This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log File

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After running Spybot, Ad-aware and CWSredder, i still don't feel confortable with my computer since I still get explorer.exe error msgs and so forth.

Please have a look at this log file if you can see something. Would be really helpful.

I also get 2-3 files that are automatically created on my c: of the style:

tjkacahano.exe
ticacahano.exe

etc…

Thanks in advance,

MikeLogfile of HijackThis v1.97.7
Scan saved at 4:46:01 PM, on 10/6/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\PROGRA~1\SYMPAT~1\GESTIO~1\app\pppoeservice.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\htpatch.exe
C:\WINNT\System32\sistray.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\PV92Tray.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Windows SyncroAd\SyncroAd.exe
C:\WINNT\system32\Nisuxm.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\WINNT\system32\taskmrg.exe
C:\Documents and Settings\mike\Application Data\prrr.exe
C:\WINNT\system32\m?iexec.exe
C:\Program Files\Navnt\navapw32.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\Documents and Settings\mike\My Documents\hi\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca/homepage.html
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4EA9362F-E717-78C1-875F-60550EF52A4D} - C:\WINNT\system32\tvu.dll
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HTpatch] C:\WINNT\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINNT\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\System32\khooker.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe
O4 - HKLM\..\Run: [blah service] msnmsgrr.exe
O4 - HKLM\..\Run: [Start Upping] taskmrg.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [Windows SyncroAd] C:\Program Files\Windows SyncroAd\SyncroAd.exe
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [Norton Personal Firewall] Nisuxm.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\RunServices: [blah service] msnmsgrr.exe
O4 - HKLM\..\RunServices: [Start Upping] taskmrg.exe
O4 - HKLM\..\RunServices: [Norton Personal Firewall] Nisuxm.exe
O4 - HKCU\..\Run: [Start Upping] taskmrg.exe
O4 - HKCU\..\Run: [Srdc] C:\Documents and Settings\mike\Application Data\prrr.exe
O4 - HKCU\..\Run: [Ydp] C:\WINNT\system32\m?iexec.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…839302c61fb4d2c
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Hello mp7.
You have at least 2 bad guys on-board :rant2:

Lets do a free online virus scan and see if we can get rid of them.

Click Here
If asked, select Clean or Fix. Let us know if it finds anything it can't clean.

After running Spybot, Ad-aware


Can you tell me what version of SpyBot and Ad-Aware you have?

Scan with HijackThis and post a new log.
By the time you responded, I could scan it and find many viruses. Just scanning it with housecall was very difficult. At one point, I couldn't access the Internet. But now it's fixed. Thanks anyway. Michel

By the time you responded, I could scan it and find many viruses.

Sorry for the delay.

If you'd like to post a new HijackThis log, we'd be more then happy to check it for you.

Either way, glad you got it fixed.
I came in this forum before and you guys were of great help, that's why I came back !!! You know how it is in information systems business. Time is after what everybody's running. Thanks again.
Michel,

We can understand the time thing, never seems to be enough. As you know, everyone here at TC does this because we like to help. Some logs take a lot of research. The TC is always looking for more helpers if you're interested :oops: Although I have received a number of pictures of cakes, donuts, etc., The best thing is knowning you've helped fix a PC. We're just glad you're up and running again. Hopefully the next time you have issues you'll come back to the TC for help :wavey:

Here is a link to the Classroom if you are interested in becoming part of the TC.
Clink Here
As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI