This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been acting like it has a mind of its own. It trips and its very weird. I would really appreciate any help and thanks in advance. =)

Logfile of HijackThis v1.98.2
Scan saved at 9:27:46 PM, on 8/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\AIM95\aim.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\scagent.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\dllcache\notepad.exe
C:\Program Files\Winamp\winamp.exe
C:\DOCUME~1\Raymond\LOCALS~1\Temp\Rar$EX00.164\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = www.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {05D4D108-3672-4318-83A8-4FF1ACC77082} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\RunOnce: [0000 - C:\Documents and Settings\Raymond\Start Menu\Programs\HP DeskJet 930C Series v2.3] C:\WINDOWS\SYSTEM32\command.com /c rmdir "C:\Documents and Settings\Raymond\Start Menu\Programs\HP DeskJet 930C Series v2.3"
O4 - HKLM\..\RunOnce: [0003 - C:\Documents and Settings\Raymond\Start Menu\Programs\HP Internet Connection Center] C:\WINDOWS\SYSTEM32\command.com /c rmdir "C:\Documents and Settings\Raymond\Start Menu\Programs\HP Internet Connection Center"
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall…w.viewpoint.com
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.soundclick.com/CFIDE/classes/CFJava.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\digfilt.dll
Let's see if you have a hidden hijacker. Do this for me.

Click here to download DllCompare. Start the Program with and click the Run Locate.com - be sure the \Windows\System32 directory is in the box and wait until the the blue text says it has 'completed the scan'.

Click the Compare button to start the next process. The results appear in two panes - files in the upper pane have been verified to 'exist', files in the lower pane were 'not able to be accessed'. Very few files should be listed in the lower pane when the Compare scan is complete. Click on each of the listed entries in the lower pane to select them. Right-click on the file and use the option Rescan. This will cause Windows Find to see if the file does exist, and then if so it will be removed from the list to reduce the number of identified files.

Click the Make a Log of what was found button and post the log here in this thread.

Click here to download a little script by Mosaic1 that reveals all running services in your system. Download, unzip and double-click getactiveservices.vbs (you may need to enable your antivirus program to run the file). This script will create and open a text file named Active.txt in the same folder as the script itself has been saved. It will then open Active.txt for you. Active text will list all active Services - copy and paste the contents of Active.txt in your next reply here.
There was nothing that showed up in the lower pane. Here's the list: These are the Current Active Services: APPLICATION LAYER GATEWAY SERVICE: ALG C:\WINDOWS\System32\alg.exe WINDOWS AUDIO: AudioSrv C:\WINDOWS\System32\svchost.exe -k netsvcs CRYPTOGRAPHIC SERVICES: CryptSvc C:\WINDOWS\system32\svchost.exe -k netsvcs DHCP CLIENT: Dhcp C:\WINDOWS\System32\svchost.exe -k netsvcs LOGICAL DISK MANAGER: dmserver C:\WINDOWS\System32\svchost.exe -k netsvcs ERROR REPORTING SERVICE: ERSvc C:\WINDOWS\System32\svchost.exe -k netsvcs COM+ EVENT SYSTEM: EventSystem C:\WINDOWS\System32\svchost.exe -k netsvcs FAST USER SWITCHING COMPATIBILITY: FastUserSwitchingCompatibility C:\WINDOWS\System32\svchost.exe -k netsvcs HELP AND SUPPORT: helpsvc C:\WINDOWS\System32\svchost.exe -k netsvcs SERVER: lanmanserver C:\WINDOWS\System32\svchost.exe -k netsvcs WORKSTATION: lanmanworkstation C:\WINDOWS\System32\svchost.exe -k netsvcs MESSENGER: Messenger C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK CONNECTIONS: Netman C:\WINDOWS\System32\svchost.exe -k netsvcs NETWORK LOCATION AWARENESS (NLA): Nla C:\WINDOWS\System32\svchost.exe -k netsvcs REMOTE ACCESS CONNECTION MANAGER: RasMan C:\WINDOWS\System32\svchost.exe -k netsvcs TASK SCHEDULER: Schedule C:\WINDOWS\System32\svchost.exe -k netsvcs SECONDARY LOGON: seclogon C:\WINDOWS\System32\svchost.exe -k netsvcs SYSTEM EVENT NOTIFICATION: SENS C:\WINDOWS\system32\svchost.exe -k netsvcs INTERNET CONNECTION FIREWALL (ICF) / INTERNET CONNECTION SHARING (ICS): SharedAccess C:\WINDOWS\System32\svchost.exe -k netsvcs SHELL HARDWARE DETECTION: ShellHWDetection C:\WINDOWS\System32\svchost.exe -k netsvcs TELEPHONY: TapiSrv C:\WINDOWS\System32\svchost.exe -k netsvcs TERMINAL SERVICES: TermService C:\WINDOWS\System32\svchost.exe -k netsvcs THEMES: Themes C:\WINDOWS\System32\svchost.exe -k netsvcs DISTRIBUTED LINK TRACKING CLIENT: TrkWks C:\WINDOWS\system32\svchost.exe -k netsvcs UPLOAD MANAGER: uploadmgr C:\WINDOWS\System32\svchost.exe -k netsvcs WINDOWS TIME: W32Time C:\WINDOWS\System32\svchost.exe -k netsvcs WINDOWS MANAGEMENT INSTRUMENTATION: winmgmt C:\WINDOWS\system32\svchost.exe -k netsvcs AUTOMATIC UPDATES: wuauserv C:\WINDOWS\system32\svchost.exe -k netsvcs WIRELESS ZERO CONFIGURATION: WZCSVC C:\WINDOWS\System32\svchost.exe -k netsvcs SYMANTEC EVENT MANAGER: ccEvtMgr C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe DNS CLIENT: Dnscache C:\WINDOWS\System32\svchost.exe -k NetworkService EVENT LOG: Eventlog C:\WINDOWS\system32\services.exe PLUG AND PLAY: PlugPlay C:\WINDOWS\system32\services.exe TCP/IP NETBIOS HELPER: LmHosts C:\WINDOWS\System32\svchost.exe -k LocalService REMOTE REGISTRY: RemoteRegistry C:\WINDOWS\system32\svchost.exe -k LocalService SSDP DISCOVERY SERVICE: SSDPSRV C:\WINDOWS\System32\svchost.exe -k LocalService WEBCLIENT: WebClient C:\WINDOWS\System32\svchost.exe -k LocalService NORTON ANTIVIRUS AUTO PROTECT SERVICE: navapsvc "C:\Program Files\Norton AntiVirus\navapsvc.exe" NORTON PERSONAL FIREWALL ACCOUNTS MANAGER: NISUM C:\Program Files\Norton Personal Firewall\NISUM.EXE NORTON UNERASE PROTECTION: NProtectService "C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE" IPSEC SERVICES: PolicyAgent C:\WINDOWS\System32\lsass.exe PROTECTED STORAGE: ProtectedStorage C:\WINDOWS\system32\lsass.exe SECURITY ACCOUNTS MANAGER: SamSs C:\WINDOWS\system32\lsass.exe REMOTE PROCEDURE CALL (RPC): RpcSs C:\WINDOWS\system32\svchost -k rpcss SPEED DISK SERVICE: Speed Disk service C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe PRINT SPOOLER: Spooler C:\WINDOWS\system32\spoolsv.exe WINDOWS IMAGE ACQUISITION (WIA): stisvc C:\WINDOWS\System32\svchost.exe -k imgsvc WAN MINIPORT (ATW) SERVICE: WANMiniportService "C:\WINDOWS\wanmpsvc.exe"
Let's see how it clears up.

Click here to download Spybot Search & Destroy - install, update, scan and fix all RED items it finds. Reboot when done.

Click here to download Ad-Aware and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Then click the gear wheel at the top and check these options:

General> activate these: "Automatically save log-file" and "Automatically quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Click "Proceed" to save your settings, then click "Start", make sure "Activate in-depth scan" is ticked green then scan your system. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done.

Create a new folder called C:\HijackThis, move the HijackThis.exe file into the new folder and run it from there. This is necessary to ensure you have backups should anything go wrong.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {05D4D108-3672-4318-83A8-4FF1ACC77082} - (no file)
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\digfilt.dll

Click on Config then click on Misc Tools. At the new screen click on the "Delete a file on reboot" button. You will be presented with a dialog asking you to pick a file. Copy and paste C:\WINDOWS\digfilt.dll into the file name field and press the open button.

Hijackthis will prompt you to reboot, please do so. Rescan with HJT and post a new log here for a final check over.
Logfile of HijackThis v1.98.2
Scan saved at 7:12:05 PM, on 8/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = www.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [0000 - C:\Documents and Settings\Raymond\Start Menu\Programs\HP DeskJet 930C Series v2.3] C:\WINDOWS\SYSTEM32\command.com /c rmdir "C:\Documents and Settings\Raymond\Start Menu\Programs\HP DeskJet 930C Series v2.3"
O4 - HKLM\..\RunOnce: [0003 - C:\Documents and Settings\Raymond\Start Menu\Programs\HP Internet Connection Center] C:\WINDOWS\SYSTEM32\command.com /c rmdir "C:\Documents and Settings\Raymond\Start Menu\Programs\HP Internet Connection Center"
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall…w.viewpoint.com
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.soundclick.com/CFIDE/classes/CFJava.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
Yes. Everything looks back to normal and is running great. Thanx a lot for the help. I really appreciate what you do for other people like myself who have trouble. Thanx again. =)
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI