Abnormal PC Symptoms

Status
Not open for further replies.
I found out that I had a little spyware on my computer a few days ago, and started trying to get rid of it. I ended up at Add/Remove Programs list and found the "The A Better Internet.." something or other, cant remember exactally what it was, but found out that I had some VX2.abetterinternet thing on my PC. Ok, no big deal, I downloaded their stupid uninstall tool, and it seemed to uninstall it. Ran Ad-Aware, and SpySweeper. AVG Anti-virus, and what not... all say I'm fine and dandy now.

But, since I'm a little more advanced with my computer, I noticed that tasks I could normally "end task" before, I could no longer do it. For instance Machine Debug Manager (mdm.exe), BlackIce (blackd.exe, blackice.exe), and a few others. Now when I try to "end task" it gives me an error, and says "Access is denied".

I have downloaded a few Task Manager programs such as TASKMAN.exe, Process Explorer, and Task Manager pro, none of which can terminate the normally terminatable processes.

After more snooping around at things...
I found a process that I didn't know what it was called C:\WINDOWS\system32\kmupml.exe in Process Explorer (I've found to be a very helpful program by the way), and a key:
O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\lxk.dll
both of which you'll see in my HTJ log file. (I dont know if the two are related, but I have reason to believe that they are)

I use to be able to see kmupml.exe in C:\WINDOWS\system32, but when I tried to delete it, it came right back. I can no longer see/find the file in that folder. I've tried disableing it with msconfig.. still no go, it keeps comming back, and re-checking its own box or something. I tried the "Fix Checked" in HTJ, but it doesn't do anything, because that lxk.dll thing stays there even after restart. This is one of the few processes that will end task, but will come right back.


Any help is appriciated, hopefully I did everything right, and explained everything as thoroughly as possible.
 

Attachments

  • hijackthis.txt
    3.9 KB · Views: 5
Hello and welcome to Techspot.

Go HERE and follow the instructions exactly.

Once you have done that, please post a fresh HJT log.


Regards Howard :wave: :wave:
 
Done

I did that, and here is some things I also did..

I made some little C++ files that did nothing, and replaced them with the exe(s) that I found were bad, the kmupml.exe is now a very small file that does nothing. Used to be a little notepad file, with the extention changed (which made ntvdm crash so I could see when it was being called.. every few minutes or so).

I checked out a few registry points including "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run" and
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion \Winlogon\Notify
...and I deleted a few things there.

Spybot S&D removed a ton of things.

I've ran/used the programs Process Explorer, Autoruns.exe, CWShreadder.exe, and l2mfix. Now it seems things are a LITTLE more back to normal because CWShreadder no longer finds VX2.Look2Me, or anything else, same with S&D, but I still cant seem to stop NVIDIA's helper drivers from running, or MySQL server, Machine Debug Manager (my test applications to see if "end task" is working yet. I've always been able to shut these off with no problem). And that stupid kmupml.exe program still tries to run (which is now a C++ program that does nothing) a black command.exe box shows up flashes up for a split second, thats all for that.

I was back at where I started, just a little bit cleaner.

EDIT: I CAN "end task", its just the program thing still tries to run.
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://69.66.162.7:6851/phpBB2/index.php
This is from: Iowa Telecom in Newton/IA, if you want that, OK, if not, FIX it in HJT.

O4 - HKCU\..\Run: [SlickRun] "C:\Program Files\SlickRun\sr.exe"
"SlickRun" is a floating command line utility for Windows. It gives you almost instant access to any program or website. SlickRun allows you to create command aliases (known as MagicWords)
If you installed this, OK, otherwise UNinstall and FIX it.

O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
UNinstall (and FIX) anything to to with FlashGet, it contains adware.
Get the safe StarDownloader V1.44 from www.StarDownloader.com instead. No ads, no nags.
 
Status
Not open for further replies.
Back