Windows XP Task Manager starts and instantly teminates

  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2855

Post 3+ Months Ago

This is going to be a long, long thread, 6 pages already. I'm in, as soon as he post the new log, I see if I can help.
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

I still see these items in the running processes section:

C:\WINDOWS\system32\MWWRQOEBN.EXE
C:\WINDOWS\System32\hdrmmzie.exe
C:\WINDOWS\system32\MSCRON.EXE

This time, stay online and do this:

Start > Run: cmd.exe
Enter these commands one at a time:
Code: [ Select ]
Taskkill /F /IM MWWRQOEBN.EXE
Taskkill /F /IM hdrmmzie.exe
Taskkill /F /IM MSCRON.EXE

Attrib -s -r -h C:\WINDOWS\system32\MWWRQOEBN.EXE
attrib -s -r -h C:\WINDOWS\System32\hdrmmzie.exe
attrib -s -r -h C:\WINDOWS\system32\MSCRON.EXE

Del C:\WINDOWS\system32\MWWRQOEBN.EXE
Del C:\WINDOWS\System32\hdrmmzie.exe
Del C:\WINDOWS\system32\MSCRON.EXE
  1. Taskkill /F /IM MWWRQOEBN.EXE
  2. Taskkill /F /IM hdrmmzie.exe
  3. Taskkill /F /IM MSCRON.EXE
  4. Attrib -s -r -h C:\WINDOWS\system32\MWWRQOEBN.EXE
  5. attrib -s -r -h C:\WINDOWS\System32\hdrmmzie.exe
  6. attrib -s -r -h C:\WINDOWS\system32\MSCRON.EXE
  7. Del C:\WINDOWS\system32\MWWRQOEBN.EXE
  8. Del C:\WINDOWS\System32\hdrmmzie.exe
  9. Del C:\WINDOWS\system32\MSCRON.EXE


Let me know if you receive any errors when you execute these commands.

Run hijack this again and post the log.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

labrego wrote:
This is going to be a long, long thread, 6 pages already. I'm in, as soon as he post the new log, I see if I can help.


Howdy Labrego! One of those tasks that are running is causing the problem. They should have been deleted but are still present. The newest log looks substantially better than the original, however.
  • dthames0702
  • Novice
  • Novice
  • dthames0702
  • Posts: 26

Post 3+ Months Ago

this is what it says when i run cmd with those commands

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Lauren>Taskkill /F /IM MWWRQOEBN.EXE
'Taskkill' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\Lauren>Taskkill /F /IM MWWRQOEBN.EXE
'Taskkill' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\Lauren>Taskkill /F /IM hdrmmzie.exe
'Taskkill' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\Lauren>Taskkill /F /IM MSCRON.EXE
'Taskkill' is not recognized as an internal or external command,
operable program or batch file.

C:\Documents and Settings\Lauren>
C:\Documents and Settings\Lauren>Attrib -s -r -h C:\WINDOWS\system32\MWWRQOEBN.E
XE

C:\Documents and Settings\Lauren>attrib -s -r -h C:\WINDOWS\System32\hdrmmzie.ex
e

C:\Documents and Settings\Lauren>attrib -s -r -h C:\WINDOWS\system32\MSCRON.EXE


C:\Documents and Settings\Lauren>
C:\Documents and Settings\Lauren>Del C:\WINDOWS\system32\MWWRQOEBN.EXE
C:\WINDOWS\system32\mwwrqoebn.exe
Access is denied.

C:\Documents and Settings\Lauren>Del C:\WINDOWS\System32\hdrmmzie.exe
C:\WINDOWS\System32\hdrmmzie.exe
The process cannot access the file because it is being used by another process.

C:\Documents and Settings\Lauren>Del C:\WINDOWS\system32\MSCRON.EXE
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Ah, okay. That explains it. Taskkill is not present.

Okay Download this tool, unzip it and place pskill.exe in your system32 folder (C:\windows\system32\).

http://members.aol.com/jrzycrim01/misc/pskill.zip

run these commands:
Code: [ Select ]
pskill MWWRQOEBN.EXE
pskill hdrmmzie.exe
pskill MSCRON.EXE

Del C:\WINDOWS\system32\MWWRQOEBN.EXE
Del C:\WINDOWS\System32\hdrmmzie.exe
Del C:\WINDOWS\system32\MSCRON.EXE
  1. pskill MWWRQOEBN.EXE
  2. pskill hdrmmzie.exe
  3. pskill MSCRON.EXE
  4. Del C:\WINDOWS\system32\MWWRQOEBN.EXE
  5. Del C:\WINDOWS\System32\hdrmmzie.exe
  6. Del C:\WINDOWS\system32\MSCRON.EXE


Run hijack this, scan and fix the following items:
O4 - HKLM\..\Run: [Yahoo Instant Messenger] MWWRQOEBN.EXE
O4 - HKLM\..\Run: [ygrtrlyklbe] C:\WINDOWS\System32\hdrmmzie.exe
O4 - HKLM\..\Run: [Microsoft CronD Service] MSCRON.EXE

Run hijack this, scan, save log, post here: :)
  • dthames0702
  • Novice
  • Novice
  • dthames0702
  • Posts: 26

Post 3+ Months Ago

sorry for so many posts, i just want to thank you in advance for helping me solve this problem
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2855

Post 3+ Months Ago

Howdy Jim, I see what I can do to help without disturb (man I hate this darn laptop keyboards)

dthames0702 how do yo manage to run taskkill before?, Jim ask you to run it two or three posts before
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

dthames0702 wrote:
sorry for so many posts, i just want to thank you in advance for helping me solve this problem


No worries. Sometimes it takes a few run-throughs to get things sorted.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

labrego wrote:
Howdy Jim, I see what I can do to help without disturb (man I hate this darn laptop keyboards)

dthames0702 how do yo manage to run taskkill before?, Jim ask you to run it two or three posts before


Your not a disturbance. Your input is always helpful. 8)

I'm wondering why taskkill is not there. As far as I know it should be available in XP home/PRO as well as 2000. Maybe something nasty happened to it.
  • dthames0702
  • Novice
  • Novice
  • dthames0702
  • Posts: 26

Post 3+ Months Ago

hey thanks everything works fine now, here is the log

Logfile of HijackThis v1.98.2
Scan saved at 12:50:09 AM, on 9/7/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\aolmsngr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [HorngTech4D] C:\PROGRA~1\MOUSES~1\bally4d.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [AOL Messenger] aolmsngr.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\RunServices: [AOL Messenger] aolmsngr.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: ImTranslator - C:\PROGRA~1\SMARTL~1\IMTRAN~1\startup.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ImTranslator - {AE436396-55E7-4ec4-AD6D-45E88A530A4C} - C:\PROGRA~1\SMARTL~1\IMTRAN~1\startup.html (HKCU)
O9 - Extra 'Tools' menuitem: ImTranslator - {AE436396-55E7-4ec4-AD6D-45E88A530A4C} - C:\PROGRA~1\SMARTL~1\IMTRAN~1\startup.html (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05f352d0bde ... xIE601.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_04) - http://zeus.findlay.edu:8011/webapps/co ... _1-win.exe
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2855

Post 3+ Months Ago

JrzyCrim wrote:
labrego wrote:
Howdy Jim, I see what I can do to help without disturb (man I hate this darn laptop keyboards)

dthames0702 how do yo manage to run taskkill before?, Jim ask you to run it two or three posts before


Your not a disturbance. Your input is always helpful. 8)

I'm wondering why taskkill is not there. As far as I know it should be available in XP home/PRO as well as 2000. Maybe something nasty happened to it.


hehe, Thanks. Don't relally know what happen... maybe the path... maybe he started cmd.exe some other way... I am thinking.

dthames0702 wrote:
hey thanks everything works fine now, here is the log
mmm I always miss the real action :roll:
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Great. Glad it's working now.

Here's a couple of things for you to do:

Go to internet options (from the control panel or tools menu of IE) and click delete cookies, delete files. That will ensure nothing nasty is left in your cache.

Also, I recommend Spywareblaster for preventing future infections:
http://www.javacoolsoftware.com/spywareblaster.html

Download and install it. Make sure to keep it updated and enable all protection.

And stay away from questionable web sites. ;)

Good luck

Oh yeah, update your virus definitions and do a full scan just to be careful. check this thread later, there are a couple of things I want to look up that may need fixing.

I noticed an entry relating to Wild Tangent:
http://techrepublic.com.com/5208-6239-0 ... dID=157036

It doesn't really seem to be harmful but if you don't use it, you might consider uninstalling it. Read through that thread and decide if you need it or not.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

labrego wrote:
mmm I always miss the real action :roll:


Don't worry, I think there is going to be plenty of action pretty soon. More and more people are going to be directed to Ozzu via google. I'm sure that's how people are finding this thread.
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

labrego wrote:
JrzyCrim wrote:
I'm wondering why taskkill is not there. As far as I know it should be available in XP home/PRO as well as 2000. Maybe something nasty happened to it.

Don't relally know what happen... maybe the path... maybe he started cmd.exe some other way... I am thinking.


Normally, taskkill is found in the system32 directory. System32 is in the command path and anything in it should be accessible from the command prompt no matter where you are.

There is also a backup in system32\dllcache which Windows File Protection keeps track of incase the original get's trashed.
  • LAbrego
  • brego from LA
  • Web Master
  • User avatar
  • Posts: 2855

Post 3+ Months Ago

That's why I said this looks like a long thread. I am learning from your skills, now I know what spyware names to look for :wink:

It's good to see people comming here from google, is incredible how many infected computers are out there
  • dthames0702
  • Novice
  • Novice
  • dthames0702
  • Posts: 26

Post 3+ Months Ago

hey JrzyCrim or anyone who can help, I have basicaly the same problem as yesterday but this time i can view task manager and msconfig but i am not able to downlaod any programs. can you help me please
  • dthames0702
  • Novice
  • Novice
  • dthames0702
  • Posts: 26

Post 3+ Months Ago

i am also unable to download any sort of file from the internet
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Posts: 23456
  • Loc: Woodbridge VA

Post 3+ Months Ago

dthames0702 -- in case you missed it, the reason you couldn't find your post here again was because it's a different problem. I split it off from this topic and started a new thread on it. Continue in the new post here:

http://www.ozzu.com/mswindows-forum/not-able-download-any-programs-t31100.html
  • welly
  • Newbie
  • Newbie
  • welly
  • Posts: 6

Post 3+ Months Ago

Hi

I stumbled across this site via Google while looking for solutions to a friend's laptop problem - msconfig, regedit and task manager all close immediately after opening.

I've downloaded the latest versions of AVG, Ad-Aware, Spybot and HijackThis and run scans as per your instructions. Here is the HijackThis log;

Logfile of HijackThis v1.97.7
Scan saved at 4:24:56 p.m., on 11/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\SDK0mCORE.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\TFNF5.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe
C:\WINDOWS\LTSMMSG.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\INITIATE.EXE
C:\WINDOWS\System32\SDKc55rezzz.exe
C:\WINDOWS\System32\SDKc55rezzz.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Documents and Settings\Tim\Desktop\Virus Checkers\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: GT Indicator - {C733AE47-6AC0-4837-93DA-70278E88E7B2} - C:\Program Files\GTRAN Wireless\GT Dialer\gtindctr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppletINIT] INITIATE.EXE
O4 - HKLM\..\Run: [SDKCprords] SDKc55rezzz.exe
O4 - HKLM\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunServices: [SDKCprords] SDKc55rezzz.exe
O4 - HKLM\..\RunServices: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SDKCprords] SDKc55rezzz.exe
O4 - HKCU\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunOnce: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\RunOnce: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\RunOnce: [AppletINIT] INITIATE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 4867446330
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/sh ... wflash.cab

Hopefully, you'll be able to help.

Many thanks,

welly
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Hello welly, welcome to ozzu. I'm looking over your log right now. In the meantime, please download the latest version of hijack this:
http://www.majorgeeks.com/download3155.html

Which version of Windows XP do you have?
  • welly
  • Newbie
  • Newbie
  • welly
  • Posts: 6

Post 3+ Months Ago

Thanks for the prompt attention - you guys are awesome!

My friend is running XP pro SP1.

His place (and the laptop!) is the other side of town so I apologise in advance if I'm a little slow in responding to requests. However, I will make sure to download the latest version of HijackThis when I'm next over there.

Cheers

welly
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

It shouldn't matter too much. Hopefully we can get rid of this in one go. :)

Copy the following instructions so you will have them handy.

Reboot the computer into safe mode and close all programs.
Disable system restore.

Go to Start > Run and enter: cmd.exe
enter the following commands one at a time into the command prompt window:
Code: [ Select ]
taskkill /F /IM SDK0mCORE.exe
taskkill /F /IM SDKc55rezzz.exe

attrib -r -s -h C:\WINDOWS\System32\SDK0mCORE.exe
attrib -r -s -h C:\WINDOWS\System32\SDKc55rezzz.exe

del C:\WINDOWS\System32\SDK0mCORE.exe
del C:\WINDOWS\System32\SDKc55rezzz.exe
  1. taskkill /F /IM SDK0mCORE.exe
  2. taskkill /F /IM SDKc55rezzz.exe
  3. attrib -r -s -h C:\WINDOWS\System32\SDK0mCORE.exe
  4. attrib -r -s -h C:\WINDOWS\System32\SDKc55rezzz.exe
  5. del C:\WINDOWS\System32\SDK0mCORE.exe
  6. del C:\WINDOWS\System32\SDKc55rezzz.exe


Run hijack this, scan, place a check beside the following items and click 'Fix Checked'.

O4 - HKLM\..\Run: [SDKCprords] SDKc55rezzz.exe
O4 - HKLM\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunServices: [SDKCprords] SDKc55rezzz.exe
O4 - HKLM\..\RunServices: [sdkupdate22] SDK0mCORE.exe

O4 - HKCU\..\Run: [SDKCprords] SDKc55rezzz.exe
O4 - HKCU\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunOnce: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\RunOnce: [sdkupdate22] SDK0mCORE.exe

Reboot, run hijack this, save log, post log. Hopefully the above will take care of the problem.
  • welly
  • Newbie
  • Newbie
  • welly
  • Posts: 6

Post 3+ Months Ago

Unfortunately I don't have access to the log file just yet but I got my friend to make the changes you suggest and it hasn't fixed the problem.

Hopefully, I'll be able to get round there tomorrow and double check that he's done it all right.

Thanks again for your quick response.

Cheers

welly
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Add this to the list of commands:

Code: [ Select ]
taskkill /F /IM INITIATE.EXE

attrib -r -s -h C:\WINDOWS\System32\INITIATE.EXE

del C:\WINDOWS\System32\INITIATE.EXE
  1. taskkill /F /IM INITIATE.EXE
  2. attrib -r -s -h C:\WINDOWS\System32\INITIATE.EXE
  3. del C:\WINDOWS\System32\INITIATE.EXE


Fix this with Hijack this:
O4 - HKLM\..\Run: [AppletINIT] INITIATE.EXE
O4 - HKCU\..\RunOnce: [AppletINIT] INITIATE.EXE
  • welly
  • Newbie
  • Newbie
  • welly
  • Posts: 6

Post 3+ Months Ago

Will do!

Out of interest, how do you know which files shouldn't be running? Experience, Googling to see if there is any mention of the file?

Cheers

welly
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

A combination of all of the above. :)

A dead giveaway is when the same program is set to launch at startup in more than one location. Example:

O4 - HKLM\..\Run: [SDKCprords] SDKc55rezzz.exe
O4 - HKCU\..\Run: [SDKCprords] SDKc55rezzz.exe
O4 - HKLM\..\RunServices: [SDKCprords] SDKc55rezzz.exe

O4 - HKLM\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunServices: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunOnce: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\RunOnce: [sdkupdate22] SDK0mCORE.exe

No legimate program will be found in all these different registry locations. That's not to say all programs in a single area are legitimate.

Check out this thread: http://www.ozzu.com/mswindows-forum/highjackthis-and-spyware-removal-resources-and-tips-t31034.html

We've just started dealing with Hijack This logs here at Ozzu but were getting better all the time.
  • welly
  • Newbie
  • Newbie
  • welly
  • Posts: 6

Post 3+ Months Ago

Thanks for all the help. I've emailed all of your instructions to my friend as I'm not able to get over there today. Hopefully he is up to fixing this!

Cheers

welly
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Hope he gets things squared away. If he has an internet connection, he can always drop by. If not, feel free to continue asking questions here.

Good luck.
  • knapkin
  • Born
  • Born
  • knapkin
  • Posts: 4

Post 3+ Months Ago

im having the same problem with windows task manager, heres my hijack this log.


Logfile of HijackThis v1.98.2
Scan saved at 11:13:12 PM, on 9/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Winad Client\Winad.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\active.exe
C:\documents and settings\robert knapp\local settings\temp\2W.exe
C:\WINDOWS\System32\EXPLORERZ.EXE
C:\Program Files\Winad Client\WinClt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\PROGRA~1\AMERIC~1.0\waol.exe
C:\PROGRA~1\AMERIC~1.0\shellmon.exe
C:\PROGRA~1\AMERIC~1.0\aolwbspd.exe
C:\Documents and Settings\Tyler Knapp\Desktop\Shtuff\HijackThis.exe
C:\Documents and Settings\Tyler Knapp\Desktop\Shtuff\aim.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O2 - BHO: (no name) - {19FF602A-C36C-5CCF-D652-64557CAC2737} - C:\WINDOWS\System32\kngncuji.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe
O4 - HKLM\..\Run: [MS Decryption Software] C:\active.exe
O4 - HKLM\..\Run: [2W] C:\documents and settings\robert knapp\local settings\temp\2W.exe
O4 - HKLM\..\Run: [Windows Explorer] EXPLORERZ.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Windows Explorer] EXPLORERZ.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Tyler Knapp\Desktop\Shtuff\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file. ... 6f8b5fbb1c
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildApp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6EE24AEC-7493-4A12-ADF8-9563F69241FB}: NameServer = 205.188.146.146

thanks for any help you can give!
  • JrzyCrim
  • Mastermind
  • Mastermind
  • User avatar
  • Posts: 2062

Post 3+ Months Ago

Welcome to Ozzu, knapkin. I'm currently looking over your log right now. It will take a few minutes so hang tight. :). In the meantime, please go to add/remove programs and remove anything related to My search, My way, My web, or My bar.
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

Post Information

  • Total Posts in this topic: 132 posts
  • Users browsing this forum: No registered users and 84 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 1998-2014. Ozzu® is a registered trademark of Unmelted, LLC.