Heavy duty Spyware on daughters pc
#1
Posted 26 May 2006 - 09:40 PM
Register to Remove
#2
Posted 27 May 2006 - 06:30 AM
I suggest you do this:
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
NewDotNet
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll (file missing)
O4 - HKLM\..\Run: [waadd] C:\WINDOWS\System32\qkret\waadd.exe
O4 - HKLM\..\Run: [pdhcgppn] C:\WINDOWS\System32\romwtoes\pdhcgppn.exe
O4 - HKLM\..\Run: [sjog] C:\WINDOWS\System32\jeexmt\sjog.exe
O4 - HKLM\..\Run: [nikn] C:\WINDOWS\System32\envmtiir\nikn.exe
O4 - HKLM\..\Run: [qoocbgob] C:\WINDOWS\System32\qcoxajc\qoocbgob.exe
O4 - HKLM\..\Run: [yvjc] C:\WINDOWS\System32\nfwveeos\yvjc.exe
O4 - HKLM\..\Run: [xhjfp] C:\WINDOWS\System32\aihxwo\xhjfp.exe
O4 - HKLM\..\Run: [sykoh] C:\WINDOWS\System32\saccvf\sykoh.exe
O4 - HKLM\..\Run: [nrvypb] C:\WINDOWS\System32\ddhdov\nrvypb.exe
O4 - HKLM\..\Run: [pefe] C:\WINDOWS\System32\kkjd\pefe.exe
O4 - HKLM\..\Run: [npwe] C:\WINDOWS\System32\gtxg\npwe.exe
O4 - HKLM\..\Run: [wesqjfmw] C:\WINDOWS\System32\fuxrwrt\wesqjfmw.exe
O4 - HKLM\..\Run: [ewtjvr] C:\WINDOWS\System32\pvdee\ewtjvr.exe
O4 - HKLM\..\Run: [nika] C:\WINDOWS\System32\khpls\nika.exe
O4 - HKLM\..\Run: [oevf] C:\WINDOWS\System32\tpck\oevf.exe
O4 - HKLM\..\Run: [vmmk] C:\WINDOWS\System32\rnvrdtik\vmmk.exe
O4 - HKLM\..\Run: [xdydw] C:\WINDOWS\System32\awokn\xdydw.exe
O4 - HKLM\..\Run: [ipnlwfwi] C:\WINDOWS\System32\yrqgcy\ipnlwfwi.exe
O4 - HKLM\..\Run: [ueihu] C:\WINDOWS\System32\sfxm\ueihu.exe
O4 - HKLM\..\Run: [kmyrod] C:\WINDOWS\System32\gpqwg\kmyrod.exe
O4 - HKLM\..\Run: [xhtghd] C:\WINDOWS\System32\vlqfnao\xhtghd.exe
O4 - HKLM\..\Run: [ppfman] C:\WINDOWS\System32\dengllb\ppfman.exe
O4 - HKLM\..\Run: [pigd] C:\WINDOWS\System32\sdxmx\pigd.exe
O4 - HKLM\..\Run: [fcvs] C:\WINDOWS\System32\uxhec\fcvs.exe
O4 - HKLM\..\Run: [hokknsfg] C:\WINDOWS\System32\iosxv\hokknsfg.exe
O4 - HKLM\..\Run: [yenyuyr] C:\WINDOWS\System32\pymsduk\yenyuyr.exe
O4 - HKLM\..\Run: [fserewc] C:\WINDOWS\System32\rkqein\fserewc.exe
O4 - HKLM\..\Run: [qofs] C:\WINDOWS\System32\kslvdmf\qofs.exe
O4 - HKLM\..\Run: [skgr] C:\WINDOWS\System32\ccenfb\skgr.exe
O4 - HKLM\..\Run: [wcxems] c:\windows\system32\xkwgzu.exe
O4 - HKLM\..\Run: [gxfug] C:\WINDOWS\System32\xybat\gxfug.exe
O4 - HKLM\..\Run: [weouuyy] C:\WINDOWS\System32\sngvflvr\weouuyy.exe
O4 - HKLM\..\Run: [loadadv64] C:\WINDOWS\system32\loadadv64
O4 - HKLM\..\Run: [NNSCAG638.EXEexeg] C:\WINDOWS\system32\NNSCAG638.EXEexeg
O4 - HKLM\..\Run: [Tagasuarus7.exerg] C:\WINDOWS\system32\Tagasuarus7.exerg
O4 - HKLM\..\Run: [FT_SilentSudokuInstaller.exe] C:\WINDOWS\system32\FT_SilentSudokuInstaller.exe
O20 - AppInit_DLLs: inicfg32.dll
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ktdgr.dll (file missing)
O23 - Service: dxvkalruvjxqdft - Unknown owner - C:\WINDOWS\system32\vjxqdft\dxvkalru.exe
O23 - Service: fcvsuxhec - Unknown owner - C:\WINDOWS\System32\uxhec\fcvs.exe
O23 - Service: fvphqfavgegdt - Unknown owner - C:\WINDOWS\System32\favgegdt\fvphq.exe (file missing)
O23 - Service: idpmtwktng - Unknown owner - C:\WINDOWS\System32\ktng\idpmtw.exe (file missing)
O23 - Service: nbjexcbrerns - Unknown owner - C:\WINDOWS\System32\erns\nbjexcbr.exe
O23 - Service: nfxfotducs - Unknown owner - C:\WINDOWS\System32\tducs\nfxfo.exe
O23 - Service: oqeqsjknpc - Unknown owner - C:\WINDOWS\System32\jknpc\oqeqs.exe
O23 - Service: pefekkjd - Unknown owner - C:\WINDOWS\System32\kkjd\pefe.exe (file missing)
O23 - Service: ppfmandengllb - Unknown owner - C:\WINDOWS\System32\dengllb\ppfman.exe (file missing)
O23 - Service: ssvuxbfrix - Unknown owner - C:\WINDOWS\System32\xbfrix\ssvu.exe (file missing)
O23 - Service: tdwheypmwgekambn - Unknown owner - C:\WINDOWS\system32\wgekambn\tdwheypm.exe (file missing)
O23 - Service: ueihusfxm - Unknown owner - C:\WINDOWS\System32\sfxm\ueihu.exe (file missing)
O23 - Service: vmmkrnvrdtik - Unknown owner - C:\WINDOWS\System32\rnvrdtik\vmmk.exe (file missing)
O23 - Service: wesqjfmwfuxrwrt - Unknown owner - C:\WINDOWS\System32\fuxrwrt\wesqjfmw.exe (file missing)
Close ALL windows and browsers except HijackThis and click "Fix checked"
Delete these Folders if listed:
C:\WINDOWS\System32\qkret
C:\WINDOWS\System32\romwtoes
C:\WINDOWS\System32\jeexmt
C:\WINDOWS\System32\envmtiir
C:\WINDOWS\System32\qcoxajc
C:\WINDOWS\System32\nfwveeos
C:\WINDOWS\System32\aihxwo
C:\WINDOWS\System32\saccvf
C:\WINDOWS\System32\ddhdov
C:\WINDOWS\System32\kkjd
C:\WINDOWS\System32\gtxg
C:\WINDOWS\System32\fuxrwrt
C:\WINDOWS\System32\pvdee
C:\WINDOWS\System32\khpls
C:\WINDOWS\System32\tpck
C:\WINDOWS\System32\rnvrdtik
C:\WINDOWS\System32\awokn
C:\WINDOWS\System32\yrqgcy
C:\WINDOWS\System32\sfxm
C:\WINDOWS\System32\gpqwg
C:\WINDOWS\System32\vlqfnao
C:\WINDOWS\System32\dengllb
C:\WINDOWS\System32\sdxmx
C:\WINDOWS\System32\uxhec
C:\WINDOWS\System32\iosxv
C:\WINDOWS\System32\pymsduk
C:\WINDOWS\System32\rkqein
C:\WINDOWS\System32\kslvdmf
C:\WINDOWS\System32\ccenfb
C:\WINDOWS\System32\xybat
C:\WINDOWS\system32\vjxqdft
C:\WINDOWS\System32\uxhec
C:\WINDOWS\System32\favgegdt
C:\WINDOWS\System32\ktng
C:\WINDOWS\System32\erns
C:\WINDOWS\System32\tducs
C:\WINDOWS\System32\jknpc
C:\WINDOWS\System32\kkjd
C:\WINDOWS\System32\dengllb
C:\WINDOWS\System32\xbfrix
C:\WINDOWS\system32\wgekambn
C:\WINDOWS\System32\sfxm
C:\WINDOWS\System32\rnvrdtik
C:\WINDOWS\System32\fuxrwrt
Delete these Files if listed:
c:\windows\system32\xkwgzu.exe
C:\WINDOWS\System32\sngvflvr
C:\WINDOWS\system32\loadadv64
C:\WINDOWS\system32\FT_SilentSudokuInstaller.exe
C:\WINDOWS\system32\ktdgr.dll
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#3
Posted 27 May 2006 - 12:16 PM
#4
Posted 27 May 2006 - 12:19 PM
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\Notify\ktdgr.dll]
On the desktop, doubleclick fix.reg and allow it to run. Let it merge.
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\ktdgr.dll (file missing)
Close ALL windows and browsers except HijackThis and click "Fix checked"
Empty Recycle Bin
Restart your computer.
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#5
Posted 27 May 2006 - 12:45 PM
#6
Posted 27 May 2006 - 12:54 PM
Log looks good How is it running any issues?
You need to create a new Clean restore point.
Note: This will remove all previous Restore Points
Turn off System Restore:
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer, turn it back on.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.
If you dont have these programs I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.
It is critical to have both a firewall and anti virus to protect your system.
Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.
Safe Surfing.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#7
Posted 27 May 2006 - 02:02 PM
#8
Posted 27 May 2006 - 02:03 PM
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#9
Posted 27 May 2006 - 02:04 PM
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.
Coyote's Installed programs for prevention:
http://forums.tomcoy...showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users