This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this log

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

What exactly are these that we are dealing with?? And do you have any idea how I could have possibly gotten them on my computer?
This is a "Qoologic" trojan "in full bloom".

I'm not sure how it get's spread?
:scratch:

One more tidbit of info is required before I compose another "fix".

Please download/unzip this:

Registry Search by Bobbi Flekman

on regsearch.exe, to run it.

Make sure ALL the boxes are "checked" under "Search", and search for this:

eridrb.exe

It may take a while to run, so be patient. When finished, the search results will appear in your text editor,

Paste the contents of the search results into your next post.
:)

P.S. - You're doing great… Keep up the good work. :thumbup:
Well thanks for the vote of confidence, but all the praise goes to you. By the way do you ever sleep, LOL On to the next step now… I'll be back ;)
so the night is still young… and this is how you are spending your vacation, LOL sleep, as in step away from the keypad and find your bed… you know, that piece of furniture that is obviously neglected by you :)
WOW that didn't take as long as I thought it would. Here are the results.. REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 7/1/2006 6:00:00 PM for strings: ; 'eridrb.exe' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\aftvs] "command"="C:\\WINDOWS\\system32\\eridrb.exe reg_run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\djmuqy] "command"="C:\\WINDOWS\\system32\\eridrb.exe reg_run" [HKEY_USERS\S-1-5-21-3881752594-1239226667-489229912-1007\Software\Google\NavClient\1.1\History] ; Contents of value: ; ¾Ù¥d "eridrb.exe"=hex:be,d9,a5,44 ; End Of The Log…

and this is how you are spending your vacation, LOL

I got no choice.

My family ran off left me until Tuesday…

SOMEONE has to feed the cats…
:rofl:

Will post a "fix" in a few…
:scratch:

I don't think all the little boxes were "checked" in the registry search tool…

Can you be sure they ALL are checked an run it again, please.
:unsure:
:scratch:I don't know what this means, but I have checked all six of the boxes and it appears to still be running because my timer (the hour glass thingy) is on. Yet a RegSearch Notepad popped up with the following: REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 7/1/2006 6:24:56 PM for strings: ; 'eridrb.exe' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\aftvs] "command"="C:\\WINDOWS\\system32\\eridrb.exe reg_run" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\djmuqy] "command"="C:\\WINDOWS\\system32\\eridrb.exe reg_run" [HKEY_USERS\S-1-5-21-3881752594-1239226667-489229912-1007\Software\Google\NavClient\1.1\History] ; Contents of value: ; ¾Ù¥d "eridrb.exe"=hex:be,d9,a5,44 ; End Of The Log…
who would have thunk it :blink: Once I closed the RegSearch Notepad the timer disappeared. So I guess that is all there is to the RegSearch log.
I got it figured out…

Copy and paste the contents of the quote box below into Notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"djmuqy"=-

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"aftvs"=-


Close Notepad.

Copy the file names in the quote box below to the clipboard by highlighting them and pressing
C (hold the key down, then press C):

C:\WINDOWS\system32\jowgd.dat
C:\WINDOWS\system32\eridrb.exe
C:\WINDOWS\system32\tbyhr.exe
C:\WINDOWS\system32\kyidijv.dll
C:\WINDOWS\system32\fvglchk.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\vytex.exe


CLOSE ALL WINDOWS/PROGRAMS.

Fix these with HijackThis!:

F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\tbyhr.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,fvglchk.exe


Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Run Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

Cross your fingers.. Better take off your shoes and cross your toes, too!!!

After the reboot, "copy/paste" a new log file into this thread. :)
sorry :( my computer froze up on me but I am back

I got it figured out…


I had no doubt :thumbup:

Cross your fingers.. Better take off your shoes and cross your toes, too!!!


I was thinking more along the lines of saying some prayers ;)

now off to do what you advised.
I don't think this is good :(

I followed all your instructions and when I came to Killbox only C:\WINDOWS\system32\jowgd.dat was removed. The others came back with the response "File could not be deleted."

I even tried to remove them in safe mode but I was not able to.

Here is the latest HJT log…

Logfile of HijackThis v1.99.1
Scan saved at 7:56:59 PM, on 7/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\hkcmd.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\dlbxcoms.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HJT.exe\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\tbyhr.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,fvglchk.exe
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI