Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection

Reply
 
LinkBack Thread Tools Display Modes
Old 12-24-2007, 10:33 AM   #1 (permalink)
Junior Techie
 
Join Date: Jun 2005
Posts: 94
Send a message via Yahoo to Thaqalain
Default Will I fix these O4; O16; O23 lines or .exe files?

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pjfk] C:\WINDOWS\System32\pjfk.exe
O4 - HKLM\..\Run: [kzujwlhidxn] C:\WINDOWS\System32\kzujwlhidxn.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/noc...1.0.0.15-3.cab

O23 - Service: Print Spooler Service (moaja2a8rou5p) - Unknown owner - C:\WINDOWS\System32\kzujwlhidxn.exe
Thaqalain is offline   Reply With Quote
Old 12-24-2007, 10:40 AM   #2 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,712
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

post the whole log
Osiris is offline   Reply With Quote
Old 12-24-2007, 11:10 AM   #3 (permalink)
Junior Techie
 
Join Date: Jun 2005
Posts: 94
Send a message via Yahoo to Thaqalain
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:53 PM, on 12/24/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\kzujwlhidxn.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo! Canada
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [pjfk] C:\WINDOWS\System32\pjfk.exe
O4 - HKLM\..\Run: [kzujwlhidxn] C:\WINDOWS\System32\kzujwlhidxn.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - Add to Windows Live Favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?76d22582b8d043fb862144efa429840f
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?76d22582b8d043fb862144efa429840f
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Print Spooler Service (moaja2a8rou5p) - Unknown owner - C:\WINDOWS\System32\kzujwlhidxn.exe

--
End of file - 4386 bytes
Thaqalain is offline   Reply With Quote
Old 12-24-2007, 12:04 PM   #4 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,712
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

Remove these

C:\WINDOWS\System32\kzujwlhidxn.exe

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [pjfk] C:\WINDOWS\System32\pjfk.exe

O4 - HKLM\..\Run: [kzujwlhidxn] C:\WINDOWS\System32\kzujwlhidxn.exe

O23 - Service: Print Spooler Service (moaja2a8rou5p) - Unknown owner - C:\WINDOWS\System32\kzujwlhidxn.exe
Osiris is offline   Reply With Quote
Old 12-24-2007, 07:45 PM   #5 (permalink)
Junior Techie
 
Join Date: Jun 2005
Posts: 94
Send a message via Yahoo to Thaqalain
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

I should not have deleted Windows Live Messenger , now I can't download it as getting a message of upgrading windows which failled validation.
Can I restore system on back dates to get baack my corrupted messenger.
Thaqalain is offline   Reply With Quote
Old 12-24-2007, 07:52 PM   #6 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,712
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

You can try. Why did you delete it?
Osiris is offline   Reply With Quote
Old 12-24-2007, 08:22 PM   #7 (permalink)
Junior Techie
 
Join Date: Jun 2005
Posts: 94
Send a message via Yahoo to Thaqalain
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

How can I restore?
Thaqalain is offline   Reply With Quote
Old 12-24-2007, 11:16 PM   #8 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,712
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

How to restore the operating system to a previous state in Windows XP
Osiris is offline   Reply With Quote
Old 12-25-2007, 01:05 AM   #9 (permalink)
Junior Techie
 
Join Date: Jun 2005
Posts: 94
Send a message via Yahoo to Thaqalain
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

Access is denied to delete:
C:\WINDOWS\System32\kzujwlhidxn.exe
Thaqalain is offline   Reply With Quote
Old 12-25-2007, 01:18 AM   #10 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,712
Default Re: Will I fix these O4; O16; O23 lines or .exe files?

either boot into safemode and delete it or use Hijackthis to delete on reboot under misc tools
Osiris is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
HijackThis logs for Security Team members only Trotter Virus - Spyware Protection / Detection 34 01-25-2008 12:13 PM
New Log enigm@tic HijackThis Logs (finished) 4 12-13-2007 07:45 PM
Osiris revenge2 HijackThis Logs (finished) 18 12-13-2007 05:57 PM
friends log Static_11 HijackThis Logs (finished) 11 11-25-2007 09:27 PM
spyware - "mywebsearch" - can't remove!! plumber4578 Virus - Spyware Protection / Detection 21 10-17-2007 06:06 PM


All times are GMT -5. The time now is 11:33 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0