Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 02-02-2009, 11:41 AM   #1 (permalink)
Registered User
 
Join Date: Feb 2009
Location: nw indiana
Posts: 2
OS: xp home sp3


Question alternate database for malicious registry keys

i am working on repairing my boss's son's computer, which has contracted the smitfraud virus. i have found a guide to repair it (http://www.pchell.com/support/smitfraud.shtml), so i am not asking for help repairing it. the only thing i need to know is this:

the hijackthis list of registries i acquired from the infected computer is not completely covered in the hijackthis online database. there are 5-10 registry entries that i have no information on. if anyone knows of another database i can use (perferably free) to crosscheck them, or if someone here could let me know (i will post them at the end of the post) i would be greatly appreciative. thank you all in advance for this service you provide.

O4 - HKCU\..\RunOnce: [SpybotDeletingB950] command /c del "C:\Program Files\GetPack\GetPack24.e xe"

O4 - HKCU\..\RunOnce: [SpybotDeletingD3461] cmd /c del "C:\Program Files\GetPack\GetPack24.e xe"O4 - HKCU\..\RunOnce: [SpybotDeletingB2371] command /c del "C:\Program Files\Mjcore\Mjcore.dll"

O4 - HKCU\..\RunOnce: [SpybotDeletingD5422] cmd /c del "C:\Program Files\Mjcore\Mjcore.dll"

O4 - HKCU\..\RunOnce: [SpybotDeletingB8839] command /c del "C:\Program Files\GetPack\trgtame.gz"

O4 - HKCU\..\RunOnce: [SpybotDeletingD5604] cmd /c del "C:\Program Files\GetPack\trgtame.gz"

O4 - HKCU\..\RunOnce: [SpybotDeletingB753] command /c del "C:\WINDOWS\system32\flxm ajpv.dll_old"

O4 - HKCU\..\RunOnce: [SpybotDeletingD4901] cmd /c del "C:\WINDOWS\system32\flxm ajpv.dll_old"

O20 - AppInit_DLLs: c:\windows\system32\ziluy uda.dll,c:\windows\system 32\yiyagefi.dll,c:\window s\sys tem32\pivetupa.dll,C:\WIN DOWS\system32\jatipife.dl l,c:\windows\system32\jay oriji .dll,ysjvgq.dll,erlwgk.dl l,njarsb.dll

O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)

O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)

O22 - SharedTaskScheduler: erajhsf8743kjrngjnf - {D5BF4552-94F1-42BD-F434-3604812C807D} - (no file)
DarthCrucias is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-06-2009, 09:53 AM   #2 (permalink)
Registered User
 
Join Date: Feb 2009
Location: nw indiana
Posts: 2
OS: xp home sp3


Re: alternate database for malicious registry keys

bump..
DarthCrucias is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-06-2009, 11:09 AM   #3 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,740
OS: 2000 Pro; XP Pro; XP Home


Re: alternate database for malicious registry keys

Hi -

This is not a discussion area. This is a section for malware removal assistance.

If you're asking for our help in this section of the forum...

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:
Having problems with spyware and pop-ups? First Steps
link at the top of each page.

---------------------------------------------------------------------------------------------

Please follow our pre-posting process outlined here:

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help

After running through all the steps, you shall have a proper set of logs.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-09-2009, 02:28 PM   #4 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,740
OS: 2000 Pro; XP Pro; XP Home


Re: alternate database for malicious registry keys

Due to lack of response, this topic will now be closed. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:47 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85