Joined
·
117 Posts
I followed the instructions properly for the advice you gave another user to remove a trojan virus that has hijacked my browser. It seems the problem has not been solved. I am sending the log report from the sdfix log for your review. Any help would be gladly appreciated...John
SDFix: Version 1.58
Sun 01/14/2007 - 12:57:02.23
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Path:
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting
Normal Mode:
Checking Files:
Files will be copied to Backups folder then removed:
C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDUI.EXE - Deleted
Could Not Remove C:\PROGRA~1\GRISOFT\AVGANT~1.5\GUARD.EXE !
Alternate Stream Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
xpsp3res.dll,-20000"
Remaining Files:
---------------
C:\PROGRA~1\GRISOFT\AVGANT~1.5\GUARD.EXE
Backups Folder: - C:\SDFix\backups\backups.zip
Listing Files with hidden attributes:
C:\NTDETECT.COM
C:\DELL\PRIMOSDK.DLL
C:\DELL\PX.DLL
C:\DELL\PXDRV.DLL
C:\DELL\PXMAS.DLL
C:\DELL\PXWAVE.DLL
C:\DELL\VXBLOCK.DLL
C:\DELL\MEDIAEXE\PRIMOSDK.DLL
C:\DELL\MEDIAEXE\PX.DLL
C:\DELL\MEDIAEXE\PXDRV.DLL
C:\DELL\MEDIAEXE\PXMAS.DLL
C:\DELL\MEDIAEXE\PXWAVE.DLL
C:\DELL\MEDIAEXE\VXBLOCK.DLL
C:\DELL\PXCPYA64.EXE
C:\DELL\PXCPYI64.EXE
C:\DELL\PXHPINST.EXE
C:\DELL\PXINSA64.EXE
C:\DELL\PXINSI64.EXE
C:\DELL\PXSETUP.EXE
C:\DELL\MEDIAEXE\PXCPYA64.EXE
C:\DELL\MEDIAEXE\PXCPYI64.EXE
C:\DELL\MEDIAEXE\PXHPINST.EXE
C:\DELL\MEDIAEXE\PXINSA64.EXE
C:\DELL\MEDIAEXE\PXINSI64.EXE
C:\DELL\MEDIAEXE\PXSETUP.EXE
C:\I386\cdplayer.exe.manifest
C:\I386\logonui.exe.manifest
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SYSTEM32\cdplayer.exe.manifest
C:\WINDOWS\SYSTEM32\logonui.exe.manifest
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\DELL\PXHELP20.SYS
C:\DELL\PXHELP64.SYS
C:\DELL\PXHELPER.SYS
C:\DELL\PXHLPA64.SYS
C:\DELL\MEDIAEXE\PXHELP20.SYS
C:\DELL\MEDIAEXE\PXHELP64.SYS
C:\DELL\MEDIAEXE\PXHELPER.SYS
C:\DELL\MEDIAEXE\PXHLPA64.SYS
C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\john ercolino.DBMKS671\Application Data\Roxio\Dragon\DiscInfoCache\HL-DT-ST_CD-RW_GCE-8483B__B105_300_DICV018_DRGV20100BC.TMP
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6752e343d22c025be1f290a6267a146d\BIT27.tmp
Finished
SDFix: Version 1.58
Sun 01/14/2007 - 12:57:02.23
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Path:
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting
Normal Mode:
Checking Files:
Files will be copied to Backups folder then removed:
C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDUI.EXE - Deleted
Could Not Remove C:\PROGRA~1\GRISOFT\AVGANT~1.5\GUARD.EXE !
Alternate Stream Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
Remaining Files:
---------------
C:\PROGRA~1\GRISOFT\AVGANT~1.5\GUARD.EXE
Backups Folder: - C:\SDFix\backups\backups.zip
Listing Files with hidden attributes:
C:\NTDETECT.COM
C:\DELL\PRIMOSDK.DLL
C:\DELL\PX.DLL
C:\DELL\PXDRV.DLL
C:\DELL\PXMAS.DLL
C:\DELL\PXWAVE.DLL
C:\DELL\VXBLOCK.DLL
C:\DELL\MEDIAEXE\PRIMOSDK.DLL
C:\DELL\MEDIAEXE\PX.DLL
C:\DELL\MEDIAEXE\PXDRV.DLL
C:\DELL\MEDIAEXE\PXMAS.DLL
C:\DELL\MEDIAEXE\PXWAVE.DLL
C:\DELL\MEDIAEXE\VXBLOCK.DLL
C:\DELL\PXCPYA64.EXE
C:\DELL\PXCPYI64.EXE
C:\DELL\PXHPINST.EXE
C:\DELL\PXINSA64.EXE
C:\DELL\PXINSI64.EXE
C:\DELL\PXSETUP.EXE
C:\DELL\MEDIAEXE\PXCPYA64.EXE
C:\DELL\MEDIAEXE\PXCPYI64.EXE
C:\DELL\MEDIAEXE\PXHPINST.EXE
C:\DELL\MEDIAEXE\PXINSA64.EXE
C:\DELL\MEDIAEXE\PXINSI64.EXE
C:\DELL\MEDIAEXE\PXSETUP.EXE
C:\I386\cdplayer.exe.manifest
C:\I386\logonui.exe.manifest
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\SYSTEM32\cdplayer.exe.manifest
C:\WINDOWS\SYSTEM32\logonui.exe.manifest
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\DELL\PXHELP20.SYS
C:\DELL\PXHELP64.SYS
C:\DELL\PXHELPER.SYS
C:\DELL\PXHLPA64.SYS
C:\DELL\MEDIAEXE\PXHELP20.SYS
C:\DELL\MEDIAEXE\PXHELP64.SYS
C:\DELL\MEDIAEXE\PXHELPER.SYS
C:\DELL\MEDIAEXE\PXHLPA64.SYS
C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\john ercolino.DBMKS671\Application Data\Roxio\Dragon\DiscInfoCache\HL-DT-ST_CD-RW_GCE-8483B__B105_300_DICV018_DRGV20100BC.TMP
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6752e343d22c025be1f290a6267a146d\BIT27.tmp
Finished