Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] How do I get rid of these?

[Fixed] Hijackthis! Logs - [Fixed] How do I get rid of these? posted in the Security & Safety forums; Ok , lets get this nasty ******. The .dat file stayed gone now , thats a good start. Start Killbox and place a tick next to [x]delete on reboot. Copy ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #29  
Old 12-23-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Ok , lets get this nasty ******. The .dat file stayed gone now , thats a good start.


Start Killbox and place a tick next to [x]delete on reboot.
Copy this list into the windows clipboard:

C:\WINDOWS\system32\ecesq.dll
C:\WINDOWS\system32\t3odm.dll
C:\WINDOWS\system32\t5rdv.dll


Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.


Copy the contents of Code box below to a notepad file. Save it to Desktop named Fixreg.reg and in the "save as" type box choose "all files".


Code:
REGEDIT4
 
[-HKEY_CLASSES_ROOT\CLSID\{incert csdl here}]
[-HKEY_CLASSES_ROOT\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}] 
[-HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebNexus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9E248641-0E24-4DDB-9A1F-705087832AD6}]
Now double click Fixreg.reg and allow it to add/merge with registry when prompted.

And then please post a new Rkfiles and findqoologic log.
Again , Please Do Not reboot youre pc until I reply back.



And just to check to make sure , i keep leaving one file since im 99.9% sure it is a false positive. Can you upload this file to these sites and report back if they find anything?

C:\WINDOWS\system32\dfrg.msc

http://virusscan.jotti.org/

http://www.virustotal.com/flash/index_en.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #30  
Old 12-23-2005
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default scan reports

Joe please find attached reports Qoologic and Rkfiles.I can not find the dfrg.msc file to upload I can find system 32 but it does not show up as dfrg.msc.
This is what it shows me in respect to anything with dfrg

dfrag
dfrg
dfrgfat
dfrgntfss
dfrgres.dll
dfrgui.dll

log.txt

report.txt


  #31  
Old 12-23-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by cartandpeg
I can not find the dfrg.msc file to upload I can find system 32 but it does not show up as dfrg.msc.
Thats is when you press "browse" on those sites , and navigate to that file?

Can you find it manually on youre pc? And do you use the windows defrag or an separete app? Try this: Paste this in the box next to the "browse" button and press "submit"

C:\WINDOWS\system32\dfrg.msc




Start Killbox and place a tick next to [x]delete on reboot.
Copy this list into the windows clipboard:


C:\WINDOWS\system32\t3odm.dll
C:\WINDOWS\system32\t5rdv.dll


Back in Killbox go > file > paste from clipboard,
(ps ,are you pressing "file"/"paste from clipboard" , or are you pasting it in the "full path of file to delete" box?)


Click the red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.


Copy the contents of Code box below to a notepad file. Save it to Desktop named Fixreg.reg and in the "save as" type box choose "all files".

Code:
REGEDIT4
 
 
[-HKEY_CLASSES_ROOT\CLSID\{incert csdl here}]
[-HKEY_CLASSES_ROOT\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}] 
[-HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebNexus]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9E248641-0E24-4DDB-9A1F-705087832AD6}]
Now double click Fixreg.reg and allow it to add/merge with registry when prompted.

And then please post a new Rkfiles and findqoologic log.
Again , Please Do Not reboot youre pc until I reply back.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 12-23-2005 at 02:43 AM.
  #32  
Old 12-23-2005
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default me again

Joe I ran both the scans as requested and i used the paste method to do the scans....both came back with a report of all ok.That was the sacn for dfrg.msc.

I use windows Defrag only,no other defrag.
When i use killbox I go to file/paste from clipboard/full path to delete.
I have not done the qool or rkfile scan as to yet, will wait to see if i am doing killbox correctly.......Thanks Andy


  #33  
Old 12-23-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by cartandpeg
Joe I ran both the scans as requested and i used the paste method to do the scans....both came back with a report of all ok.That was the sacn for dfrg.msc.
Thats what i expected but i was trying to find the reason why only one entry at a time was removed , but see below for that , lol.

Originally Posted by cartandpeg
When i use killbox I go to file/paste from clipboard/full path to delete.
I think thats why only one file at a time gets removed , after "paste from clipboard" , just press the red X. If you also enter it in the "full path to delete" line , then only the first entry/line gets removed.

But where down to 2 anyway by now , so almost there.:cheesy:


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #34  
Old 12-23-2005
cartandpeg's Avatar
Moderator
 
Join Date: Nov 2005
Location: Victoria,Australia
Posts: 841
cartandpeg - See this Members User comments on their Profile page cartandpeg - See this Members User comments on their Profile page
Default scan results

Joe here r the scan results for qool and rkfiles,when i went to files/paste clipboard in Killbox the files went to delete full path?So i clicked on delete all files box on bottom of Killbox,it looked as though i had single files delete selected b 4?
Hope I got it okay......thanks Joe

log.txt

report.txt


  #35  
Old 12-23-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by cartandpeg
,when i went to files/paste clipboard in Killbox the files went to delete full path?So i clicked on delete all files box on bottom of Killbox,it looked as though i had single files delete selected b 4?
Hmm , lol. That button hasn't always been there..:icon_joke They must have added that to the latest version(s). Sorry about that , my mistake.

All the files are now gone , only the reg entrys came back or are still there.

Ive made a reg file this time and attached it to this post , please download it , unpack it , double click on it and allow it to merge with the registry.

Then please post a new Qoologic log.
Attached Files
File Type: rar Fixreg.rar (342 Bytes, 2 views)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On