This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Adaware keeps showing adrotator and begin2search toolbar exists

Logfile of HijackThis v1.98.2
Scan saved at 6:54:46 PM, on 9/20/04
Platform: Windows NT 4 SP6 (WinNT 4.00.1381)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolss.exe
C:\WINNT\System32\cusrvc.exe
C:\WINNT\system32\RpcSs.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
c:\winnt\system32\pstores.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\nddeagnt.exe
C:\WINNT\System32\NWTRAY.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Microsoft Office\Office\findfast.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\dpmw32.exe
Q:\Drivers and Patches\Utilities\Diagnosis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/googlesidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/googlesidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:80
R3 - URLSearchHook: (no name) - {F820DE09-0F75-AA7A-9292-929570741286} - C:\WINNT\Uwllinvw.dll
F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:\Program Files\Recommended Hotfix - 421701D\v15\RH.DLL
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINNT\SYSTEM32\winb2s32.dll
O2 - BHO: (no name) - {E163880C-BCA8-1F49-667B-7638F4B0B6CF} - C:\WINNT\Uwllinvw.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINNT\SYSTEM32\winb2s32.dll
O3 - Toolbar: Search - {575DFEB6-1CDC-0054-7382-A15AB896855C} - C:\WINNT\Uwllinvw.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /logon
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKCU\..\Run: [Mmgsvc] C:\WINNT\mmgsvc.exe
O4 - Startup: Microsoft Outlook.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O13 - WWW. Prefix: http://
jeffmarshall – Your HijackThis logfile looks incomplete. Normally, there are entries in the O16 category, and the O13 n your log looks like it was 'cut off' Please create another logfile and paste it into a reply to this message (in this thread). I'll be automatically notified when that happens. Thanks daveai
I've run this several times and it stops this way each time. I've successfully gotten rid of everything except the adrotator… Thanks for your help.. Logfile of HijackThis v1.98.2 Scan saved at 8:58:52 PM, on 9/20/04 Platform: Windows NT 4 SP6 (WinNT 4.00.1381) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\spoolss.exe C:\WINNT\System32\cusrvc.exe C:\WINNT\system32\RpcSs.exe C:\Program Files\RealVNC\WinVNC\WinVNC.exe c:\winnt\system32\pstores.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\nddeagnt.exe C:\WINNT\Explorer.EXE C:\WINNT\System32\dpmw32.exe C:\WINNT\System32\NWTRAY.EXE C:\Program Files\Microsoft Hardware\Mouse\point32.exe C:\Program Files\Microsoft Office\Office\findfast.exe C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Q:\Drivers and Patches\Utilities\Diagnosis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:80 R3 - URLSearchHook: (no name) - {F820DE09-0F75-AA7A-9292-929570741286} - C:\WINNT\Uwllinvw.dll F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:\Program Files\Recommended Hotfix - 421701D\v15\RH.DLL O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINNT\SYSTEM32\winb2s32.dll O2 - BHO: (no name) - {E163880C-BCA8-1F49-667B-7638F4B0B6CF} - C:\WINNT\Uwllinvw.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINNT\SYSTEM32\winb2s32.dll O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exe O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /logon O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper O4 - HKCU\..\Run: [Mmgsvc] C:\WINNT\mmgsvc.exe O4 - Startup: Microsoft Outlook.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O13 - WWW. Prefix: http://
jeffmarshall – Thanks for sending your HijackThis log. I appreciate you taking the time to make sure for me.


Since you will not be able to access this page in safe mode during this fix, please print these instructions now, or save them to your desktop, to help keep track of the steps.


To start, allow yourself to view "Hidden files". Open Windows Explorer and go to "Tools" => "Folder Options" => "View" then click on the "Show Hidden Files and Folders" option, and un-check "Hide extensions for known file types" and "Hide protected operating system files" options. Then click the "Apply To All Folders" button.


1 – Reboot into Safe Mode (How do I boot into "Safe" mode?).


2 – Use Windows Explorer to open the 'Downloaded Program Files' folder in the Windows folder. Look for the following objects,and for any that you find, right-click the object, then click 'Remove':

'I-Lookup.com Bar'
'GlobalWebSearch.com Bar'
'SearchBus.com Bar'
'GlobalToolbar.com Bar'
'Search Bar'


3 – Next, use Control Panel > Add/Remove Programs to remove any of the following malware that it finds:

"SmartPops" or
"Network Essentials".


4 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up. Make sure all browsers and program windows are closed except for HijackThis.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - URLSearchHook: (no name) - {F820DE09-0F75-AA7A-9292-929570741286} - C:\WINNT\Uwllinvw.dll

O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:\Program Files\Recommended Hotfix - 421701D\v15\RH.DLL
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINNT\SYSTEM32\winb2s32.dll
O2 - BHO: (no name) - {E163880C-BCA8-1F49-667B-7638F4B0B6CF} - C:\WINNT\Uwllinvw.dll

O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINNT\SYSTEM32
\winb2s32.dll

O4 - HKCU\..\Run: [Mmgsvc] C:\WINNT\mmgsvc.exe

O13 - WWW. Prefix: http://

And, this is an optional item you may choose to fix:

Office Startup Asistant is an optional item that if checked, will eliminate a known resource hog. You will still be able to start Office components from the Start menu. This is the item to fix in HJT:
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

Once you have selected all the items for HJT to fix, make sure all browsers and program windows are closed except for HijackThis, and click fix checked.


5 – While still in safe mode, use Windows Explorer to delete the following lists of program files and folders, if they still exist.

C:\WINNT\Uwllinvw.dll <– this file (may already be gone)
C:\WINNT\mmgsvc.exe <– this file

C:\WINNT\SYSTEM32\winb2s32.dll <– this file (may already be gone)

C:\Program Files\Recommended Hotfix - 421701D\ <– this folder

Please let me know about any problems with the file/folder deletes.


5 – Next, use "Start > Run" and type in "%temp%" (without the quotes). Delete the entire contents of that "temp" folder (use "Edit > Select All", press "Delete", click "Yes").

Then, Empty your Temporary Internet Cache completely. Close all instances of Outlook and and Internet Explorer, then use "Control Panel > Internet Options > General tab" and click the "Delete File" button. When prompted place a check in: "Delete all offline content", then click OK.

Then, use Windows Explorer to clean out ALL the other temp folders on your system (navigate to the folder, use "Edit > Select All", press "Delete", click "Yes"):

* C:\Documents and Settings\\Local Settings\Temp\
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\\Local Settings\Temp\
* Empty your "Recycle Bin".

Please let me know about any problems with the temp file deletes.


6 – Then reboot normally, and run either of these two Online virus scans: Panda Active Scan or TrendMicro Housecall and put on Auto Clean.


Please let me know if anything can not be cleaned by these utilities.



Now, reboot normally once more, and we'll take another look at your system.

Please run HijackThis to create a new logfile. Repost it here, and if you had any problems with the steps outlined above, please let us know what they were. Your response and the new logfile will determine the next steps for this fix.



Meanwhile, I could not help noticing that you seem to be running zero real-time protection software on your system.

So, please allow me to suggest some prevention steps to keep your computer clean and secure going forward. You may have already taken a few of the steps, but it never hurts to take a quick look :)

I recommend you implement the suggestions in #1 and #2 immediately.

1 – Use an AntiVirus Software, and be sure you update it at least once a week. There are several very good free programs available. Grinler offers an outstanding overview at Virus, Spyware, and Malware Protection and Removal Resources

2 – To reduce re-infection potential for malware in the future, I strongly recommend installing three free programs: SpywareBlaster, SpywareGuard, and IE/Spyad.

3 – Use AdAware SE and Spybot S&D; to regularly to scan your system.

4 – It is very important to make sure that both Internet Explorer and XP are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

5 – Consider using a Firewall. Just by using a Firewall in its default configuration can lower your risk greatly. Check out what Lawrence Abrams has to say at Understanding and Using Firewalls

An excellent overview is: So how did I get infected in the first place?. Be sure to visit the browser test link at the end of the article to really see how secure your system is!!

Thanks
daveai

Thanks
daveai
I thought everything was good, but after running adaware, here is the new log file. Of note… when I run adaware I get 4 AdRotator alerts in the registry.


Logfile of HijackThis v1.98.2
Scan saved at 6:58:33 PM, on 9/21/04
Platform: Windows NT 4 SP6 (WinNT 4.00.1381)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolss.exe
C:\WINNT\System32\cusrvc.exe
C:\WINNT\system32\RpcSs.exe
C:\Program Files\RealVNC\WinVNC\WinVNC.exe
c:\winnt\system32\pstores.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\nddeagnt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\dpmw32.exe
C:\WINNT\System32\NWTRAY.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINNT\System32\ddhelp.exe
C:\WINNT\Profiles\Administrator\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:80
F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NDPS] C:\WINNT\System32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /logon
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - Startup: Microsoft Outlook.lnk = ?
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Thanks The log looks clean to me. What can you tell me about the AdAware alerts. Can you copy/paste them fromthe log? I'll take a look in the morning. Thanks daveai
Glad we could be of assistance. This topic is now closed. If you wish it
reopened, please send us an email (Click here to email) with a link to your thread.


Donations in support of this Web Site are always appreciated

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI