Unsolved

This post is more than 5 years old

5 Posts

17899

December 2nd, 2004 16:00

Help with Registry Run

I need to find out which of the following items I can delete.
(default)                            
  • Aida       
  • h0sFRgc2T
  • MoneyAgent
  • sdkkti
  • (default)
  • AOL SpywarePro
  • conscorr
  • DwlClient
  • McAgentExe
  • McUpdateExe
  • MM Tray
  • QuickTime Task
  • TBPS
  • VirusScan Online
  • ASOCheckTask
  • WhenUSave
  • WinTools
  • zkdyzusgdmy

 

When I do delete the items do I just  hightlight and delete.  I am lost when it comes to this computer stuff. If you have any advice I would appericate it.  Please help.

4.4K Posts

December 3rd, 2004 18:00

zbestwun2001,

Oops...I thought one of Santa's other helpers was working on the video card. Here you are!

Mike definitely deserves everyone's thanks for the good work he's doing.

Jim

4.8K Posts

December 3rd, 2004 18:00

Thanks Jim.

Mike.

 

4 Apprentice

 • 

8.8K Posts

December 3rd, 2004 18:00

Jim,
Words fail me at the moment.
I am overwhelmed buy the LOVE.

There is a Santa Claus !!!!

Thanks Jim

Message Edited by zbestwun2001 on 12-03-2004 02:55 PM

4.4K Posts

December 3rd, 2004 18:00


 

Coundn't find one with Jolt... :smileywink:


Jim

46 Posts

December 3rd, 2004 19:00

ChrisM,
 
quote in more than one post:
Ad-aware targets some versions of WinTools, so try the scans I suggested first.
If it does not fix the variant that you have, removal can be a little tricky or WinTools will return.
Do it this way:
 
Sorry but that is a sign he thinks he better than the rest of the guys, condescension. Mike does not deserve that, if you do not see it that is too bad, there is a way to provide help without stepping on the others, who`s say his way had to be first. My support was for Mike and I am done here.
 
Linda Sue

32 Posts

December 3rd, 2004 19:00

Apparently I misinterpreted a few things. I am so sorry. I was only trying to help because some people who come to other forums that I work on have been saying that they were sent there by the Dell forums. We thought you needed help. As you experienced people know, when it comes to fixing malware, there is a certain sequence that must be followed to be effective in a timely manner.
You seem to have everything under control, so I shall let you finish those threads which I have participated in.

4 Apprentice

 • 

8.8K Posts

December 3rd, 2004 20:00

Linda Sue,
I really don't think that Linlay means no harm, and is not worth leaving this forum over.
Just relax and take some deep breaths and all will be well.
I am sure he meant no harm. Some people just have a problem coming off the way they mean.
Just cut him some slack.
This is a good community and very informative.

Heak,
Not only have these guys helped me fix my computer but they are in tight with Santa Claus, and they got Santa to get me some RAM and a new Video Card.

Mike's got the real good connection with him. I believe they are cousins once removed.

So stick around, it's Christmas time and Mike's the guy to get in tight with!!!!

Message Edited by zbestwun2001 on 12-03-2004 02:51 PM

4.8K Posts

December 6th, 2004 15:00

Amanda,

Have you resolved all the issues with your system?

Mike.

 

5 Posts

December 9th, 2004 15:00

Sorry this toook so long to do.  I still cannot get the scan at housecall or panda to work.  Everytime is says server not responsding.  Here is my new list.  Does it look like we made any progress.  Thank you so much again for your help.

 

Logfile of HijackThis v1.98.2
Scan saved at 12:27:38 PM, on 12/9/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.cannotfind.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {60FC3307-E442-5CCF-8255-65550CF72F4E} - C:\WINDOWS\System32\eohiyve.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{259A12D7-278D-44FC-96E1-F45684034744}: NameServer = 205.188.146.146
O17 - HKLM\System\CS1\Services\Tcpip\..\{259A12D7-278D-44FC-96E1-F45684034744}: NameServer = 205.188.146.146
O18 - Filter: text/plain - {943E37F9-B16B-4594-823D-261D4A7B66F9} - (no file)

 

4.8K Posts

December 9th, 2004 15:00

Amanda,

You've made excellent progress! Good work!

-----

Reboot your computer into "Safe Mode".


 
Run HiJackThis and click " Scan", then check(tick) the following:
 
 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.cannotfind.net/
(If you didn't set this, have hjt 'fix' it.)
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
 
O2 - BHO: (no name) - {60FC3307-E442-5CCF-8255-65550CF72F4E} - C:\WINDOWS\System32\eohiyve.dll
 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
 
O18 - Filter: text/plain - {943E37F9-B16B-4594-823D-261D4A7B66F9} - (no file)
 
 
Now with all windows closed except HiJackThis, click " Fix checked".
 

Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

C:\WINDOWS\System32\eohiyve.dll

Run "Disk Cleanup" and have it remove all that it finds.


Now for the cleanup...

Run AdAware SE Personal and Spybot S&D to remove any residual registry entry(s) that we're left by the infection.

Disable, then re-enable system restore (to 'flush' your current restore points), then immediately create one manually.


Post back if your having any more problems.

Happy surfing,

Mike.

 

Message Edited by Midnight Star on 12-09-2004 11:57 AM

5 Posts

December 10th, 2004 18:00

To everyone that helped me, I just wanted you all to know it was very helpful and infomative.  I feel I have a better understanding now.  However, is there anything I can do to prevent this happening in the future, as in viruses invading my computer.  Here is also my new log and I hope all seems well now.  I can't thank you all enough and only hope I did not cause too much problems.

Logfile of HijackThis v1.98.2
Scan saved at 3:41:40 PM, on 12/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

 

4.8K Posts

December 10th, 2004 20:00

    Amanda,

    Posters who require help never cause a problem (unless of course they're looking to do so ... :( ), but in this case there was a difference of opinion, which does exists in what we're doing; it shouldn't, but does. That's why responders generally don't post in each others logs.

    The reason i'd posted the add/remove entry(s) as a first step, was to address your question and work the problem from your angle, that way both the responder and victim learn at the same time. It would take alot longer than having someone download an entire batch of fix-it programs and tossing them at the 'infection' and then have the victim just say ... Wow! - but better in the long run.

    Your system looks resolved and should be in good shape.  :smileyvery-happy:

    Can you tell me about when you came across this problem? Maybe that can help us to understand where it came from?

    Mike.

Edits: happy face to sad...

Message Edited by Midnight Star on 12-10-2004 04:12 PM

5 Posts

December 13th, 2004 15:00

The problem with my computer started pretty much the first week we recieved the Dell computer.  I have no idea what cause the problem.  I do know my husband does go on many sports and trivia sites all the time.  I am not sure if this would cause a virus to appear.  Do you have any advice to try to stay away from this happening in the future.  thank you so much again.

4.8K Posts

December 14th, 2004 13:00

Amanda,

Everyone has to be careful where they surf. Some sites are setup and run by those who either know, or hires someone who knows, how to exploit visitors to their websites. Their webpages, and links are so designed to 'infect' the target system the moment the webpage loads on the victim's computer via an ActiveX or Java script.

Also, be careful what you download. Always treat everything as a possible threat.

Remember, there's no amount of 'anti-anything' will be able to catch every possible 'problem' from reaching your computer; you are the best resource your pc has.

Mike.
 
No Events found!

Top