Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Exe and INK registry goes missing

[Fixed] Hijackthis! Logs - [Resolved] Exe and INK registry goes missing posted in the Security & Safety forums; Ok here is the shorthand. My EXE and INK registry goes missing and i have to keep repacing it, and I cant see the contents of my System 32 folder ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 04-24-2006
Bronze Member
My PC
 
Join Date: Apr 2006
Posts: 15
nessn12 - See this Members User comments on their Profile page
Default [Resolved] Exe and INK registry goes missing

Ok here is the shorthand. My EXE and INK registry goes missing and i have to keep repacing it, and I cant see the contents of my System 32 folder at all

here is my Log


if yo uguys could help that would be appreciated, i came here as my last resort before re-installing windows
Attached Files
File Type: txt hjtlog.txt (11.0 KB, 2 views)



Last edited by joe5; 04-24-2006 at 01:58 AM.
  #2  
Old 04-24-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Nessn12 , welcome to pchf.

You have a hole bunch of infections on there , but dont worry , we can clean that up. No need to format.

First please do a Panda active scan here:

http://www.pandasoftware.com/products/activescan

and save the log from it.

Then follow the instructions in the "Prework" link below in my sig and post back the 2 resulting log files from that plus the Panda scan log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 04-25-2006
Bronze Member
My PC
 
Join Date: Apr 2006
Posts: 15
nessn12 - See this Members User comments on their Profile page
Default

sorry i had a family emergency.

i am doing the activescan now

Spysweeper kept shutting down when i tried to scan in safe mode
Attached Files
File Type: txt Activescan.txt (8.6 KB, 1 views)
File Type: txt Scan report_20060424.txt.txt (31.6 KB, 2 views)



Last edited by nessn12; 04-25-2006 at 02:35 AM.
  #4  
Old 04-25-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by nessn12
sorry i had a family emergency.
Sorry to hear that , i hope it isn't to serious.


But you can run Ewido again and let it fix all it finds this time , and after that please run hjt again and post a new hjt log plus the new Ewido log.


PS , no need to run Spysweeper , that is only an optional extra scan option , or for people who cant run Ewido.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 04-25-2006 at 03:32 PM.
  #5  
Old 04-26-2006
Bronze Member
My PC
 
Join Date: Apr 2006
Posts: 15
nessn12 - See this Members User comments on their Profile page
Default

here ya go but now i am getting this unicode or wingdings stuff when I login and/or logout/start windows
Attached Files
File Type: txt Scan report_20060425.txt.txt (34.4 KB, 1 views)
File Type: log hijackthis.log (11.3 KB, 1 views)



Last edited by nessn12; 04-26-2006 at 02:10 AM.
  #6  
Old 04-26-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Nessn12.


Ewido did a great job and removed lots , but the Panda scan proved to be quite useless this time. It didn't find anything really , im abit suprised about that.


O well , we'll get it clean anyway.


First uninstall these in add/remove programs if present:

QuickSearch Search Bar
MySearch
WildTangent
MyWebSearch
MyWebSearch Email Plugin



Then boot in safemode and fix these entrys with hijackthis:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=w...D/YOx16Q+SeWch vZea9ZweIyWoh7r9pTss0AIFl7akl+Yi8Njb2fNIvC7SOpwSzC 3OtXCwLicbLo2qXQXx5swLFmsApBg3 Q0r+qUYHlMfrU+5LOp+04yAOpRxzwT6p4S7ypMY2Sqm7/KUpca3CwhLbACgeFz5DUR14JANcblJGkE=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll (file missing)
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL (file missing)
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [hostdll.exe] C:\WINDOWS\hostdll.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
O4 - HKLM\..\RunOnce: [SVCHOST] C:\WINDOWS\SPOOLSV.EXE Load
O4 - HKCU\..\Run: [Notn] "C:\DOCUME~1\baldy\MYDOCU~1\RACLE~1\wuauboot.exe" -vt yax
O4 - HKCU\..\Run: [Crnprr] C:\Program Files\Common Files\?icrosoft\m?hta.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZB
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/We.../bridge-c9.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...consFWBInitial Setup1.0.0.8-2.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/inst...l/pinstall.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgUS2404.exe
And then manually delete all the files/folders marked in bold.


After that i would also disable the Windows Messenger service:

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state — running or disabled — that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.

Originally Posted by Nessn12
now i am getting this unicode or wingdings stuff when I login
Wingdings is a font afaik , but have a look how it goes after all the malware is gone. If it is still there then please describe a little better what happens and what errors you get.


When done please post a new hjt log to check.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 04-26-2006 at 02:32 AM.
  #7  
Old 04-26-2006
Bronze Member
My PC
 
Join Date: Apr 2006
Posts: 15
nessn12 - See this Members User comments on their Profile page
Default

here ya go sir.
Attached Files
File Type: log hijackthis.log (10.0 KB, 1 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 12:01 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top