Buckeye Sam - Need your help with kuajuu.exe!!

I was referred to you by Nightowl (in a different forum). He says that you are the man that can kill my nasty bug!

I'm having several problems, but it seems the most common ones that spybot and Ad-aware SE are catching and Temporarily fixing are ABetterInternet, PeopleonPage, Apropos Media, and Flashtrack Flashenhancer. ABI Network was recently on my Add/Remove programs list and I managed to get it off, but I don't know if it's still here and hidden. Everytime I restart or connect to the net things go back to messing up again. PCcillin catches several viruses most common are Troj Angent MJ and Troj Buddy A. I also have a 16bit MS dos Subsystem that pops up quite frequently with aurora.exe, svcproc.exe, and nail.exe in it.
I seem to get things under control until I restart or connect to the net then it goes back to messing up again.
Looking forward to relief!! Here's My Most Recent Log:

Logfile of HijackThis v1.99.1
Scan saved at 4:34:09 PM, on 6/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\kuajuu.exe
C:\WINDOWS\system32\icfonf.exe
C:\Program Files\Messenger\MSMSGS.EXE
c:\windows\system32\qwrhnc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [tvs_b] C:\program files\tvs\tvs_b.exe
O4 - HKLM\..\Run: [FlaCPY] "C:\Program Files\Common Files\Java\flacpy.exe"
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\system32\PSof1.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
O4 - HKLM\..\Run: [o7sk3pQ] icfonf.exe
O4 - HKLM\..\Run: [kqyshtt] c:\windows\system32\qwrhnc.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

Comments

  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited June 2005
    Let's get you fixed up. I see a few problems now and I'm guessing from your comments that we might find a few more that aren't showing up right now.

    Download rkfiles.zip
    http://skads.org/special/rkfiles.zip
    Unzip the contents to a permanent folder.

    Reboot your computer into Safe Mode


    Doubleclick rkfiles.bat
    It will scan for a while, so please be patient.
    Wait till the DOS window closes and reboot back to normal mode.

    Post the contents of C:\log.txt in your next reply.
  • edited June 2005
    Thanks so much for helping me! Did as you said, here is C:\log.txt contents:

    C:\Documents and Settings\Gidget\Desktop

    PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
    Files Found in system Folder............
    C:\WINDOWS\system32\PSof1.exe: UPX!
    C:\WINDOWS\system32\uci.exe: UPX!
    C:\WINDOWS\system32\mpujepb.exe: UPX!
    C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213

    Files Found in all users startup Folder............
    Files Found in all users windows Folder............
    C:\WINDOWS\icont.exe: UPX!
    C:\WINDOWS\RMAgentOutput.dll: UPX!
    C:\WINDOWS\tsc.exe: UPX!
    C:\WINDOWS\vsapi32.dll: UPX!t4
    Finished
    bye
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited June 2005
    Download the Pocket Killbox.

    Unzip the contents of KillBox.zip to a convenient location and then double-click on KillBox.exe to launch the program.
    • Highlight the lines below and press the Ctrl key and the C key at the same time to copy them to the clipboard:

        C:\WINDOWS\system32\PSof1.exe
        C:\WINDOWS\system32\uci.exe
        C:\WINDOWS\system32\mpujepb.exe
        C:\WINDOWS\icont.exe
        C:\WINDOWS\RMAgentOutput.dll

      [*]Now go to the Killbox application and click on the File menu and then the Paste from Clipboard menu item. In the Full Path of File to Delete box you should see the first file. If you dropdown that box you should see the rest of them. Make sure that they are all there.
      [*]Click on the Delete on Reboot option and then click on the red circle with a white 'X' in to to delete the files. Killbox will tell you that all listed files will be deleted on next reboot, click YES. When it asks if you would like to Reboot now, click YES. If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

      Your system will reboot now.


      Please post a new rkfiles log and a new hijackthis log.
    • edited June 2005
      Trying to follow you instructions exactly, but there's a problem...

      C:\WINDOWS\system32\mpujepb.exe will not copy. What should I do??
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited June 2005
      All you need to do is copy the text C:\WINDOWS\system32\mpujepb.exe
      Not the file itself.
    • edited June 2005
      Here they are...

      rkfiles log...

      C:\Documents and Settings\Gidget\Desktop

      PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
      Files Found in system Folder............
      C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213

      Files Found in all users startup Folder............
      Files Found in all users windows Folder............
      C:\WINDOWS\tsc.exe: UPX!
      C:\WINDOWS\vsapi32.dll: UPX!t4
      Finished
      bye


      hijackthis log...

      Logfile of HijackThis v1.99.1
      Scan saved at 7:34:11 PM, on 6/27/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
      C:\WINDOWS\system32\kuajuu.exe
      C:\WINDOWS\system32\icfonf.exe
      C:\Program Files\Messenger\MSMSGS.EXE
      c:\windows\system32\sdjeagx.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      C:\HijackThis\HijackThis.exe

      O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
      O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
      O4 - HKLM\..\Run: [tvs_b] C:\program files\tvs\tvs_b.exe
      O4 - HKLM\..\Run: [FlaCPY] "C:\Program Files\Common Files\Java\flacpy.exe"
      O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\system32\PSof1.exe
      O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKLM\..\Run: [o7sk3pQ] icfonf.exe
      O4 - HKLM\..\Run: [fcapyb] c:\windows\system32\sdjeagx.exe r
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited June 2005
      Please make sure that you can VIEW ALL HIDDEN FILES.

      Place a checkmark next to these entries, close all browsers and windows, and have HijackThis fix them by clicking Fix Checked:

      O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
      O4 - HKLM\..\Run: [tvs_b] C:\program files\tvs\tvs_b.exe
      O4 - HKLM\..\Run: [FlaCPY] "C:\Program Files\Common Files\Java\flacpy.exe"
      O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\system32\PSof1.exe
      O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKLM\..\Run: [o7sk3pQ] icfonf.exe
      O4 - HKLM\..\Run: [fcapyb] c:\windows\system32\sdjeagx.exe r


      Reboot your computer into SAFE MODE

      Then delete these files or directories (Do not be concerned if they do not exist):


      C:\program files\tvs
      C:\Program Files\Common Files\Java\flacpy.exe
      C:\WINDOWS\cfgmgr52.dll
      C:\WINDOWS\system32\PSof1.exe
      C:\WINDOWS\system32\kuajuu.exe
      C:\WINDOWS\system32\icfonf.exe
      c:\windows\system32\sdjeagx.exe
      C:\WINDOWS\system32\n20050308.EXE



      ===============================


      Please download, install, update and scan your system with the free version of Ewido trojan scanner:
      1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
      2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
      3. From the main ewido screen, click on update in the left menu, then click the Start update button.
      4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack....
      5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
      6. When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread, along with a new HijackThis log.
    • edited June 2005
      After seeing what this report had to say, I think my pc is way worse than I thought! :bawling: Is there hope for it to ever be clean??


      ewido security suite - Scan report

      + Created on: 10:26:20 PM, 6/28/2005
      + Report-Checksum: 51E2E69

      + Date of database: 6/29/2005
      + Version of scan engine: v3.0

      + Duration: 31 min
      + Scanned Files: 95429
      + Speed: 50.58 Files/Second
      + Infected files: 90
      + Removed files: 90
      + Files put in quarantine: 90
      + Files that could not be opened: 0
      + Files that could not be cleaned: 0

      + Binder: Yes
      + Crypter: Yes
      + Archives: Yes

      + Scanned items:
      C:\
      D:\
      E:\

      + Scan result:
      C:\WINDOWS\system32\ofe2.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\iswphbk.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\sucur32.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p -> Cleaned with backup
      C:\WINDOWS\system32\elcdec.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\sacsccp.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\redit.cpl -> TrojanDownloader.Qoologic.p -> Cleaned with backup
      C:\WINDOWS\system32\nsa79.dll -> Spyware.HotSearchBar -> Cleaned with backup
      C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\k0js0a17ed.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg -> Cleaned with backup
      C:\WINDOWS\system32\ennql1551.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system32\iM49.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
      C:\WINDOWS\system32\p66slgj716o.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\WINDOWS\system\UpdInst.exe -> Spyware.Look2Me.ab -> Cleaned with backup
      C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SDUVCTEF\pcs_0026[1].exe -> Spyware.Pacer.b -> Cleaned with backup
      C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UFKPMBI5\stubinstaller4292[1].exe -> TrojanDownloader.Small.asf -> Cleaned with backup
      C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UFKPMBI5\bundle_mediamotor1004[1].exe -> Spyware.Sahat.m -> Cleaned with backup
      C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\U5M5UDUP\TDKT2891[1].exe -> TrojanDropper.Small.qn -> Cleaned with backup
      C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\U5M5UDUP\thin-143-1-x-x[1].exe -> Spyware.BetterInternet -> Cleaned with backup
      C:\WINDOWS\Temp\Cookies\gidget@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\WINDOWS\Temp\Cookies\gidget@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\WINDOWS\Temp\Cookies\gidget@adopt.hotbar[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\WINDOWS\Temp\Cookies\gidget@S154275[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\WINDOWS\Temp\Cookies\gidget@www.eadexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\WINDOWS\Temp\bw2.com -> TrojanDropper.Agent.kd -> Cleaned with backup
      C:\WINDOWS\Temp\!update.exe -> Spyware.PurityScan -> Cleaned with backup
      C:\WINDOWS\Temp\installer_MARKETING49 -> TrojanDownloader.Adload.a -> Cleaned with backup
      C:\WINDOWS\Temp\res4C.tmp -> Spyware.180Solutions -> Cleaned with backup
      C:\WINDOWS\Temp\bundle_mediamotor1004.exe -> Spyware.Sahat.m -> Cleaned with backup
      C:\WINDOWS\Downloaded Program Files\pcs_0026.exe -> Spyware.Pacer.b -> Cleaned with backup
      C:\WINDOWS\autoload.exe -> Not-A-Virus.Tool.Autoloader -> Cleaned with backup
      C:\WINDOWS\TDKT2891.exe -> TrojanDropper.Small.qn -> Cleaned with backup
      C:\WINDOWS\bundle_mediamotor1004.exe -> Spyware.Sahat.m -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\Temporary Internet Files\Content.IE5\CJ6VAN6T\abiuninst[1].exe -> Spyware.BetterInternet -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\Cookies\gidget@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\Cookies\gidget@search.msn[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\Cookies\gidget@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\Cookies\gidget@www.eadexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\Cookies\gidget@ads.monster[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\ESEK30OP.dll -> Spyware.Sahat.m -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\uptodater.exe -> Spyware.DelphinMediaViewer -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Small.qn -> Cleaned with backup
      C:\Documents and Settings\Gidget\Local Settings\Temp\MediaAccessInstPack.exe -> Spyware.WinAD -> Cleaned with backup
      C:\Documents and Settings\Gidget\Cookies\gidget@com[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Cookies\gidget@search.msn[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Cookies\gidget@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Cookies\gidget@www.eadexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Cookies\gidget@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Documents and Settings\Gidget\Cookies\gidget@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
      C:\Program Files\Common Files\Java\flaclean.exe -> Spyware.Broadcap.b -> Cleaned with backup
      C:\Program Files\Common Files\Java\flacpy.cfg -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\Program Files\Aprps\CxtPls.dll -> TrojanDownloader.Apropo.ad -> Cleaned with backup
      C:\Program Files\Fla\Fla.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000003.EXE -> TrojanDownloader.Apropo.ac -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000005.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000009.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000015.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000019.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000032.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000036.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000037.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000061.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000065.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000069.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000073.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000107.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000113.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000116.dll -> Spyware.Look2Me -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000126.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000137.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000172.exe -> Spyware.FlashEnhancer.a -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000173.exe -> Spyware.Broadcap.b -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000174.cfg -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000185.exe -> Spyware.Broadcap.a -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000189.exe -> Spyware.Broadcap.b -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP1\A0000191.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP2\A0000232.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP2\A0000267.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP3\A0000311.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP4\A0000340.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP4\A0000355.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP4\A0000389.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP5\A0000428.exe -> TrojanDropper.Agent.hl -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP5\A0000429.exe -> Spyware.AdURL -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP5\A0000434.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP5\A0000482.dll -> Spyware.FlashEnhancer -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP6\A0000497.exe -> Spyware.FlashEnhancer.a -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP6\A0000500.exe -> Spyware.FlashEnhancer.a -> Cleaned with backup
      C:\System Volume Information\_restore{52185A74-DE0C-4048-860E-7D32AB5535D3}\RP6\A0000501.exe -> TrojanDownloader.Apropo.ac -> Cleaned with backup


      ::Report End



      Logfile of HijackThis v1.99.1
      Scan saved at 10:27:42 PM, on 6/28/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\WINDOWS\system32\kuajuu.exe
      C:\Program Files\Messenger\MSMSGS.EXE
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\HijackThis\HijackThis.exe

      O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited June 2005
      Don't get discouraged. Most of those items that Ewido found were nothing to worry about. But you do still have an active infection that is being difficult.

      Download L2mfix from one of these two locations:

      http://www.atribune.org/downloads/l2mfix.exe
      http://www.downloads.subratam.org/l2mfix.exe

      Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

      IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
    • edited June 2005
      Boy, am I glad you're here - I'd be sooooo lost without your help! Thanks again! :) BTW, is there a way of finding out how I got these problems in the first place - so I know what to avoid!!

      Did as you said, here's my log:

      L2MFIX find log 1.03
      These are the registry keys present
      **********************************************************************************
      Winlogon/notify:
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

      **********************************************************************************
      useragent:
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      "{2085DDB2-C91B-4D09-BD5B-72D2003E48E9}"=""

      **********************************************************************************
      Shell Extension key:
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
      "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
      "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
      "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
      "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
      "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
      "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
      "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
      "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
      "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
      "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
      "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
      "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
      "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
      "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
      "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
      "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
      "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
      "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
      "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
      "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
      "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
      "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
      "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
      "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
      "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
      "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
      "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
      "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
      "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
      "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
      "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
      "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
      "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
      "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
      "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
      "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
      "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
      "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
      "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
      "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
      "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
      "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
      "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
      "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
      "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
      "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
      "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
      "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
      "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
      "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
      "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
      "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
      "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
      "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
      "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
      "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
      "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
      "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
      "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
      "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
      "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
      "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
      "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
      "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
      "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
      "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
      "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
      "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
      "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
      "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
      "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
      "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
      "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
      "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
      "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
      "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
      "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
      "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
      "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
      "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
      "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
      "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
      "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
      "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
      "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
      "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
      "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
      "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
      "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
      "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
      "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
      "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
      "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
      "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
      "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
      "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
      "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
      "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
      "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
      "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
      "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
      "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
      "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
      "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
      "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
      "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
      "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
      "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
      "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
      "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
      "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
      "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
      "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
      "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
      "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
      "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
      "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
      "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
      "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
      "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
      "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
      "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
      "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
      "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
      "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
      "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
      "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
      "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
      "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
      "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
      "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
      "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
      "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
      "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
      "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
      "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
      "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
      "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
      "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
      "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
      "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
      "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
      "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
      "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
      "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
      "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
      "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
      "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
      "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
      "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
      "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
      "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
      "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
      "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
      "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
      "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
      "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
      "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
      "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
      "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
      "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
      "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
      "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
      "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
      "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
      "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
      "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
      "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
      "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
      "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
      "{48F45200-91E6-11CE-8A4F-0080C81A28D4}"="TMD Shell Extension"
      "{771A9DA0-731A-11CE-993C-00AA004ADB6C}"="VBPropSheet"
      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
      "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
      "{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
      "{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
      "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
      "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
      "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
      "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"

      **********************************************************************************
      HKEY ROOT CLASSIDS:
      **********************************************************************************
      Files Found are not all bad files:
      Locate .tmp files:
      **********************************************************************************
      Directory Listing of system files:
      Volume in drive C has no label.
      Volume Serial Number is 10BA-F640

      Directory of C:\WINDOWS\System32

      05/31/2005 07:21 PM <DIR> dllcache
      05/31/2005 06:23 PM <DIR> Microsoft
      0 File(s) 0 bytes
      2 Dir(s) 3,597,942,784 bytes free
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited June 2005
      We'll talk about prevention once you are all cleaned up.

      Download rkfiles.zip
      http://skads.org/special/rkfiles.zip
      Unzip the contents to a permanent folder.

      Reboot your computer into Safe Mode


      Doubleclick rkfiles.bat
      It will scan for a while, so please be patient.
      Wait till the DOS window closes and reboot back to normal mode.

      Post the contents of C:\log.txt in your next reply.
    • edited June 2005
      Contents of C:\log.txt...

      C:\Documents and Settings\Gidget\Desktop

      PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
      Files Found in system Folder............
      C:\WINDOWS\system32\locate.com: WAUPX!
      C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213

      Files Found in all users startup Folder............
      Files Found in all users windows Folder............
      C:\WINDOWS\tsc.exe: UPX!
      C:\WINDOWS\vsapi32.dll: UPX!t4
      Finished
      bye
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      Fix this line with Hijackthis.

      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run


      Reboot and post a new hijackthis log.
    • edited July 2005
      Unfortunately, I think kuajuu.exe likes it here. He doesn't want to leave!
      Ran and fixed with Hijackthis, here's my log:

      Logfile of HijackThis v1.99.1
      Scan saved at 9:30:02 AM, on 7/1/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
      C:\Program Files\Messenger\MSMSGS.EXE
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dcak.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\HijackThis\HijackThis.exe

      O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      Please disable Spyware Guard and then fix that line with Hijackthis.
    • edited July 2005
      Did as you said. Here is new log:

      Logfile of HijackThis v1.99.1
      Scan saved at 10:59:55 PM, on 7/1/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
      C:\Program Files\Messenger\MSMSGS.EXE
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dcak.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\HijackThis\HijackThis.exe

      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      It's a stubborn little guy isn't it? :shakehead
      Don't worry. We are getting close to a clean system for you.


      Open Notepad, copy and paste the bold text below and "Save As" fixit.reg
      In the "Save as type" select: All Files and save it to your desktop.

      As a security measure this forum inserts spaces in long strings of text. Make sure you remove the spaces before saving the reg file. It should read CurrentVersion, not Curr entVersion.


      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "KavSvc"=-
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\KavSvc]



      Reboot into Safe mode. Double click on fixit.reg and OK the prompt that comes up. Reboot back to normal mode and post a new hijackthis log.



      I would also like to see a new log from you.

      Please download FindQoologic from here:
      http://forums.net-integration.net/index.php?act=Attach&type=post&id=134981
      Save it to the desktop and run Find-Qoologic2.bat. This will generate a log file; please post the entire contents of the log file here for me to see.



      So please post a new hijackthis log and the log from FindQoologic.
    • edited July 2005
      Not sure if this means anything, but when I ran find-qoologic it kept popping up a 16bit ms-dos subsystem message that would say:

      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\SYSTEM32\AUTOEXEC.NT. The system file is not sutible for running MS-DOS and Microsoft Windows Applications. Choose 'Close' to terminate the application.

      I clicked 'ignore' seveal times before I finally got to this log, and each time I would choose 'ingore' the main window would say: The process cannot access the file because it is being used by another process.

      Here are logs:
      PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
      some examples are MRT.EXE NTDLL.DLL.
      »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


      »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

      (fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

      Global Startup:
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup
      .
      ..
      desktop.ini
      Adobe Gamma Loader.lnk
      dcak.exe

      User Startup:
      C:\Documents and Settings\Gidget\Start Menu\Programs\Startup
      .
      ..
      desktop.ini
      SpywareGuard.lnk

      »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»»

      ! REG.EXE VERSION 3.0

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\gkynkkfs
      <NO NAME> REG_SZ {2436d3d3-7699-48ce-9669-04ec6963d02b}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
      <NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
      <NO NAME> REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
      <NO NAME> REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
      <NO NAME> REG_SZ {B41DB860-8EE4-11D2-9906-E49FADC173CA}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
      <NO NAME> REG_SZ

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
      <NO NAME> REG_SZ Start Menu Pin



      Logfile of HijackThis v1.99.1
      Scan saved at 9:03:55 AM, on 7/2/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
      C:\Program Files\Messenger\MSMSGS.EXE
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dcak.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\HijackThis\HijackThis.exe

      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      One of your security programs is interferring with the fix by hijackthis. The underlying infection appears to be gone.
      Reboot into Safe mode(where nothing is running) and fix this line.

      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run


      Is this file present?

      C:\WINDOWS\system32\kuajuu.exe
    • edited July 2005
      I did a reboot into safe mode, deleted it, it was not present after a rescan in safe mode, but when I switched back to normal mode and did a scan/save log, it was there again.

      I searched my pc for kuajuu.exe and did not find anything under C:\WINDOWS\system32, however, there is a kuajuu.exe-2110F308.pf in the C:\WINDOWS\Prefetch if that means anything????

      New Log:
      Logfile of HijackThis v1.99.1
      Scan saved at 9:17:17 AM, on 7/3/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
      C:\Program Files\Messenger\MSMSGS.EXE
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dcak.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      C:\WINDOWS\System32\svchost.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\HijackThis\HijackThis.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\pcclient.exe

      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
      O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
      O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      Go to C:\Windows\repair and look for a file named autoexec.nt
      Right click on the file and select Copy.
      Now go to C:\Windows\system32 and right click and select Paste.


      Now run FindQoologic again and post the log for me to see.
    • edited July 2005
      It ran MUCH smoother this time, no subsystem messages!! Here's the log:

      PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
      some examples are MRT.EXE NTDLL.DLL.
      »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      * KavSvc C:\WINDOWS\System32\ECKPCCR.DLL
      * KavSvc C:\WINDOWS\System32\RVKWV.DLL
      * aspack C:\WINDOWS\System32\QYUAY.DAT
      * aspack C:\WINDOWS\System32\KUAJUU.EXE
      * aspack C:\WINDOWS\System32\CQANQQB.EXE
      * aspack C:\WINDOWS\System32\MRT.EXE
      * aspack C:\WINDOWS\System32\NTDLL.DLL
      * aspack C:\WINDOWS\System32\ECKPCCR.DLL
      * aspack C:\WINDOWS\System32\RVKWV.DLL
      * aspack C:\WINDOWS\VSAPI32.DLL
      * UPX! C:\WINDOWS\TSC.EXE
      * UPX! C:\WINDOWS\VSAPI32.DLL
      »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      * exe C:\docume~1\alluse~1\startm~1\programs\startup\DCAK.EXE

      »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

      (fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

      Global Startup:
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup
      .
      ..
      desktop.ini
      Adobe Gamma Loader.lnk
      dcak.exe

      User Startup:
      C:\Documents and Settings\Gidget\Start Menu\Programs\Startup
      .
      ..
      desktop.ini
      SpywareGuard.lnk

      »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»»

      ! REG.EXE VERSION 3.0

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\gkynkkfs
      <NO NAME> REG_SZ {2436d3d3-7699-48ce-9669-04ec6963d02b}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
      <NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
      <NO NAME> REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
      <NO NAME> REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
      <NO NAME> REG_SZ {B41DB860-8EE4-11D2-9906-E49FADC173CA}

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
      <NO NAME> REG_SZ

      HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
      <NO NAME> REG_SZ Start Menu Pin
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      Ok, let's see if we can get it all this time.

      Fix this line with hijackthis:

      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run


      Delete temp files

      Navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

      Navigate to the C:\Windows\Prefetch folder. Open the Prefetch folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Prefetch folder.

      Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

      Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

      Empty the Recycle Bin.


      ================



      [*]Highlight the lines below and press the Ctrl key and the C key at the same time to copy them to the clipboard:

        C:\WINDOWS\System32\ECKPCCR.DLL
        C:\WINDOWS\System32\RVKWV.DLL
        C:\WINDOWS\System32\QYUAY.DAT
        C:\WINDOWS\System32\KUAJUU.EXE
        C:\WINDOWS\System32\CQANQQB.EXE
        C:\WINDOWS\System32\ECKPCCR.DLL
        C:\WINDOWS\System32\RVKWV.DLL
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dcak.exe



        [*]Now go to the Killbox application and click on the File menu and then the Paste from Clipboard menu item. In the Full Path of File to Delete box you should see the first file. If you dropdown that box you should see the rest of them. Make sure that they are all there.
        [*]Click on the Delete on Reboot option and then click on the red circle with a white 'X' in to to delete the files. Killbox will tell you that all listed files will be deleted on next reboot, click YES. When it asks if you would like to Reboot now, click YES. If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.
        [/LIST]
        Your system will reboot now.


        Post a new hijackthis log and a new findqoologic log.
      • edited July 2005
        Did as you said...the only problem that I had was when deleting the files in the Start>run type %temp% step, a file called ~DF654D.tmp would not delete. I kept getting a message that said another program or person is using it.
        My Logs:

        Logfile of HijackThis v1.99.1
        Scan saved at 6:17:17 PM, on 7/5/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\ewido\security suite\ewidoctrl.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
        C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
        C:\Program Files\Messenger\MSMSGS.EXE
        C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
        C:\Program Files\SpywareGuard\sgmain.exe
        C:\HijackThis\HijackThis.exe
        C:\WINDOWS\system32\wuauclt.exe

        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
        O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
        O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run :shakehead
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
        O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
        O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
        O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
        O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
        O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe



        PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
        some examples are MRT.EXE NTDLL.DLL.
        »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

        * aspack C:\WINDOWS\System32\MRT.EXE
        * aspack C:\WINDOWS\System32\NTDLL.DLL
        * aspack C:\WINDOWS\VSAPI32.DLL
        * UPX! C:\WINDOWS\TSC.EXE
        * UPX! C:\WINDOWS\VSAPI32.DLL
        »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


        »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

        (fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

        Global Startup:
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup
        .
        ..
        desktop.ini
        Adobe Gamma Loader.lnk
        Microtek Scanner Finder.lnk

        User Startup:
        C:\Documents and Settings\Gidget\Start Menu\Programs\Startup
        .
        ..
        desktop.ini
        SpywareGuard.lnk

        »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»»

        ! REG.EXE VERSION 3.0

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\gkynkkfs
        <NO NAME> REG_SZ {2436d3d3-7699-48ce-9669-04ec6963d02b}

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
        <NO NAME> REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03}

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
        <NO NAME> REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936}

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
        <NO NAME> REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46}

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
        <NO NAME> REG_SZ {B41DB860-8EE4-11D2-9906-E49FADC173CA}

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4}
        <NO NAME> REG_SZ

        HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
        <NO NAME> REG_SZ Start Menu Pin
      • Buckeye_SamBuckeye_Sam Columbus, Ohio
        edited July 2005
        Please uninstall Spyware Guard. I think it is restoring this registry entry. Once it is uninstalled fix this line with hijackthis.

        O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\kuajuu.exe reg_run


        Reboot and post a new hijackthis log.
      • edited July 2005
        OMG, Could it be???? Is Kuajuu.exe finally gone???? :D


        Logfile of HijackThis v1.99.1
        Scan saved at 8:53:48 PM, on 7/6/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\SOUNDMAN.EXE
        C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
        C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
        C:\Program Files\Messenger\MSMSGS.EXE
        C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
        C:\Program Files\ewido\security suite\ewidoctrl.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
        C:\WINDOWS\System32\svchost.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
        C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
        C:\Short-Media\HijackThis\HijackThis.exe

        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
        O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117589296423
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
        O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
        O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
        O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
        O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
      • Buckeye_SamBuckeye_Sam Columbus, Ohio
        edited July 2005
        Your log looks clean to me! :thumbsup:

        You can reinstall Spyware Guard now.
        Are you having any more problems?
      • edited July 2005
        Buckeye Sam - YOU ROCK!! :mullet: I'm not having any problems and I'm sooo glad to hear that I'm clean - Thanks so much!!

        Now, what should I do to STAY clean??? I already have PC-cillin, Ad-Aware SE, & Spybot installed so do I really nead spyware guard too or is what I have enough? How often should these programs be ran?

        Also, do I need to keep the programs and files on my pc that we used to fix it such as ewido, killbox, find-qoologic, l2mfix or should I just delete them?

        I really do appreciate all your time and effort to get this junk off my pc!!! :D:D:D
      • Buckeye_SamBuckeye_Sam Columbus, Ohio
        edited July 2005
        You can just delete killbox, find-qoologic, and l2mfilx. I would keep Ewido as a complement to your antivirus program. It's an excellent program that will catch a lot of spyware that your antivirus will never see.

        Here are more recommendations.

        Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
        1. Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

          You can find instructions on how to enable and reenable system restore here:

          Managing Windows Millenium System Restore

          or

          Windows XP System Restore Guide

          Renable system restore with instructions from tutorial above

        2. Make your Internet Explorer more secure - This can be done by following these simple instructions:
          1. From within Internet Explorer click on the Tools menu and then click on Options.
          2. Click once on the Security tab
          3. Click once on the Internet icon so it becomes highlighted.
          4. Click once on the Custom Level button.
            1. Change the Download signed ActiveX controls to Prompt
            2. Change the Download unsigned ActiveX controls to Disable
            3. Change the Initialize and script ActiveX controls not marked as safe to Disable
            4. Change the Installation of desktop items to Prompt
            5. Change the Launching programs and files in an IFRAME to Prompt
            6. Change the Navigate sub-frames across different domains to Prompt
            7. When all these settings have been made, click on the OK button.
            8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
          5. Next press the Apply button and then the OK to exit the Internet Properties page.

        3. Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

          See this link for a listing of some online & their stand-alone antivirus programs:

          Virus, Spyware, and Malware Protection and Removal Resources

        4. Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

        5. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

          For a tutorial on Firewalls and a listing of some available ones see the link below:

          Understanding and Using Firewalls

        6. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

        7. Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

          A tutorial on installing & using this product can be found here:

          Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

        8. Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

          A tutorial on installing & using this product can be found here:

          Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

        9. Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

          A tutorial on installing & using this product can be found here:

          Using SpywareBlaster to protect your computer from Spyware and Malware

        10. Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
        Follow this list and your potential for being infected again will reduce dramatically.
      • edited July 2005
        Thank You Buckeye Sam!!! You can put a big honkin' green check next to my thread 'cause my problem is solved!! ;D

        I will DEFINITELY recommend this site to others!
      This discussion has been closed.