Unsolved
This post is more than 5 years old
5 Posts
0
17899
December 2nd, 2004 16:00
Help with Registry Run
I need to find out which of the following items I can delete.
(default)
- Aida
- h0sFRgc2T
- MoneyAgent
- sdkkti
- (default)
- AOL SpywarePro
- conscorr
- DwlClient
- McAgentExe
- McUpdateExe
- MM Tray
- QuickTime Task
- TBPS
- VirusScan Online
- ASOCheckTask
- WhenUSave
- WinTools
- zkdyzusgdmy
When I do delete the items do I just hightlight and delete. I am lost when it comes to this computer stuff. If you have any advice I would appericate it. Please help.
No Events found!


jwatt
4.4K Posts
0
December 3rd, 2004 18:00
Oops...I thought one of Santa's other helpers was working on the video card. Here you are!
Mike definitely deserves everyone's thanks for the good work he's doing.
Jim
Midnight Star
4.8K Posts
0
December 3rd, 2004 18:00
Thanks Jim.
Mike.
zbestwun2001
4 Apprentice
•
8.8K Posts
0
December 3rd, 2004 18:00
Words fail me at the moment.
I am overwhelmed buy the LOVE.
There is a Santa Claus !!!!
Thanks Jim
Message Edited by zbestwun2001 on 12-03-2004 02:55 PM
jwatt
4.4K Posts
0
December 3rd, 2004 18:00
Jim
Linda Sue
46 Posts
0
December 3rd, 2004 19:00
If it does not fix the variant that you have, removal can be a little tricky or WinTools will return.
Do it this way:
Linlay
32 Posts
0
December 3rd, 2004 19:00
You seem to have everything under control, so I shall let you finish those threads which I have participated in.
zbestwun2001
4 Apprentice
•
8.8K Posts
0
December 3rd, 2004 20:00
I really don't think that Linlay means no harm, and is not worth leaving this forum over.
Just relax and take some deep breaths and all will be well.
I am sure he meant no harm. Some people just have a problem coming off the way they mean.
Just cut him some slack.
This is a good community and very informative.
Heak,
Not only have these guys helped me fix my computer but they are in tight with Santa Claus, and they got Santa to get me some RAM and a new Video Card.
Mike's got the real good connection with him. I believe they are cousins once removed.
So stick around, it's Christmas time and Mike's the guy to get in tight with!!!!
Message Edited by zbestwun2001 on 12-03-2004 02:51 PM
Midnight Star
4.8K Posts
0
December 6th, 2004 15:00
Amanda,
Have you resolved all the issues with your system?
Mike.
helpbailey
5 Posts
0
December 9th, 2004 15:00
Sorry this toook so long to do. I still cannot get the scan at housecall or panda to work. Everytime is says server not responsding. Here is my new list. Does it look like we made any progress. Thank you so much again for your help.
Logfile of HijackThis v1.98.2
Scan saved at 12:27:38 PM, on 12/9/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.cannotfind.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {60FC3307-E442-5CCF-8255-65550CF72F4E} - C:\WINDOWS\System32\eohiyve.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{259A12D7-278D-44FC-96E1-F45684034744}: NameServer = 205.188.146.146
O17 - HKLM\System\CS1\Services\Tcpip\..\{259A12D7-278D-44FC-96E1-F45684034744}: NameServer = 205.188.146.146
O18 - Filter: text/plain - {943E37F9-B16B-4594-823D-261D4A7B66F9} - (no file)
Midnight Star
4.8K Posts
0
December 9th, 2004 15:00
Amanda,
You've made excellent progress! Good work!
-----
Reboot your computer into "Safe Mode".
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.cannotfind.net/
(If you didn't set this, have hjt 'fix' it.)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
C:\WINDOWS\System32\eohiyve.dll
Run "Disk Cleanup" and have it remove all that it finds.
Now for the cleanup...
Run AdAware SE Personal and Spybot S&D to remove any residual registry entry(s) that we're left by the infection.
Disable, then re-enable system restore (to 'flush' your current restore points), then immediately create one manually.
Post back if your having any more problems.
Happy surfing,
Mike.
Message Edited by Midnight Star on 12-09-2004 11:57 AM
helpbailey
5 Posts
0
December 10th, 2004 18:00
To everyone that helped me, I just wanted you all to know it was very helpful and infomative. I feel I have a better understanding now. However, is there anything I can do to prevent this happening in the future, as in viruses invading my computer. Here is also my new log and I hope all seems well now. I can't thank you all enough and only hope I did not cause too much problems.
Logfile of HijackThis v1.98.2
Scan saved at 3:41:40 PM, on 12/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
Midnight Star
4.8K Posts
0
December 10th, 2004 20:00
Amanda,
Posters who require help never cause a problem (unless of course they're looking to do so ... :( ), but in this case there was a difference of opinion, which does exists in what we're doing; it shouldn't, but does. That's why responders generally don't post in each others logs.
The reason i'd posted the add/remove entry(s) as a first step, was to address your question and work the problem from your angle, that way both the responder and victim learn at the same time. It would take alot longer than having someone download an entire batch of fix-it programs and tossing them at the 'infection' and then have the victim just say ... Wow! - but better in the long run.
Your system looks resolved and should be in good shape. :smileyvery-happy:
Can you tell me about when you came across this problem? Maybe that can help us to understand where it came from?
Mike.
Edits: happy face to sad...
Message Edited by Midnight Star on 12-10-2004 04:12 PM
helpbailey
5 Posts
0
December 13th, 2004 15:00
Midnight Star
4.8K Posts
0
December 14th, 2004 13:00
Amanda,
Everyone has to be careful where they surf. Some sites are setup and run by those who either know, or hires someone who knows, how to exploit visitors to their websites. Their webpages, and links are so designed to 'infect' the target system the moment the webpage loads on the victim's computer via an ActiveX or Java script.
Also, be careful what you download. Always treat everything as a possible threat.
Remember, there's no amount of 'anti-anything' will be able to catch every possible 'problem' from reaching your computer; you are the best resource your pc has.