Start a Conversation

Unsolved

This post is more than 5 years old

727

June 27th, 2011 08:00

Hijack This Log - Symptoms: Prevents Microsoft Security Essentials from Starting, occasional URL Redirect from Antivirus sites.

I believe the executable was XVL.exe and its partner XVC.exe. I have purged those and their registry entry, but the symptoms persist.

Any assistance would be wonderful.

 

Logfile of Trend Micro HijackThis v2.0.4Scan saved at 9:07:22 AM, on 6/27/2011Platform: Windows 7  (WinNT 6.00.3504)MSIE: Internet Explorer v9.00 (9.00.8112.16421)Boot mode: Normal
Running processes:C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exeC:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exeC:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exeC:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exeC:\Program Files (x86)\iTunes\iTunesHelper.exeC:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exeC:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exeC:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exeC:\Users\Kyle Akers\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exeC:\Windows\Xxogia.exeC:\Users\Kyle Akers\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Kyle Akers\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Kyle Akers\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Kyle Akers\AppData\Local\Google\Chrome\Application\chrome.exeC:\Windows\SysWOW64\NOTEPAD.EXEC:\Users\Kyle Akers\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Kyle Akers\Downloads\avg_free_stb_all_2011_1388_cnet.exeC:\Users\KYLEAK~1\AppData\Local\Temp\7zS4CD7.tmp\avgmfapx.exeC:\Users\Kyle Akers\AppData\Local\Google\Chrome\Application\chrome.exeC:\Windows\SysWOW64\NOTEPAD.EXEC:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?babsrc=HP_ss&mntrId=30f54b360000000000000024e8e362e6&tlver=1.4.23.10&affID=19591R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=30f54b360000000000000024e8e362e6&tlver=1.4.23.10&affID=19591R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htmR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exeO2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Increase performance and video formats for your HTML5

1.5K Posts

July 20th, 2011 14:00

Hi,

Sorry for the delay in getting to you.

If you are still in need of assistance, please post a fresh HJT log.

Please make sure when you post all logs that Word Wrap is OFF in Notepad.

When Notepad opens with the logs please go to Format on the Notepad tool bar at the top of its page and

make sure WordWrap is UNCHECKED.

1.5K Posts

July 24th, 2011 13:00

This topic is Inactive.....

The fixes in this topic were written specifically for this user, following them may cause harm to your machine and render it a brick (useless)

If you are the original poster and would like further assistance please post a fresh HJT log in a NEW topic along with details of the problems you are having.

All other user's, please read THIS page and then please start a New Topic at the top of the Malware Removal Forum by clicking the DCFnewpost.png button.

No Events found!

Top