Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

winfixer and aurora will not go away


  • Please log in to reply

#16
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Copy the text in the Code Box to a blank notepad page and Save it to your desktop as Rem.reg but dont run it yet!

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
"pifwav"=-

[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\kgynmsqx]

[-HKEY_CLASSES_ROOT\CLSID\{91a5d091-c4a6-418b-8063-cd9ecf6e8f7f}]

Restart in Safe Mode and Run all these entries through Killbox just as you did before!

C:\WINDOWS\Tasks\RUTASK.job
C:\WINDOWS\System32\pifwav.exe
C:\WINDOWS\System32\kdane.dll
C:\WINDOWS\SYSTEM32\md26us0g.ini
C:\WINDOWS\SYSTEM32\phjphudc.ini
C:\WINDOWS\SYSTEM32\bef2n1mb.ini
C:\WINDOWS\vanom.dll
C:\WINDOWS\SYSTEM32\stlb2.xml
C:\DOCUMENTS AND SETTINGS\OWNER.DEN\LOCAL SETTINGS\TEMP\!update.exe
C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.8-2.inf
C:\staff.html
C:\WINDOWS\cfgmgr52.ini
C:\WINDOWS\eZinstall.exe
C:\PROGRAM FILES\AutoUpdate
C:\PROGRAM FILES\Comet
C:\PROGRAM FILES\Lycos
C:\PROGRAM FILES\MedCh
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\AdDestroyer
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\nsv
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\VBouncer
C:\DOCUMENTS AND SETTINGS\ALL USERS.WINDOWS\APPLICATION DATA\vidctrl
C:\PROGRAM FILES\COMMON FILES\FreeProdFetch
C:\WINDOWS\SYSTEM32\cache32dsrf4535dfs
C:\WINDOWS\SYSTEM32\FLEOK
C:\Documents and Settings\Owner.DEN\Local Settings\Temp\Temporary Internet Files\Content.IE5\0D2Z0TYB\!update-2454[1].0000
C:\Documents and Settings\Owner.DEN\Local Settings\Temporary Internet Files\Content.IE5\ABEX4XCH\!update-2444[1].0000
Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Owner.DEN\Local Settings\Temporary Internet Files\Content.IE5\ABEX4XCH\!update-2495[1].0000
C:\Documents and Settings\Owner.DEN\Start Menu\Programs\TopText iLookup\My Keywords.lnk
C:\Documents and Settings\Owner.DEN\Start Menu\Programs\TopText iLookup\My Preferences.lnk
C:\Documents and Settings\Owner.DEN\Start Menu\Programs\TopText iLookup\TopText Button Show - Hide.lnk
C:\Documents and Settings\Owner.DEN\Start Menu\Programs\TopText iLookup
C:\k.html
C:\Program Files\Comet\Data\csres.dat
C:\Program Files\Comet\Data
C:\Program Files\Comet


Once all are deleted,locate and double click Rem.reg-> Allow it to merge into the registry!

Now we need to deal with this entry

C:\WINDOWS\System32\F?nts\dexplore.exe

Look and See how many folders you have that are named "Fonts"

If more than one,look inside each and find the one with "dexplore.exe"

Thats the one that needs to go!

If you want to be Safe,Move the folder you suspect is bad to the C drive and let it be for now!

Restart Normal,assure no errors were found at bootup and then have the PC Scanned here
http://support.f-sec.../home/ols.shtml

Save the Report and post it along with a fresh HijackThis log!
  • 0

Advertisements


#17
ginger3

ginger3

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
O.K. the http://support.f-sec.../home/ols.shtml worked up to 88% three times then froze here is the hijack file. If you think this is hopeless please let me know, the kids are getting restless.

Logfile of HijackThis v1.99.1
Scan saved at 6:31:29 PM, on 8/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Owner.DEN\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsear...US_ZNxdm006YYUS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...rl/SymAData.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#18
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
We have to find this folder!

C:\WINDOWS\System32\F?nts

Look and See how many folders you have that are named "Fonts"

How is the PC running now?

Edited by Cretemonster, 19 August 2005 - 05:50 PM.

  • 0

#19
ginger3

ginger3

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
I forgot to mention that I couldn't find C:\WINDOWS\System32\F?nts
the PC does seem to be running better
  • 0

#20
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Copy everything inside the quote box below (starting with dir) and paste it into notepad. Go up to "File > Save As" and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.

dir C:\WINDOWS\system32\F?nts /a h > files.txt
notepad files.txt


Locate findfile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the contents of that Notepad back here!
  • 0

#21
ginger3

ginger3

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
here it is

Volume in drive C has no label.
Volume Serial Number is 30E9-F6F7

Directory of C:\WINDOWS\system32

08/13/2005 01:56 PM <DIR> F?nts
0 File(s) 0 bytes

Directory of C:\Documents and Settings\Owner.DEN\Desktop
  • 0

#22
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,go into Safe Mode and be sure Windows is Showing Hidden Files
http://www.bleepingc...torial=62#winxp

Now look in the System32 folder for a folder labeled similar or just like

F?nts

Open the Search Assistant(Click Start>>Click Search)
Select All Files and Folders,
Select Advanced Options,
Make sure there is a check by every box under Advanced Options

Now under All Files and Folders,enter this into the text box:

F?nts

Delete any Exact Matches!

Install these 2 for some added security

SpywareBlaster:
http://www.javacools...areblaster.html
Update Immediatly!


WinHelp2002 Hosts File
http://www.mvps.org/...p2002/hosts.htm

Made Easy
http://www.mvps.org/...2002/hosts2.htm

Disable System Restore
http://service1.syma...src=sec_doc_nam

Post back and let me know if you found the folder and if the PC is still running OK!

I think its Safe for all Kids to enjoy the Home Computer now! :tazz:

Is Norton paid for and up to date?

Is there a firewall running on the PC other than Windows Firewall?
  • 0

#23
ginger3

ginger3

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Yes I did find the folder and the PC does seem better. Thanks for all the help.
  • 0

#24
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Good deal,go ahead and Renable System Restore!

Read through those 3 little black links in my signature for some good ideas on how to avoid this in the future!

Also have a look at Metallicas Spyware Page
http://metallica.geekstogo.com/

If you have anymore questions,feel free to ask!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP