This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Registry Cleaner Malware

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not sure where I picked this up since this computer does not go on the internet much but… The system tray has had an icon added that looks somewhat like the Microsoft update shield. This icon periodically places a ballon up that has among other things a like that states "Your computer is infested" and wants you to load a product named registry cleaner fro a company named sysregistry.com. I have emailed them with no result. If I try to right click on the icon it works the same as a left click and brings up a dialog box wanting to install registry cleaner. I am trying to remove said icon and any other malware associated with it. My HJT file follows. All help is appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 8:19:55 AM, on 4/17/2007
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\ni_nic.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
D:\Programs\TightVNC\WinVNC.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\PROMon.exe
C:\WINNT\Mixer.exe
D:\Programs\RealPlayer\RealPlay.exe
C:\WINNT\System32\atiptaxx.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINNT\System32\spoolsvc.exe
C:\WINNT\System32\gugzow.exe
C:\WINNT\System32\tcpipmon.exe
C:\WINNT\System32\tcpipmon.exe
D:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\CreateCD.exe
C:\Program Files\ATI Multimedia\main\launchpd.exe
D:\Programs\MSOffice\Office\1033\OLFSNT40.EXE
D:\Programs\MSOffice\Office\1033\msoffice.exe
C:\WINNT\System32\wcugmj.exe
C:\WINNT\System32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINNT\System32\csrs.exe
C:\WINNT\System32\japthao.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\pnvfl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Grisoft\AVG7\avgw.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINNT\System32\noxdwayq.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {B5D1644E-6F4F-4117-B438-F7A6B94B7767} - C:\WINNT\System32\kdoympgr.dll
O2 - BHO: (no name) - {E44527F6-1296-4A84-B67D-A6CEA6ED4B69} - C:\WINNT\System32\hggedab.dll
O2 - BHO: (no name) - {E51B4B44-8647-4FB2-8601-82794BC647B2} - C:\WINNT\System32\geebb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [tcpipmon] tcpipmon.exe
O4 - Startup: Microsoft Office Fast Start.lnk = D:\Programs\MSOffice\Office\FASTBOOT.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Programs\MSOffice\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = D:\Programs\MSOffice\Office\1033\OLFSNT40.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://winantivirus.com/download/2007/down…5d3487_3daa5283 3702ffa100a04703b731108821568056&lng=en&cnt=us
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1158538492375
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1158535707265
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: geebb - C:\WINNT\System32\geebb.dll (file missing)
O20 - Winlogon Notify: hggedab - C:\WINNT\SYSTEM32\hggedab.dll
O20 - Winlogon Notify: rpcc - C:\WINNT\System32\rpcc.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel Client Instrumentation for DMI (ni_nic) - Intel® Corporation - C:\WINNT\System32\ni_nic.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - D:\Programs\TightVNC\WinVNC.exe" -service (file missing)

Thanks.

Regards,
Redbeard
Hi and welcome to the forums. :) I'm Markka and I will be helping you with your malware issues. I check your HijackThis log. Right now I'm MRU Undergrad, everything that I post to you must be checked by teachers of Malware Removal University. Please be patient. :)
Hello and sorry for the delay :(


1. Download this file - combofix.exe ans save it to your desktop !
2. Then start -> run -> copy & paste into the area this text from code box and after that click ok.
"%userprofile%\desktop\combofix.exe" /v hggedab
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Please download SmitfraudFix (by S!Ri)

Double-click SmitfraudFix.exe.
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm



Post:
- A fresh HijackThis log
- Contents of C:\Combofix.txt
- Contents of Report.txt
- Logfile of SmitfraudFix
Makka, Thank you for responding, however my attempts prior to my posting to you evedently fixed the problem. I ran toolbarcop hijackthis, and AVG but forgot to reboot because I was interrupted while AVG was running. The path I was following (based on something I found on the Web) said to remove everything that toolbarcop marked as startup which I did. When I did reboot (after my posting) everything but the standard system tray items were gone. This does not cause me problems since on that computer I really had nothing there that I use. For other computers this is not the case and a selective approach would be more appropriate. If this occurs again I will come here first, and maybe if someone else has this happen they may use this as a starting point. Thank you again for your prompt response. Regards, Redbeard

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI