This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Hijackthis Log

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks in advance for any help you can offer. I ran Ad Aware (6.0) and Zerospyware. I then rebooted and ran the hijackthis executable.
My system is running 2000. Here is the hijackthis log contents:

Logfile of HijackThis v1.98.2
Scan saved at 8:31:55 AM, on 10/29/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\WINNT\system32\pctspk.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NavNT\vptray.exe
C:\WINNT\system32\wujntx.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\FBM Software\ZeroSpyware 2004\ZeroSpyware.exe
C:\Program Files\FBM Software\ZeroSpyware 2004\NetGuard.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
C:\PROGRA~1\HEWLET~1\HPPSC7~1\bin\hpoevm07.exe
C:\WINNT\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\HPOSTS07.exe
C:\WINNT\system32\aylui.exe
C:\Download\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
O1 - Hosts: ˜J¶˜J¶ W¶ W¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶¨g¶¨g¶à¶à¶è¶è¶ð¶ð¶ø¶ø¶ ˆ¶¶¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶à¶è¶è¶ð¶ð¶ø¶ø¶
O1 - Hosts: ¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶à¶è¶è¶ð¶ð¶ø¶ø¶
O1 - Hosts: ÈK²ÈK²²²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²à²è²è²ð²ð²ø²ø² ˆ²²²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²à²è²è²ð²ð²ø²ø²
O1 - Hosts: ²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²à²è²è²ð²ð²ø²ø²
O1 - Hosts: ˜Jª˜Jªªª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀª ˆªªª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàªàªèªèªðªðªøªøª
O1 - Hosts: ª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàªàªèªèªðªðªøªøª
O1 - Hosts: ˜J½˜J½V½V½˜½˜½Hf½Hf½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Z½Z½à½à½è½è½ð½ð½ø½ø½ ˆ½½½˜½˜½ ½ ½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Ø½Ø½à½à½è½è½ð½ð½ø½ø½
O1 - Hosts: ½˜½˜½ ½ ½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Ø½Ø½à½à½è½è½ð½ð½ø½ø½
O1 - Hosts: ª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàªàªôªôªðªðªøªøª
O1 - Hosts: ¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶à¶p\¶p\¶ð¶ð¶ø¶ø¶
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\system32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ztpgao] C:\WINNT\system32\wujntx.exe
O4 - HKLM\..\RunOnce: [RemoveFileUAF] "C:\Program Files\FBM Software\ZeroSpyware 2004\FileDeleter.exe" C:\Program Files\FBM Software\ZeroSpyware 2004\uaf.dat
O4 - HKCU\..\Run: [aylui] C:\WINNT\system32\aylui.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware 2004\ZeroSpyware.exe" -STARTUP
O4 - HKCU\..\Run: [NetGuard] "C:\Program Files\FBM Software\ZeroSpyware 2004\NetGuard.exe" -STARTUP
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…347bcb40c723607
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe…etup1.0.0.6.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {D534A0F8-E0F2-4F11-8E53-345819B2451F} (Streaming VisualFX) - http://www.rmgdrs.com/update/x1ff.cab
Greetings and welcome to TomCoyote.org!

Please download and run Spybot-Search&Destroy and Ad-Aware; they are the standard programs for finding and cleaning malware off your system. Here are links to both programs, and instructions for their use.

Get Spybot - Search & Destroy from http://security.kolla.de
(This is the NEW Version 1.3)
Get AdAware SE Personal from http://www.lavasoft.de/support/download
(This is the NEW Build 1.05)

Download and install these programs if you don't already have them. If you do have them, make sure they are UPDATED AND CONFIGURED AS DESCRIBED here:

http://www.cjwd.demon.co.uk/spybot-adaware.html

Reboot after running each program.

Then "copy/paste" a new log file into this thread. :)
Thanks for the quick response. I've followed your instructions and have re-run hijackthis.exe. Here's the latest log:

Logfile of HijackThis v1.98.2
Scan saved at 9:22:10 AM, on 10/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\WINNT\system32\pctspk.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NavNT\vptray.exe
C:\WINNT\system32\wujntx.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
C:\PROGRA~1\HEWLET~1\HPPSC7~1\bin\hpoevm07.exe
C:\WINNT\system32\hpoipm07.exe
C:\Download\HijackThis.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\HPOSTS07.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\aylui.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ˜J¶˜J¶ W¶ W¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶¨g¶¨g¶à¶à¶è¶è¶ð¶ð¶ø¶ø¶ ˆ¶¶¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶à¶è¶è¶ð¶ð¶ø¶ø¶
O1 - Hosts: ¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶à¶è¶è¶ð¶ð¶ø¶ø¶
O1 - Hosts: ÈK²ÈK²²²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²à²è²è²ð²ð²ø²ø² ˆ²²²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²à²è²è²ð²ð²ø²ø²
O1 - Hosts: ²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²à²è²è²ð²ð²ø²ø²
O1 - Hosts: ˜Jª˜Jªªª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀª ˆªªª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàªàªèªèªðªðªøªøª
O1 - Hosts: ª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàªàªèªèªðªðªøªøª
O1 - Hosts: ˜J½˜J½V½V½˜½˜½Hf½Hf½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Z½Z½à½à½è½è½ð½ð½ø½ø½ ˆ½½½˜½˜½ ½ ½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Ø½Ø½à½à½è½è½ð½ð½ø½ø½
O1 - Hosts: ½˜½˜½ ½ ½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Ø½Ø½à½à½è½è½ð½ð½ø½ø½
O1 - Hosts: ª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàªàªôªôªðªðªøªøª
O1 - Hosts: ¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶à¶p\¶p\¶ð¶ð¶ø¶ø¶
O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ztpgao] C:\WINNT\system32\wujntx.exe
O4 - HKLM\..\RunOnce: [RemoveFileUAF] "C:\Program Files\FBM Software\ZeroSpyware 2004\FileDeleter.exe" C:\Program Files\FBM Software\ZeroSpyware 2004\uaf.dat
O4 - HKCU\..\Run: [aylui] C:\WINNT\system32\aylui.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware 2004\ZeroSpyware.exe" -STARTUP
O4 - HKCU\..\Run: [NetGuard] "C:\Program Files\FBM Software\ZeroSpyware 2004\NetGuard.exe" -STARTUP
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…f7edadac81f3fd5
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {D534A0F8-E0F2-4F11-8E53-345819B2451F} (Streaming VisualFX) - http://www.rmgdrs.com/update/x1ff.cab
You've definitely got one of the most bizarre logs i've seen. :weee:

The "hosts" file is supposed to be "man readable" ASCII text. You've got some binary "thing" going on in it, which isn't right.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O1 - Hosts: ˜J¶˜J¶ W¶ W¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶

O1 - Hosts: ¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶

O1 - Hosts: ÈK²ÈK²²²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²

O1 - Hosts: ²˜²˜² ² ²¨²¨²°²°²¸²¸²À²À²È²È²Ð²Ð²Ø²Ø²à²

O1 - Hosts: ˜Jª˜Jªªª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀª ˆªªª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØª

O1 - Hosts: ª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàª

O1 - Hosts: ˜J½˜J½V½V½˜½˜½Hf½Hf½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½

O1 - Hosts: ½˜½˜½ ½ ½¨½¨½°½°½¸½¸½À½À½È½È½Ð½Ð½Ø½Ø½à½

O1 - Hosts: ª˜ª˜ª ª ª¨ª¨ª°ª°ª¸ª¸ªÀªÀªÈªÈªÐªÐªØªØªàª

O1 - Hosts: ¶˜¶˜¶ ¶ ¶¨¶¨¶°¶°¶¸¶¸¶À¶À¶È¶È¶Ð¶Ð¶Ø¶Ø¶à¶

O2 - BHO: (no name) - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - (no file)

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)

O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINNT\system32\msbe.dll

O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)

O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [ztpgao] C:\WINNT\system32\wujntx.exe

O4 - HKCU\..\Run: [aylui] C:\WINNT\system32\aylui.exe

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…f7edadac81f3fd5

Check these if you did not knowingly put these restrictions in place:

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\winnt\system32\aylui.exe <— file

c:\winnt\system32\msbe.dll <— file
(should already be deleted - be sure!)

c:\winnt\system32\wujntx.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Looks like the entries you had me check are staying away. Again, I appreciate your help and quick response. Here's the latest log from Hijackthis:

Logfile of HijackThis v1.98.2
Scan saved at 11:39:05 PM, on 10/30/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\WINNT\system32\pctspk.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
C:\PROGRA~1\HEWLET~1\HPPSC7~1\bin\hpoevm07.exe
C:\WINNT\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\HPOSTS07.exe
C:\Download\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [nvrofq] C:\WINNT\system32\wujntx.exe
O4 - HKLM\..\RunOnce: [RemoveFileUAF] "C:\Program Files\FBM Software\ZeroSpyware 2004\FileDeleter.exe" C:\Program Files\FBM Software\ZeroSpyware 2004\uaf.dat
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware 2004\ZeroSpyware.exe" -STARTUP
O4 - HKCU\..\Run: [NetGuard] "C:\Program Files\FBM Software\ZeroSpyware 2004\NetGuard.exe" -STARTUP
O4 - HKCU\..\Run: [aylui] C:\WINNT\system32\aylui.exe
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {D534A0F8-E0F2-4F11-8E53-345819B2451F} (Streaming VisualFX) - http://www.rmgdrs.com/update/x1ff.cab
A few items have returned…. <_<

Let's try a slightly different approach.

Boot in "safe" mode FIRST.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [nvrofq] C:\WINNT\system32\wujntx.exe

O4 - HKCU\..\Run: [aylui] C:\WINNT\system32\aylui.exe

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\winnt\system32\aylui.exe <— file

c:\winnt\system32\wujntx.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
I "Fix Checked" the two items listed and rebooted in safe mode but did not find the two executables listed. I did do the "show hidden files" to make sure they were gone. I don't see them in the latest log I ran from Hijackthis. I looked again after rebooting in normal mode to see if the files re-appeared in c:\winnt\system32 and I still don't show them.

Thanks for the continued help! :D

Log results:

Logfile of HijackThis v1.98.2
Scan saved at 9:31:15 PM, on 10/31/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\WINNT\system32\pctspk.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
C:\PROGRA~1\HEWLET~1\HPPSC7~1\bin\hpoevm07.exe
C:\WINNT\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\HPOSTS07.exe
C:\Download\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {D534A0F8-E0F2-4F11-8E53-345819B2451F} (Streaming VisualFX) - http://www.rmgdrs.com/update/x1ff.cab


I'm also including a list of my current "running processes" taken from task manager, in case it's of any value to your evaluation:

System Idle Process 0 99 0:07:57 16 K
System 8 00 0:00:35 212 K
SMSS.EXE 204 00 0:00:01 376 K
CSRSS.EXE 228 00 0:00:07 1,836 K
WINLOGON.EXE 248 00 0:00:59 4,228 K
SERVICES.EXE 276 00 0:00:02 5,636 K
LSASS.EXE 288 00 0:00:00 1,148 K
MSGSVS.EXE 364 00 0:00:01 3,076 K
hpoevm07.exe 368 00 0:00:00 4,936K
svchost.exe 476 00 0:00:00 4,156 K
spoolsv.exe 508 00 0:00:01 4,296 K
defwatch.exe 536 00 0:00:00 1,380 K
svchost.exe 552 00 0:00:05 9,540 K
rtvscan.exe 588 00 0:00:02 10,864 K
TASKMGR.EXE 612 01 0:00:01 2,492 K
regsvc.exe 640 00 0:00:00 972 K
mstask.exe 664 00 0:00:00 3,344 K
WinMgmt.exe 744 00 0:00:07 932 K
svchost.exe 772 00 0:00:00 6,772 K
explorer.exe 860 00 0:00:45 8,508 K
hposts07.exe 1048 00 0:00:03 5,524 K
IEXPLORE.EXE 1112 00 0:00:34 22,408 K
hPoipm07.exe 1120 00 0:00:00 1,184 K
Directcd.exe 1224 00 0:00:01 4,880 K
CREATE~1.EXE 1248 00 0:00:00 2,740 K
pctspk.exe 1256 00 0:00:01 2,348 K
jusched.exe 1284 00 0:00:00 1,776 K
vptray.exe 1292 00 0:00:00 4,612 K
msnmsgr.exe 1316 00 0:00:00 4,532 K
hpodev07.exe 1336 00 0:01:35 6,400 K
Log looks good!!! :thumbup:

GOD bless!!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI