; -h
O4 - HKCU&#092;..&#092;Run&#58; &#91;zSearch&#93; C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;ZSTB.EXE
O4 - Startup&#58; Watch.lnk = C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.exe
O4 - Startup&#58; Event Reminder.lnk = c&#58;&#092;PMW&#092;PMREMIND.EXE
O4 - User Startup&#58; Watch.lnk = C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.exe
O4 - User Startup&#58; Event Reminder.lnk = c&#58;&#092;PMW&#092;PMREMIND.EXE
O8 - Extra context menu item&#58; &Download with &DAP - C&#58;&#092;PROGRA~1&#092;DAP&#092;dapextie.htm
O8 - Extra context menu item&#58; Download &all with DAP - D&#58;&#092;PROGRA~1&#092;DAP&#092;dapextie2.htm
O8 - Extra context menu item&#58; Yahoo&#33; Search - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycsrch.htm
O8 - Extra context menu item&#58; Yahoo&#33; Dictionary - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycdict.htm
O9 - Extra button&#58; AIM &#40;HKLM&#41;
O9 - Extra button&#58; Sidesearch &#40;HKLM&#41;
O16 - DPF&#58; {D27CDB6E-AE6D-11CF-96B8-444553540000} &#40;Shockwave Flash Object&#41; - http&#58;//download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF&#58; Yahoo&#33; Literati - http&#58;//download.games.yahoo.com/games/clients/y/tt2_x.cab
O16 - DPF&#58; {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} &#40;WebCam Control&#41; - http&#58;//www.webcamnow.com/broadcast/ActiveXWebCam.cab
O17 - HKLM&#092;System&#092;CCS&#092;Services&#092;VxD&#092;MSTCP&#58; Domain = aoldsl.net

How&#39;s it looking now?
Looking at this log is makin my head hurt a lil... Can anyone tell me which ones I need to have HiJackThis fix???

Jg427
06-30-2004, 11:41 AM
Check in add/remove programs for wintools and uninstall if it&#39;s listed, it&#39;s still running. Try booting into safemode and running stinger again. I would run spybot and adaware again while in safemode.
If stinger still crashes, try an online scan at http://housecall.trendmicro.com/

We can start fixing with hjt after you do that and post a new log. I&#39;ll check back after work.

Damnatory
07-01-2004, 08:04 AM
Ok:

WinTools is gone.
Stinger worked in SafeMode. ( No infections )
Spybot S&D removed 30 unwanted programs, including 10 instances of ClientMan. lol
Adaware didn&#39;t catch anything new in SafeMode.


Logfile of HijackThis v1.97.7
Scan saved at 1&#58;56&#58;01 AM, on 7/1/2004
Platform&#58; Windows ME &#40;Win9x 4.90.3000&#41;
MSIE&#58; Internet Explorer v5.51 SP2 &#40;5.51.4807.2300&#41;

Running processes&#58;
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;KERNEL32.DLL
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSGSRV32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;mmtask.tsk
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MPREXE.EXE
C&#58;&#092;WINDOWS&#092;MWW32&#092;MANAGER&#092;MWSSW32.EXE
C&#58;&#092;PROGRAM FILES&#092;DISKEEPER&#092;DKSERVICE.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSTASK.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;CMD32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;RESTORE&#092;STMGR.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;RPCSS.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SPOOL32.EXE
C&#58;&#092;WINDOWS&#092;EXPLORER.EXE
C&#58;&#092;WINDOWS&#092;TASKMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SYSTRAY.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;IRMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;WMIEXE.EXE
C&#58;&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER&#092;DPPS2.EXE
C&#58;&#092;WINDOWS&#092;LOADQM.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE
C&#58;&#092;WINDOWS&#092;DHUPDT.EXE
C&#58;&#092;WINDOWS&#092;DHBRWSR.EXE
C&#58;&#092;WINDOWS&#092;DESKTOP&#092;HIJACKTHIS.EXE

R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//www.mallmonkeys.com/forum/index.php
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//default-homepage-network.com/start.cgi?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http&#58;//server224.smartbotpro.net/7search/?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http&#58;//www.yahoo.com
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http&#58;//my.yahoo.com
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http&#58;//www.yahoo.com
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;SearchURL,&#40;Default&#41; = http&#58;//red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http&#58;//www.yahoo.com
O2 - BHO&#58; &#40;no name&#41; - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSKHHE.DLL
O2 - BHO&#58; &#40;no name&#41; - {94927A13-4AAA-476A-989D-392456427688} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSJFBL.DLL
O2 - BHO&#58; &#40;no name&#41; - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSIBKD.DLL
O2 - BHO&#58; &#40;no name&#41; - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C&#58;&#092;WINDOWS&#092;DEALHLPR.DLL
O2 - BHO&#58; &#40;no name&#41; - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - C&#58;&#092;PROGRAM FILES&#092;ZSEARCH&#092;zSearch.dll &#40;file missing&#41;
O2 - BHO&#58; &#40;no name&#41; - {53707962-6F74-2D53-2644-206D7942484F} - C&#58;&#092;Program Files&#092;Spybot&#092;SDHelper.dll
O3 - Toolbar&#58; @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSDXM.OCX
O3 - Toolbar&#58; Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C&#58;&#092;WINDOWS&#092;DEALHLPR.DLL
O4 - HKLM&#092;..&#092;Run&#58; &#91;ScanRegistry&#93; C&#58;&#092;WINDOWS&#092;scanregw.exe /autorun
O4 - HKLM&#092;..&#092;Run&#58; &#91;TaskMonitor&#93; C&#58;&#092;WINDOWS&#092;taskmon.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;SystemTray&#93; SysTray.Exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;IrMon&#93; irmon.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;PCHealth&#93; C&#58;&#092;WINDOWS&#092;PCHealth&#092;Support&#092;PCHSchd.exe -s
O4 - HKLM&#092;..&#092;Run&#58; &#91;LoadPowerProfile&#93; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM&#092;..&#092;Run&#58; &#91;SoundFusion&#93; RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM&#092;..&#092;Run&#58; &#91;Modem Update Reminder&#93; C&#58;&#092;WINDOWS&#092;MWW32&#092;manager&#092;mwremind.exe autorun
O4 - HKLM&#092;..&#092;Run&#58; &#91;Pop-Up Stopper&#93; &#34;C&#58;&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER&#092;DPPS2.EXE&#34;
O4 - HKLM&#092;..&#092;Run&#58; &#91;LoadQM&#93; loadqm.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;Gtwatch&#93; C&#58;&#092;WINDOWS&#092;gtwatch.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;CMD&#93; cmd32.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;QuickTime Task&#93; &#34;C&#58;&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE&#34; -atboottime
O4 - HKLM&#092;..&#092;Run&#58; &#91;DealHelperUpdate&#93; C&#58;&#092;WINDOWS&#092;DHUpdt.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;DealHelperBrwsr&#93; C&#58;&#092;WINDOWS&#092;dhbrwsr.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;RealTray&#93; C&#58;&#092;Program Files&#092;Real&#092;RealPlayer&#092;RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;DkService&#93; C&#58;&#092;Program Files&#092;Diskeeper&#092;DkService.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;LoadPowerProfile&#93; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;SchedulingAgent&#93; mstask.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;*StateMgr&#93; C&#58;&#092;WINDOWS&#092;System&#092;Restore&#092;StateMgr.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;StillImageMonitor&#93; C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;CMD&#93; cmd32.exe
O4 - Startup&#58; Watch.lnk = C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.exe
O4 - Startup&#58; Event Reminder.lnk = c&#58;&#092;PMW&#092;PMREMIND.EXE
O4 - User Startup&#58; Watch.lnk = C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.exe
O4 - User Startup&#58; Event Reminder.lnk = c&#58;&#092;PMW&#092;PMREMIND.EXE
O8 - Extra context menu item&#58; &Download with &DAP - C&#58;&#092;PROGRA~1&#092;DAP&#092;dapextie.htm
O8 - Extra context menu item&#58; Download &all with DAP - D&#58;&#092;PROGRA~1&#092;DAP&#092;dapextie2.htm
O8 - Extra context menu item&#58; Yahoo&#33; Search - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycsrch.htm
O8 - Extra context menu item&#58; Yahoo&#33; Dictionary - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycdict.htm
O9 - Extra button&#58; AIM &#40;HKLM&#41;
O9 - Extra button&#58; Real.com &#40;HKLM&#41;
O16 - DPF&#58; {D27CDB6E-AE6D-11CF-96B8-444553540000} &#40;Shockwave Flash Object&#41; - http&#58;//download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF&#58; Yahoo&#33; Literati - http&#58;//download.games.yahoo.com/games/clients/y/tt2_x.cab
O16 - DPF&#58; {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} &#40;WebCam Control&#41; - http&#58;//www.webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF&#58; {9F1C11AA-197B-4942-BA54-47A8489BB47F} &#40;Update Class&#41; - http&#58;//v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38168.5109490741

How&#39;s it looking now?
There is still those weird instances of the programs that have been removed, like Dealhelper, Download accelerator plus... Anything else looking out of the ordinary?

dopey
07-01-2004, 09:18 AM
hi,

run an online scan here (the virus is still there :():

http&#58;//housecall.trendmicro.com/housecall/start_corp.asp

download cwshredder here (http://www.spywareinfo.com/~merijn/files/cwshredder.zip) extract the program, close all browser windows and hit fix.

reboot.

using taskmanager end task on this file:
mwremind.exe

rescan with hijack this and check the following: (if still there)
R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://default-homepage-network.com/start.cgi?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http://server224.smartbotpro.net/7search/?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com (http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com)
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com (http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com)
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com (http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com)
R1 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com (http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com)

O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C:&#092;WINDOWS&#092;SYSTEM&#092;MSKHHE.DLL
O2 - BHO: (no name) - {94927A13-4AAA-476A-989D-392456427688} - C:&#092;WINDOWS&#092;SYSTEM&#092;MSJFBL.DLL
O2 - BHO: (no name) - {447160CD-ECF5-4EA2-8A8A-1F70CA363F85} - C:&#092;WINDOWS&#092;SYSTEM&#092;MSIBKD.DLL
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:&#092;WINDOWS&#092;DEALHLPR.DLL
O2 - BHO: (no name) - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - C:&#092;PROGRAM FILES&#092;ZSEARCH&#092;zSearch.dll (file missing)

O3 - Toolbar: Band Class - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:&#092;WINDOWS&#092;DEALHLPR.DLL

O4 - HKLM&#092;..&#092;Run: [Modem Update Reminder] C:&#092;WINDOWS&#092;MWW32&#092;manager&#092;mwremind.exe autorun
O4 - HKLM&#092;..&#092;Run: [LoadQM] loadqm.exe
O4 - HKLM&#092;..&#092;Run: [CMD] cmd32.exe
O4 - HKLM&#092;..&#092;Run: [DealHelperUpdate] C:&#092;WINDOWS&#092;DHUpdt.exe
O4 - HKLM&#092;..&#092;Run: [DealHelperBrwsr] C:&#092;WINDOWS&#092;dhbrwsr.exe
O4 - HKLM&#092;..&#092;RunServices: [CMD] cmd32.exe

O8 - Extra context menu item: &Download with &DAP - C:&#092;PROGRA~1&#092;DAP&#092;dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:&#092;PROGRA~1&#092;DAP&#092;dapextie2.htm

close all browser windows and hit fix checked. reboot in safe mode and delete
C:&#092;WINDOWS&#092;SYSTEM&#092;CMD32.EXE
C:&#092;WINDOWS&#092;MWW32&#092; <-- folder

reboot into normal mode and post a new log when done. :)

Damnatory
07-01-2004, 09:46 AM
WindowsME doesn&#39;t have the ability to end specific process&#39;... And the program suggested before to do that ( Process Explorer), won&#39;t work on this machine for some reason.

Isn&#39;t CMD32.exe the executable for Windows&#39; MS-Dos explorer?

Whats the cwShredder do?

dopey
07-01-2004, 09:59 AM
the cmd32.exe is definitely a baddie.


http&#58;//www.liutilities.com/products/wintaskspro/processlibrary/cmd32/

these lines here tell me you have the coolwebsearch trojan:

R0 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http://default-homepage-network.com/start.cgi?hklm
R1 - HKLM&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Search Bar = http://server224.smartbotpro.net/7search/?hklm

it basically redirects your searches to their search engines, adding bogus results as well. :ph34r:


edit: you should try again using the process explorer and highlight the file, then control-k to kill it.

Damnatory
07-01-2004, 10:10 AM
Oh I believe you, but I&#39;m just trying to find a way around the fact that I have to close out the mwrewind.exe, without having a process tab.

dopey
07-01-2004, 10:19 AM
hopefully housecall will be able to take care of it for you.

but the process explorer should work. is there some error that it gives you? maybe i can get in touch with the developer to find out what&#39;s going on.

i&#39;m not too familiar with windows me. :(

hopefully Jg427 will have some new ideas in the meantime

Damnatory
07-01-2004, 01:42 PM
Ok, so I did all that, but the folder MWW32 had some tie with the modem, and I was unable to connect when I deleted it, so I had to restore that folder. Here&#39;s an update of the HJT log.


Logfile of HijackThis v1.97.7
Scan saved at 6&#58;44&#58;10 AM, on 7/1/2004
Platform&#58; Windows ME &#40;Win9x 4.90.3000&#41;
MSIE&#58; Internet Explorer v5.51 SP2 &#40;5.51.4807.2300&#41;

Running processes&#58;
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;KERNEL32.DLL
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSGSRV32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;mmtask.tsk
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MPREXE.EXE
C&#58;&#092;PROGRAM FILES&#092;DISKEEPER&#092;DKSERVICE.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSTASK.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SPOOL32.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;RPCSS.EXE
C&#58;&#092;WINDOWS&#092;EXPLORER.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;RESTORE&#092;STMGR.EXE
C&#58;&#092;WINDOWS&#092;TASKMON.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;SYSTRAY.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;IRMON.EXE
C&#58;&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER&#092;DPPS2.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE
C&#58;&#092;WINDOWS&#092;SYSTEM&#092;WMIEXE.EXE
C&#58;&#092;PROGRAM FILES&#092;REAL&#092;REALPLAYER&#092;REALPLAY.EXE
C&#58;&#092;WINDOWS&#092;DESKTOP&#092;HIJACKTHIS.EXE

R0 - HKCU&#092;Software&#092;Microsoft&#092;Internet Explorer&#092;Main,Start Page = http&#58;//www.mallmonkeys.com/forum/index.php
O2 - BHO&#58; &#40;no name&#41; - {53707962-6F74-2D53-2644-206D7942484F} - C&#58;&#092;Program Files&#092;Spybot&#092;SDHelper.dll
O3 - Toolbar&#58; @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C&#58;&#092;WINDOWS&#092;SYSTEM&#092;MSDXM.OCX
O4 - HKLM&#092;..&#092;Run&#58; &#91;ScanRegistry&#93; C&#58;&#092;WINDOWS&#092;scanregw.exe /autorun
O4 - HKLM&#092;..&#092;Run&#58; &#91;TaskMonitor&#93; C&#58;&#092;WINDOWS&#092;taskmon.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;SystemTray&#93; SysTray.Exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;IrMon&#93; irmon.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;PCHealth&#93; C&#58;&#092;WINDOWS&#092;PCHealth&#092;Support&#092;PCHSchd.exe -s
O4 - HKLM&#092;..&#092;Run&#58; &#91;LoadPowerProfile&#93; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM&#092;..&#092;Run&#58; &#91;SoundFusion&#93; RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM&#092;..&#092;Run&#58; &#91;Pop-Up Stopper&#93; &#34;C&#58;&#092;PROGRAM FILES&#092;PANICWARE&#092;POP-UP STOPPER&#092;DPPS2.EXE&#34;
O4 - HKLM&#092;..&#092;Run&#58; &#91;Gtwatch&#93; C&#58;&#092;WINDOWS&#092;gtwatch.exe
O4 - HKLM&#092;..&#092;Run&#58; &#91;QuickTime Task&#93; &#34;C&#58;&#092;WINDOWS&#092;SYSTEM&#092;QTTASK.EXE&#34; -atboottime
O4 - HKLM&#092;..&#092;Run&#58; &#91;RealTray&#93; C&#58;&#092;Program Files&#092;Real&#092;RealPlayer&#092;RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;DkService&#93; C&#58;&#092;Program Files&#092;Diskeeper&#092;DkService.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;LoadPowerProfile&#93; Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;SchedulingAgent&#93; mstask.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;*StateMgr&#93; C&#58;&#092;WINDOWS&#092;System&#092;Restore&#092;StateMgr.exe
O4 - HKLM&#092;..&#092;RunServices&#58; &#91;StillImageMonitor&#93; C&#58;&#092;WINDOWS&#092;SYSTEM&#092;STIMON.EXE
O4 - Startup&#58; Watch.lnk = C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.exe
O4 - Startup&#58; Event Reminder.lnk = c&#58;&#092;PMW&#092;PMREMIND.EXE
O4 - User Startup&#58; Watch.lnk = C&#58;&#092;WINDOWS&#092;TWAIN_32&#092;S6U12BX&#092;WATCH.exe
O4 - User Startup&#58; Event Reminder.lnk = c&#58;&#092;PMW&#092;PMREMIND.EXE
O8 - Extra context menu item&#58; Yahoo&#33; Search - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycsrch.htm
O8 - Extra context menu item&#58; Yahoo&#33; Dictionary - file&#58;///C&#58;&#092;Program Files&#092;Yahoo&#33;&#092;Common/ycdict.htm
O9 - Extra button&#58; AIM &#40;HKLM&#41;
O9 - Extra button&#58; Real.com &#40;HKLM&#41;
O16 - DPF&#58; {D27CDB6E-AE6D-11CF-96B8-444553540000} &#40;Shockwave Flash Object&#41; - http&#58;//download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF&#58; Yahoo&#33; Literati - http&#58;//download.games.yahoo.com/games/clients/y/tt2_x.cab
O16 - DPF&#58; {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} &#40;WebCam Control&#41; - http&#58;//www.webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF&#58; {9F1C11AA-197B-4942-BA54-47A8489BB47F} &#40;Update Class&#41; - http&#58;//v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38168.5109490741
O16 - DPF&#58; {74D05D43-3236-11D4-BDCD-00C04F9A3B61} &#40;HouseCall Control&#41; - http&#58;//a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab

Jg427
07-01-2004, 03:42 PM
I don&#39;t see any more problems listed. Maybe dopey will see something I missed. That&#39;s a big difference from your first hjt log.

I would still look for the following files and delete any you find, hopefully most are already gone.

C:&#092;WINDOWS&#092;SYSTEM&#092;CMD32.EXE
C:&#092;WINDOWS&#092;DHBRWSR.EXE
C:&#092;WINDOWS&#092;DHSVR.EXE
C:&#092;WINDOWS&#092;SYSTEM&#092;MSNKMI.DLL
C:&#092;WINDOWS&#092;SYSTEM&#092;MSKCEO.DLL
C:&#092;WINDOWS&#092;SYSTEM&#092;MSEDAH.DLL
C:&#092;WINDOWS&#092;SYSTEM&#092;MSKHHE.DLL
C:&#092;WINDOWS&#092;SYSTEM&#092;MSDAIM.DLL
C:&#092;WINDOWS&#092;SYSTEM&#092;MSJFBL.DLL
C:&#092;WINDOWS&#092;SYSTEM&#092;MSIBKD.DLL
C:&#092;WINDOWS&#092;DEALHLPR.DLL

C:&#092;PROGRAM FILES&#092;ZSEARCH&#092;zSearch.dll <folder

I would also update IE to IE v6_SP1
I don&#39;t see any antivirus or firewall running.

The free version of Zone alarm (http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp) works well.
AVG (http://www.grisoft.com/us/us_dwnl_free.php) is the free antivirus that I use.

Disable system restore to get rid of infected restore points and then enable it.

Damnatory
07-02-2004, 10:34 AM
Thanks Alot for all the help&#33; The OS is staying active and it&#39;s running faster than it used to. :clap: