Hey i managed to fix the glitch that was having my comp to reboot twice in order to stay online.. but this " oekxl virus" came back, zone alarm picks it up and aks if i want it to access the internet..


heres my hijack log


Logfile of HijackThis v1.97.7
Scan saved at 2:16:12 PM, on 8/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sstray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\oekxz.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijack this\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {308C1458-E010-48F3-8875-16550CA02A4B} - C:\WINDOWS\System32\wblvuewr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Rrou] C:\Documents and Settings\julio\Application Data\onsa.exe
O4 - HKCU\..\Run: [Fxbcbjcl] C:\WINDOWS\System32\oekxz.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Dani AI

Generated

ZoneAlarm prompting means a local process is trying to make an outbound connection. That can be a legitimate updater or a piece of malware. , and as suggested, run up‑to‑date anti‑spyware, but follow a short, safe workflow to contain and remove the offender.

Immediate containment: disconnect the PC from the network (unplug ethernet / disable Wi‑Fi) and set the firewall to block the unknown program so it cannot phone home. Back up personal documents (not programs or system folders) to external media before you start removing anything.

Cleanup workflow: boot into Safe Mode (F8) so fewer items run, then run at least two updated scanners (one signature-based and one heuristic/behavioral). If in‑place scanners fail to remove it, use a bootable rescue ISO from a reputable vendor so the file can be deleted when it is not running.

Troubleshooting & verification: identify which process is responsible and where it persists. Useful commands/tools: Process Explorer or TCPView, and the following command sequence to map network sockets to a PID, inspect that PID, then stop it:

netstat -ano | findstr ESTABLISHED
tasklist /fi "PID eq 1234"
taskkill /PID 1234 /F

After killing the process, remove any startup/persistence entries with msconfig, Task Scheduler, and Autoruns (or edit Run/RunOnce entries carefully). If you are not confident which entries are safe to remove, capture and post an updated startup/Autoruns log for analysis rather than deleting at random.

Aftercare: fully patch Windows and applications, change passwords that were used on the machine, and monitor for reappearance. If the system shows signs of deep compromise or you cannot be sure it is clean, plan a clean reinstall and restore only trusted data.

Have you tried all the software like adaware, spybot search and destroy and CWShredder?

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.