Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93100 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Heavy duty Spyware on daughters pc


  • This topic is locked This topic is locked
8 replies to this topic

#1 DrLyle

DrLyle

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 26 May 2006 - 09:40 PM

Here you guys and gals go: ogfile of HijackThis v1.99.1 Scan saved at 11:36:17 PM, on 5/26/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\vjxqdft\dxvkalru.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rfgu\hognqlqq.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\system32\geuhj\erwqdrsn.exe C:\WINDOWS\system32\bdqupjnc\qtlqthd.exe C:\WINDOWS\system32\lqrhvqvx\qdwh.exe C:\WINDOWS\system32\hyjf\mdocetdl.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\giogtw\babnnnu.exe C:\DOCUME~1\Grace\LOCALS~1\Temp\cinfo.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\system32\devldr32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\DOCUME~1\Grace\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing) O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll (file missing) O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [waadd] C:\WINDOWS\System32\qkret\waadd.exe O4 - HKLM\..\Run: [pdhcgppn] C:\WINDOWS\System32\romwtoes\pdhcgppn.exe O4 - HKLM\..\Run: [sjog] C:\WINDOWS\System32\jeexmt\sjog.exe O4 - HKLM\..\Run: [nikn] C:\WINDOWS\System32\envmtiir\nikn.exe O4 - HKLM\..\Run: [qoocbgob] C:\WINDOWS\System32\qcoxajc\qoocbgob.exe O4 - HKLM\..\Run: [yvjc] C:\WINDOWS\System32\nfwveeos\yvjc.exe O4 - HKLM\..\Run: [xhjfp] C:\WINDOWS\System32\aihxwo\xhjfp.exe O4 - HKLM\..\Run: [sykoh] C:\WINDOWS\System32\saccvf\sykoh.exe O4 - HKLM\..\Run: [nrvypb] C:\WINDOWS\System32\ddhdov\nrvypb.exe O4 - HKLM\..\Run: [pefe] C:\WINDOWS\System32\kkjd\pefe.exe O4 - HKLM\..\Run: [npwe] C:\WINDOWS\System32\gtxg\npwe.exe O4 - HKLM\..\Run: [wesqjfmw] C:\WINDOWS\System32\fuxrwrt\wesqjfmw.exe O4 - HKLM\..\Run: [ewtjvr] C:\WINDOWS\System32\pvdee\ewtjvr.exe O4 - HKLM\..\Run: [nika] C:\WINDOWS\System32\khpls\nika.exe O4 - HKLM\..\Run: [oevf] C:\WINDOWS\System32\tpck\oevf.exe O4 - HKLM\..\Run: [vmmk] C:\WINDOWS\System32\rnvrdtik\vmmk.exe O4 - HKLM\..\Run: [xdydw] C:\WINDOWS\System32\awokn\xdydw.exe O4 - HKLM\..\Run: [ipnlwfwi] C:\WINDOWS\System32\yrqgcy\ipnlwfwi.exe O4 - HKLM\..\Run: [ueihu] C:\WINDOWS\System32\sfxm\ueihu.exe O4 - HKLM\..\Run: [kmyrod] C:\WINDOWS\System32\gpqwg\kmyrod.exe O4 - HKLM\..\Run: [xhtghd] C:\WINDOWS\System32\vlqfnao\xhtghd.exe O4 - HKLM\..\Run: [ppfman] C:\WINDOWS\System32\dengllb\ppfman.exe O4 - HKLM\..\Run: [pigd] C:\WINDOWS\System32\sdxmx\pigd.exe O4 - HKLM\..\Run: [fcvs] C:\WINDOWS\System32\uxhec\fcvs.exe O4 - HKLM\..\Run: [hokknsfg] C:\WINDOWS\System32\iosxv\hokknsfg.exe O4 - HKLM\..\Run: [yenyuyr] C:\WINDOWS\System32\pymsduk\yenyuyr.exe O4 - HKLM\..\Run: [fserewc] C:\WINDOWS\System32\rkqein\fserewc.exe O4 - HKLM\..\Run: [qofs] C:\WINDOWS\System32\kslvdmf\qofs.exe O4 - HKLM\..\Run: [skgr] C:\WINDOWS\System32\ccenfb\skgr.exe O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [wcxems] c:\windows\system32\xkwgzu.exe O4 - HKLM\..\Run: [gxfug] C:\WINDOWS\System32\xybat\gxfug.exe O4 - HKLM\..\Run: [weouuyy] C:\WINDOWS\System32\sngvflvr\weouuyy.exe O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\system32\loadadv64 O4 - HKLM\..\Run: [NNSCAG638.EXEexeg] C:\WINDOWS\system32\NNSCAG638.EXEexeg O4 - HKLM\..\Run: [Tagasuarus7.exerg] C:\WINDOWS\system32\Tagasuarus7.exerg O4 - HKLM\..\Run: [FT_SilentSudokuInstaller.exe] C:\WINDOWS\system32\FT_SilentSudokuInstaller.exe O4 - HKLM\..\Run: [ZICORN] C:\WINDOWS\system32\ZICORN O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22.dll' missing O20 - AppInit_DLLs: inicfg32.dll O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ktdgr.dll (file missing) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: dxvkalruvjxqdft - Unknown owner - C:\WINDOWS\system32\vjxqdft\dxvkalru.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: fcvsuxhec - Unknown owner - C:\WINDOWS\System32\uxhec\fcvs.exe O23 - Service: fvphqfavgegdt - Unknown owner - C:\WINDOWS\System32\favgegdt\fvphq.exe (file missing) O23 - Service: idpmtwktng - Unknown owner - C:\WINDOWS\System32\ktng\idpmtw.exe (file missing) O23 - Service: nbjexcbrerns - Unknown owner - C:\WINDOWS\System32\erns\nbjexcbr.exe O23 - Service: nfxfotducs - Unknown owner - C:\WINDOWS\System32\tducs\nfxfo.exe O23 - Service: oqeqsjknpc - Unknown owner - C:\WINDOWS\System32\jknpc\oqeqs.exe O23 - Service: pefekkjd - Unknown owner - C:\WINDOWS\System32\kkjd\pefe.exe (file missing) O23 - Service: ppfmandengllb - Unknown owner - C:\WINDOWS\System32\dengllb\ppfman.exe (file missing) O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: ssvuxbfrix - Unknown owner - C:\WINDOWS\System32\xbfrix\ssvu.exe (file missing) O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe O23 - Service: tdwheypmwgekambn - Unknown owner - C:\WINDOWS\system32\wgekambn\tdwheypm.exe (file missing) O23 - Service: ueihusfxm - Unknown owner - C:\WINDOWS\System32\sfxm\ueihu.exe (file missing) O23 - Service: vmmkrnvrdtik - Unknown owner - C:\WINDOWS\System32\rnvrdtik\vmmk.exe (file missing) O23 - Service: wesqjfmwfuxrwrt - Unknown owner - C:\WINDOWS\System32\fuxrwrt\wesqjfmw.exe (file missing) Thanks for the help.....Dr. Lyle

    Advertisements

Register to Remove


#2 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 27 May 2006 - 06:30 AM

Hello DrLyle, Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
NewDotNet



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)

O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll (file missing)

O4 - HKLM\..\Run: [waadd] C:\WINDOWS\System32\qkret\waadd.exe
O4 - HKLM\..\Run: [pdhcgppn] C:\WINDOWS\System32\romwtoes\pdhcgppn.exe
O4 - HKLM\..\Run: [sjog] C:\WINDOWS\System32\jeexmt\sjog.exe
O4 - HKLM\..\Run: [nikn] C:\WINDOWS\System32\envmtiir\nikn.exe
O4 - HKLM\..\Run: [qoocbgob] C:\WINDOWS\System32\qcoxajc\qoocbgob.exe
O4 - HKLM\..\Run: [yvjc] C:\WINDOWS\System32\nfwveeos\yvjc.exe
O4 - HKLM\..\Run: [xhjfp] C:\WINDOWS\System32\aihxwo\xhjfp.exe
O4 - HKLM\..\Run: [sykoh] C:\WINDOWS\System32\saccvf\sykoh.exe
O4 - HKLM\..\Run: [nrvypb] C:\WINDOWS\System32\ddhdov\nrvypb.exe
O4 - HKLM\..\Run: [pefe] C:\WINDOWS\System32\kkjd\pefe.exe
O4 - HKLM\..\Run: [npwe] C:\WINDOWS\System32\gtxg\npwe.exe
O4 - HKLM\..\Run: [wesqjfmw] C:\WINDOWS\System32\fuxrwrt\wesqjfmw.exe
O4 - HKLM\..\Run: [ewtjvr] C:\WINDOWS\System32\pvdee\ewtjvr.exe
O4 - HKLM\..\Run: [nika] C:\WINDOWS\System32\khpls\nika.exe
O4 - HKLM\..\Run: [oevf] C:\WINDOWS\System32\tpck\oevf.exe
O4 - HKLM\..\Run: [vmmk] C:\WINDOWS\System32\rnvrdtik\vmmk.exe
O4 - HKLM\..\Run: [xdydw] C:\WINDOWS\System32\awokn\xdydw.exe
O4 - HKLM\..\Run: [ipnlwfwi] C:\WINDOWS\System32\yrqgcy\ipnlwfwi.exe
O4 - HKLM\..\Run: [ueihu] C:\WINDOWS\System32\sfxm\ueihu.exe
O4 - HKLM\..\Run: [kmyrod] C:\WINDOWS\System32\gpqwg\kmyrod.exe
O4 - HKLM\..\Run: [xhtghd] C:\WINDOWS\System32\vlqfnao\xhtghd.exe
O4 - HKLM\..\Run: [ppfman] C:\WINDOWS\System32\dengllb\ppfman.exe
O4 - HKLM\..\Run: [pigd] C:\WINDOWS\System32\sdxmx\pigd.exe
O4 - HKLM\..\Run: [fcvs] C:\WINDOWS\System32\uxhec\fcvs.exe
O4 - HKLM\..\Run: [hokknsfg] C:\WINDOWS\System32\iosxv\hokknsfg.exe
O4 - HKLM\..\Run: [yenyuyr] C:\WINDOWS\System32\pymsduk\yenyuyr.exe
O4 - HKLM\..\Run: [fserewc] C:\WINDOWS\System32\rkqein\fserewc.exe
O4 - HKLM\..\Run: [qofs] C:\WINDOWS\System32\kslvdmf\qofs.exe
O4 - HKLM\..\Run: [skgr] C:\WINDOWS\System32\ccenfb\skgr.exe
O4 - HKLM\..\Run: [wcxems] c:\windows\system32\xkwgzu.exe
O4 - HKLM\..\Run: [gxfug] C:\WINDOWS\System32\xybat\gxfug.exe
O4 - HKLM\..\Run: [weouuyy] C:\WINDOWS\System32\sngvflvr\weouuyy.exe
O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\system32\loadadv64
O4 - HKLM\..\Run: [NNSCAG638.EXEexeg] C:\WINDOWS\system32\NNSCAG638.EXEexeg
O4 - HKLM\..\Run: [Tagasuarus7.exerg] C:\WINDOWS\system32\Tagasuarus7.exerg
O4 - HKLM\..\Run: [FT_SilentSudokuInstaller.exe] C:\WINDOWS\system32\FT_SilentSudokuInstaller.exe

O20 - AppInit_DLLs: inicfg32.dll
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ktdgr.dll (file missing)

O23 - Service: dxvkalruvjxqdft - Unknown owner - C:\WINDOWS\system32\vjxqdft\dxvkalru.exe
O23 - Service: fcvsuxhec - Unknown owner - C:\WINDOWS\System32\uxhec\fcvs.exe
O23 - Service: fvphqfavgegdt - Unknown owner - C:\WINDOWS\System32\favgegdt\fvphq.exe (file missing)
O23 - Service: idpmtwktng - Unknown owner - C:\WINDOWS\System32\ktng\idpmtw.exe (file missing)
O23 - Service: nbjexcbrerns - Unknown owner - C:\WINDOWS\System32\erns\nbjexcbr.exe
O23 - Service: nfxfotducs - Unknown owner - C:\WINDOWS\System32\tducs\nfxfo.exe
O23 - Service: oqeqsjknpc - Unknown owner - C:\WINDOWS\System32\jknpc\oqeqs.exe
O23 - Service: pefekkjd - Unknown owner - C:\WINDOWS\System32\kkjd\pefe.exe (file missing)
O23 - Service: ppfmandengllb - Unknown owner - C:\WINDOWS\System32\dengllb\ppfman.exe (file missing)
O23 - Service: ssvuxbfrix - Unknown owner - C:\WINDOWS\System32\xbfrix\ssvu.exe (file missing)
O23 - Service: tdwheypmwgekambn - Unknown owner - C:\WINDOWS\system32\wgekambn\tdwheypm.exe (file missing)
O23 - Service: ueihusfxm - Unknown owner - C:\WINDOWS\System32\sfxm\ueihu.exe (file missing)
O23 - Service: vmmkrnvrdtik - Unknown owner - C:\WINDOWS\System32\rnvrdtik\vmmk.exe (file missing)
O23 - Service: wesqjfmwfuxrwrt - Unknown owner - C:\WINDOWS\System32\fuxrwrt\wesqjfmw.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Folders if listed:

C:\WINDOWS\System32\qkret
C:\WINDOWS\System32\romwtoes
C:\WINDOWS\System32\jeexmt
C:\WINDOWS\System32\envmtiir
C:\WINDOWS\System32\qcoxajc
C:\WINDOWS\System32\nfwveeos
C:\WINDOWS\System32\aihxwo
C:\WINDOWS\System32\saccvf
C:\WINDOWS\System32\ddhdov
C:\WINDOWS\System32\kkjd
C:\WINDOWS\System32\gtxg
C:\WINDOWS\System32\fuxrwrt
C:\WINDOWS\System32\pvdee
C:\WINDOWS\System32\khpls
C:\WINDOWS\System32\tpck
C:\WINDOWS\System32\rnvrdtik
C:\WINDOWS\System32\awokn
C:\WINDOWS\System32\yrqgcy
C:\WINDOWS\System32\sfxm
C:\WINDOWS\System32\gpqwg
C:\WINDOWS\System32\vlqfnao
C:\WINDOWS\System32\dengllb
C:\WINDOWS\System32\sdxmx
C:\WINDOWS\System32\uxhec
C:\WINDOWS\System32\iosxv
C:\WINDOWS\System32\pymsduk
C:\WINDOWS\System32\rkqein
C:\WINDOWS\System32\kslvdmf
C:\WINDOWS\System32\ccenfb
C:\WINDOWS\System32\xybat
C:\WINDOWS\system32\vjxqdft
C:\WINDOWS\System32\uxhec
C:\WINDOWS\System32\favgegdt
C:\WINDOWS\System32\ktng
C:\WINDOWS\System32\erns
C:\WINDOWS\System32\tducs
C:\WINDOWS\System32\jknpc
C:\WINDOWS\System32\kkjd
C:\WINDOWS\System32\dengllb
C:\WINDOWS\System32\xbfrix
C:\WINDOWS\system32\wgekambn
C:\WINDOWS\System32\sfxm
C:\WINDOWS\System32\rnvrdtik
C:\WINDOWS\System32\fuxrwrt



Delete these Files if listed:

c:\windows\system32\xkwgzu.exe
C:\WINDOWS\System32\sngvflvr
C:\WINDOWS\system32\loadadv64
C:\WINDOWS\system32\FT_SilentSudokuInstaller.exe
C:\WINDOWS\system32\ktdgr.dll





Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#3 DrLyle

DrLyle

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 27 May 2006 - 12:16 PM

LD Tate, Thanks for the help. Things appear to be getting better. I completed all of your instructions and here is second hijack log: Logfile of HijackThis v1.99.1 Scan saved at 2:08:32 PM, on 5/27/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\devldr32.exe C:\WINDOWS\system32\wuauclt.exe C:\DOCUME~1\Grace\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ktdgr.dll (file missing) O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

#4 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 27 May 2006 - 12:19 PM

Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ktdgr.dll]



On the desktop, doubleclick fix.reg and allow it to run. Let it merge.





Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ktdgr.dll (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"



Empty Recycle Bin

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#5 DrLyle

DrLyle

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 27 May 2006 - 12:45 PM

LD Tate, Things appear to be running better. Start up time is decreasing, no popups, and no internet misdirections. Appreciate your assistance on this weekend. Here is 3rd log: Logfile of HijackThis v1.99.1 Scan saved at 2:39:44 PM, on 5/27/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\devldr32.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\wuauclt.exe C:\DOCUME~1\Grace\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

#6 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 27 May 2006 - 12:54 PM

Good Job :thumbup:

Log looks good :D :thumbup: How is it running any issues?


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these programs I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#7 DrLyle

DrLyle

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 27 May 2006 - 02:02 PM

LD Tate, Completed all. I have Norton and Webroot Spy Sweeper scheduled to run daily. I really appreciate your help! Thank you Dr. Lyle

#8 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 27 May 2006 - 02:03 PM

Great job :thumbup: You're more then welcome. Glad we were able to help Peace be with you :wavey:

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#9 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 27 May 2006 - 02:04 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users