Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Virus, Spyware, and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

2 Pages V  < 1 2  
Closed TopicStart new topic
> Win32.agent.at/ Smitfraud-c.toolbar888/ Psapianalyzer, Cannot Remove Persistent Browser Hijacker
RichieUK
post Jun 6 2007, 02:28 PM
Post #16


Malware Assassin
******

Group: HJT Team
Posts: 13,611
Joined: 13-July 06
Member No.: 75,975



QUOTE
I'm about 99.999999% certain they're really GONE from EVERYWHERE but the SpyBot "System Startup" page!

So am i,but if you're still concerned you might want to register at the following forum and seek help there.
Safer Networking Forums [Spybot Search and Destroy]:
http://forums.spybot.info/

Let me know how you get on if you do decide to try the above.


--------------------
If I have helped you in any way, please consider a donation:

Proud Member of ASAP (Alliance of Security Analysis Professionals).
Proud Member of U-N-I-T-E (Unified Network of Instructors and Trusted Eliminators).
Go to the top of the page
 
+Quote Post
Uralten
post Jun 6 2007, 02:43 PM
Post #17


New Member
*

Group: Members
Posts: 11
Joined: 3-June 07
Member No.: 134,528



I decided to try one more thing, and it actually turned up some references. I did a search with Registry Editor looking for comdb.dll. I found all four of the files (in order) listed in HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU, along with entries for other files whose names have become familiar over the last few days (such as cuqnogoh.exe). This same list is repeated in HKEY_USERS\S-1-5-21-839522115-152049171-854245398-1000\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}\FilesNamedMRU. Do you think it's possible SpyBot is picking the names up from those entries? Should I delete them by hand and just leave those numbered keys without any data and see if that makes them go away?
Go to the top of the page
 
+Quote Post
RichieUK
post Jun 6 2007, 03:04 PM
Post #18


Malware Assassin
******

Group: HJT Team
Posts: 13,611
Joined: 13-July 06
Member No.: 75,975



QUOTE
Should I delete them by hand and just leave those numbered keys without any data and see if that makes them go away?

Yes,try that but backup the registry first by doing the following:

Click on Start>Run,copy and paste the following bold text into the 'Open:' space,then press Ok.
regedit /e c:\registrybackup.reg
It won't appear to be doing anything,that's normal.
Your mouse pointer may have an hour glass along side it for a minute or so.
Please be patient and continue when the hour glass disappears.

This post has been edited by RichieUK: Jun 6 2007, 03:05 PM


--------------------
If I have helped you in any way, please consider a donation:

Proud Member of ASAP (Alliance of Security Analysis Professionals).
Proud Member of U-N-I-T-E (Unified Network of Instructors and Trusted Eliminators).
Go to the top of the page
 
+Quote Post
Uralten
post Jun 7 2007, 11:27 AM
Post #19


New Member
*

Group: Members
Posts: 11
Joined: 3-June 07
Member No.: 134,528



Hey, Richie, deleting those last few references in the MRU lists in the registry didn't work, either. I'll take your suggestion and go over to the SpyBot forum and see if they can shed any light on this one last glitch. If they come up with an answer, I'll come back here and let you know what it is, so you can use it to advise the NEXT poor sap who catches Vundo! whistling.gif

Thanks again for your EXCELLENT assistance in solving my my problem. As promised, I made a PayPal donation to BleepingComputer this morning. I really appreciate all your help!
Go to the top of the page
 
+Quote Post
RichieUK
post Jun 7 2007, 11:45 AM
Post #20


Malware Assassin
******

Group: HJT Team
Posts: 13,611
Joined: 13-July 06
Member No.: 75,975



You're most welcome and thanks for the site donation smile.gif


--------------------
If I have helped you in any way, please consider a donation:

Proud Member of ASAP (Alliance of Security Analysis Professionals).
Proud Member of U-N-I-T-E (Unified Network of Instructors and Trusted Eliminators).
Go to the top of the page
 
+Quote Post
Uralten
post Jun 12 2007, 10:42 AM
Post #21


New Member
*

Group: Members
Posts: 11
Joined: 3-June 07
Member No.: 134,528



Hey, Richie, the mystery of those last four entries in SpyBot's System Startup page has been resolved on the Safer Networking forum. There WAS still a reference to those files in my registry, but I didn't find it with my regedit.exe searches because I was searching for the file names (for example, comdb.dll), while the entries were only the names assigned by SpyBot to those files (for example, comdb). With the help I received at the other forum, I was able to find the following registry branch:

[Begin quoted text]

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify_Disabled]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify_Disabled\comdb]
"Asynchronous"=dword:00000001
"DllName"="c:\\winnt\\inf\\comdb.dll"
"Impersonate"=dword:00000000
"Startup"="UserLogOn"
"Logoff"="UserLogOff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify_Disabled\hggebaa]
"Asynchronous"=dword:00000001
"DllName"="hggebaa.dll"
"Impersonate"=dword:00000000
"Logon"="Logon"
"Logoff"="Logoff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify_Disabled\nnlkj]
"Asynchronous"=dword:00000001
"DllName"="C:\\WINNT\\system32\\nnlkj.dll"
"Impersonate"=dword:00000000
"Startup"="RealLogon"
"Logoff"="RealLogoff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify_Disabled\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[End quoted text]

The items SpyBot's System Startup page shows as loading from "system.ini" are actually loading from the Notify branch. Unlike the corresponding entries in SpyBot, which regenerated when deleted, the entries in this branch did NOT regenerate when deleted, and once it was gone, the four offending entries in SpyBot disappeared, as well. As a result, the LAST traces of my Vundo/Psapianalyzer adventure are now eliminated from my computer.

I don't know if you'll be able to use this information to help anybody else, but if you can, you're more than welcome to it. Thanks once again for all your help!! clapping.gif
Go to the top of the page
 
+Quote Post
RichieUK
post Jun 12 2007, 10:55 AM
Post #22


Malware Assassin
******

Group: HJT Team
Posts: 13,611
Joined: 13-July 06
Member No.: 75,975



Thanks for the info Uralten,glad you got the issue resolved smile.gif

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.


This post has been edited by RichieUK: Jun 12 2007, 01:07 PM


--------------------
If I have helped you in any way, please consider a donation:

Proud Member of ASAP (Alliance of Security Analysis Professionals).
Proud Member of U-N-I-T-E (Unified Network of Instructors and Trusted Eliminators).
Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Closed TopicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 21st November 2009 - 07:00 PM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides

© 2003-2009 All Rights Reserved Bleeping Computer LLC.