This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help With Browser Hijack

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I have run spybot many times…it finds something everytime after start -up; however, popups keep appearing throughout the day. They seem to replicate themselves even after they have been deleted.

Here is my HiJack log……Any help is greatly appreciated.

Thanks

Tabb

Logfile of HijackThis v1.98.2
Scan saved at 3:20:30 PM, on 9/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\apvxdwin.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\documents and settings\administrator\local settings\temp\J.exe
C:\documents and settings\administrator\local settings\temp\BPgjto.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\WINDOWS\System32\dmuadu.exe
C:\WINDOWS\System32\avicap32.exe
C:\documents and settings\administrator\local settings\temp\Ci3kLqC.exe
C:\WINDOWS\System32\avtapi90.exe
C:\documents and settings\administrator\local settings\temp\IKQ8m8OlJ.exe
C:\documents and settings\administrator\local settings\temp\SC.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\doscerpt.exe
C:\PROGRA~1\Web Offer\wo.exe
C:\Program Files\Omega Research\Program\orschd.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\WINDOWS\System32\Yfwz.exe
C:\WINDOWS\System32\Akhw.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HiJackThis-GOOD\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.elocaltrading.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\spe\start.chm::/start.html#
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\jtgXbu.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [J.exe] C:\documents and settings\administrator\local settings\temp\J.exe
O4 - HKLM\..\Run: [BPgjto.exe] C:\documents and settings\administrator\local settings\temp\BPgjto.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [4#6Q9Q53HK#GHC] C:\WINDOWS\System32\WnwExd.exe
O4 - HKLM\..\Run: [5sFT35O] dmuadu.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [bae5c3e65007] C:\WINDOWS\System32\avicap32.exe
O4 - HKLM\..\Run: [Ci3kLqC.exe] C:\documents and settings\administrator\local settings\temp\Ci3kLqC.exe
O4 - HKLM\..\Run: [108fba256c56] C:\WINDOWS\System32\avtapi90.exe
O4 - HKLM\..\Run: [IKQ8m8OlJ.exe] C:\documents and settings\administrator\local settings\temp\IKQ8m8OlJ.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [SC.exe] C:\documents and settings\administrator\local settings\temp\SC.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [KBw3RRi5O] doscerpt.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Omega Research Task Scheduler.lnk = C:\Program Files\Omega Research\Program\orschd.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file)
O9 - Extra button: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file) (HKCU)
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix: http://www.heretofind.com/show.php?id=18&q=
O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=18&q=
O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=18&q=
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://208.62.27.145/TSCOM_TOOL/IFTWCLIENTS/IFTWCLIX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096377303046
O16 - DPF: {6BA1270C-B969-4234-B827-7B3BBB4F5FFC} - http://63.99.207.62/builds//build1563/install.cab
O16 - DPF: {7CEEAB76-D59E-11D3-8394-00C04F7BDF10} (Application Class) - http://www.tradestation.com/tscom/ClientPlugIn/tsTemp.cab
Welcome to the forum. :D

You have a few things going on in there so lets get started.

Step 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/download4086.html

Scan with hijackthis and put a check beside these lines and choose FIX.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q;=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.heretofind.com/show.php?id=18&q;=%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\spe\start.chm::/start.html#
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O9 - Extra button: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file)
O9 - Extra button: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {D19AB298-BADA-464A-8460-F4257664ED87} - (no file) (HKCU)

O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix: http://www.heretofind.com/show.php?id=18&q;=
O13 - Mosaic Prefix: http://www.heretofind.com/show.php?id=18&q;=
O13 - Gopher Prefix: http://www.heretofind.com/show.php?id=18&q;=


Delete the directory c:\spe

Click on START –> CONTROL PANNEL –> INTERNET OPTIONS —> DELETE FILES –> Put the check on DELETE ALL OFFLINE CONTENTS.
Next, DELETE COOKIES and then Clear Histories.

Then Reboot.

Step 2

Go to add/remove programs and look for and remove these if present.

Web Offer
TV Media

Step 3

You have a peper infection that we need to remove

http://www.memorywatcher.com/uninst.exe

When you run the uninstaller, you MUST have an internet connection active for it to work

This Peper removal tool only works if run twice. To complete each stage of the Peper removal you need to REBOOT to clear the peper infection each time you run the tool, or the infection will remain.


REBOOT

Step 4

Please download and run Spybot Search & Destroy and AdAware SE . Then follow the instructions in the links below to run.

Spybot Tutorial

AdAware Tutorial

Step 5

Please empty all you temp folders. DO NOT DELETE THE FOLDERS ONLY THE CONTENTS.
C:\WINDOWS\Temp\ CONTENTS
C:\Temp\ CONTENTS
C:\Documents and Settings\username\Local Settings\Temp\ CONTENTS
Also delete your Temporary Internet Files Tools>InternetOptions delete all cookies, files as well as offline files. Also make sure that you clean out your recycle bin.

Reboot and post a new HiJackThis log. There will be more to remove in the next step mostly clean up ;)
Hi,

I ran all your initial fixes and here is the latest HiJack log….

Thanks for all of your help…..

Tabb



Logfile of HijackThis v1.98.2
Scan saved at 10:40:40 AM, on 10/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\apvxdwin.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\avicap32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Omega Research\Program\orschd.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\HiJackThis-GOOD\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.elocaltrading.com/
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\qHvqhiN.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [bae5c3e65007] C:\WINDOWS\System32\avicap32.exe
O4 - HKLM\..\Run: [SC.exe] C:\documents and settings\administrator\local settings\temp\SC.exe
O4 - HKLM\..\Run: [IKQ8m8OlJ.exe] C:\documents and settings\administrator\local settings\temp\IKQ8m8OlJ.exe
O4 - HKLM\..\Run: [Ci3kLqC.exe] C:\documents and settings\administrator\local settings\temp\Ci3kLqC.exe
O4 - HKLM\..\Run: [BPgjto.exe] C:\documents and settings\administrator\local settings\temp\BPgjto.exe
O4 - HKLM\..\Run: [J.exe] C:\documents and settings\administrator\local settings\temp\J.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [5sFT35O] dmuadu.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [KBw3RRi5O] doscerpt.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Omega Research Task Scheduler.lnk = C:\Program Files\Omega Research\Program\orschd.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://208.62.27.145/TSCOM_TOOL/IFTWCLIENTS/IFTWCLIX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096377303046
O16 - DPF: {6BA1270C-B969-4234-B827-7B3BBB4F5FFC} - http://63.99.207.62/builds//build1563/install.cab
O16 - DPF: {7CEEAB76-D59E-11D3-8394-00C04F7BDF10} (Application Class) - http://www.tradestation.com/tscom/ClientPlugIn/tsTemp.cab
:thumbup: Looking much better.

Please boot to safe mode (tap f8 while bios loads) then scan again with hijackthis and put a check beside these lines and choose FIX.

R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)

O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Administrator\Local Settings\Temp\qHvqhiN.dll (file missing)

O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll (file missing)

O4 - HKLM\..\Run: [bae5c3e65007] C:\WINDOWS\System32\avicap32.exe
O4 - HKLM\..\Run: [SC.exe] C:\documents and settings\administrator\local settings\temp\SC.exe
O4 - HKLM\..\Run: [IKQ8m8OlJ.exe] C:\documents and settings\administrator\local settings\temp\IKQ8m8OlJ.exe
O4 - HKLM\..\Run: [Ci3kLqC.exe] C:\documents and settings\administrator\local settings\temp\Ci3kLqC.exe
O4 - HKLM\..\Run: [BPgjto.exe] C:\documents and settings\administrator\local settings\temp\BPgjto.exe
O4 - HKLM\..\Run: [J.exe] C:\documents and settings\administrator\local settings\temp\J.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [KBw3RRi5O] doscerpt.exe
O4 - HKLM\..\Run: [5sFT35O] dmuadu.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\Run: [KBw3RRi5O] doscerpt.exe

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096377303046

Then while still in safe mode delete these files(some may be gone because of hijackthis removal) you will need to show hidden files tutorial here >>> http://www.microsoft.com/windowsxp/using/h…iddenfiles.mspx

C:\WINDOWS\System32\avicap32.exe<< C:\documents and settings\administrator\local settings\temp\SC.exe<< C:\documents and settings\administrator\local settings\temp\IKQ8m8OlJ.exe<< C:\documents and settings\administrator\local settings\temp\Ci3kLqC.exe<< C:\documents and settings\administrator\local settings\temp\BPgjto.exe<<\J.exe<< C:\PROGRA~1\Web Offer<< doscerpt.exe<< dmuadu.exe<< C:\Program Files\TV Media<<
Then reboot and post a new log. How is it running after the reboot?
Thanks…..here is the latest HiJack Log after all deletions were completed in Safe Mode….

I did not find the SC.exe in the doc-settings\admin\localsettings\temp folder however, I did find this file in the C:\Windows\System32 folder. Should I delete it from there?

Thanks again for your timely help.

Tabb


Logfile of HijackThis v1.98.2
Scan saved at 11:32:08 AM, on 10/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Omega Research\Program\orschd.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\HiJackThis-GOOD\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.elocaltrading.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [5sFT35O] dmuadu.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Omega Research Task Scheduler.lnk = C:\Program Files\Omega Research\Program\orschd.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://208.62.27.145/TSCOM_TOOL/IFTWCLIENTS/IFTWCLIX.CAB
O16 - DPF: {6BA1270C-B969-4234-B827-7B3BBB4F5FFC} - http://63.99.207.62/builds//build1563/install.cab
O16 - DPF: {7CEEAB76-D59E-11D3-8394-00C04F7BDF10} (Application Class) - http://www.tradestation.com/tscom/ClientPlugIn/tsTemp.cab
You can test the file to see if it is infected. In this link >>> http://www.kaspersky.com/scanforvirus you can upload the file and it will generate a report on it. Post the log of that report please in your next post.

Is it this file name?

C:\WINDOWS\System32\SC.exe


Boot to safe mode again and scan with hijackthis and put a check beside these lines and choose FIX.

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [5sFT35O] dmuadu.exe

Then while still in safe mode delete these files/folders


C:\Program Files\AutoUpdate<<
dmuadu.exe<<
Then I would like you to do a virus scan

Panda Online Scan http://www.pandasoftware.com/activescan/

Allow it to fix anything it finds.

Then reboot and post a new hijackthis log and the file scan report please.
Hi,

Ok…..the on-line virus scan is listed below as well as the new HiJack log….

I also ran Panda before exiting safe mode and it came back clean….

Tabb


Logfile of HijackThis v1.98.2
Scan saved at 1:38:53 PM, on 10/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\apvxdwin.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Omega Research\Program\orschd.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\HiJackThis-GOOD\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.elocaltrading.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Omega Research Task Scheduler.lnk = C:\Program Files\Omega Research\Program\orschd.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://208.62.27.145/TSCOM_TOOL/IFTWCLIENTS/IFTWCLIX.CAB
O16 - DPF: {6BA1270C-B969-4234-B827-7B3BBB4F5FFC} - http://63.99.207.62/builds//build1563/install.cab
O16 - DPF: {7CEEAB76-D59E-11D3-8394-00C04F7BDF10} (Application Class) - http://www.tradestation.com/tscom/ClientPlugIn/tsTemp.cab




Online Virus Scanner


You're clean!
Kaspersky Anti-Virus has not detected any viruses at this time in the file you submitted.
However, only a fully-functional antivirus solution with regularly updated virus definitions can ensure comprehensive protection against malware. If you do not have an antivirus solution installed, you may wish to consider purchasing one today.
• Download a trial version of Kaspersky Anti-Virus
• Purchase Kaspersky Anti-Virus in our E-Store
• Purchase Kaspersky Anti-Virus from a certified partner

Scanned file: sc.exe
sc.exe - OK
Statistics:
Known viruses: 99876 Updated: 01-10-2004
File size (Kb): 31 Virus bodies: 0
Files: 1 Warnings: 0
Archives: 0 Suspicious: 0
Looks Good :thumbup: How is it running any issues?

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help. Safe surfing. ;)
Glad we could help.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI