Author Topic: I Have Tro Jans HELP  (Read 18858 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: I Have Tro Jans HELP
« Reply #15 on: June 24, 2007, 03:24:21 PM »
Cracking is closely related to pornography and these two with malware.
Safe browsing is not that close with these activities.
The best things in life are free.

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #16 on: June 24, 2007, 03:48:55 PM »
Essexboy has kindly offered to write a registry fix.  It will be posted shortly.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I Have Tro Jans HELP
« Reply #17 on: June 24, 2007, 04:33:27 PM »
Please download the OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system32\jbscyogw.exe
C:\WINDOWS\system32\ggf.exe
C:\WINDOWS\system32\gutfclrd.exe
C:\DOCUME~1\Slayer\xdkntevekill.bat
C:\WINDOWS\system32\xdknteve.exe
C:\WINDOWS\system32\cgdncaox.dll
C:\WINDOWS\system32\msgemkdu.dll
C:\WINDOWS\system32\sxbwslgv.exe
C:\WINDOWS\System32\cgdncaox.dll
C:\WINDOWS\System32\pobohgdk.dll
C:\WINDOWS\System32\arwlapwl.exe
C:\WINDOWS\System32\bgjcpcji.exe
C:\WINDOWS\System32\bmbqpkvy.exe
C:\WINDOWS\System32\cbqzidut.exe
C:\WINDOWS\System32\dkvwdapk.exe
C:\WINDOWS\System32\dkzelohy.exe
C:\WINDOWS\System32\dmjkdazs.exe
C:\WINDOWS\System32\dmzqrely.exe
C:\WINDOWS\System32\dybenetq.exe
C:\WINDOWS\System32\ebezizsn.exe
C:\WINDOWS\System32\epyngpar.exe
C:\WINDOWS\System32\eviholov.exe
C:\WINDOWS\System32\ezodefqf.exe
C:\WINDOWS\System32\fklcrqdm.exe
C:\WINDOWS\System32\fonyrgtk.exe
C:\WINDOWS\System32\fsjujszm.exe
C:\WINDOWS\System32\fuxqpchc.exe
C:\WINDOWS\System32\ulhrysdx.dll
C:\WINDOWS\System32\gpuzqrsn.exe
C:\WINDOWS\System32\gtabetsp.exe
C:\WINDOWS\System32\hmhuvwju.exe
C:\WINDOWS\System32\hmrezmtw.exe
C:\WINDOWS\System32\hynupatw.exe
C:\WINDOWS\System32\inqrqnal.exe
C:\WINDOWS\System32\ivybmvmb.exe
C:\WINDOWS\System32\ixevgdoz.exe
C:\WINDOWS\System32\j3241731.dll
C:\WINDOWS\System32\jgfunafq.exe
C:\WINDOWS\System32\jizkjcnw.exe
C:\WINDOWS\System32\jqlwdojk.exe
C:\WINDOWS\System32\jqpwvgjs.exe
C:\WINDOWS\System32\jsnoxiza.exe
C:\WINDOWS\System32\jyhadqly.exe
C:\WINDOWS\System32\kbglanyj.exe
C:\WINDOWS\System32\khofengf.exe
C:\WINDOWS\System32\knwlalqt.exe
C:\WINDOWS\System32\lcfidcns.exe
C:\WINDOWS\System32\lmjsjuni.exe
C:\WINDOWS\System32\mbypqbej.exe
C:\WINDOWS\System32\mfalmjaf.exe
C:\WINDOWS\System32\mfizgtez.exe
C:\WINDOWS\System32\mhijmvqd.exe
C:\WINDOWS\System32\mhoxwdyv.exe
C:\WINDOWS\System32\mlqvgzgb.exe
C:\WINDOWS\System32\mzsxszwd.exe
C:\Documents and Settings\All Users\Application Data\nebyzkdm.exe
C:\WINDOWS\System32\nydqjapo.exe
C:\WINDOWS\System32\obspotal.exe
C:\WINDOWS\System32\ojmnctax.exe
C:\WINDOWS\System32\olsfkdyz.exe
C:\WINDOWS\System32\otwdmfin.exe
C:\WINDOWS\System32\ovuvadgn.exe
C:\WINDOWS\System32\pcxihedu.exe
C:\WINDOWS\System32\pehcbcdy.exe
C:\WINDOWS\System32\pkbefaxc.exe
C:\WINDOWS\System32\pqnqfavi.exe
C:\WINDOWS\System32\pqxupqpu.exe
C:\WINDOWS\System32\qbclwdwp.exe
C:\WINDOWS\System32\qfsvajob.exe
C:\WINDOWS\System32\qjqnepgl.exe
C:\WINDOWS\System32\qjyjcdmn.exe
C:\WINDOWS\System32\qtqzaxql.exe
C:\WINDOWS\System32\qxajexcf.exe
C:\DOCUME~1\Slayer\MYDOCU~1\YMANTE~1
C:\WINDOWS\System32\ropmzork.exe
C:\WINDOWS\System32\rslkxgnm.exe
C:\WINDOWS\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
C:\WINDOWS\System32\ruvsfglg.exe
C:\WINDOWS\System32\sjwpufex.exe
C:\WINDOWS\System32\spobozyf.exe
C:\WINDOWS\System32\srsxafsh.exe
C:\WINDOWS\System32\tcjspube.exe
C:\WINDOWS\System32\tghoboji.exe
C:\WINDOWS\System32\tqtghkbi.exe
C:\WINDOWS\System32\tsbqnybm.exe
C:\WINDOWS\System32\tudglytw.exe
C:\WINDOWS\System32\twpabuja.exe
C:\WINDOWS\System32\tytunopk.exe
C:\WINDOWS\System32\tyvubivk.exe
C:\WINDOWS\System32\unadgpgr.exe
C:\WINDOWS\System32\uvixwxon.exe
C:\WINDOWS\System32\uvkrujqn.exe
C:\WINDOWS\System32\wnkvazyp.exe
C:\WINDOWS\System32\wvuxqbkl.exe
C:\WINDOWS\System32\xmjmjcri.exe
C:\WINDOWS\System32\xspotslk.exe
C:\WINDOWS\System32\xulalydm.exe
C:\WINDOWS\System32\ylkryzqn.exe
C:\WINDOWS\System32\ylqzmjaz.exe
C:\WINDOWS\System32\ypelyvch.exe
C:\WINDOWS\System32\yrqpulih.exe
C:\WINDOWS\System32\ytepqhcp.exe
C:\WINDOWS\System32\zgjivwtc.exe
C:\WINDOWS\System32\zozgzcnm.exe
C:\WINDOWS\System32\zsvuruly.exe
C:\WINDOWS\System32\zwpiduzg.exe
C:\WINDOWS\System32\zybiloxk.exe


Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply with a new Hijack log.
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Microsoft files should then be back in the majority  ;D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I Have Tro Jans HELP
« Reply #18 on: June 24, 2007, 04:36:52 PM »
Please download ERUNT from here and back up your entire registry http://www.snapfiles.com/get/erunt.html

Having done that then please apply the registry fix below

REGISTRY FIX
Quote
REGEDIT4

[-HKEY_CLASSES_ROOT\CLSID\{18C7DC10-D544-4398-8B09-7477CAAA896b}]

[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{18C7DC10-D544-4398-8B09-7477CAAA896b}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18C7DC10-D544-4398-8B09-7477CAAA896b}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winkcv32]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"ApachInc"=-
"arwlapwl"=-
"bgjcpcji"=-
"bmbqpkvy"=-
"cbqzidut"=-
"dkvwdapk"=-
"dkzelohy"=-
"dmjkdazs"=-
"dmzqrely"=-
"dybenetq"=-
"ebezizsn"=-
"epyngpar"=-
"eviholov"=-
"ezodefqf"=-
"fklcrqdm"=-
"fonyrgtk"=-
"fsjujszm"=-
"fuxqpchc"=-
"GPLv3"=-
"gpuzqrsn"=-
"gtabetsp"=-
"hmhuvwju"=-
"hmrezmtw"=-
"hynupatw"=-
"inqrqnal"=-
"ivybmvmb"=-
"ixevgdoz"=-
"j3241731"=-
"jgfunafq"=-
"jizkjcnw"=-
"jqlwdojk"=-
"jqpwvgjs"=-
"jsnoxiza"=-
"jyhadqly"=-
"kbglanyj"=-
"khofengf"=-
"knwlalqt"=-
"lcfidcns"=-
"lmjsjuni"=-
"mbypqbej"=-
"mfalmjaf"=-
"mfizgtez"=-
"mhijmvqd"=-
"mhoxwdyv"=-
"mlqvgzgb"=-
"mzsxszwd"=-
"nebyzkdm.exe"=-
"nydqjapo"=-
"obspotal"=-
"ojmnctax"=-
"olsfkdyz"=-
"otwdmfin"=-
"ovuvadgn"
"pcxihedu"=-
"pehcbcdy"=-
"pkbefaxc"=-
"pqnqfavi"=-
"pqxupqpu"=-
"qbclwdwp"=-
"qfsvajob"=-
"qjqnepgl"=-
"qjyjcdmn"=-
"qtqzaxql"=-
"qxajexcf"=-
"Rooh"=-
"ropmzork"=-
"rslkxgnm"=-
"runner1"=-
"ruvsfglg"=-
"sjwpufex"=-
"spobozyf"=-
"srsxafsh"=-
"tcjspube"=-
"tghoboji"=-
"tqtghkbi"=-
"tsbqnybm"=-
"tudglytw"=-
"twpabuja"=-
"tytunopk"=-
"tyvubivk"=-
"unadgpgr"=-
"uvixwxon"=-
"uvkrujqn"=-
"wnkvazyp"=-
"wvuxqbkl"=-
"xmjmjcri"=-
"xspotslk"=-
"xulalydm"=-
"ylkryzqn"=-
"ylqzmjaz"=-
"ypelyvch"=-
"yrqpulih"=-
"ytepqhcp"=-
"yzytwxqt"=-
"zgjivwtc"=-
"zozgzcnm"=-
"zsvuruly"=-
"zwpiduzg"=-
"zybiloxk"=-


Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file.  Ensure there is no space above the REGEDIT4.
Then in notepad go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
Then in the FILE NAME box type fix.reg
This will create a fix.reg file on your desktop

To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.

Download WinPFind3u.exe  to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.
« Last Edit: June 24, 2007, 04:42:44 PM by essexboy »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I Have Tro Jans HELP
« Reply #19 on: June 24, 2007, 04:38:39 PM »
I require the winpfind to destroy the other hidden elements not detected by combofix

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #20 on: June 24, 2007, 04:51:40 PM »
Ta essexboy.

@Tom2Die - if you haven't already done the AVG AS scan discussed on page 1 you can skip that for now.  Give priority to Essexboy's instructions.

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #21 on: June 24, 2007, 08:54:04 PM »
I scanned with AVG - 109 'traces' - but it wont let me make a log.  the button is unavailable.  It did tell me xdknteve.exe was bad and quarantined it for me when i tried to end it using the Analysis tab.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I Have Tro Jans HELP
« Reply #22 on: June 25, 2007, 12:01:39 AM »
Hi  Tom2Die follow my instructions re OTMoveit and the registry fix and follow that up with with the Winpfind.
You are so badly infected that until we nuke the base files not a lot is going to go right

No more cracks please otherwise you will never be clean

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #23 on: June 25, 2007, 12:52:20 AM »
Complete scanning result of "xdknteve.exe", received in VirusTotal at 06.24.2007, 20:58:10 (CET).

Antivirus   Version   Update   Result
AhnLab-V3   2007.6.21.1   06.22.2007   Win-Trojan/Xema.variant
AntiVir   7.4.0.34   06.24.2007   TR/Agent.aoy.1
Authentium   4.93.8   06.22.2007   no virus found
Avast   4.7.997.0   06.24.2007   no virus found
AVG   7.5.0.476   06.24.2007   Generic5.CF
BitDefender   7.2   06.24.2007   Trojan.Fotomoto.A
CAT-QuickHeal   9.00   06.23.2007   Trojan.Agent.aoy
ClamAV   devel-20070416   06.24.2007   Trojan.Agent-4880
DrWeb   4.33   06.24.2007   Trojan.EzulaAd
eSafe   7.0.15.0   06.24.2007   no virus found
eTrust-Vet   30.8.3736   06.22.2007   no virus found
Ewido   4.0   06.24.2007   Trojan.Agent.aoy
FileAdvisor   1   06.24.2007   no virus found
Fortinet   2.91.0.0   06.24.2007   no virus found
F-Prot   4.3.2.48   06.22.2007   no virus found
F-Secure   6.70.13030.0   06.22.2007   Trojan.Win32.Agent.aoy
Ikarus   T3.1.1.8   06.24.2007   Trojan.Win32.Agent.aoy
Kaspersky   4.0.2.24   06.24.2007   Trojan.Win32.Agent.aoy
McAfee   5059   06.22.2007   no virus found
Microsoft   1.2701   06.23.2007   Trojan:Win32/Fotomoto.gen!A
NOD32v2   2349   06.23.2007   no virus found
Norman   5.80.02   06.22.2007   W32/Agent.BSOF
Panda   9.0.0.4   06.24.2007   Trj/Downloader.OZB
Sophos   4.19.0   06.22.2007   no virus found
Sunbelt   2.2.907.0   06.21.2007   no virus found
Symantec   10   06.24.2007   Trojan.Vundo
TheHacker   6.1.6.137   06.22.2007   Trojan/Agent.aoy
VBA32   3.12.0.2   06.23.2007   Trojan.Win32.Agent.aoy
VirusBuster   4.3.23:9   06.24.2007   no virus found
Webwasher-Gateway   6.0.1   06.22.2007   Trojan.Agent.aoy.1

Aditional Information
File size: 122900 bytes
MD5: 23819fc93b5dcbf55f1b809e82e4743e
SHA1: 3a4aad3692cf0406eb07a08bc2f3bef791aed334



Complete scanning result of "cgdncaox.dll", received in VirusTotal at 06.24.2007, 21:04:52 (CET).

Antivirus   Version   Update   Result
AhnLab-V3   2007.6.21.1   06.22.2007   no virus found
AntiVir   7.4.0.34   06.24.2007   TR/Dldr.ConHook.Gen
Authentium   4.93.8   06.22.2007   no virus found
Avast   4.7.997.0   06.24.2007   no virus found
AVG   7.5.0.476   06.24.2007   no virus found
BitDefender   7.2   06.24.2007   Trojan.BHO.AR
CAT-QuickHeal   9.00   06.23.2007   no virus found
ClamAV   devel-20070416   06.24.2007   no virus found
DrWeb   4.33   06.24.2007   no virus found
eSafe   7.0.15.0   06.24.2007   Suspicious Trojan/Worm
eTrust-Vet   30.8.3736   06.22.2007   no virus found
Ewido   4.0   06.24.2007   no virus found
FileAdvisor   1   06.24.2007   no virus found
Fortinet   2.91.0.0   06.24.2007   no virus found
F-Prot   4.3.2.48   06.22.2007   no virus found
F-Secure   6.70.13030.0   06.22.2007   Packed.Win32.Morphine.a
Ikarus   T3.1.1.8   06.24.2007   MalwareScope.Trojan-Spy.BZub.1
Kaspersky   4.0.2.24   06.24.2007   Packed.Win32.Morphine.a
McAfee   5059   06.22.2007   no virus found
Microsoft   1.2701   06.23.2007   VirTool:Win32/Obfuscator.E
NOD32v2   2349   06.23.2007   probably a variant of Win32/Adware.BHO.V
Norman   5.80.02   06.22.2007   W32/BHO.QG
Panda   9.0.0.4   06.24.2007   Suspicious file
Sophos   4.19.0   06.22.2007   Mal/BHO-C
Sunbelt   2.2.907.0   06.21.2007   no virus found
Symantec   10   06.24.2007   no virus found
TheHacker   6.1.6.137   06.22.2007   Trojan/Morphine.a
VBA32   3.12.0.2   06.23.2007   Adware.Crew
VirusBuster   4.3.23:9   06.24.2007   no virus found
Webwasher-Gateway   6.0.1   06.22.2007   Trojan.Dldr.ConHook.Gen

Aditional Information
File size: 125972 bytes
MD5: 6807bb03664f055d6a09966e819bb76f
SHA1: 47924b97d472cfd129d68711969ac2b6754b1198
packers: MORPHINE
packers: Morphine

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: I Have Tro Jans HELP
« Reply #24 on: June 25, 2007, 01:01:19 AM »
Complete scanning result of "xdknteve.exe", received in VirusTotal at 06.24.2007, 20:58:10 (CET).
Complete scanning result of "cgdncaox.dll", received in VirusTotal at 06.24.2007, 21:04:52 (CET).
I won't have that much doubts about the infection of these two files.
I hope avast improve detection.  :-\ :'(
The best things in life are free.

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #25 on: June 25, 2007, 01:55:10 AM »
In addition to the files essexboy posted to be removed by OTMoveIt, add these two files to the list

C:\WINDOWS\system32\cgdncaox.dll
C:\WINDOWS\System32\xdknteve.exe


You can do this by appending them to the bottom of the list and doing a single run with OTMoveIt, or you can do a separate run with just these two files if its easier.

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #26 on: June 25, 2007, 03:47:21 AM »
I'm an idiot.  I had trouble reading the forum because I was too stupid to realize that there were two pages... But i suppose I'm not the first one to do that huh.  I will follow your advice and check to see if it works.  I will post results.  Thank you all for your help.  If you do want to see the actual log of the AVG scan, somebody will have to tell me how to activate the 'Create Log' command button.  It won't work.

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #27 on: June 25, 2007, 03:51:44 AM »
C:\WINDOWS\system32\jbscyogw.exe moved successfully.
C:\WINDOWS\system32\ggf.exe moved successfully.
C:\WINDOWS\system32\gutfclrd.exe moved successfully.
C:\DOCUME~1\Slayer\xdkntevekill.bat moved successfully.
C:\WINDOWS\system32\xdknteve.exe moved successfully.
C:\WINDOWS\system32\cgdncaox.dll unregistered successfully.
C:\WINDOWS\system32\cgdncaox.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\msgemkdu.dll
C:\WINDOWS\system32\msgemkdu.dll NOT unregistered.
C:\WINDOWS\system32\msgemkdu.dll moved successfully.
C:\WINDOWS\system32\sxbwslgv.exe moved successfully.
File/Folder C:\WINDOWS\System32\cgdncaox.dll not found.
File/Folder C:\WINDOWS\System32\pobohgdk.dll not found.
File/Folder C:\WINDOWS\System32\arwlapwl.exe not found.
File/Folder C:\WINDOWS\System32\bgjcpcji.exe not found.
File/Folder C:\WINDOWS\System32\bmbqpkvy.exe not found.
File/Folder C:\WINDOWS\System32\cbqzidut.exe not found.
File/Folder C:\WINDOWS\System32\dkvwdapk.exe not found.
File/Folder C:\WINDOWS\System32\dkzelohy.exe not found.
File/Folder C:\WINDOWS\System32\dmjkdazs.exe not found.
File/Folder C:\WINDOWS\System32\dmzqrely.exe not found.
File/Folder C:\WINDOWS\System32\dybenetq.exe not found.
File/Folder C:\WINDOWS\System32\ebezizsn.exe not found.
File/Folder C:\WINDOWS\System32\epyngpar.exe not found.
File/Folder C:\WINDOWS\System32\eviholov.exe not found.
File/Folder C:\WINDOWS\System32\ezodefqf.exe not found.
File/Folder C:\WINDOWS\System32\fklcrqdm.exe not found.
File/Folder C:\WINDOWS\System32\fonyrgtk.exe not found.
File/Folder C:\WINDOWS\System32\fsjujszm.exe not found.
File/Folder C:\WINDOWS\System32\fuxqpchc.exe not found.
File/Folder C:\WINDOWS\System32\ulhrysdx.dll not found.
File/Folder C:\WINDOWS\System32\gpuzqrsn.exe not found.
File/Folder C:\WINDOWS\System32\gtabetsp.exe not found.
File/Folder C:\WINDOWS\System32\hmhuvwju.exe not found.
File/Folder C:\WINDOWS\System32\hmrezmtw.exe not found.
File/Folder C:\WINDOWS\System32\hynupatw.exe not found.
File/Folder C:\WINDOWS\System32\inqrqnal.exe not found.
File/Folder C:\WINDOWS\System32\ivybmvmb.exe not found.
File/Folder C:\WINDOWS\System32\ixevgdoz.exe not found.
File/Folder C:\WINDOWS\System32\j3241731.dll not found.
File/Folder C:\WINDOWS\System32\jgfunafq.exe not found.
File/Folder C:\WINDOWS\System32\jizkjcnw.exe not found.
File/Folder C:\WINDOWS\System32\jqlwdojk.exe not found.
File/Folder C:\WINDOWS\System32\jqpwvgjs.exe not found.
File/Folder C:\WINDOWS\System32\jsnoxiza.exe not found.
File/Folder C:\WINDOWS\System32\jyhadqly.exe not found.
File/Folder C:\WINDOWS\System32\kbglanyj.exe not found.
File/Folder C:\WINDOWS\System32\khofengf.exe not found.
File/Folder C:\WINDOWS\System32\knwlalqt.exe not found.
File/Folder C:\WINDOWS\System32\lcfidcns.exe not found.
File/Folder C:\WINDOWS\System32\lmjsjuni.exe not found.
File/Folder C:\WINDOWS\System32\mbypqbej.exe not found.
File/Folder C:\WINDOWS\System32\mfalmjaf.exe not found.
File/Folder C:\WINDOWS\System32\mfizgtez.exe not found.
File/Folder C:\WINDOWS\System32\mhijmvqd.exe not found.
File/Folder C:\WINDOWS\System32\mhoxwdyv.exe not found.
File/Folder C:\WINDOWS\System32\mlqvgzgb.exe not found.
File/Folder C:\WINDOWS\System32\mzsxszwd.exe not found.
C:\Documents and Settings\All Users\Application Data\nebyzkdm.exe moved successfully.
File/Folder C:\WINDOWS\System32\nydqjapo.exe not found.
File/Folder C:\WINDOWS\System32\obspotal.exe not found.
File/Folder C:\WINDOWS\System32\ojmnctax.exe not found.
File/Folder C:\WINDOWS\System32\olsfkdyz.exe not found.
File/Folder C:\WINDOWS\System32\otwdmfin.exe not found.
File/Folder C:\WINDOWS\System32\ovuvadgn.exe not found.
File/Folder C:\WINDOWS\System32\pcxihedu.exe not found.
File/Folder C:\WINDOWS\System32\pehcbcdy.exe not found.
File/Folder C:\WINDOWS\System32\pkbefaxc.exe not found.
File/Folder C:\WINDOWS\System32\pqnqfavi.exe not found.
File/Folder C:\WINDOWS\System32\pqxupqpu.exe not found.
File/Folder C:\WINDOWS\System32\qbclwdwp.exe not found.
File/Folder C:\WINDOWS\System32\qfsvajob.exe not found.
File/Folder C:\WINDOWS\System32\qjqnepgl.exe not found.
File/Folder C:\WINDOWS\System32\qjyjcdmn.exe not found.
File/Folder C:\WINDOWS\System32\qtqzaxql.exe not found.
File/Folder C:\WINDOWS\System32\qxajexcf.exe not found.
File/Folder C:\DOCUME~1\Slayer\MYDOCU~1\YMANTE~1 not found.
File/Folder C:\WINDOWS\System32\ropmzork.exe not found.
File/Folder C:\WINDOWS\System32\rslkxgnm.exe not found.
File/Folder C:\WINDOWS\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 not found.
File/Folder C:\WINDOWS\System32\ruvsfglg.exe not found.
File/Folder C:\WINDOWS\System32\sjwpufex.exe not found.
File/Folder C:\WINDOWS\System32\spobozyf.exe not found.
File/Folder C:\WINDOWS\System32\srsxafsh.exe not found.
File/Folder C:\WINDOWS\System32\tcjspube.exe not found.
File/Folder C:\WINDOWS\System32\tghoboji.exe not found.
File/Folder C:\WINDOWS\System32\tqtghkbi.exe not found.
File/Folder C:\WINDOWS\System32\tsbqnybm.exe not found.
File/Folder C:\WINDOWS\System32\tudglytw.exe not found.
File/Folder C:\WINDOWS\System32\twpabuja.exe not found.
File/Folder C:\WINDOWS\System32\tytunopk.exe not found.
File/Folder C:\WINDOWS\System32\tyvubivk.exe not found.
File/Folder C:\WINDOWS\System32\unadgpgr.exe not found.
File/Folder C:\WINDOWS\System32\uvixwxon.exe not found.
File/Folder C:\WINDOWS\System32\uvkrujqn.exe not found.
File/Folder C:\WINDOWS\System32\wnkvazyp.exe not found.
File/Folder C:\WINDOWS\System32\wvuxqbkl.exe not found.
File/Folder C:\WINDOWS\System32\xmjmjcri.exe not found.
File/Folder C:\WINDOWS\System32\xspotslk.exe not found.
File/Folder C:\WINDOWS\System32\xulalydm.exe not found.
File/Folder C:\WINDOWS\System32\ylkryzqn.exe not found.
File/Folder C:\WINDOWS\System32\ylqzmjaz.exe not found.
File/Folder C:\WINDOWS\System32\ypelyvch.exe not found.
File/Folder C:\WINDOWS\System32\yrqpulih.exe not found.
File/Folder C:\WINDOWS\System32\ytepqhcp.exe not found.
File/Folder C:\WINDOWS\System32\zgjivwtc.exe not found.
File/Folder C:\WINDOWS\System32\zozgzcnm.exe not found.
File/Folder C:\WINDOWS\System32\zsvuruly.exe not found.
File/Folder C:\WINDOWS\System32\zwpiduzg.exe not found.
File/Folder C:\WINDOWS\System32\zybiloxk.exe not found.
 
Created on 06/24/2007 21:49:12

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #28 on: June 25, 2007, 03:52:11 AM »
Logfile of HijackThis v1.99.1
Scan saved at 9:50:09 PM, on 6/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Documents and Settings\Slayer\Desktop\OTMoveIt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: (no name) - {18C7DC10-D544-4398-8B09-7477CAAA896b} - C:\WINDOWS\System32\cgdncaox.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: YPOPs.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O20 - Winlogon Notify: winkcv32 - winkcv32.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\xdknteve.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #29 on: June 25, 2007, 03:53:01 AM »
... I had trouble reading the forum ...
No worries ...  :)

I see now that xdknteve.exe so you only need to add

C:\WINDOWS\system32\cgdncaox.dll

to the OTMoveIt list.
« Last Edit: June 25, 2007, 04:17:29 AM by mauserme »