Hello !
I am quite new with Avast software but already very happy with it as it removed viruses that were never “seen” before with another software !
However after the virus were removed, when I rebooted the pc 2 DLLs files are mentionned as being missing.
These are kozodobe.dll and kefuguhi.dllA small window opens and mentions they are missing.
Is this only because the registers were not cleaned ?
A solution would be welcome !
The question is why they were there in the first place?
Please download HijackThis from the link below. Do not download HJT to the desktop but instead download it into it’s own folder on the hard drive.
Run the program but do not make any fixes and then post the log results using the “copy & paste” method. It will probably take more than one post to be able to get the complete log posted.
OR, you can post it as an attachment to your post by clicking on “Additional Options…” below left of the posting box. Someone will review your log and then offer help.
It is nice to see the below as it is often that they are not up to date.
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Here are the problem entries:
[b]O2 - BHO: (no name) - {76a9a7ec-1c22-4bb4-8f48-4f48495cc1e1} - C:\WINDOWS\system32\gopikobi.dll (file missing)[/b]
Unnecessary (deactivated) entry that can be fixed. This is related to the other 2 files listed above.
See ... http://www.prevx.com/filenames/16749204660543537-X1/GOPIKOBI2EDLL.html
[b]O4 - HKLM\..\Run: [CPM0fd7dbe0] Rundll32.exe "c:\windows\system32\kefuguhi.dll",a[/b]
Unknown application which is related to the file mentioned my last post.
[b]O4 - HKLM\..\Run: [kifelopeya] Rundll32.exe "C:\WINDOWS\system32\kozodobe.dll",s[/b]
Unknown application which is related to the file mentioned my last post.
[b]O4 - HKUS\S-1-5-19\..\Run: [kifelopeya] Rundll32.exe "C:\WINDOWS\system32\kozodobe.dll",s (User 'SERVICE LOCAL')[/b]
Unknown application which is related to the file mentioned my last post.
[b]O20 - AppInit_DLLs: c:\windows\system32\kefuguhi.dll,C:\WINDOWS\system32\tojowebo.dll[/b]
Unknown application which is related to the file mentioned my last post.
[b]O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kefuguhi.dll (file missing)[/b]
Unknown application which is related to the file mentioned my last post.
[b]O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kefuguhi.dll (file missing)[/b]
Unknown application which is related to the file mentioned my last post.
So, yes, the registry entries were not removed causing the small window to open.
To fix these unneeded entries, follow the below steps:
1 - Ensure that all other windows & programs are closed/not running.
2 - Run HJT again.
3 - When the log is presented, click the box to the left of the entries in the above listing.
4 - At the bottom, click the "Fix checked" button.
5 - Wait for it to finish it's work and then restart your computer.
On restart, you should no longer get the small window.
Please let me know the results.
***
Thank you so much CharleyO,
The result is now perfect after I followed your recommandations
Thank you too for your remark about my computer state (up to date), I try indeed to keep it that way all the time, I think many problems can be avoided this way.
I wouldn’t like you to spend too much time for me because others also need your help, so just in a few words:
I am about to instal Avast on my main computer at home, but I had like first to remove a problem I have in it with SVCHOST.EXE considered by my previous antivirus software as dangerous (what follows “svchost.exe” in fact !)
Enclosed the logfile generated with hijackthis
The window alert of my future ex-antivirus … cannot be sent, unfortunaly (highly exceeds 200kb !) but it “says” object: C:\System Volume Information_restore{D0128875-862B-4C8…\A0147088.exe and An event happened on a file modified by the application C:\WINDOWS\SYSTEM32\svchost.exe
A0147088.exe is related to your recent infection with C:\System Volume Information_restore{D0128875-862B-4C8…\A0147088.exe being in system restore (System Volume Information). It would be my suggestion to turn off system restore, restart your computer, and then turn on system restore again to set a new restore point.
An analysis of your latest HJT this log had only 3 questionable entries.
My research shows that there might be nothing wrong if you know these programs and web sites.
O4 - Startup: Shrink Pic.lnk = C:\Program Files\Shrink Pic\shrink_pic.exe http://www.threatexpert.com/files/shrink_pic.exe.html
If the program Shrink Pic is known to you, it should be OK. If not, then it can be fixed.
Many thanks to both of you !
I corrected the problem in the “restore”, it is now ok and the other programs/websites are indeed known, one of them being my personal website dedicated to photography (www.geosolve.be) you may want to have a look…
The problems are now completely solved !!
Have a good night