Jump to content


Photo

Cannot delete mxTarget.dll


  • Please log in to reply
1 reply to this topic

#1 RNult13

RNult13

    Member

  • New Member
  • Pip
  • 2 posts

Posted 22 July 2004 - 04:15 PM

I am having trouble deleting the file mxTarget.dll. I have tried to delete the file in Safe Mode without success. CWShredder does not find any problems.

Here is my HiJackThis log -
Logfile of HijackThis v1.97.7
Scan saved at 2:01:08 PM, on 7/22/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
c:\apps\dvlp\clearcase\bin\albd_server.exe
C:\Apps\Utils\BackWeb\BackWeb\program\ServiceWrapper.exe
C:\Program Files\Connected\CBRegCap.EXE
c:\apps\pcd32\client32.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Apps\Utils\BackWeb\BackWeb\PROGRAM\BackWeb.exe
C:\Apps\Db\DB2odbc8\BIN\db2jds.exe
C:\Apps\Db\DB2odbc8\BIN\db2sec.exe
C:\Apps\NortonAV\DefWatch.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\system32\cba\pds.exe
c:\apps\dvlp\clearcase\bin\lockmgr.exe
c:\apps\db\MSSQL\binn\sqlservr.exe
C:\Apps\NortonAV\Rtvscan.exe
C:\Apps\Db\Oracle920\bin\omtsreco.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Apps\Utils\Speed Disk\nopdb.exe
C:\Apps\Tux65\bin\tuxipc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
c:\apps\dvlp\clearcase\bin\cccredmgr.exe
C:\WINNT\system32\cba\xfr.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\CCM\CcmExec.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Apps\NortonAV\vptray.exe
C:\PROGRA~1\COMMON~1\MERCUR~1\SHARED~1\JAVAAD~1\bin\JAVASU~1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\chehle.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lotus\Sametime Client\Connect.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PS\Bat\PSVer.exe
C:\Apps\InterWise\Student\pull.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Apps\notes\NLNOTES.EXE
C:\Apps\notes\nhldaemn.EXE
C:\Documents and Settings\RNULTEME\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://planet.peoplesoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://planet.peoplesoft.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://planet.peoplesoft.com/
O1 - Hosts: 209.17.22.180 jprehm042803.peoplesoft.com
O1 - Hosts: 209.17.22.70 jprehm100902.peoplesoft.com
O1 - Hosts: 209.17.22.64 jprehm062602.peoplesoft.com
O1 - Hosts: 209.17.22.93 dsrikant032703.peoplesoft.com
O1 - Hosts: 209.17.22.169 jprehm121201.peoplesoft.com
O1 - Hosts: 209.17.22.125 jprehm2102902.peoplesoft.com
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll (file missing)
O2 - BHO: (no name) - {474264BC-9571-47C1-85B9-780F756DC9CE} - C:\WINNT\system32\BHOManager.dll
O2 - BHO: (no name) - {8527E364-B29D-2F89-6A25-DD6D40315186} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [vptray] C:\Apps\NortonAV\vptray.exe
O4 - HKLM\..\Run: [PC-Duo System Snapshot] c:\apps\pcd32\CLBOOT32.EXE
O4 - HKLM\..\Run: [CCDoctorLogonTesting] "c:\apps\dvlp\clearcase\bin\ccdoctor.exe" /LogonStartup
O4 - HKLM\..\Run: [MicJavaSwitch] C:\PROGRA~1\COMMON~1\MERCUR~1\SHARED~1\JAVAAD~1\bin\JAVASU~1.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [prcbspmlijf] C:\WINNT\system32\chehle.exe
O4 - HKLM\..\Run: [alchem] C:\WINNT\alchem.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [PSD Tools Channel] C:\Program Files\Common Files\PSD Tools\ChannelUp.exe
O4 - HKCU\..\Run: [Sametime Connect] C:\Program Files\Lotus\Sametime Client\Connect.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Check ClearCase Environment.lnk = windows\utils\cccheck.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\PTPNDFLS\PTPNDFLS.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Apps\Office2000\Office\OSA9.EXE
O4 - Global Startup: PSVer.LNK = C:\PS\Bat\PSVer.exe
O4 - Global Startup: Push Client.lnk = C:\Apps\InterWise\Student\pull.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://planet.peoplesoft.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://ttsweb01/tdbin/Spider80.ocx
O16 - DPF: {CDBD9968-7BF1-11D4-9D36-0001029DEBEB} (Loader Class) - http://ttsweb01/tdbin/Spider.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = peoplesoft.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = peoplesoft.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = peoplesoft.com,corp.peoplesoft.com,jdedwards.com,aps.jdedwards.com,cnc.jdedwards.com,mlab.jdedwards.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = peoplesoft.com,corp.peoplesoft.com,jdedwards.com,aps.jdedwards.com,cnc.jdedwards.com,mlab.jdedwards.com

Thank You

#2 RNult13

RNult13

    Member

  • New Member
  • Pip
  • 2 posts

Posted 26 July 2004 - 07:01 PM

I was able to delete it after I made all the system files viewable.

Thanks




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button