This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Hijackthislog

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I'm new to this site. Where exactly can I put my highjackthis log so someone who knows what they are talking about can have a look at it ? Cheers Jim
Jim – Here's how…

Please download the newest version of HijackThis (version 1.98.2) and unzip it into a newly created folder (such as "C:\HJT) to ensure that backup files will be saved reliably .

Run the new version and create a logfile:

Press 'Scan' then 'Save Log' then 'Save' then 'Yes'.
In the Notepad window, use 'Edit > Select All', then 'Edit > Copy'

Then paste into a reply to this message and send it.

I'll be automatically alerted when that happens.

Thanks
daveai
Hi Dave,
Cheers for this.
The log is below.

Logfile of HijackThis v1.98.2
Scan saved at 14:59:42, on 14/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\ESOE\ELogSrv.exe
C:\Program Files\ESOE\ESrv.exe
C:\WINNT\system32\Hummbird\inetd32.exe
C:\PROGRA~1\NETMAN~1\APPS\NFS\wlpd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\PROT_SRV.EXE
C:\WINNT\system32\pagents.exe
C:\WINNT\system32\PSTARTSR.EXE
C:\WINNT\system32\regsvc.exe
c:\PROGRA~1\SYMANT~1\SYMANT~1\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\FLRSERV.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\ESOE\EDMS\ECIS.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Pointsec\P95tray.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\internat.exe
C:\Program Files\ESOE\ECC.exe
C:\Program Files\Lotus\Sametime Client\Connect.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Orl\Vnc\WinVNC.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\calc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Line\Mystuff\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…www.yahoo.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://internal.ericsson.se/page/hub_globa…land/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…www.yahoo.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.rggjkewsibdyk.org/jT31CChoP22td…z4ZMOnw4E8d.jpg
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…www.yahoo.co.uk
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www-proxy.ericsson.se:3132/accelerated_pac_base.pac
O2 - BHO: (no name) - {3EAC6CF0-521E-5CAE-793C-ABFD76E6964F} - C:\PROGRA~1\IDLEDA~1\Bags corn.exe
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINNT\questmod-1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NetManageImport] "C:\PROGRA~1\NETMAN~1\setup\nmcpdata.exe" I
O4 - HKLM\..\Run: [NetManage LaunchNow Init] RunDLL32 C:\Progra~1\NETMAN~1\common\nmgoinn.dll,VerifyStartMenu
O4 - HKLM\..\Run: [StoreCleanup] RunDLL32 c:\progra~1\NETMAN~1\common\nmconfig.dll,StoreCleanup
O4 - HKLM\..\Run: [Protect Tray] "C:\Program Files\Pointsec\P95tray.exe"
O4 - HKLM\..\Run: [Cdrom defy] C:\PROGRA~1\CAKEAX~1\waybrowse.exe
O4 - HKLM\..\Run: [JavaVM] C:\WINNT\java.exe
O4 - HKLM\..\Run: [Services] C:\DOCUME~1\lmijlge\LOCALS~1\Temp\services.exe
O4 - HKLM\..\Run: [InternetDvdBrowseCake] C:\Documents and Settings\All Users\Application Data\spam bone internet dvd\Gpl 01.exe
O4 - HKLM\..\Run: [Spyware Stormer] C:\Program Files\Spyware Stormer\SpywareStormer.Exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: ASE Scheduler.lnk = C:\Program Files\Aluria Software\ASE\ASE Scheduler.exe
O4 - Global Startup: Check for Pal Update.lnk = C:\Program Files\RDC\Dial-up Client\PALUpdate.exe
O4 - Global Startup: Ericsson Corporate Templates Check.lnk = C:\Program Files\Microsoft Office\Templates\1033\Ericsson Corporate Templates\CheckECorpTemplates.exe
O4 - Global Startup: EriDoc Update.lnk = C:\Program Files\Eridoc\Eridoc.exe
O4 - Global Startup: ESOE 2000 Client Update.lnk = C:\Program Files\ESOE2000ClientUpdate\eMsgBox.exe
O4 - Global Startup: ESOE Control Center.lnk = C:\Program Files\ESOE\ECC.exe
O4 - Global Startup: InterwovenTeamsiteTemplatingClient Update Check.lnk = C:\Program Files\Interwoven\TemplatingClient\InterwovenTeamsiteTemplatingClient.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Sametime Connect.lnk = C:\Program Files\Lotus\Sametime Client\Connect.exe
O4 - Global Startup: VN User Update.lnk = C:\Documents and Settings\eeicsc\Application Data\NetManage\Data\VN User Update.exe
O4 - Global Startup: WinVNC.exe.lnk = C:\Program Files\Orl\Vnc\WinVNC.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: ConferenceRoom Java Client - http://irc.theamateurchat.com/java/cr.cab
O16 - DPF: Documentum Content Transfer 5.2.5 SP - http://esealmw066:8080/r8a10/wdk/contentXfer/ContentXfer.cab
O16 - DPF: RightSiteApplet - https://eridoc.ericsson.se/RightSiteDir/applet/rs_applet.cab
O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) - http://directplugin.com/tl7000.dll
O16 - DPF: {037B3D58-D14A-4C41-BDFD-BD779B0B97BA} (vxiewer control) - http://www.thepaymentcentre.com/build/vxiewer.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {AA14C86B-DA22-4811-8186-BB496A299C5F} (Be Here TotalView Player ActiveX Control, Version 3.0) - http://www.spincam.com/360video/plugins/iVideoViewer3_0.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://217.73.66.1/del/loader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {C3CBFE35-9BE8-11D1-B31B-006008948294} (OrgPublisher PluginX) - http://www.timevision.com/codebase40/OrgPubX.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eemea.ericsson.se
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eemea.ericsson.se
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eemea.ericsson.se
Jim – Thanks for sending your HijackThis log.


You are running Spyware Stormer, which is a known 'rogue anti-spyware application'. Read about it here: http://www.spywarewarrior.com/rogue_anti-spyware.htm I strongly suggest you remove it from your system and have included that items to do that in this fix.


Since you will not be able to access this page in safe mode during this fix, please print these instructions now, or save them to your desktop, to help keep track of the steps.


1 – To start,, follow this link for instructions to enable 'show all files' for your system.


2 – You show evidence of hte MyDoom virus. Please download and run Stinger - A tool which updates frequently and is very effective against the well known virus infections.


3 – Please follow the instructions in this link below to download and run Spybot & AdAware SE: Spybot & Adaware Tutorial

Please let me know if anything can not be cleaned by these utilities.


4 – Next, use Control Panel > Add/Remove Programs to remove any of the following malware that you find:

Spyware Stormer

Window Search,
Window Searching,
Lop.com,
LOP Search,
Browser Enhancer,
Ultimate Browser Enhancer (If you are given a code to insert, do so)



5 – Run HijackThis, and press Scan, and put a check against the following entries, if they still show up. Make sure all browsers and program windows are closed except for HijackThis.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…www.yahoo.co.uk

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://internal.ericsson.se/page/hub_globa…land/index.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://uk.red.clientapps.yahoo.com/customi…www.yahoo.co.uk

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.rggjkewsibdyk.org/jT31CChoP22td…z4ZMOnw4E8d.jpg

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.red.clientapps.yahoo.com/customi…www.yahoo.co.uk

O2 - BHO: (no name) - {3EAC6CF0-521E-5CAE-793C-ABFD76E6964F} - C:\PROGRA~1\IDLEDA~1\Bags corn.exe

O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINNT\questmod-1.dll

O4 - HKLM\..\Run: [Cdrom defy] C:\PROGRA~1\CAKEAX~1\waybrowse.exe

O4 - HKLM\..\Run: [JavaVM] C:\WINNT\java.exe

O4 - HKLM\..\Run: [Services] C:\DOCUME~1\lmijlge\LOCALS~1\Temp\services.exe

O4 - HKLM\..\Run: [InternetDvdBrowseCake] C:\Documents and Settings\All Users\Application Data\spam bone internet
dvd\Gpl 01.exe

O4 - HKLM\..\Run: [Spyware Stormer] C:\Program Files\Spyware Stormer\SpywareStormer.Exe

O16 - DPF: {0191ABF4-9421-435E-9FFD-CD827A2A82D8} (SBITAX7Ctrl Class) - http://directplugin.com/tl7000.dll

O16 - DPF: {037B3D58-D14A-4C41-BDFD-BD779B0B97BA} (vxiewer control) -
http://www.thepaymentcentre.com/build/vxiewer.cab

O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://217.73.66.1/del/loader.cab


Do you recognize these? I cannot determine thier status in the databases we use, or by using google. They may be related to your work.

If you know them to be good, then leave them alone. Otherwise, fix them now:

O4 - Global Startup: Ericsson Corporate Templates Check.lnk = C:\Program Files\Microsoft Office\Templates\1033\Ericsson Corporate Templates\CheckECorpTemplates.exe

O4 - Global Startup: EriDoc Update.lnk = C:\Program Files\Eridoc\Eridoc.exe

O4 - Global Startup: ESOE 2000 Client Update.lnk = C:\Program Files\ESOE2000ClientUpdate\eMsgBox.exe

O4 - Global Startup: ESOE Control Center.lnk = C:\Program Files\ESOE\ECC.exe

O4 - Global Startup: InterwovenTeamsiteTemplatingClient Update Check.lnk = C:\Program Files\Interwoven
\TemplatingClient\InterwovenTeamsiteTemplatingClient.exe

O4 - Global Startup: VN User Update.lnk = C:\Documents and Settings\eeicsc\Application Data\NetManage\Data\VN
User Update.exe


And, this is an optional item you may choose to fix:

Office Startup Asistant is an optional item that if checked, will eliminate a known resource hog. You will still be able to start Office components from the Start menu. This is the item to fix in HJT:
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


Once you have selected all the items for HJT to fix, and remember to make sure all browsers and program windows are closed except for HijackThis, then click fix checked.



6 – Reboot into Safe Mode (How do I boot into "Safe" mode?), then use Windows Explorer to delete the following lists of program files and folders, if they still exist.

C:\WINNT\java.exe <– this file

C:\WINNT\questmod-1.dll <– this file (may already be gone)

C:\Program Files\CAKEAX~1\ <– this folder (use "Start > Search" to find a folder starting with the letters "CAKEAX")

C:\Program Files\IDLEDA~1\ <– this folder (use "Start > Search" to find a folder starting with the letters "IDLEDA")

C:\Documents and Settings\All Users\Application Data\spam bone internet dvd\ <– this folder

C:\Program Files\Spyware Stormer\ <– this folder


Please let me know about any problems with the file/folder deletes.


7 – Next, use "Start > Run" and type in "%temp%" (without the quotes). Delete the entire contents of that "temp" folder (use "Edit > Select All", press "Delete", click "Yes").

Then, Empty your Temporary Internet Cache completely. Close all instances of Outlook and and Internet Explorer, then use "Control Panel > Internet Options > General tab" and click the "Delete File" button. When prompted place a check in: "Delete all offline content", then click OK.

Then, use Windows Explorer to clean out ALL the other temp folders on your system (navigate to the folder, use "Edit > Select All", press "Delete", click "Yes"):

* C:\Documents and Settings\\Local Settings\Temp\
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\\Local Settings\Temp\
* Empty your "Recycle Bin".


Be sure that 'C:\Documents and Settings\lmijlge\Local Settings\Temp\' is included in this process.

Please let me know about any problems with the temp file deletes.


8 – Now, reboot normally and run either of these two Online virus scans: Panda Active Scan or TrendMicro Housecall and put on Auto Clean.


Now, reboot once again, and run HijackThis to create a new logfile. Repost it here, and if you had any problems with the steps outlined above, please let us know what they were. Your response and the new logfile will determine the next steps for this fix.

Thanks
daveai
Hello again
Thanks for the info.
I followed your list of things to do.

Problems I incurred:

(i) I couldn't log in, in SAFE Mode, my normal password wouldn't work. I looked for the files you list in normal login , they were not present(all hidden files visible).

(ii) Anything I recognised as being work related I left in.

(iii) Panda found 2 viruses which it deleted.

I've included the new Hijackthis log below.

Cheers
Jim


Logfile of HijackThis v1.98.2
Scan saved at 16:39:51, on 21/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\ESOE\ELogSrv.exe
C:\Program Files\ESOE\ESrv.exe
C:\WINNT\system32\Hummbird\inetd32.exe
C:\PROGRA~1\NETMAN~1\APPS\NFS\wlpd.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\PROT_SRV.EXE
C:\WINNT\system32\pagents.exe
C:\WINNT\system32\PSTARTSR.EXE
C:\WINNT\system32\regsvc.exe
c:\PROGRA~1\SYMANT~1\SYMANT~1\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\FLRSERV.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\ESOE\EDMS\ECIS.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Pointsec\P95tray.exe
C:\WINNT\system32\internat.exe
C:\Program Files\ESOE\ECC.exe
C:\Program Files\Lotus\Sametime Client\Connect.exe
C:\Program Files\Orl\Vnc\WinVNC.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Line\Mystuff\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ericsson.com/ie/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www-proxy.ericsson.se:3132/accelerated_pac_base.pac
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Line\Mystuff\Hijackthis\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NetManageImport] "C:\PROGRA~1\NETMAN~1\setup\nmcpdata.exe" I
O4 - HKLM\..\Run: [NetManage LaunchNow Init] RunDLL32 C:\Progra~1\NETMAN~1\common\nmgoinn.dll,VerifyStartMenu
O4 - HKLM\..\Run: [StoreCleanup] RunDLL32 c:\progra~1\NETMAN~1\common\nmconfig.dll,StoreCleanup
O4 - HKLM\..\Run: [Protect Tray] "C:\Program Files\Pointsec\P95tray.exe"
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Check for Pal Update.lnk = C:\Program Files\RDC\Dial-up Client\PALUpdate.exe
O4 - Global Startup: Ericsson Corporate Templates Check.lnk = C:\Program Files\Microsoft Office\Templates\1033\Ericsson Corporate Templates\CheckECorpTemplates.exe
O4 - Global Startup: EriDoc Update.lnk = C:\Program Files\Eridoc\Eridoc.exe
O4 - Global Startup: ESOE 2000 Client Update.lnk = C:\Program Files\ESOE2000ClientUpdate\eMsgBox.exe
O4 - Global Startup: ESOE Control Center.lnk = C:\Program Files\ESOE\ECC.exe
O4 - Global Startup: InterwovenTeamsiteTemplatingClient Update Check.lnk = C:\Program Files\Interwoven\TemplatingClient\InterwovenTeamsiteTemplatingClient.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Sametime Connect.lnk = C:\Program Files\Lotus\Sametime Client\Connect.exe
O4 - Global Startup: VN User Update.lnk = C:\Documents and Settings\eeicsc\Application Data\NetManage\Data\VN User Update.exe
O4 - Global Startup: WinVNC.exe.lnk = C:\Program Files\Orl\Vnc\WinVNC.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: ConferenceRoom Java Client - http://irc.theamateurchat.com/java/cr.cab
O16 - DPF: Documentum Content Transfer 5.2.5 SP - http://esealmw066:8080/r8a10/wdk/contentXfer/ContentXfer.cab
O16 - DPF: RightSiteApplet - https://eridoc.ericsson.se/RightSiteDir/applet/rs_applet.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AA14C86B-DA22-4811-8186-BB496A299C5F} (Be Here TotalView Player ActiveX Control, Version 3.0) - http://www.spincam.com/360video/plugins/iVideoViewer3_0.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {C3CBFE35-9BE8-11D1-B31B-006008948294} (OrgPublisher PluginX) - http://www.timevision.com/codebase40/OrgPubX.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = eemea.ericsson.se
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = eemea.ericsson.se
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = eemea.ericsson.se
Thanks for the response.

Your comments:

(i) I couldn't log in, in SAFE Mode, my normal password wouldn't work. I looked for the files you list in normal login , they were not present(all hidden files visible).

Can you log in as 'administrator in safe mode'? Does your normal username have administrator privledges? you need that level of permission, either in your own userename or as 'administrator'.

(ii) Anything I recognised as being work related I left in.

good

(iii) Panda found 2 viruses which it deleted.

also good

I've included the new Hijackthis log below.

The logfile looks pretty clean. There is a 'broken' O16 that will not cause problems, and other than that, the malware is gone.

How is your system running? Are your initial problems gone?


And, please allow me to suggest some prevention steps to keep your computer clean and secure going forward. You may have already taken a few of the steps, but it never hurts to take a quick look :)

1 – Use an AntiVirus Software, and be sure you update it at least once a week. There are several very good free programs available. Grinler offers an outstanding overview at Virus, Spyware, and Malware Protection and Removal Resources

2 – To reduce re-infection potential for malware in the future, I strongly recommend installing three free programs: SpywareBlaster, SpywareGuard, and IE/Spyad.

3 – Use AdAware SE and Spybot S&D; to regularly to scan your system.

4 – It is very important to make sure that both Internet Explorer and XP are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

5 – I strongly recommend that you consider using a Firewall. Just by using a Firewall in its default configuration can lower your risk greatly. Check out what Lawrence Abrams has to say at Understanding and Using Firewalls

An excellent overview is: So how did I get infected in the first place?. Be sure to visit the browser test link at the end of the article to really see how secure your system is!!

Thanks
daveai

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI