This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Recurring Hijacks, Please See Log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry to keep coming back with more stuff! I followed your instructions till the part "Delete the entry in the AppInit_DLLs Value key which will look like: C:\Windows\System32]wdmmhjp.dll " The value key was empty when I double clicked on AppInit_DLL so am not quite sure what to do, :( Bonu
Hi again, Sorry this is taking so long but the tea timer was not on (I had exited it previously because it popped up everytime I would open or close internet explorer and after about 25 times I had no idea what it was trying to say so I had turned it off). So even with the teatimer off the value entry is empty, Thanks, Bonu.
Thanks! Did all that and run hijackthis. It did not show all the entries in your instructions so I am going to delete ones that match entries in your instructions, here is the log file if you wanted to look at it, Logfile of HijackThis v1.98.2 Scan saved at 8:48:13 AM, on 10/8/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\scagent.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\wstata.exe C:\Program Files\Advanced Browser\browser.exe C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe C:\Program Files\Microsoft Office\Office\EXCEL.EXE C:\Program Files\hijackthis\HijackThis.exe O2 - BHO: (no name) - {60E09102-8060-4AAF-998A-1B87D7B4DBDD} - C:\WINDOWS\system32\dnc.dll O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winmik32.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\httpfilter.dll Thanks, Bonu
Ignore last post, as I ran it HJT again to delete the ones I mentioned, a longer list came up! I will fix the matching entries from the instructions, if you wanted to see the log file, here it is Logfile of HijackThis v1.98.2 Scan saved at 9:09:56 AM, on 10/8/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\scagent.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\wstata.exe C:\Program Files\Advanced Browser\browser.exe C:\Program Files\Adobe\Acrobat 4.0\Reader\AcroRd32.exe c:\bobby.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\hijackthis\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\bonumark\LOCALS~1\Temp\sp.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2 - BHO: (no name) - {60E09102-8060-4AAF-998A-1B87D7B4DBDD} - C:\WINDOWS\system32\dnc.dll O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winmik32.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\httpfilter.dll O18 - Filter: text/plain - {F665CD84-F102-494E-B4F7-6676BA4F1585} - C:\WINDOWS\system32\dnc.dll
HELP! When I run hijack this and fix the winmik32 entry, it comes right back (without rebooting) when I run it again in 5 seconds. Also, it will not let me delete this in my system32 folder and keeps saying access is denied!
I also have a file called bobby on my C that just got created today when I first ran hijackthis and it is not letting me delete it! Bonu
Its no problem. We're no longer being hijacked (I can't believe it!) so something worked even though I was unable to delete the files you asked me to, here is the log - please let me know if anything looks suspicious, thanks.


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\scagent.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Advanced Browser\browser.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winmik32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\httpfilter.dll
Boot into safe mode and run hijackthis again, fix the following in the same way that you did before;

O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winmik32.exe

Then find and delete this file;

C:\windows\system32\winmik32.exe

Empty your temp files by using disk cleanup

Go to Start>Programs>Acccessories>System Tools> Disk Cleanup and put a check mark beside all the entries in the disk cleanup window that ask you what you want to clean. Clean all hard drives and all files. This will get rid of any malware that is hiding in the temporary folders.

You do not appear to have any anti virus on your system, here are a couple of free ones to choose from

Avast

AVG

You do not appear to have a firewall running and there are a few available for free that have excellent reputations:

Zone Alarm

Kerio

Sygate

Here are some suggestions to reduce the potential for spyware infection in the future. I strongly recommend installing the following :

Spyware Blaster - It will prevent most spyware from ever being installed.
Spyware Guard - It offers realtime protection from spyware installation attempts.
IE-Spyad - IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
I also recommend reading this article written by Tony Klein How did I get infected in the first placeHow did I get infected in the first place?
Thankyou very very much, Everything loooks good!!!! I will follow your advice about the anti spyware programs, again, thanks for the work you're doing, Bonu.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI