Page 1 of 3 123 LastLast
Results 1 to 10 of 21

Thread: systs.exe, Win32.Backdoor.SDbot

  1. #1
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default systs.exe, Win32.Backdoor.SDbot

    I'm running Windows 2000 and yesterday morning zonealarm warned me that systs.exe was trying to access the internet.

    Adaware detected win32.backdoor.SDbot and removed it which deleted systs.exe from my system32 folder.

    On next reboot systs.exe came back.

    I followed some forum instructions including running SDFix in Safe Mode but Systs.exe still came back.

    Last night I formatted my C drive (important files always on a backup D drive) and reinstalled Windows 2000.

    At first there was no sign of systs.exe but after installing h/d utilities, graphics card, adaware, etc it came back.

    This morning Spybot detected and removed Win32.Delf.Uc but systs.exe remained though has now been deleted by adaware again but probably only until my next reboot.

    Any help would be greatly appreciated.

    This is my current hijackthis log:
    Logfile of HijackThis v1.99.1
    Scan saved at 09:43:53, on 20/10/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Unable to get Internet Explorer version! (Note: that is V5 from clean W2k install)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\Ati2evxx.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\Ati2evxx.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///c:/home.htm
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1192831589406
    O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    O23 - Service: tjk8rla0zxexp - Unknown owner - C:\WINNT\system32\systs.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

  2. #2
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default

    In the hope that someone will be going to help from reading other threads it seems the first thing to do is rename hijackthis to bettingmad and post a new log file.

    I have also disabled teatimer.


    Logfile of HijackThis v1.99.1
    Scan saved at 10:48:10, on 20/10/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Unable to get Internet Explorer version!

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\Ati2evxx.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\Ati2evxx.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\HijackThis\bettingmad.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///c:/home.htm
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1192831589406
    O20 - Winlogon Notify: klogon - C:\WINNT\system32\klogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    O23 - Service: tjk8rla0zxexp - Unknown owner - C:\WINNT\system32\systs.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

  3. #3
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
    "BEFORE you POST" (READ this Procedure before Requesting Assistance)
    http://forums.spybot.info/showthread.php?t=288
    All advice given is taken at your own risk.
    Please make sure you have read this information so we are on the same page.

    You know what, the best thing to do is read the directions which are posted at the top of the forum and I also posted them above for you.
    Had you done this, you would not have posted an out of date version of HJT.
    C:\Program Files\HijackThis\bettingmad.exe <<< delete that version and download the newest version 2.0.2 from the link in the instructions. Please download it following the prompts to the default location and there is no need to rename HJT, I see no evidence of a Vundo trojan.

    This appears to be your problem but I would prefer to look at the new HJT log before proceeding.
    O23 - Service: tjk8rla0zxexp - Unknown owner - C:\WINNT\system32\systs.exe (file missing)

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  4. #4
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default

    pskelley,

    I'm sorry about not reading that thread in full. I only scanned the opening post assuming it was just a warning and missed the instructions below. Perhaps you need a big red notice to 'read it' all for impatient folk like me.

    I could not do the kaspersky online check because it needs IE6 and I only have IE5 on after a new W2k install. I tried via MS update to get IE6 but finished up in a rebooting/failed installing loop as the software was unsigned. I eventually stopped it but didn't try install IE6 again. Not sure if this is to do with the problem.

    After running S&D in safe mode on rebooting vrt1.tmp was trying to access the internet.

    Apologies again about not reading the instructions and thanks for your help.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:18:04, on 20/10/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Unable to get Internet Explorer version!
    Boot mode: Normal

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\Ati2evxx.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\Ati2evxx.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Trend Micro\HijackThis\bettingmad.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///c:/home.htm
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1192831589406
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    O23 - Service: tjk8rla0zxexp - Unknown owner - C:\WINNT\system32\systs.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

    --
    End of file - 2811 bytes

  5. #5
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Thanks for the feedback, we will find a scanner that will run on this OS. One reason I don't like working on it, I have never had it and am not 100% sure about anything. Like how to turn off this service. I can give you instructions for XP but I am not sure they are them same for
    Windows 2000.

    http://www.techspot.com/tweaks/win2k...es/print.shtml <<< looks similiar to XP, navigate to that service:
    O23 - Service: tjk8rla0zxexp - Unknown owner - C:\WINNT\system32\systs.exe (file missing)
    and disable it. The navigate to that file:
    C:\WINNT\system32\systs.exe <<< and delete it. If it gives you issues, use this tool and instructions.

    How to use the Delete on Reboot tool
    http://www.bleepingcomputer.com/tuto...42.html#delreb
    Start Hijackthis
    Click on the Config button
    Click on the Misc Tools button
    Click on the button labeled Delete a file on reboot...
    A new window will open asking you to select the file that you would like to delete on reboot. Navigate to the file: C:\WINNT\system32\systs.exe and click on it once, and then click on the Open button.
    You will now be asked if you would like to reboot your computer to delete the file. Click on the Yes button if you would like to reboot now.

    This looks like an upgrade from another OS, you might have to enter the file as C:\WINDOWS\SYSTEM32\systs.exe
    Only thing I am sure of is that file and service needs to go. You may also try removing the file in safe mode. Once it is gone, post a new log with your feedback so we can see what else needs to be done.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  6. #6
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default

    I stopped the service systs.exe is not there.

    This is the hijackthis log:Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:12:10, on 20/10/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Unable to get Internet Explorer version!
    Boot mode: Normal

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\System32\Ati2evxx.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    C:\Program Files\AMD\Cool'n'Quiet\gemback.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\Ati2evxx.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\bettingmad.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///c:/home.htm
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1192831589406
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: AMD PowerNow! (tm) Technology Service (GemServ) - Advanced Micro Devices - C:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

    --
    End of file - 2769 bytes

  7. #7
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default

    Just rebooted and vrt2.tmp is in the task list and trying get on the net.

  8. #8
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default

    I exported my services list in case there might be something else that caught anyone's eye:


    Name Description Status Startup Type Log On As
    Alerter Notifies selected users and computers of administrative alerts. Manual LocalSystem
    AMD PowerNow! (tm) Technology Service Started Automatic LocalSystem
    Application Management Provides software installation services such as Assign, Publish, and Remove. Manual LocalSystem
    Ati HotKey Poller Started Automatic LocalSystem
    ATI Smart Automatic LocalSystem
    Automatic Updates Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Started Automatic LocalSystem
    Background Intelligent Transfer Service Transfers files in the background using idle network bandwidth. If the service is disabled, then any functions that depend on BITS, such as Windows Update or MSN Explorer will be unable to automatically download programs and other information. Manual LocalSystem
    ClipBook Supports ClipBook Viewer, which allows pages to be seen by remote ClipBooks. Manual LocalSystem
    COM+ Event System Provides automatic distribution of events to subscribing COM components. Started Manual LocalSystem
    Computer Browser Maintains an up-to-date list of computers on your network and supplies the list to programs that request it. Started Automatic LocalSystem
    DHCP Client Manages network configuration by registering and updating IP addresses and DNS names. Started Automatic LocalSystem
    Distributed Link Tracking Client Sends notifications of files moving between NTFS volumes in a network domain. Started Automatic LocalSystem
    Distributed Transaction Coordinator Coordinates transactions that are distributed across two or more databases, message queues, file systems, or other transaction protected resource managers. Manual LocalSystem
    DNS Client Resolves and caches Domain Name System (DNS) names. Started Automatic LocalSystem
    Event Log Logs event messages issued by programs and Windows. Event Log reports contain information that can be useful in diagnosing problems. Reports are viewed in Event Viewer. Started Automatic LocalSystem
    Fax Service Helps you send and receive faxes Manual LocalSystem
    Indexing Service Manual LocalSystem
    Internet Connection Sharing Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection. Manual LocalSystem
    IPSEC Policy Agent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Started Automatic LocalSystem
    Logical Disk Manager Logical Disk Manager Watchdog Service Started Automatic LocalSystem
    Logical Disk Manager Administrative Service Administrative service for disk management requests Manual LocalSystem
    Messenger Sends and receives messages transmitted by administrators or by the Alerter service. Disabled LocalSystem
    Net Logon Supports pass-through authentication of account logon events for computers in a domain. Manual LocalSystem
    NetMeeting Remote Desktop Sharing Allows authorized people to remotely access your Windows desktop using NetMeeting. Manual LocalSystem
    Network Connections Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. Started Manual LocalSystem
    Network DDE Provides network transport and security for dynamic data exchange (DDE). Manual LocalSystem
    Network DDE DSDM Manages shared dynamic data exchange and is used by Network DDE Manual LocalSystem
    NT LM Security Support Provider Provides security to remote procedure call (RPC) programs that use transports other than named pipes. Manual LocalSystem
    Performance Logs and Alerts Configures performance logs and alerts. Manual LocalSystem
    Plug and Play Manages device installation and configuration and notifies programs of device changes. Started Automatic LocalSystem
    Print Spooler Loads files to memory for later printing. Started Automatic LocalSystem
    Protected Storage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Started Automatic LocalSystem
    QoS RSVP Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets. Manual LocalSystem
    Remote Access Auto Connection Manager Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address. Manual LocalSystem
    Remote Access Connection Manager Creates a network connection. Started Manual LocalSystem
    Remote Procedure Call (RPC) Provides the endpoint mapper and other miscellaneous RPC services. Started Automatic LocalSystem
    Remote Procedure Call (RPC) Locator Manages the RPC name service database. Manual LocalSystem
    Remote Registry Service Allows remote registry manipulation. Started Automatic LocalSystem
    Removable Storage Manages removable media, drives, and libraries. Started Automatic LocalSystem
    Routing and Remote Access Offers routing services to businesses in local area and wide area network environments. Disabled LocalSystem
    RunAs Service Enables starting processes under alternate credentials Started Automatic LocalSystem
    Security Accounts Manager Stores security information for local user accounts. Started Automatic LocalSystem
    Server Provides RPC support and file, print, and named pipe sharing. Started Automatic LocalSystem
    Smart Card Manages and controls access to a smart card inserted into a smart card reader attached to the computer. Manual LocalSystem
    Smart Card Helper Provides support for legacy smart card readers attached to the computer. Manual LocalSystem
    System Event Notification Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Started Automatic LocalSystem
    Task Scheduler Enables a program to run at a designated time. Started Automatic LocalSystem
    TCP/IP NetBIOS Helper Service Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Started Automatic LocalSystem
    Telephony Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service. Started Manual LocalSystem
    Telnet Allows a remote user to log on to the system and run console programs using the command line. Disabled LocalSystem
    tjk8rla0zxexp tjk8rla0zxexp Disabled LocalSystem
    TrueVector Internet Monitor Monitors internet traffic and generates alerts for disallowed access. Started Automatic LocalSystem
    Uninterruptible Power Supply Manages an uninterruptible power supply (UPS) connected to the computer. Manual LocalSystem
    Utility Manager Starts and configures accessibility tools from one window Manual LocalSystem
    Windows Installer Installs, repairs and removes software according to instructions contained in .MSI files. Manual LocalSystem
    Windows Management Instrumentation Provides system management information. Started Automatic LocalSystem
    Windows Management Instrumentation Driver Extensions Provides systems management information to and from drivers. Started Manual LocalSystem
    Windows Time Sets the computer clock. Manual LocalSystem
    Wireless Configuration Provides authenticated network access control using IEEE 802.1x for wired and wireless Ethernet networks. Manual LocalSystem
    Workstation Provides network connections and communications. Started Automatic LocalSystem

  9. #9
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Thanks, use HJT to get rid of this item unless you know what it is:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///c:/home.htm

    Some information about this: vrt2.tmp
    http://www.prevx.com/filenames/X2082.../VRT2.TMP.html
    We can use Prevx if we need to, they offer a free trial, let's see what else we can do first.

    Have you scanned to see where this: vrt2.tmp <<< is located?

    Let me look at an uninstall list in case something is running you are not aware of:
    Open Hijackthis.
    Click the "Open the Misc Tools" section Button.
    Click the "Open Uninstall Manager" Button.
    Click the "Save list..." Button.
    Save it to your desktop. Copy and paste the contents into your reply.
    (You may edit out Microsoft, Hotfixes, Security Update for Windows XP, Update for Windows XP and Windows XP Hotfix to shorten the list)

    Am I missing something? I see no antivirus program? If you do not have one, here is a free one:
    http://free.grisoft.com/doc/2/.
    Download the free version, update it and run a complete system scan. It should find that junk.

    Post a new HJT log when it is running, the uninstall list and some feedback. How do you figure to stay secure without antivirus protection?
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  10. #10
    Junior Member
    Join Date
    Oct 2007
    Posts
    14

    Default

    c:\home.htm is OK I use it as my browser home page, it is just full of my links.

    I located vrt2.tmp in the windows\temp directory and deleted it. I did the same earlier but think it was vrt5.tmp.

    I did an uninstall list and there didn't look to be anything suspicious to me. Unfortunately I can't post it because I can no longer get into the PC. I installed AVG and rebooted. Now when I log in it accepts my password and quickly displays loading settings, applying settings and saving settings but then throws me back out asking for a password again. It seems a never ending loop.

    I was using AVG before and put it back on after my new windows install. AVG said the PC had no problems even though Spybot (Win32.delf.uc) and adaware (win32.backdoor.SDbot) both reported problems. AVG didn't seem to be helping so I took it off in case it might get in the way of a fix.

    Any idea how I can log in? If not just pass me a very large hammer....

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •