The Mudcat Café TM
Thread #117375   Message #2528991
Posted By: Simon G
01-Jan-09 - 10:26 AM
Thread Name: Tech: Trojan infection
Subject: RE: Tech: Trojan infection
From a search, does this help.

Run hijackthis and click on "scan system only" button and put checks next to these:


O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdkis.exe] C:\WINDOWS\system32\kdkis.exe
O4 - HKCU\..\Run: [LDM] \Program\
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B57B443-2B41-4966-83A1-B156011CCAA3}: NameServer = 85.255.112.126;85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{D852A8A8-3D49-42FF-B36C-649B808A2D30}: NameServer = 85.255.112.126;85.255.112.131


Please close ALL browser windows (including this one).

Everything closed out but hijackthis and click on "fix checked"






Now reboot into safe mode by tapping your F8 key upon restart and safe mode screen appears, select safe mode and press enter.


Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):


DELETE FILES:

C:\WINDOWS\system32\kdkis.exe


Reboot and...


Please download and install the latest version of HijackThis v2.0.2:Delete the old version you have

CLICK HERE to download the HijackThis Installer:TrendSecure | Download TrendMicro HijackThis

1. Save HJTInstall.exe to your desktop.
2. Double-click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5. Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
8. Come back here to this thread and paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.