1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

I know I did not catch them all... easy to help me....

Discussion in 'Virus & Other Malware Removal' started by Wendy!, Jan 25, 2005.

Thread Status:
Not open for further replies.
  1. Wendy!

    Wendy! Thread Starter

    Joined:
    Jul 1, 2004
    Messages:
    175
    what did I miss?

    Logfile of HijackThis v1.99.0
    Scan saved at 8:02:13 PM, on 1/25/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\documents and settings\madawinnie\local settings\temp\1URguj.exe
    C:\documents and settings\madawinnie\local settings\temp\Eh.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\The Weather Channel\The Weather Channel.exe
    C:\Documents and Settings\Madawinnie\Application Data\lale.exe
    C:\WINDOWS\system32\d?xplore.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\system32\slserv.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Madawinnie\My Documents\My Downloads\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.averatec.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {00EB29C5-9A5F-9BAE-7B61-9BDC473BE099} - C:\WINDOWS\system32\ehjhogye.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {36DC117E-B246-2EBB-8002-675504F47E4E} - C:\WINDOWS\system32\daxnzm.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Madawinnie\Local Settings\Temp\bXEA74sk.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [yP.exe] C:\documents and settings\madawinnie\local settings\temp\yP.exe
    O4 - HKLM\..\Run: [1URguj.exe] C:\documents and settings\madawinnie\local settings\temp\1URguj.exe
    O4 - HKLM\..\Run: [Eh.exe] C:\documents and settings\madawinnie\local settings\temp\Eh.exe
    O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINDOWS\Temp\TBuninst.exe /remove
    O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINDOWS\Temp\WTuninst.exe /remove
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Desktop Weather 3] C:\Program Files\The Weather Channel\The Weather Channel.exe
    O4 - HKCU\..\Run: [Otec] C:\Documents and Settings\Madawinnie\Application Data\lale.exe
    O4 - HKCU\..\Run: [Unw] C:\WINDOWS\system32\d?xplore.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: *.dollidol.com
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
  2. wdm2291

    wdm2291

    Joined:
    Nov 4, 2004
    Messages:
    403
    do CTRL+ATL+DEL and under running "processes" kill ("end process") EACH and EVERY occurance of EACH of the following:

    ehjhogye.dll
    1URguj.exe
    Eh.exe
    d?xplore.exe
    yP.exe


    Run Hijack This again, put a check mark next to each of the following items, close all other windows and browsers (including this one), leaving only Hijack This open, and click "Fix Checked":

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: (no name) - {00EB29C5-9A5F-9BAE-7B61-9BDC473BE099} - C:\WINDOWS\system32\ehjhogye.dll

    O4 - HKLM\..\Run: [yP.exe] C:\documents and settings\madawinnie\local settings\temp\yP.exe

    O4 - HKLM\..\Run: [1URguj.exe] C:\documents and settings\madawinnie\local settings\temp\1URguj.exe

    O4 - HKLM\..\Run: [Eh.exe] C:\documents and settings\madawinnie\local settings\temp\Eh.exe

    O4 - HKLM\..\Run: [Uninstall_TBPS] C:\WINDOWS\Temp\TBuninst.exe /remove

    O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINDOWS\Temp\WTuninst.exe /remove

    O4 - HKCU\..\Run: [Otec] C:\Documents and Settings\Madawinnie\Application Data\lale.exe

    O4 - HKCU\..\Run: [Unw] C:\WINDOWS\system32\d?xplore.exe


    boot to Safe Mode

    How to boot to Safe Mode:
    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf.docid/2001052409420406


    To make your hidden files and folders visible, go to Start > Search and under "More advanced search options". Make sure there is a check next to "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"

    Now click on My Computer. Go to Tools > Folder Options. Click on the "View" tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
    Click "Apply" then "OK"

    Delete all of the following:

    C:\documents and settings\madawinnie\local settings\temp\yP.exe
    C:\documents and settings\madawinnie\local settings\temp\Eh.exe
    C:\documents and settings\madawinnie\local settings\temp\1URguj.exe
    C:\Documents and Settings\Madawinnie\Application Data\lale.exe
    C:\WINDOWS\system32\d?xplore.exe
    C:\WINDOWS\system32\ehjhogye.dll


    Delete files/folder from the following directories (But not the directory itself, for example delete all files/folder IN temp.
    C:\Windows\Temp\
    C:\Documents and Settings\<Your Profile>\Local Settings\Temp\
    C:\Documents and Settings\<All other users Profile>\Local Settings\Temp\
    C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <<<This will delete your files in your internet cache--including cookies.
    C:\Documents and Settings\<All other users Profile>\Local Settings\Temporary Internet Files\

    Then empty the Recycle Bin.

    Then reboot to normal mode, run Hijack This and post a new log here


    Wayne
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/323450

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice