Author Topic: Yet another person needing Win 32: BHO-KD [Trj] removal assistance  (Read 8583 times)

0 Members and 1 Guest are viewing this topic.

samsonwk

  • Guest
Re: Yet another person needing Win 32: BHO-KD [Trj] removal assistance
« Reply #15 on: January 04, 2008, 06:14:30 PM »
I attempted to complete the rest of the instructions.  All of the highjack this files that you asked me to check were present.  It appears, however, that the C:\WINDOWS\System32\msrd3x40.exe is not present.  I only have a file named C:\WINDOWS\System32\msrd3x40.dll.  I tried to copy this file to the OTmoveit but am unable to.

Could you please advise whenever you have a spare moment?  No rush, as I will be offline now for the next 8 days.

Your assistance & patience is greatly appreciated!!!

samsonwk

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Yet another person needing Win 32: BHO-KD [Trj] removal assistance
« Reply #16 on: January 05, 2008, 07:08:41 AM »
.  I only have a file named C:\WINDOWS\System32\msrd3x40.dll.  I tried to copy this file to the OTmoveit but am unable to.

C:\WINDOWS\System32\msrd3x40.dll is a legimate file.  :)

Please use copy and paste to copy and paste the lines I post, for both removing and submitting files. This way we won't accidently remove the wrong file.
 

When I made my new canned HJT fix, I forgot a line. Here is the corrected procedure.

Open HJT, run a system scan only, check mark these lines if present

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O4 - HKLM\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\Run: [Windows Compliant] suptnq.exe
O4 - HKLM\..\RunServices: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\Run: [Windows Compliant] suptnq.exe
O4 - HKCU\..\Run: [Sygate Personal Firewall Start] servic.exe
O4 - HKLM\..\Run: [Windows Compliant] suptnq.exe
O4 - HKCU\..\Run: [msrd3x40] C:\WINDOWS\System32\msrd3x40.exe
O4 - HKUS\S-1-5-18\..\Run: [Sygate Personal Firewall Start] servic.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Compliant] suptnq.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [RSPC Driver D] hwfsv.exe (User 'Default user')
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)


Close all browser/windows except HJT, click fix, close HJT.

Please do the above and post a new HJT log. Thanks



« Last Edit: January 05, 2008, 07:33:54 AM by oldman »

seanyeung

  • Guest
I also have Win 32: BHO-KD [Trj] in my computer[need help!!]
« Reply #17 on: January 10, 2008, 02:28:34 PM »
i have combofix and hijack this.....

pls...anyone can help.....10000 times thanks....thank you!!!