error messages(RESOLVED)

  1. #11
    Crewie is offline Full Member

    Re: error messages

    I still keep getting

    "RUNDLL
    ERROR LOADING C:\Documents and Settings\owner\Local Settings\Aplication Data\deyxeod.dll
    The Specified module could not be found"

    when I start the machine up and

    and on closing the machine down, I get the message

    " NVIDIA Twin View Window
    The program is not responding"

    Other than that, things are fine, thanks.


  2. #12
    Neal is offline Dedicated Member
    Let me see a new hijackthis log and also...


    Find this file again:

    C:\Documents and Settings\Owner\Local Settings\Application Data\deyxeod.dll",yxagpn



    For each one that shows in the search:
    Right click on it and select Properties. Click on the Version tab. Under Other version information click on Company, post back all information you find on that please.

  3. #13
    Crewie is offline Full Member
    Logfile of HijackThis v1.99.1
    Scan saved at 21:46:08, on 08/01/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_ 3dsmax8server.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\vsnpstd2.exe
    C:\WINDOWS\system32\obwzchsf.exe
    C:\freeserve\freeserveconnectionkit\atdialler1.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
    C:\Program Files\EndItAll\enditall.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\HJT\HijackThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.freeserve.co.uk/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.freeserve.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
    F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {4CD9BA25-6604-E2C4-F0DF-09350E115578} - blank (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {84873f92-1dd2-11b2-b404-d0304aaf4e10} - C:\WINDOWS\system32\msahgjee.dll
    O3 - Toolbar: Freeserve - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 8.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [obwzchsf.exe] C:\WINDOWS\system32\obwzchsf.exe
    O4 - HKLM\..\Run: [deyxeod.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Owner\Local Settings\Application Data\deyxeod.dll",yxagpn
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - Global Startup: Freeserve Connection Kit.lnk = C:\freeserve\freeserveconnectionkit\atdialler1.exe
    O8 - Extra context menu item: Search with Freeserve - res://C:\PROGRA~1\FREESE~1\FSBar\FSBar.dll/VSearch.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn...taller_gmn.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1094658181656
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1136660031375
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex...l_v1-0-3-0.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B34AEBB0-CBCD-4D47-891A-C77200462462}: NameServer = 85.255.113.114 85.255.112.8
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O19 - User stylesheet: (file missing)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_ 3dsmax8server.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe




    I ran VIRUSTOTAL this one again also.
    C:\WINDOWS\system32\obwzchsf.exe



    AntiVir 7.3.0.21 01.08.2007 TR/Obfus.Gen.31
    Authentium 4.93.8 12.30.2006 no virus found
    Avast 4.7.892.0 12.30.2006 no virus found
    AVG 386 01.08.2007 no virus found
    BitDefender 7.2 01.08.2007 Trojan.Obfus.Gen
    CAT-QuickHeal 9.00 01.08.2007 (Suspicious) - DNAScan
    ClamAV devel-20060426 01.08.2007 no virus found
    DrWeb 4.33 01.08.2007 no virus found
    eSafe 7.0.14.0 01.08.2007 Win32.Polipos.sus
    eTrust-InoculateIT 23.73.107 01.06.2007 no virus found
    eTrust-Vet 30.3.3311 01.08.2007 no virus found
    Ewido 4.0 01.08.2007 no virus found
    Fortinet 2.82.0.0 01.08.2007 suspicious
    F-Prot 3.16f 01.05.2007 no virus found
    F-Prot4 4.2.1.29 01.05.2007 no virus found
    Ikarus T3.1.0.27 01.08.2007 Trojan.Obfus.Gen
    Kaspersky 4.0.2.24 01.08.2007 no virus found
    McAfee 4934 01.08.2007 no virus found
    Microsoft 1.1904 01.07.2007 no virus found
    NOD32v2 1963 01.08.2007 no virus found
    Norman 5.80.02 12.31.2007 no virus found
    Panda 9.0.0.4 01.08.2007 no virus found
    Prevx1 V2 01.08.2007 no virus found
    Sophos 4.13.0 01.05.2007 no virus found
    Sunbelt 2.2.907.0 01.05.2007 VIPRE.Suspicious
    TheHacker 6.0.3.146 01.08.2007 no virus found
    UNA 1.83 01.06.2007 no virus found
    VBA32 3.11.2 01.08.2007 no virus found


    Then this one as requested

    C:\Documents and Settings\Owner\Local Settings\Application Data\deyxeod.dll",yxagpn



    AntiVir 7.3.0.21 01.08.2007 no virus found
    Authentium 4.93.8 12.30.2006 no virus found
    Avast 4.7.892.0 12.30.2006 no virus found
    AVG 386 01.08.2007 no virus found
    BitDefender 7.2 01.08.2007 no virus found
    CAT-QuickHeal 9.00 01.08.2007 no virus found
    ClamAV devel-20060426 01.08.2007 no virus found
    DrWeb 4.33 01.08.2007 no virus found
    eSafe 7.0.14.0 01.08.2007 no virus found
    eTrust-InoculateIT 23.73.107 01.06.2007 no virus found
    eTrust-Vet 30.3.3311 01.08.2007 no virus found
    Ewido 4.0 01.08.2007 no virus found
    Fortinet 2.82.0.0 01.08.2007 no virus found
    F-Prot 3.16f 01.05.2007 no virus found
    F-Prot4 4.2.1.29 01.05.2007 no virus found
    Ikarus T3.1.0.27 01.08.2007 no virus found
    Kaspersky 4.0.2.24 01.08.2007 no virus found
    McAfee 4934 01.08.2007 no virus found
    Microsoft 1.1904 01.07.2007 no virus found
    NOD32v2 1963 01.08.2007 no virus found
    Norman 5.80.02 12.31.2007 no virus found
    Panda 9.0.0.4 01.08.2007 no virus found
    Prevx1 V2 01.08.2007 no virus found
    Sophos 4.13.0 01.05.2007 no virus found
    Sunbelt 2.2.907.0 01.05.2007 no virus found
    TheHacker 6.0.3.146 01.08.2007 no virus found
    UNA 1.83 01.06.2007 no virus found
    VBA32 3.11.2 01.08.2007 no virus found



    where do I find these above, so that I can right click for properties? I can not manualy find the C:\Documents and Settings\Owner\Local Settings\Application Data\deyxeod.dll",yxagpn . The only way I can get to scan this one is simply by copy/pasting the details in the browse box. There is no visible file of this name in the folder that you specified.
    Last edited by Crewie; 08-01-2007 at 11:30 PM.

  4. #14
    Neal is offline Dedicated Member
    Did you do this?


    Go here to learn how to show hidden files/folders:

    http://www.xtra.co.nz/help/0,,4155-1916458,00.html#5


    File in question is in Application Data folder.

  5. #15
    Crewie is offline Full Member
    I have done the above, and I can still not find this file.
    I have also looked in the administrators application data folder and I can not find it there either.

  6. #16
    Neal is offline Dedicated Member
    1. Launch Windows Defender
    2. Click Tools > General Settings
    3. Under Realtime Protection Options uncheck "Turn on real real-time protection (recommended)".
    4. Click the Save button
    5. Close Windows Defender



    Run hijackthis and click on scan button and put checks next to these:


    O2 - BHO: (no name) - {4CD9BA25-6604-E2C4-F0DF-09350E115578} - blank (file missing)
    O2 - BHO: (no name) - {84873f92-1dd2-11b2-b404-d0304aaf4e10} - C:\WINDOWS\system32\msahgjee.dll

    O4 - HKLM\..\Run: [obwzchsf.exe] C:\WINDOWS\system32\obwzchsf.exe
    O4 - HKLM\..\Run: [deyxeod.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Owner\Local Settings\Application Data\deyxeod.dll",yxagpn



    Nothing open but hijackthis and click on fix checked




    Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.


    Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):


    DELETE FILES:

    C:\WINDOWS\system32\obwzchsf.exe


    Reboot normal mode and tell me how things are now.

  7. #17
    Crewie is offline Full Member

    Thanks a million! Its back to normal.

  8. #18
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    Fantastic,




    If you are no longer having any more trouble here is some preventative measures for you.

    Be sure to re-hide hidden files/folders if you were asked to unhide them

    Here are some preventive measures you can take to keep your computer from getting infected again. also keep all these and Ad-awareSE and SpybotS&D updated.

    http://www.d-a-l.com/help/showthread.php?t=32403

    Flush your restore points in ME and XP, by turning System Restore off and then back on.
    This will create a fresh restore point.


    Explained Here:
    Windows XP: http://vil.nai.com/vil/SystemHelpDoc...ysRestore.aspx

    Explained Here
    Microsoft ME:
    http://service1.symantec.com/SUPPORT...rc=sec_doc_nam


    RegProtect

    This small registry protection tool will save you hours of heartache by notifying you when some program good or bad is trying to access your registry.

    You have the option of allowing(good) items or blocking(bad)items.


    http://www.diamondcs.com.au/index.php?page=regprot


    To reduce the re-infection potential for malware and protect yourself against spyware, here are a few helpful suggestions:

    1. Keep Windows and Internet Explorer current with the latest critical security updates from Microsoft. This will patch many of the security holes through which attackers can gain access to your computer. You CANNOT complete this update using an alternate browser.
    http://v5.windowsupdate.microsoft.co....aspx?ln=en-us

    http://www.microsoft.com/windows/ie/default.asp


    2. Run your antivirus software regularly, and to keep its definitions up-to-date. If you are thinking about switching, there are a some good free Antivirus programs that are decent, including AVG and Avast!.
    AVG: http://free.grisoft.com/doc/1

    Avast: http://www.avast.com/eng/avast_4_home.html


    3. In addtion to using Ad-aware consider using another free malware scanning/removal program:
    Windows Defender

    http://www.microsoft.com/athome/secu...e/default.mspx


    4. Consider using a free firewall if you are not already using one. Some good free ones are:
    Kerio
    http://www.sunbelt-software.com/Kerio.cfm

    Zone Labs Personal Firewall:
    Zone Labs



    5. Consider using an alternate free browser for general web surfing but you must use IE for windows update.
    Mozilla Firefox: www.mozilla.org/products/firefox/


    6. Consider increasing your browser security by using these programs:
    SpywareGuard will protect your homepage from being hijacked: http://www.javacoolsoftware.com/spywareguard.html
    SpywareBlaster will increase browser protection by blocking Thousands of known malware sites by adding them to IE's restricted sites zone. Download it here:

    http://www.javacoolsoftware.com/spywareblaster.html


    If you use SpywareBlaster, you can also use a customblocklist to add even more entries into IE restricted sites zone. Go to this site for the current list and how to use instructions: http://customblockinglist.cjb.net/


    IE-SPYAD is similar in that it adds thousands more known malware sites to IE's restricted zone. Download it here:
    https://netfiles.uiuc.edu/ehowes/www/resource.htm


    Block access to Untrustworthy Sites

    You can prevent your computer from visiting a myriad of untrustworthy sites and ad-servers by installing a customised hosts file. One of the best available is the: MVPS Hosts File. Simply follow the instructions to install the file in the correct location. This will not only make surfing safer but will improve website load times and block popups from many of the large ad-servers.



    *Remember just like your primary anti-virus software, it is important to keep all of these programs up-to-date and use them on a regular basis. It's Free

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2