Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

My hijackthis log done just 10 mins ago plz help


  • Please log in to reply

#46
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
You sure you uploaded the file to that site? I dont see it.
  • 0

Advertisements


#47
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
They are there now:

cnml.exe - infected by not-a-virus:AdWare.CommonName.l

Profile.dat has this inside:

.H...\.P.r.o.g.r.a.m. .F.i.l.e.s.\.u.s.q.w.s.p.t.x.\.G.M.g.C.A.4.B.N...d.l.l...
H...\.P.r.o.g.r.a.m. .F.i.l.e.s.\.u.s.q.w.s.p.t.x.\.G.M.g.C.A.4.B.N...e.x.e...
H...\.P.r.o.g.r.a.m. .F.i.l.e.s.\.u.s.q.w.s.p.t.x.\.N.B.4.A.C.g.M.G...e.x.e...
@...\.P.r.o.g.r.a.m. .F.i.l.e.s.\.u.s.q.w.s.p.t.x.\.c.n.m.l...e.x.e..
.F...\.P.r.o.g.r.a.m. .F.i.l.e.s.\.u.s.q.w.s.p.t.x.\.p.r.o.f.i.l.e...d.a.t..
.F...\.W.I.N.D.O.W.S.\.s.y.s.t.e.m.3.2.\.d.r.i.v.e.r.s.\.W.i.n.I.K...s.y.s.......
\.R.E.G.I.S.T.R.Y.\.M.A.C.H.I.N.E.\.S.O.F.T.W.A.R.E.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.C.u.r.r.e.n.t.V.e.r.s.i.o.n.\.R.u.n.\.Q.Y.V.H.Y.k.E.x...r...
\.R.E.G.I.S.T.R.Y.\.M.A.C.H.I.N.E.\.S.y.s.t.e.m.\.C.u.r.r.e.n.t.C.o.n.t.r.o.l.S.e.t.\.S.e.r.v.i.c.e.s.\.w.i.n.i.k...j...
\.R.E.G.I.S.T.R.Y.\.M.A.C.H.I.N.E.\.S.y.s.t.e.m.\.C.o.n.t.r.o.l.S.e.t.0.0.1.\.S.e.r.v.i.c.e.s.\.w.i.n.i.k.

I think therock247uk will know what to do now. :tazz:

Regards,
  • 0

#48
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
1. Make sure your PC is set to show all hidden files and folders go here for instructions on how to do this. http://www.xtra.co.n...1916458,00.html

2. Go into safemode by tapping F8 while your PC starts up you will get a menu select safemode.

3. Then open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.

O4 - HKLM\..\Run: [QYVHYkEx] C:\PROGRA~1\usqwsptx\GMgCA4BN.exe

4. Delete the files.

C:\Program Files\usqwsptx\GMgCA4BN.dll
C:\Program Files\usqwsptx\GMgCA4BN.exe
C:\Program Files\usqwsptx\NB4ACgMG.exe
C:\Program Files\usqwsptx\cnml.exe
C:\Program Files\usqwsptx\profile.dat
C:\WINDOWS\system32\drivers\WinIK.sys

5. Delete the folders.

C:\Program Files\usqwsptx

6. Open Notepad and copy and paste the following.

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winik.j]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winik]

Save the file as all types name it fix.reg save it to the dekstop and run it it will ask to merge into the registery say yes.

7. Reboot then post a new Hijackthis log here in a reply.
  • 0

#49
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
rocky I cant run hijackthis in safemode
  • 0

#50
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
Ok do the other steps.
  • 0

#51
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
I could not delte the folders or winik I dunno why it said the "write protected " error and I red/l hijackthis for tha safe mode and it worked

Edited by thakid, 14 May 2005 - 01:23 PM.

  • 0

#52
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
1. Click here to download Pocket Killbox by Option^Explicit.

2. Double-click on Killbox.exe to run it. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each. Keep track of any files it tells you either could not be found or could not be deleted, as you'll need those later:

C:\Program Files\usqwsptx\GMgCA4BN.dll
C:\Program Files\usqwsptx\GMgCA4BN.exe
C:\Program Files\usqwsptx\NB4ACgMG.exe
C:\Program Files\usqwsptx\cnml.exe
C:\Program Files\usqwsptx\profile.dat
C:\WINDOWS\system32\drivers\WinIK.sys

For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.

3. Delete the folders.

C:\Program Files\usqwsptx

4. Then open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.

O4 - HKLM\..\Run: [QYVHYkEx] C:\PROGRA~1\usqwsptx\GMgCA4BN.exe

5. Open Notepad and copy and paste the following.

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winik.j]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winik]

Save the file as all types name it fix.reg save it to the dekstop and run it it will ask to merge into the registery say yes.

6. Then post a new Hijackthis log here in a reply.
  • 0

#53
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
I cant install killbox to work cause of the exe problom
  • 0

#54
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
Can you tell me what it exactly does when you try and run it.
  • 0

#55
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
it tells me to pick a program to run it and I select it self and it does not work :tazz: ;) ;) :)
  • 0

Advertisements


#56
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Download, save and doubleclick:
http://www.kellys-ko...dits/exefix.reg

Confirm you want to merge it with the registry when prompted.

Then try running Killbox again.

Regards,
  • 0

#57
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
ok a big big big big plus my exe files are 100% fixed only problom lest is winik and the common name thingh the "q" file stuff and musicnet for aol is not working but I think a simple reinstall will work that out and I got rid of tha qs file

Edited by thakid, 15 May 2005 - 03:44 AM.

  • 0

#58
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
Logfile of HijackThis v1.99.1
Scan saved at 6:02:15 AM, on 5/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SpamKiller\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee\SpamKiller\MSKAgent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\jerimie piccola\Desktop\HijackThis.exe
C:\Program Files\America Online 9.0c\waol.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\America Online 9.0c\shellmon.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOL Spyware Protection] C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\regmech.exe /S
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SpamKiller\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SpamKiller\MSKDetct.exe /startup
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0c\AOL.EXE" -b
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\jerimie piccola\Desktop\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SpamKiller\MSKAgent.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\Messenger\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\Messenger\YPager.exe
O12 - Plugin for .wmv: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comne...login-devel.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...484/mcfscan.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SpamKiller\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
  • 0

#59
thakid

thakid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 132 posts
ok I did not do step 5 or 6 cause I dont know if I gotta do it and my musicnet for aol wont work right:( and I dont know if I should go get ad-aware and my spyware doctor or what ??

Edited by thakid, 15 May 2005 - 04:35 AM.

  • 0

#60
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
You should do step 5.

AdAware and SpywareDoctor can be combined.

Did you already try to reinstall Musicnet for AOL?

Regards,
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP