This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Coworker's Hjt Log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My coworker is getting pop-up galore. Here is the log

Logfile of HijackThis v1.97.7
Scan saved at 8:59:57 AM, on 9/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\System32\cusrvc.exe
C:\PROGRA~1\NavNT\DefWatch.exe
c:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\PROGRA~1\NavNT\rtvscan.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
c:\Program Files\Novell\ZENworks\wm.exe
C:\XPAPPS\PCOMM\PCS_AGNT.EXE
c:\WINDOWS\System32\drivers\ldlcserv.exe
C:\XPAPPS\PCOMM\tpattmgr.exe
c:\Program Files\Novell\ZENworks\WMRUNDLL.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\System32\NWTRAY.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\documents and settings\i03303c\local settings\temp\Ss4.exe
C:\WINDOWS\System32\IEHost.exe
C:\WINDOWS\System32\qistiwi.exe
C:\documents and settings\i03303c\local settings\temp\Ss4.exe
C:\documents and settings\i03303c\local settings\temp\gu.exe
C:\WINDOWS\System32\cmpbk328.exe
C:\Program Files\Novell\ZENworks\NALDESK.EXE
C:\WINDOWS\System32\weventn.exe
C:\WINDOWS\System32\cmpi.exe
Y:\clntrust.exe
C:\NTAPPS\notes\HCSCNOTE.EXE
C:\NTAPPS\notes\nlnotes.exe
C:\WINDOWS\SYSTEM32\wscript.exe
C:\NTAPPS\notes\nhldaemn.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
W:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.fyiblue.com/side.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.fyiblue.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.fyiblue.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://home.fyiblue.com/_config/xpupdate.ins
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C:\WINDOWS\System32\mskhhe.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {80672997-D58C-4190-9843-C6C61AF8FE97} - C:\WINDOWS\rundll16.dll (file missing)
O2 - BHO: (no name) - {94927A13-4AAA-476A-989D-392456427688} - C:\WINDOWS\System32\msjfbl.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\i03303c\Local Settings\Temp\eL.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] c:\WINDOWS\System32\zentray.exe
O4 - HKLM\..\Run: [Ss4.exe] C:\documents and settings\i03303c\local settings\temp\Ss4.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost.exe
O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe
O4 - HKLM\..\Run: [sylxdoij] C:\WINDOWS\System32\qistiwi.exe
O4 - HKLM\..\Run: [Ss4] C:\documents and settings\i03303c\local settings\temp\Ss4.exe
O4 - HKLM\..\Run: [gu.exe] C:\documents and settings\i03303c\local settings\temp\gu.exe
O4 - HKLM\..\Run: [10d496352462] C:\WINDOWS\System32\cmpbk328.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [weventn] C:\WINDOWS\System32\weventn.exe
O4 - HKLM\..\Run: [cmpi] C:\WINDOWS\System32\cmpi.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NALDESK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: SideStep (HKLM)
O9 - Extra button: Novell delivered applications (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.fyiblue.com
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.sidestep.com/get/k00719/sb028.cab
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) - http://static.flingstone.com/cab/2000XP/CDTInc/bridge.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
You have the Peper Trojan. It is a very stubborn infection which requires a specific tool to remove. There are two tools available. Please follow these instructions in order:

1. Download Newuninst.exe.

2. Run it with an active internet connection.

3. Reboot to finish removing the entries it found.

4. Run the tool a second time (with an active internet connection).

5. Reboot to finish removing the entries it found.


The second tool which does not require Internet Access to Clean is:

1. Please Download PeperFix.exe,

2. Start the tool and click Find and Fix.

3. Reboot to finish removing what it found.

4. Run the tool a second time (again with an active internet connection).

5. Reboot to finish removing the entries.

Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed

Then post another log.
There is a newer of HijackThis
Download "HijackThis" here
When downloading, choose "save to disk" and NOT open!

Now create a new folder for it, C:\Hijackthis, for example.
After unzipping the file. to C:\Hijack This, you'll end up with the file itself, which is Hijackthis.exe, and that's the one you'll need to doubleclick.'

When the program launches, hit the "Scan" button
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, and save the log anywhere you like.

Now if you doubleclick the log file.Go to Edit > Select all, then to Edit > copy.
Now you've copied the entire text to the Windows Clipboard (this happens behind your back.)

Next, go back to this forum thread, and click "Add Reply".
In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.
Downloaded and ran Newuninst.exe twice. New log here:

Logfile of HijackThis v1.98.2
Scan saved at 9:47:17 AM, on 9/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\System32\cusrvc.exe
C:\PROGRA~1\NavNT\DefWatch.exe
c:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\PROGRA~1\NavNT\rtvscan.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
c:\Program Files\Novell\ZENworks\wm.exe
C:\XPAPPS\PCOMM\PCS_AGNT.EXE
c:\WINDOWS\System32\drivers\ldlcserv.exe
C:\XPAPPS\PCOMM\tpattmgr.exe
c:\Program Files\Novell\ZENworks\WMRUNDLL.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\System32\NWTRAY.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\documents and settings\i03303c\local settings\temp\Ss4.exe
C:\WINDOWS\System32\IEHost.exe
C:\WINDOWS\System32\qistiwi.exe
C:\documents and settings\i03303c\local settings\temp\Ss4.exe
C:\documents and settings\i03303c\local settings\temp\gu.exe
C:\WINDOWS\System32\cmpbk328.exe
C:\Program Files\Novell\ZENworks\NALDESK.EXE
Y:\clntrust.exe
C:\WINDOWS\System32\pcupsa.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\HLWAPIS.exe
C:\Documents and Settings\i03303c\Desktop\HJT\HIJACK~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.fyiblue.com/side.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.fyiblue.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.fyiblue.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://home.fyiblue.com/_config/xpupdate.ins
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C:\WINDOWS\System32\mskhhe.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IAdvertisementBHO Class - {80672997-D58C-4190-9843-C6C61AF8FE97} - C:\WINDOWS\rundll16.dll (file missing)
O2 - BHO: CUrlCliObj Object - {94927A13-4AAA-476A-989D-392456427688} - C:\WINDOWS\System32\msjfbl.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\i03303c\Local Settings\Temp\eL.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] c:\WINDOWS\System32\zentray.exe
O4 - HKLM\..\Run: [Ss4.exe] C:\documents and settings\i03303c\local settings\temp\Ss4.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost.exe
O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe
O4 - HKLM\..\Run: [sylxdoij] C:\WINDOWS\System32\qistiwi.exe
O4 - HKLM\..\Run: [Ss4] C:\documents and settings\i03303c\local settings\temp\Ss4.exe
O4 - HKLM\..\Run: [gu.exe] C:\documents and settings\i03303c\local settings\temp\gu.exe
O4 - HKLM\..\Run: [10d496352462] C:\WINDOWS\System32\cmpbk328.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [pcupsa] C:\WINDOWS\System32\pcupsa.exe
O4 - HKLM\..\Run: [HLWAPIS] C:\WINDOWS\System32\HLWAPIS.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NALDESK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - c:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.fyiblue.com
O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.sidestep.com/get/k00719/sb028.cab
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) - http://static.flingstone.com/cab/2000XP/CDTInc/bridge.cab
http://home.fyiblue.com << Program Files\Novell And do you know anything program?

Close all Browser and Program Windows and have HijackThis fix the following by checking the box beside each and then clicking on Fix checked.

O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C7B0B1015808} - C:\WINDOWS\System32\mskhhe.dll
O2 - BHO: IAdvertisementBHO Class - {80672997-D58C-4190-9843-C6C61AF8FE97} - C:\WINDOWS\rundll16.dll (file missing)
O2 - BHO: CUrlCliObj Object - {94927A13-4AAA-476A-989D-392456427688} - C:\WINDOWS\System32\msjfbl.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\i03303c\Local Settings\Temp\eL.dll

O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost.exe
O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\System32\dp-him.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKLM\..\Run: [10d496352462] C:\WINDOWS\System32\cmpbk328.exe

O16 - DPF: {0837121A-6472-43BD-8A40-D9221FF1C4CE} - http://download.sidestep.com/get/k00719/sb028.cab
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) - http://static.flingstone.com/cab/2000XP/CDTInc/bridge.cab

The following have randomly named file names, and as such are normally malware, UNLESS you know what they are, and they are from a safe source,
please check for removal.

O4 - HKLM\..\Run: [Ss4.exe] C:\documents and settings\i03303c\local settings\temp\Ss4.exe
O4 - HKLM\..\Run: [sylxdoij] C:\WINDOWS\System32\qistiwi.exe
O4 - HKLM\..\Run: [Ss4] C:\documents and settings\i03303c\local settings\temp\Ss4.exe
O4 - HKLM\..\Run: [gu.exe] C:\documents and settings\i03303c\local settings\temp\gu.exe
O4 - HKLM\..\Run: [pcupsa] C:\WINDOWS\System32\pcupsa.exe
O4 - HKLM\..\Run: [HLWAPIS] C:\WINDOWS\System32\HLWAPIS.exe

Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following files and folder listed

C:\WINDOWS\System32\IEHost.exe << C:\WINDOWS\System32\dp-him.exe << C:\WINDOWS\wupdt.exe << C:\PROGRA~1\CLOCKS~1\Sync.exe /q << C:\WINDOWS\System32\cmpbk328.exe << C:\documents and settings\i03303c\local settings\temp\Ss4.exe << C:\WINDOWS\System32\qistiwi.exe << C:\documents and settings\i03303c\local settings\temp\Ss4.exe << C:\documents and settings\i03303c\local settings\temp\gu.exe << C:\WINDOWS\System32\pcupsa.exe << C:\WINDOWS\System32\HLWAPIS.exe <<

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Yes, that is our homepage.
Novell is our logon authentication application http://www.novell.com


I did as you asked. Here is the latest log:

Logfile of HijackThis v1.98.2
Scan saved at 1:10:20 PM, on 9/20/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\System32\cusrvc.exe
C:\PROGRA~1\NavNT\DefWatch.exe
c:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\PROGRA~1\NavNT\rtvscan.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
C:\XPAPPS\PCOMM\PCS_AGNT.EXE
c:\Program Files\Novell\ZENworks\wm.exe
c:\WINDOWS\System32\drivers\ldlcserv.exe
C:\XPAPPS\PCOMM\tpattmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\System32\NWTRAY.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\WINDOWS\System32\qistiwi.exe
C:\Program Files\Novell\ZENworks\NALDESK.EXE
Y:\clntrust.exe
C:\WINDOWS\System32\dpddr.exe
C:\WINDOWS\System32\pengl32o.exe
C:\WINDOWS\SYSTEM32\wscript.exe
C:\Documents and Settings\i03303c\Desktop\HJT\HIJACK~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.fyiblue.com/side.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.fyiblue.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.fyiblue.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://home.fyiblue.com/_config/xpupdate.ins
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] c:\WINDOWS\System32\zentray.exe
O4 - HKLM\..\Run: [tipuqyswunan] C:\WINDOWS\System32\qistiwi.exe
O4 - HKLM\..\Run: [dpddr] C:\WINDOWS\System32\dpddr.exe
O4 - HKLM\..\Run: [pengl32o] C:\WINDOWS\System32\pengl32o.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NALDESK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - c:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.fyiblue.com
O18 - Filter: text/html - {CC905FF6-B553-496C-9DFA-CFF65ADCD0FC} - C:\WINDOWS\System32\msdhmd.dll

Thanks for your help!!
Close all Browser and Program Windows and have HijackThis fix the following by checking the box beside each and then clicking on Fix checked.

O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com

O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll

O4 - HKLM\..\Run: [tipuqyswunan] C:\WINDOWS\System32\qistiwi.exe

O18 - Filter: text/html - {CC905FF6-B553-496C-9DFA-CFF65ADCD0FC} - C:\WINDOWS\System32\msdhmd.dll


Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following files and folder listed

C:\WINDOWS\System32\qistiwi.exe<<
C:\WINDOWS\System32\msdhmd.dll <<

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed

Then run System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Thank you so much for hrlping with this. I have been all over the tutorials for HJT and hope to get comfortable with these logs soon.

Here is the lates log:

Logfile of HijackThis v1.98.2
Scan saved at 8:23:48 AM, on 9/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\System32\cusrvc.exe
C:\PROGRA~1\NavNT\DefWatch.exe
c:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\XPAPPS\PCOMM\PCS_AGNT.EXE
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
c:\Program Files\Novell\ZENworks\wm.exe
c:\WINDOWS\System32\drivers\ldlcserv.exe
C:\XPAPPS\PCOMM\tpattmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\System32\NWTRAY.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\Program Files\Novell\ZENworks\NALDESK.EXE
C:\WINDOWS\System32\dshostr.exe
C:\WINDOWS\System32\sadomdm.exe
Y:\clntrust.exe
C:\WINDOWS\SYSTEM32\wscript.exe
C:\Documents and Settings\i03303c\Desktop\HJT\HIJACK~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.fyiblue.com/side.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.fyiblue.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.fyiblue.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://home.fyiblue.com/_config/xpupdate.ins
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] c:\WINDOWS\System32\zentray.exe
O4 - HKLM\..\Run: [zvwljmdc] C:\WINDOWS\System32\qistiwi.exe
O4 - HKLM\..\Run: [dshostr] C:\WINDOWS\System32\dshostr.exe
O4 - HKLM\..\Run: [sadomdm] C:\WINDOWS\System32\sadomdm.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NALDESK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - c:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.fyiblue.com


The one in Red above was deleted but reappeared.
Close all Browser and Program Windows and have HijackThis fix the following by checking the box beside each and then clicking on Fix checked.

O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O4 - HKLM\..\Run: [zvwljmdc] C:\WINDOWS\System32\qistiwi.exe
O4 - HKLM\..\Run: [dshostr] C:\WINDOWS\System32\dshostr.exe
O4 - HKLM\..\Run: [sadomdm] C:\WINDOWS\System32\sadomdm.exe

Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following files and folder listed

C:\WINDOWS\System32\qistiwi.exe<< C:\WINDOWS\System32\dshostr.exe<< C:\WINDOWS\System32\sadomdm.exe <<

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then run System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Little Eagle, you ROCK.

PC seems to be running great with NO POP-UPS!!! Here is the latest log:

Logfile of HijackThis v1.98.2
Scan saved at 10:47:55 AM, on 9/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\System32\cusrvc.exe
C:\PROGRA~1\NavNT\DefWatch.exe
c:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\PROGRA~1\NavNT\rtvscan.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
c:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
c:\Program Files\Novell\ZENworks\wm.exe
C:\XPAPPS\PCOMM\PCS_AGNT.EXE
c:\WINDOWS\System32\drivers\ldlcserv.exe
C:\XPAPPS\PCOMM\tpattmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\System32\NWTRAY.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\Program Files\Novell\ZENworks\NALDESK.EXE
Y:\clntrust.exe
C:\WINDOWS\SYSTEM32\wscript.exe
C:\Documents and Settings\i03303c\Desktop\HJT\HIJACK~1.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.fyiblue.com/side.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.fyiblue.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.fyiblue.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://home.fyiblue.com/_config/xpupdate.ins
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] c:\WINDOWS\System32\zentray.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NALDESK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINDOWS\Downloaded Program Files\SbCIe028.dll
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - c:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.fyiblue.com

:thumbup:
One more. ;)

Close all Browser and Program Windows and have HijackThis fix the following by checking the box beside each and then clicking on Fix checked.

O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe

Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following files and folder listed

C:\WINDOWS\wupdt.exe <<

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Please read through the ideas and free software listed below that will help to keep your computer clean.
Some of these you may have install or may have done already.

Install a firewall.ZoneAlarm FREE

Ensure that an Antivirus is updated weekly and running. AVG antivirus from Grisoft is a very good FREE antivirus program.

Make sure you have the latest critical updates from windows update.

SpywareBlaster will prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.

IE-SPYAD puts over 4000 known 'bad' sites into your IE restricted zone so that they cannot install malware on your PC.

Google toolbar has a very good built in popup blocker with a nice search bar. To provide privacy, select disable advanced features when installing.

Check your system for latest virus definitions with an online virus scan every week or two.
TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan

Check your system for latest trojan definitions with an Online trojan scan also every week or two.

And also see this link for additional security information.
So how did I get infected in the first place?

Please consider using Firefox
http://texturizer.net/firefox/index.html

Do not let any site install anything if you do not know what it is.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI