This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me with this have tried to remove "Search For" and "Cool search" using a variety of progs including CW shredder but they keep coming back esp when i get near to downloading XP 2
thanks martin

Logfile of HijackThis v1.98.2
Scan saved at 21:11:24, on 10/09/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\sg3ftgjjhe3a2.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Archivos de programa\Spyware Doctor\spydoctor.exe
C:\WINDOWS\System32\wuauclt.exe
C:\CW Shedder\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = VĂ­nculos
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\odpz64fcd5.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 7
O4 - HKLM\..\Run: [Network Security Guard] C:\WINDOWS\System32\sg3ftgjjhe3a2.exe
O4 - HKLM\..\Run: [cleaner] C:\WINDOWS\System32\03aocmoefil6.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Archivos de programa\Spyware Doctor\spydoctor.exe" /Q
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\MSMSGS.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{4F8CEB61-61E7-4C6C-884D-3E91242D6285}: NameServer = 80.58.4.33 80.58.34.97
Reboot in SAFE MODE. If you don't know how click here

Close all Browser and Program Windows and have HijackThis fix the following by checking the box beside each and then clicking on Fix checked.
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\System32\odpz64fcd5.dll
O4 - HKCU\..\Run: [romahere] C:\WINDOWS\System32\matrixhere.exe
O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dll


Delete the following files not the folders
C:\WINDOWS\System32\odpz64fcd5.dll
C:\WINDOWS\System32\matrixhere.exe

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

run CWShredder to clean up clicking "FIX" to have it remove all it finds.


Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Many thanks little Eagle, hard to tell how my computer is acting as i have had a chip set failure lost half of the RAM the box was always underpowered i am awaing delivery of new RAM/chip set. That apart it seems to be working better but maybe that is due to me unloading Progs, i have run another scan with trend "house calls" it says i have a the following viruses a worm called "Nachid" and a Trojan called "Disseca". i will go back into web and see if it starts "hijacking" my browser again. I had also already fixed some of the Hijack this boxes (sheer desperation) ie (romahere) as it repicated itself and looked highly sus prior to your message. I will go and look for "Nachid" and a Trojan called "Disseca", and see what they are, hope to hear from you soon. many thanks and best wishes martin Logfile of HijackThis v1.98.2 Scan saved at 13:29:07, on 13/09/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\System32\atievxx.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\ctfmon.exe C:\Archivos de programa\Spyware Doctor\spydoctor.exe C:\CW Shedder\Hijack this\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = VĂ­nculos O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 7 O4 - HKLM\..\Run: [cleaner] C:\WINDOWS\System32\03aocmoefil6.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [Spyware Doctor] "C:\Archivos de programa\Spyware Doctor\spydoctor.exe" /Q O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
Dear little Eagle I have just been back into "House Call" and it shows the system as clean. For your info i do have two Norton products "System works Pro 2004" and "Personal firewall" but i have had to un install as they take to much of my temporary limited system resources, they also do not seem to either pick up or avoid the problems that i have had and or correct them as i have been running them from disc only. It does seem that for the moment i am not getting the "hijacking" i am going to try and download xp patch sp1a to block the entry and then xp 2 although they will probabley take up more of my limited resources. More later thanks again martin
:) Many thanks to Little Eagle thank you for all your help Little Eagle, looks like i am in the clear with no more hijack problems just the wait for more RAM, i will take your advice and hold of for the time being on download of Sp2 as i will need more memory for it. Once again many many thanks for your help Very best wishes from martin in Spain.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI