Annoyances.org
Home » Windows XP Discussion Forum » Message 1106057474 Search | Help | Home
  
re: spyware?
Tuesday, January 18, 2005 at 6:11 am
Windows XP Annoyances Discussion Forum
Posted by Falcon (13489 messages posted)


Odd. Once again, the hijacker seems to be disappearing in pieces. We'll just continue attacking it and see if it'll go away before trying more drastic measures... :)
  1. Download the Pocket Killbox: http://www.bleepingcomputer.com/files/killbox.php
  2. Reboot to Safe Mode
  3. End these processes in Task Manager, if running:
    • C:\WINDOWS\system32\ieng.exe
    • C:\WINDOWS\ipwd32.exe
    • C:\WINDOWS\System32\Vocaav.exe
    • C:\WINDOWS\System32\HinEV5G.exe
    • C:\WINDOWS\system32\Jel387h.exe
    • WindowsUpdate72843[1].exe
    • C:\WINDOWS\system32\netvn.exe
  4. Fix these with HijackThis:
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {30C16827-1FE8-9C39-95A4-CA3E7FEC6A5D} - C:\WINDOWS\system32\sdkid32.dll
    O4 - HKLM\..\Run: [5CL8NTE2LGG@XK] C:\WINDOWS\system32\Jel387h.exe
    O4 - HKLM\..\Run: [ipwd32.exe] C:\WINDOWS\ipwd32.exe
    O4 - HKLM\..\RunOnce: [ieng.exe] C:\WINDOWS\system32\ieng.exe
    O4 - Startup: WindowsUpdate72843[1].exe
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.static.topconverting.com
    O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
    O15 - Trusted Zone: *.static.topconverting.com (HKLM)
    O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
    O23 - Service: Network Security Service - Unknown - C:\WINDOWS\system32\netvn.exe (file missing)
    
  5. Delete these files. Make sure hidden any system files are visible.
    • C:\WINDOWS\system32\sdkid32.dll
    • C:\WINDOWS\system32\ieng.exe
    • C:\WINDOWS\ipwd32.exe
    • C:\WINDOWS\System32\Vocaav.exe
    • C:\WINDOWS\System32\HinEV5G.exe
    • C:\WINDOWS\system32\Jel387h.exe
    • WindowsUpdate72843[1].exe
    • C:\WINDOWS\system32\netvn.exe
    If you are unable to delete a file, try these simple steps to remove them:
    • Rename the file, then delete it.
    • Open the file in a text editor. Edit->Select All. Delete. Save. Close the text editor. Right-click the file-> Properties->Check the "Read Only" box. Delete the file after a reboot.
    • The KillBox
  6. Reboot normally and post another HijackThis log.

The Wereotter




Written in response to:
re: spyware? (Willie: Monday, January 17, 2005 at 10:46 pm)

Responses to this message:
*re: spyware? (Willie: Tuesday, January 18, 2005 at 11:29 am)

All messages in this thread [show all]
-spyware? (meyer: Tue, Aug 3, 2004, 12:06 pm)
-re: spyware? (jcw: Tue, Aug 3, 2004, 12:52 pm)
*re: spyware? (Falcon: Tue, Aug 3, 2004, 2:13 pm)
-re: spyware? (Falcon: Tue, Aug 3, 2004, 2:14 pm)
-re: spyware? (triplate: Tue, Aug 3, 2004, 2:45 pm)
-re: spyware? (Falcon: Tue, Aug 3, 2004, 2:46 pm)
-re: spyware? (triplate: Tue, Aug 3, 2004, 2:59 pm)
-re: spyware? (Falcon: Tue, Aug 3, 2004, 3:01 pm)
*re: spyware? (triplate: Tue, Aug 3, 2004, 3:05 pm)
-re: spyware? (Willie: Thu, Jan 13, 2005, 7:10 am)
-re: spyware? (Falcon: Thu, Jan 13, 2005, 8:01 am)
-re: spyware? (Willie: Mon, Jan 17, 2005, 10:46 pm)
-re: spyware? (Falcon: Tue, Jan 18, 2005, 6:11 am)
-re: spyware? (Willie: Tue, Jan 18, 2005, 11:29 am)
*re: spyware? (Falcon: Tue, Jan 18, 2005, 11:45 am)
-re: spyware? (Falcon: Tue, Jan 18, 2005, 11:53 am)
*re: spyware? (Willie: Wed, Jan 19, 2005, 6:40 am)
*re: spyware? (Willie: Wed, Jan 19, 2005, 6:43 am)
-re: spyware? (Pakolainen: Tue, Nov 2, 2004, 11:17 pm)
-re: spyware? (Falcon: Wed, Nov 3, 2004, 5:24 am)
-re: spyware? (Pakolainen: Thu, Nov 4, 2004, 10:32 pm)
-re: spyware? (Falcon: Fri, Nov 5, 2004, 9:34 am)
*re: spyware? (Pakolainen: Sun, Nov 7, 2004, 10:26 pm)
-re: spyware? (Pakolainen: Sun, Nov 7, 2004, 11:10 pm)
-re: spyware? (Falcon: Mon, Nov 8, 2004, 6:04 am)
*re: spyware? (Pakolainen: Mon, Nov 8, 2004, 10:28 pm)
-re: spyware? (Scott: Sun, Nov 28, 2004, 12:38 pm)
-re: spyware? (Falcon: Sun, Nov 28, 2004, 1:50 pm)
-re: spyware? (Scott: Sun, Nov 28, 2004, 1:53 pm)
-re: spyware? (Falcon: Sun, Nov 28, 2004, 2:43 pm)
*re: spyware? (Falcon: Sun, Nov 28, 2004, 2:47 pm)
*re: spyware? (Lumos: Sun, Feb 6, 2005, 10:05 am)
*re: spyware? (Lorraine: Fri, Apr 1, 2005, 2:22 pm)
*re: spyware? (Steve: Tue, Aug 3, 2004, 5:14 pm)
Return to the Windows XP Discussion Forum

All content at Annoyances.org is Copyright © 1995-2008 Creative Elementtm All rights reserved.
Please do not plagiarize; redistributing these pages without permission is strictly prohibited.