Unsolved

This post is more than 5 years old

34 Posts

1544

October 26th, 2005 01:00

please help, i ran hijack this.

I ran hijack this because my computer is absolutly frozen so i have to run it in safe mode. Here is the saved log from it. I hope i did this right. thanks.
 
Logfile of HijackThis v1.99.1
Scan saved at 9:52:07 PM, on 10/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ryan\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\PDF6fa6.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - (no file)
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: (no name) - {E434D3C7-A673-4100-8140-79C020945017} - (no file)
O2 - BHO: (no name) - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - (no file)
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: (no name) - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - (no file)
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {53829F91-1B06-4DB9-B13E-812A986169F9} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe
O4 - HKLM\..\Run: [cmdwave] C:\WINDOWS\system32\MUI\0409\cmdwave.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Avcyl.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost.exe
O4 - HKLM\..\Run: [82486373b11d] C:\WINDOWS\System32\CMPROPS5.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\PDF6fa6.dll"
O4 - HKLM\..\Run: [cb4fcd3b71cb] C:\WINDOWS\System32\BCMSM168.exe
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe
O4 - HKLM\..\Run: [firewall_anti] C:\WINDOWS\firewall_anti.exe
O4 - HKLM\..\Run: [Voyljevy] C:\Program Files\Vswb\Cvwjaky.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O4 - HKCU\..\Run: [ssgrate.exe] C:\WINDOWS\System32\wintems.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: v3cab - http://searchmiracle.com/cab/v3cab.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=206a699e9ed002b764e389490796fb536ca1eceedef00fe00861e04964b74e26b235adf0c31b37010e8e2c69b6760c019447ee1641cd70938325:23e58dabdfe8c5d6602b8bf1fcecd7ff
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {8EF27A70-DD04-11D6-B7F6-00A0C9CD5F8A} - http://www.quikshield.com/qshsetup.exe
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChatENU/TLIEFlash.CAB
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 26th, 2005 11:00

walt,
not sure about running in safe mode --- and how much [if any] of the following you'll be able to do there, but among other things, you have a NAIL infection... I'm going to try to help you to remove this first.   This fix involves using Ad-Aware, and its VX2-cleaner.   It is critical that you use the current versions as indicated below... if you use an older/obsolete version, the fix will not work.
 
If you don't already have it, download Ad-Aware SE Personal 1.06 from http://www.majorgeeks.com/Ad-Aware_SE_Personal_d506.html
[Note:  If you have an older "build" of Ad-Aware SE --- or even worse, if you're still using Ad-Aware 6 --- you must upgrade to this version/build,  SE 1.06 ]
 
Install the Ad-Aware program (following any indicated directions).   [As part of the installation, it will check to see if you already have an older version of Ad-Aware installed, and if one is found, it will ask ("advise") you to allow the older one to be removed...  so if asked, please allow it.]
 
Open/start Ad-Aware SE.     Click on Check for Updates Now, and Connect .  if found, follow the directions to download/install the latest reference file, till you FINISH.
 
After updating, from the STATUS screen, click on START.  
then make sure you have a RED X in front of "Search for negligible risk entries
(if you see a GREEN CHECK, then CLICK on it, to change it to the RED X )
then hit NEXT to perform a S mart Scan.  Allow it to remove any problems founds.
 
Close-down Ad-Aware.  
 
then download the VX2-cleaner add-on by clicking-on the link near the bottom of
This will download the file  vx2cleaner_inst.exe ; click on it, and follow the directions to install the VX2-cleaner.
 
Start Ad-Aware SE again.  Click on the Add-Ons button.   Click on the VX2-Cleaner.  Click on Run Tool, and then click OK .    If it finds any VX2 problems, follow all the directions to CLEAN things.   (I believe this will include a reboot, and directions to run another smart scan.   Follow all indicated directions [i.e., various/multiple scans] until it tells you you're clean of VX2.
 
This should have removed all traces of NAIL/Aurora [as well as epolvy and SvcProc, which i didn't see in your log].  Please generate and post a new HiJackThis log, appending it to this same thread.

Message Edited by ky331 on 10-26-2005 10:01 AM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 26th, 2005 21:00

please post an updated HJT log. 
 
by "it has worked", i take that to mean you no longer get popups from Aurora?   were there any other differences you noted? 
 
can you boot into normal mode ---- or are you still "stuck" in SAFE mode

34 Posts

October 26th, 2005 21:00

So far it has worked thank you very much.

34 Posts

October 26th, 2005 21:00

Ok i take that back. I logged on and i got a pop-up right away but i closed it and i opened internet explorer(in normal mode) and it worked so i signed off of my user name and went on another one to see if they were all working and it was back to the same, frozen again. Any suggestions? I also forget how to get to the hijack this log to post it. thanks.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 26th, 2005 21:00

double-click on HiJackThis. EXE

Click on  Do a System Scan and Save a LogFile

This will automatically open NotePad

Copy the entire file from NotePad:  EDIT/SelectAll, EDIT/Copy

then come back to this thread, hit on REPLY, and PASTE the results here.

34 Posts

October 26th, 2005 22:00

Logfile of HijackThis v1.99.1

Scan saved at 6:38:02 PM, on 10/26/2005

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\ryan\Local Settings\Temporary Internet Files\Content.IE5\97BE7VSX\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/

O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\PDF6fa6.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: (no name) - {E434D3C7-A673-4100-8140-79C020945017} - (no file)

O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll

O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe

O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Tovs.exe

O4 - HKLM\..\Run: [82486373b11d] C:\WINDOWS\System32\CMPROPS5.exe

O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\PDF6fa6.dll"

O4 - HKLM\..\Run: [cb4fcd3b71cb] C:\WINDOWS\System32\BCMSM168.exe

O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe

O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe

O4 - HKLM\..\Run: [firewall_anti] C:\WINDOWS\firewall_anti.exe

O4 - HKLM\..\Run: [Voyljevy] C:\Program Files\Vswb\Cvwjaky.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe

O4 - HKCU\..\Run: [ssgrate.exe] C:\WINDOWS\System32\wintems.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll

O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 26th, 2005 22:00

Download the latest version of HJT(hijackthis) (version 1.99.1) from

http://majorgeeks.com/download3155.html

you must create a separate folder and place it there.... people commonly use C:\HJT.   Note:  Please do *NOT* use a TEMP (temporary) folder, *NOR* your DESKTOP, as HJT will be generating log files and backup files in the folder from which it is run... you risk accidentally losing these if you use a TEMP folder, and you will generate extreme clutter if you use your DESKTOP.

The file above comes as a compressed .ZIP file... you have to UNzip it (hopefully, you have an UNzip utility built into your Windows Explorer.   If for any reason, you're unable to UNzip it, you can download the already-unzipped .EXE file from http://downloads.malwareremoval.com/HijackThis.exe )

After Unzipping, double click on HiJackThis.EXE

Click on  Do a System Scan and Save a LogFile

This will automatically open NotePad

Copy the entire file from NotePad:  EDIT/SelectAll, EDIT/Copy

then come back to this thread, hit on REPLY, and PASTE the results here.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 26th, 2005 22:00

walt...
 
several points... when you reply, be sure to carefully answer the questions i've raised here.
 
this second log is MUCH "cleaner" than the first one you submitted.   NAIL is no longer showing up :smileyhappy:.... and that's all that I was aiming for with the particular fix I gave you.   but a whole lot of other things are gone as well.
 
you mentioned earlier that you have (at least 2) "users" on your system:   "your" user name, and "another one".    were the two logs generated under the same user logon, or different user logons?
 
did you (knowingly) remove anything else?  (for example, did you run any other anti-virus, anti-spyware, anti-adware programs, that removed stuff?)   i'm not saying that you did anything wrong... "clean" is good.... i'm just trying to figure out what's going on here.
 
there can be many types/sources of popups.   the NAIL one, that seems to be removed, generally has the name "Aurora" associated with it.   Do you remember getting popups from Aurora?   And if so, have those particular popups stopped?  If you're still getting OTHER popups (besides Aurora), that's a different matter... any names you see associated with them?
 
 
 
also:  

You're still running HJT from a TEMP directory:

your first log had it in:

C:\Documents and Settings\ryan\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

your second log has it in:

C:\Documents and Settings\ryan\Local Settings\Temporary Internet Files\Content.IE5\97BE7VSX\HijackThis[1].exe

When you do so, either HJT will not create its log files and backup files; or if it does, you risk losing them when the TEMP's cache is cleared. It's important that you save these backup files, in case you have to "undo" [restore] some of the things you "FIX" incorrectly.

So you need to move HJT into a separate, non-temporary, non-Desktop, directory of its own. We recommend using the directory C:\HJT , so that it will then appear in your log, under running processes, as C:\HJT\HiJackThis.exe

You'll have to create this new directory, C:\HJT , and then either "drag"/move or copy/paste HiJackThis from the TEMP directory into C:\HJT ; or if you're not sure how to drag or copy, then just download yet another copy of HJT, but this time, save it directly into the C:\HJT directory.

So:  try to answer all the questions that i've asked here.   move Hijack this to a separate, NON-TEMP (NON-DESKTOP) directory.   log on under the same user name that you used for the first log.  and generate/post yet another copy.

 

Message Edited by ky331 on 10-26-2005 09:00 PM

34 Posts

October 26th, 2005 23:00

The 2 logs were generated from the same user name.
 
I removed a couple of things manually such as toolbars, webrebates, stuff that i was sure, or maybe not, was not needed.
 
I do remember Aurora, we also get the same desktop items that appear from nowhere like, meet singles, lower your debt, and advance you career, which did appear right after running the Ad-Aware, when i thought it was back to normal.  Besides that there were all kids of pop-ups but i don't exactly remember what they were. But i also cannot get on in normal mode so i don't know if they will still appear.
 
I don't know how to move the HJT to a different place. When i download it , it doesn't give me a choice of where to put it. Step by step might help if possible, sorry. I also don't know where to find HJT itself after it downloads, all i can find are the logs that i saved.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 27th, 2005 00:00

see if you can follow this:

first, let's create the new folder... as per my suggestion, it's gonna be C:\HJT 

there's more than one way to do this... here's one:

from your desktop, open (double-click on) My Computer

then double-click on Local Disk C:

you should now see a bunch of folders

place your cursor into the white area around these folders and RIGHT-click

you'll get a drop-down menu,,, highlight NEW

that gives another drop-down menu... click on FOLDER

and that will create a new folder, initially named NEW FOLDER, which we will immediately change/rename to HJT.

 

 

Assuming you can do all that, next we have to find your old copy of HiJackThis, and move it:  

(Things may be slightly different for you, as I see you're running XP sp1 --- and I'm on an sp2 system at the moment, but hopefully, you'll be able to work your way thru any  differences)

Look up toward the toolbar, and click on SEARCH .   click on All files or Folders ; and where it says All or part of the filename , type in HijackThis .  Make sure that you Look in Local Disk C: and the More advanced options includes Search Subfolders.   then click on SEARCH .  it should find (at least one) copy of HiJackThis.exe (or HiJackThis[1].exe ) .  RIGHT-click on one of these, and then select COPY.

look toward the toolbar again, and click on FOLDERS .  click on the plus-sign in front of MY COMPUTER.   click on the plus-sign in front of local drive C:  and click-on the HJT folder we created earlier.   the screen should have two "halves", and the right half should be empty.  place your cursor anywhere in the right half section, RIGHT-click, and select PASTE.  hopefully, that will place a copy of HiJackThis.exe there.   Right-click on it, and select Send to Desktop as shortcut.   then go to your desktop, and click on the shortcut to HiJackThis, to generate and post another log.

[i'm gonna keep my fingers crossed you can get through all this]

34 Posts

October 27th, 2005 00:00

ok i have a shortcut to WordPad Document Scrap Logfile of HJT on my desktop, is that correct? and what next?

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 27th, 2005 10:00

no, that doesn't seem right....
 
how much of the last set of directions were you able to follow "smoothly"?  
 
were you able to create the new folder C:\HJT ?
 
and if so, were you able to move a copy of some HiJackThis .EXE file into that folder ?
 
if so, can you get back into that folder, click on (i.e. run) that copy of HiJackThis, to generate your latest log, and REPLY to post it here?

34 Posts

October 27th, 2005 12:00

Yes i was able to create the folder, but when search in the subfolders what kind of file am i looking for, a file, file folder, text document, there are a bunch of things showing up,  i don't know which one is the actual program. None of them have exe. on them though. Also when i run the windows in normal mode and sign on any user name it loads and the sand timer goes away but when you put it on the start button it is still there, like a program is trying to start but it never does, it just stays frozen. Then when i hit ctrl+alt+del to restart, a couple of programs show up that say shutting down such and such where you can click end now. So i don't know if they are the programs that aren't starting right and are causing it to freeze. Maybe some of this will help. thanks.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

October 27th, 2005 12:00

in the search of subfolders, you should be looking for a   file.  
and where it asks (something like) All or part of the filename , this time, type in Hijack*.exe (which should find ONLY Hijack-related .EXE files this time)
 
if NO .exe files are found, it could be because your temp-file's cache is being emptied automatically [which is the reason why i'm trying to move it out of there], in which case, you should download HJT again, and then immediately try this seach again.

34 Posts

October 27th, 2005 20:00

OK, I think I finaly got it. Here's the new logfile.

Logfile of HijackThis v1.99.1

Scan saved at 4:59:56 PM, on 10/27/2005

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Internet Explorer\iexplore.exe

C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/

O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\PDF6fa6.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: (no name) - {E434D3C7-A673-4100-8140-79C020945017} - (no file)

O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll

O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe

O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Cjo9g.exe

O4 - HKLM\..\Run: [82486373b11d] C:\WINDOWS\System32\CMPROPS5.exe

O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\PDF6fa6.dll"

O4 - HKLM\..\Run: [cb4fcd3b71cb] C:\WINDOWS\System32\BCMSM168.exe

O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe

O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe

O4 - HKLM\..\Run: [firewall_anti] C:\WINDOWS\firewall_anti.exe

O4 - HKLM\..\Run: [Voyljevy] C:\Program Files\Vswb\Cvwjaky.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe

O4 - HKCU\..\Run: [ssgrate.exe] C:\WINDOWS\System32\wintems.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll

O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

No Events found!

Top