This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Baseline

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This computer seems to be eaten up with trojans. Some of them are:
Troj.Vundo.H, Agent & others

I have tried to rid them from the unit by using programs such as:
SpyHunter (file= rkdijcrk.dll) (Finds them but will not remove them on reboot)
TrojanHunter (Locks up and quits running)
VundoFix (Finds them but will not remove them on reboot)
Malwarebytes Anti-Malware (Finds them, also cannot remove them on reboot)
SpyBot S & D (Did remove a majority of the spyware but cannot remove Vundo on reboot)

Below is a HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:39:33 PM, on 5/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\TrojanHunter 5.1\THGuard.exe
C:\Program Files\TrojanHunter 5.1\THGuard.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.myembarq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ewol.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Provided by EWOL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: (no name) - {02d51dc4-f5df-444c-a572-1be383ca6c85} - C:\WINDOWS\system32\rkdijcrk.dll
O2 - BHO: (no name) - {d48366f7-7073-4b97-b003-dfa7e1992610} - c:\windows\system32\dkcawdc.dll
O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SprintDSLSetup] E:\installs\BrdJmp\SprintDSLSetup.exe
O4 - HKLM\..\Run: [SprintModemUpdate] javaw.exe -cp "C:\Program Files\Motive\FirmwareUpdater\lib\SprintModemUpdate.jar" com.motive.firmwareUpdater.client.SprintModemUpdate
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.1\THGuard.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\ljn1n.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\ljn1n.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\2161359820.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\ljn1n.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - AppInit_DLLs: C:\WINDOWS\system32\ c:\windows\system32\yeyepowi.dll
O20 - Winlogon Notify: ahsvrjfk - C:\WINDOWS\SYSTEM32\dkcawdc.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O24 - Desktop Component 0: (no name) - http://www.flalottery.com/lottery/images/bgimage.jpg

–
End of file - 7198 bytes
Any help you can lend will be greatly appreciated.
Thanks, Don
Hi, I reread your instructions for self-cleaning prior to submitting information and see you also asked for a log from Malwarebytes' Anti-Malware, Below is posted such a log. I hope someone reads this soon as I have been working on it for almost a week now and need to move to other fisk I have to fry. Malwarebytes' Log: Malwarebytes' Anti-Malware 1.36 Database version: 2060 Windows 5.1.2600 Service Pack 3 4/30/2009 4:23:15 PM mbam-log-2009-04-30 (16-23-15).txt Scan type: Quick Scan Objects scanned: 84251 Time elapsed: 19 minute(s), 23 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 7 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\rkdijcrk.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d48366f7-7073-4b97-b003-dfa7e1992610} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ahsvrjfk (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{d48366f7-7073-4b97-b003-dfa7e1992610} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02d51dc4-f5df-444c-a572-1be383ca6c85} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{02d51dc4-f5df-444c-a572-1be383ca6c85} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jrrwdyvu (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jrrwdyvu (Trojan.Vundo.H) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\dkcawdc.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\rkdijcrk.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\hqmkqni.dll (Trojan.Vundo.H) -> Delete on reboot. Thank you for your help. *************************************************
Hi,

Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi CatByte Thanks for the comeback. I cannot download the combofix program from the infected computer. Whenever I connect the cable to the infected comp it starts downloading all kinds of junk and I cannot use the browser. I have been downloading from a non infected comp and xferring through a thumb drive to the infected comp. I did that with combofix and came up with a message that combofix had been compromised and could not continue. So what now? Don
Hi,

Keep the infected computer off the internet until we can get it cleaned up somewhat then.

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:7171
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: (no name) - {02d51dc4-f5df-444c-a572-1be383ca6c85} - C:\WINDOWS\system32\rkdijcrk.dll
O2 - BHO: (no name) - {d48366f7-7073-4b97-b003-dfa7e1992610} - c:\windows\system32\dkcawdc.dll
O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\ljn1n.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\ljn1n.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\2161359820.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\ljn1n.exe (User 'Default user')
O20 - AppInit_DLLs: C:\WINDOWS\system32\ c:\windows\system32\yeyepowi.dll
O20 - Winlogon Notify: ahsvrjfk - C:\WINDOWS\SYSTEM32\dkcawdc.dll

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT

Open Notepad

Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.
Copy the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')
Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')
Note: There must be NO blank lines in front of the pasted text, but ensure that there is a blank line at the end of the text, otherwise the registry merge will not work.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02d51dc4-f5df-444c-a572-1be383ca6c85}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d48366f7-7073-4b97-b003-dfa7e1992610}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}"=-

[-HKEY_CLASSES_ROOT\CLSID\{02d51dc4-f5df-444c-a572-1be383ca6c85}]

[-HKEY_CLASSES_ROOT\CLSID\{d48366f7-7073-4b97-b003-dfa7e1992610}]

[-HKEY_CLASSES_ROOT\CLSID\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Resurections"=-
"Diagnostic Manager"=-
"[]"=-

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in fixme.reg as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.
You should now see a file on your desktop that looks like this:
[external image: Posted Image]
Locate the fixme.reg icon on your desktop and double click it, an information box will pop up asking if you want to merge the information in the file into the registry, click YES.
Once the file has run, the information will have merged with your registry so you can delete fixme.reg from your desktop as you won't be needing it any more.



Next - we need to delete some of the bad files:


Open Notepad
Click Start >Run type notepad into the run box click OK
Click Format and make certain that Word Wrap is NOT checked.

Copy all the text inside of the code box, put your mouse cursor at the very beginning of the text and then hold down the left button and drag your mouse so that all of the text is highlighted. Press Ctrl+C (or right click on the highlighted section and choose 'copy')

@echo off
attrib -s -h -r C:\WINDOWS\system32\rkdijcrk.dll
del /f /q C:\WINDOWS\system32\rkdijcrk.dll
attrib -s -h -r c:\windows\system32\dkcawdc.dll
del /f /q c:\windows\system32\dkcawdc.dll
attrib -s -h -r C:\WINDOWS\TEMP\ljn1n.exe 
del /f /q C:\WINDOWS\TEMP\ljn1n.exe 
attrib -s -h -r C:\WINDOWS\TEMP\2161359820.exe 
del /f /q C:\WINDOWS\TEMP\2161359820.exe 
attrib -s -h -r c:\windows\system32\yeyepowi.dll
del /f /q c:\windows\system32\yeyepowi.dll
del %0

Now paste the copied text into the open notepad. To do this click in the blank page so that your cursor is flashing there and press CTRL+V (or right click and choose 'paste')

Now go to File > and click Save As,
From the drop down menu at the top of the box choose Desktop as the location to save this file.
Go down to the File Name box and type in runme.bat as the file name, then choose All Files as the save as file type.
Then click the save button.
Once you have clicked the save button, close Notepad.

You will now have a file on your desktop that looks like this [external image: Posted Image]

Locate runme.bat on your Desktop and double-click it
A black window will flash up and disappear again, and runme.bat will be deleted.

This is normal.


NEXT

Delete the copy of ComboFix that you have.

From a clean computer download a fresh copy of ComboFix onto a USB from the links provided and transfer it to the infected PC,
see if it will now run.

Post the resulting log
Hi CatByte, I tried to merge the first file into the registery. The computer is giving me an error message saying "cannot import …. error accessing the registry". What do you think of those apples? Where to now? Don
well, the malware is playing havok with your system and your registry, were you at least able to get the HJT fixes done?
try the batch file to delete those bad files.

If the batch won't work either - see if you can show hidden files and folders

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

then navigate to the following files and delete them

C:\WINDOWS\system32\rkdijcrk.dll
c:\windows\system32\dkcawdc.dll
C:\WINDOWS\TEMP\ljn1n.exe
C:\WINDOWS\TEMP\2161359820.exe
c:\windows\system32\yeyepowi.dll

Then try and transfer over ComboFix, but this time I am going to give you a different renamed version, which may work better -

try this:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
C:\WINDOWS\system32\rkdijcrk.dll Access denied cannot delete c:\windows\system32\dkcawdc.dll " " " " C:\WINDOWS\TEMP\ljn1n.exe gone C:\WINDOWS\TEMP\2161359820.exe gone c:\windows\system32\yeyepowi.dll gone OK, I downloaded combofix to the desktop of my noninfected computer and renamed it in the process to combo-fix.exe. I copyed it to a USB and moved it to the desktop of the infected comp. I get the error message saying the contents of the combofix package has been compromised. Do not proceed. May be infected with a file patching virus. OK? I have to go now. Will be back in the AM and we can have another go. Thanks for your efforts.
Well, unfortunately, if Combo Fix is reporting that, then in all likely hood you are infected with a polymorphic file infector.

The only reasonable recourse you have is to totally wipe and reformat your machine.

When you have a "file-patching" virus, it means that your legitimate system files have been over written with malware files and it is going to make your system totally unstable.

The fact your registry could not be accessed is a clear indication of the problems this infection is causing.

The only thing we recommend is to do a full reformat and install.

We have an excellent tutorial on how to reformat here

Things to bear in mind, only back up data files (word, excell etc.) DO NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.pif/.com/.rar files… as they could all be infected and will simply re-infect your system again, there is no way of being certain what this infection can do.

If you don't have a Windows Installation Disk (if this came with Windows pre-installed), you may have a Manufacturer restore disk to restore the computer to its original state - this depends on the Manufacturer though. Otherwise, give the Manufacturer a call and ask them to send you a restore disk or Windows installation CD.

Here is a guide on backing up your data;
Although you can use whatever method you prefer.

Do not back up to another machine, as it may become compromised.

Burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups.

I am sorry there is nothing more that we can do.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI