re: Evil "lexplore" virus hijacked me
Tuesday, June 8, 2004 at 9:32 pm Windows 98 Annoyances Discussion Forum
Posted by geehawgirl
(47 messages posted)
I'm Holly, by the way. Here are the files you asked me to post. The items that
showed up on my desktop are backups of everything I deleted from the HijackThis scan
list you sent me to take care of. The RPCSS was on a list that you had prefaced
with: "Delete the items I mentioned below" which is why I did so - would that have
anything to do with a "fatal error" blue screen I got while shutting down? *sigh*
I'm not on a network anyway (or I'd have had the IT guy in, wouldn't I?!) I'm off
to do the Panda Active Scan and Bitdefender. Can't imagine why you're willing to
put all this time into me, but I sure am glad for it. Some people volunteer at the
senior citizen center, you do this - thanks.
Logfile of HijackThis v1.97.7
Scan saved at 9:27:07 PM, on 6/8/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\COMPAQ\ACCESS\ENCOMPASS\MONITOR.EXE
C:\PROGRAM FILES\MCAFEE\PGP\IKESERVICE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\BITWARE\CBWATTN.EXE
C:\PROGRAM FILES\BITWARE\CBWHOST.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\COMPAQ\INTERNET\CISRVR.EXE
C:\WINDOWS\SYSTEM\SXGDSENU.EXE
C:\PROGRAM FILES\SONIC IMPACT A3D\VRTXCTRL.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE
C:\WINDOWS\SYSTEM\CQSCP2PS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SHPC32.EXE
C:\WINDOWS\SYSTEM\CQSCP2PS.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\HPZTSB03.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\WINDOWS\MSCMGR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\NETSCP.EXE
C:\PROGRAM FILES\MCAFEE\OIL CHANGE\SCHEDAPP.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\HPZSTATX.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c99&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c99&s=search&i=enu
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c99&s=search&i=enu
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT
5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot
- Search & Destroy\SDHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
/NORESTART
O4 - HKLM\..\Run: [Compaq Internet Setup] C:\Compaq\Internet\InetWizard.exe /RUN
O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\McAfee\VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe
O4 - HKLM\..\Run: [VortexTray] C:\WINDOWS\asp4setp.exe 3
O4 - HKLM\..\Run: [SonicA3DControl] C:\PROGRA~1\SONICI~1\VrtxCtrl.exe
O4 - HKLM\..\Run: [CPQEASYACC] "C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\Cpqeaui.exe"
O4 - HKLM\..\Run: [cqscp2ps.exe] C:\WINDOWS\SYSTEM\cqscp2ps.exe
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [CompaqSysTray] cpqpscp.exe
O4 - HKLM\..\Run: [SHPC32] shpc32.exe
O4 - HKLM\..\Run: [CQSCP2PSERVER] CQSCP2PS.EXE
O4 - HKLM\..\Run: [Oil Change] C:\PROGRA~1\MCAFEE\OILCHA~1\OCTray32.exe Start
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb03.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
/hook
O4 - HKLM\..\Run: [MSN Manager] C:\WINDOWS\mscmgr.exe
O4 - HKLM\..\RunServices: [CBWHost] C:\PROGRA~1\BITWARE\CBWEXEC.EXE /Run C:\PROGRA~1\BITWARE\CBWHOST.EXE
O4 - HKLM\..\RunServices: [CBWAttn] C:\PROGRA~1\BITWARE\CBWEXEC.EXE /Run C:\PROGRA~1\BITWARE\CBWATTN.EXE
O4 - HKLM\..\RunServices: [EncMonitor] c:\compaq\access\Encompass\Monitor.exe
O4 - HKLM\..\RunServices: [IKEService95] C:\Program Files\McAfee\PGP\IKEService.exe
O4 - HKLM\..\RunServices: [McAfee Image] C:\PROGRA~1\MCAFEE\MCAFEE~1\image32.exe
/auto
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe"
-turbo
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GOOGLETOOLBAR_EN_2.0.95-DELEON.DLL/cmtrans.html
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Print Favorites (HKLM)
O9 - Extra 'Tools' menuitem: Print &Favorites... (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O12 - Plugin for .swf: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPSWF32.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
Startup List:
StartupList report, 6/8/04, 9:28:12 PM
StartupList version: 1.52
Started from : C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
Detected: Windows 98 Gold (Win9x 4.10.1998)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\COMPAQ\ACCESS\ENCOMPASS\MONITOR.EXE
C:\PROGRAM FILES\MCAFEE\PGP\IKESERVICE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\BITWARE\CBWATTN.EXE
C:\PROGRAM FILES\BITWARE\CBWHOST.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\COMPAQ\INTERNET\CISRVR.EXE
C:\WINDOWS\SYSTEM\SXGDSENU.EXE
C:\PROGRAM FILES\SONIC IMPACT A3D\VRTXCTRL.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE
C:\WINDOWS\SYSTEM\CQSCP2PS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SHPC32.EXE
C:\WINDOWS\SYSTEM\CQSCP2PS.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\HPZTSB03.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\WINDOWS\MSCMGR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\NETSCP.EXE
C:\PROGRAM FILES\MCAFEE\OIL CHANGE\SCHEDAPP.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\SYSTEM\HPZSTATX.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = c:\windows\scanregw.exe /autorun
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
AtiCwd32 = Aticwd32.exe
AtiKey = Atitask.exe
EM_EXEC = c:\mouse\system\em_exec.exe
EACLEAN = C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe /NORESTART
Compaq Internet Setup = C:\Compaq\Internet\InetWizard.exe /RUN
CISrvr Program = C:\COMPAQ\INTERNET\CISRVR.EXE
VsecomrEXE = C:\Program Files\McAfee\VirusScan\VSECOMR.EXE
SXGDSENU = SXGDSENU.exe
VortexTray = C:\WINDOWS\asp4setp.exe 3
SonicA3DControl = C:\PROGRA~1\SONICI~1\VrtxCtrl.exe
CPQEASYACC = "C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\Cpqeaui.exe"
cqscp2ps.exe = C:\WINDOWS\SYSTEM\cqscp2ps.exe
LexStart = Lexstart.exe
CompaqSysTray = cpqpscp.exe
SHPC32 = shpc32.exe
CQSCP2PSERVER = CQSCP2PS.EXE
Oil Change = C:\PROGRA~1\MCAFEE\OILCHA~1\OCTray32.exe Start
NB Common Dialog Enhancements = C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
Start Menu Enhancements = C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
HPDJ Taskbar Utility = C:\WINDOWS\SYSTEM\hpztsb03.exe
Icon Animation = C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
MSN Manager = C:\WINDOWS\mscmgr.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
CBWHost = C:\PROGRA~1\BITWARE\CBWEXEC.EXE /Run C:\PROGRA~1\BITWARE\CBWHOST.EXE
CBWAttn = C:\PROGRA~1\BITWARE\CBWEXEC.EXE /Run C:\PROGRA~1\BITWARE\CBWATTN.EXE
ConfigServices =
EncMonitor = c:\compaq\access\Encompass\Monitor.exe
IKEService95 = C:\Program Files\McAfee\PGP\IKEService.exe
McAfee Image = C:\PROGRA~1\MCAFEE\MCAFEE~1\image32.exe /auto
SchedulingAgent = mstask.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo! Pager = C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
Weather = C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
Mozilla Quick Launch = "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 8/6/2004, 16:21:44)
[rename]
NUL=C:\WINDOWS\WT\UPDATER\WCMDMGR.EXE
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
SET BLASTER=A220 I5 D3 T4
LH C:\WINDOWS\ASP4DOS.COM
C:\PROGRA~1\MCAFEE\VIRUSS~1\SCANPM.EXE C:\ /NOEXPIRE
IF ERRORLEVEL 1 PAUSE
\CPQS\TOOLS\DNY E:
IF ERRORLEVEL 1 GOTO SKIPE
IF EXIST E:\MFG00.BAT CALL E:\MFG00.BAT
IF EXIST E:\MFG00.BAT DEL E:\MFG00.BAT
IF EXIST E:\CONFIG.BAT E:\CONFIG.BAT
:SKIPE
\CPQS\TOOLS\DNY D:
IF ERRORLEVEL 1 GOTO SKIPED
IF EXIST D:\MFG00.BAT CALL D:\MFG00.BAT
IF EXIST D:\MFG00.BAT DEL D:\MFG00.BAT
IF EXIST D:\CONFIG.BAT D:\CONFIG.BAT
:SKIPED
:XIT
IF EXIST D:\PATCHES\PATCHES.BAT CALL D:\PATCHES\PATCHES.BAT
IF EXIST D:\SEHCTAP\NUL REN D:\SEHCTAP PATCHES
IF EXIST \PIPOST.BAT CALL \PIPOST.BAT
IF EXIST \PIPOST.BAT DEL \PIPOST.BAT
IF EXIST C:\CPQS\BACKWEB\BWSETUP.BAT CALL C:\CPQS\BACKWEB\BWSETUP.BAT
SET PATH=C:\PROGRA~1\ASYMET~1\DVP50
SET CLASSPATH=C:\Program Files\HEAT\navbar;%CLASSPATH%
SET PATH=%PATH%;C:\PROGRA~1\MCAFEE\PGP
SET PATH=%PATH%;C:\PROGRA~1\MCAFEE\MCAFEE~1
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
Maintenance-Defragment programs.job
Maintenance-ScanDisk.job
Maintenance-Disk cleanup.job
{30C834C0-5F4B-11D4-8CE2-B9A6F7EB2C26}_Default.job
{41B37C8A-7D29-11D4-8CE2-0008C713A59E}_Default.job
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 7,380 bytes
Report generated in 0.126 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
|
All messages in this thread [show all]
 |  |  |  |  |  |  |  |  |  |  |  |  |  |  | re: Evil "lexplore" virus hijacked me (geehawgirl: Tue, Jun 8, 2004, 9:32 pm) |
| |
| |
Return to the Windows 98 Discussion Forum
|
|