This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log - Help Requested

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have ran Spybot and Adware numerous times and fixed any found items. However, I am still getting an ad pop up occasionally. It is using up a lot of my system virutal memory whatever it is, because I am constantly getting messages now that my virtual memory is too low.

Here is the log:

Logfile of HijackThis v1.98.2
Scan saved at 12:00:07 PM, on 10/30/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~4\CPQWEB~1\WebDmi.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\Compaq\COMPAQ~4\cpqdmi.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Compaq\COMPAQ~4\CHKADMIN.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Documents and Settings\Application Data\brwe.exe
C:\WINDOWS\System32\w?nlogon.exe
C:\Program Files\Microsoft Office\Office\Osa.exe
C:\Program Files\Msnia\Trayclnt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Local Settings\Temporary Internet Files\Content.IE5\8FUBKBYR\HijackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Telerx
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {69A56029-9B15-2794-8724-615579862867} - C:\WINDOWS\System32\qwlrtv.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~4\CHKADMIN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [jwUU5B3M] C:\documents and settings\local settings\temp\jwUU5B3M.exe
O4 - HKLM\..\Run: [0K] C:\documents and settings\blevins\local settings\temp\0K.exe
O4 - HKLM\..\Run: [2E@Y9K74HKGXEW] C:\WINDOWS\System32\Bwd9m.exe
O4 - HKLM\..\Run: [5f3f52134973] C:\WINDOWS\System32\ATIVPEAG.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Uahe] C:\Documents and Settings\Application Data\brwe.exe
O4 - HKCU\..\Run: [Npbx] C:\WINDOWS\System32\w?nlogon.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: MSN Internet Access.lnk = C:\Program Files\MSNIA\TRAYCLNT.EXE
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: www.telerx.com
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} - http://playroom.icq.com/odyssey_web11.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BCC347AE-3002-4AD7-9321-B51EA9274788} (TelerxWeb.MultiCal) - http://go/cabs/telweb.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://telerx.webex.com/client/latest/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{72943D09-80E6-4BC5-9B2A-AFD70D19A17C}: NameServer = 54.3.1.240,54.3.1.239,172.19.5.233

Can you please help?
You have the Peper Trojan. It is a very stubborn infection which requires a specific tool to remove. There are two tools available. Please follow these instructions in order:

1. Download Newuninst.exe.

2. Run it with an active internet connection.

3. Reboot to finish removing the entries it found.

4. Run the tool a second time (with an active internet connection).

5. Reboot to finish removing the entries it found.


The second tool which does not require Internet Access to Clean is:

1. Please Download PeperFix.exe,

2. Start the tool and click Find and Fix.

3. Reboot to finish removing what it found.

4. Run the tool a second time (again with an active internet connection).

5. Reboot to finish removing the entries.

Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done. Rescan with HJT and post a new log here.

Please click here for instructions on how to set up a HijackThis folder.
Thanks Little Eagle,

I followed the instructions above to the letter.

In the first virus scan these two were uncleanable:

BKDR_Sandbox_A located at C:\Peperfix\BKi6sa6.exe

Troj_Delf_Ar located at c:\temp\instolle7.exe

The last two virus scans came out clean - everything fixed.

Here is my new HJT log, however did follow the folder instructions - but I still see my last name… I don't really care though :)

Logfile of HijackThis v1.98.2
Scan saved at 11:41:11 AM, on 10/31/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~4\CPQWEB~1\WebDmi.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\Compaq\COMPAQ~4\cpqdmi.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Compaq\COMPAQ~4\CHKADMIN.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ATIVPEAG.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Documents and Settings\Blevins\Application Data\brwe.exe
C:\WINDOWS\System32\w?nlogon.exe
C:\Program Files\Microsoft Office\Office\Osa.exe
C:\Program Files\Msnia\Trayclnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Telerx
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {69A56029-9B15-2794-8724-615579862867} - C:\WINDOWS\System32\qwlrtv.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~4\CHKADMIN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [jwUU5B3M] C:\documents and settings\blevins\local settings\temp\jwUU5B3M.exe
O4 - HKLM\..\Run: [0K] C:\documents and settings\blevins\local settings\temp\0K.exe
O4 - HKLM\..\Run: [5f3f52134973] C:\WINDOWS\System32\ATIVPEAG.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Uahe] C:\Documents and Settings\Blevins\Application Data\brwe.exe
O4 - HKCU\..\Run: [Npbx] C:\WINDOWS\System32\w?nlogon.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: MSN Internet Access.lnk = C:\Program Files\MSNIA\TRAYCLNT.EXE
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: www.telerx.com
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} - http://playroom.icq.com/odyssey_web11.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BCC347AE-3002-4AD7-9321-B51EA9274788} (TelerxWeb.MultiCal) - http://go/cabs/telweb.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://telerx.webex.com/client/latest/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{72943D09-80E6-4BC5-9B2A-AFD70D19A17C}: NameServer = 54.3.1.240,54.3.1.239,172.19.5.233

Please go to add and remove programs and remove,

Viewpoint

Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {69A56029-9B15-2794-8724-615579862867} - C:\WINDOWS\System32\qwlrtv.dll (file missing)
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
{not necessary and resource hog}



The following have randomly named file names, and as such are normally malware.
UNLESS you know what they are, and they are from a safe source, follow their process tree.
Right click on the file and go to Properties. Then go to the Version tab to see what company name it's from:
If it's from some name you never heard of or if it's blank, please check for removal also.

O4 - HKLM\..\Run: [jwUU5B3M] C:\documents and settings\blevins\local settings\temp\jwUU5B3M.exe
O4 - HKLM\..\Run: [0K] C:\documents and settings\blevins\local settings\temp\0K.exe
O4 - HKLM\..\Run: [5f3f52134973] C:\WINDOWS\System32\ATIVPEAG.exe
O4 - HKCU\..\Run: [Uahe] C:\Documents and Settings\Blevins\Application Data\brwe.exe
O4 - HKCU\..\Run: [Npbx] C:\WINDOWS\System32\w?nlogon.exe


]Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following file(s) and folder(s) listed

C:\Program Files\Microsoft Office\Office\OSA.EXE <<
C:\documents and settings\blevins\local settings\temp\jwUU5B3M.exe]<< C:\documents and settings\blevins\local settings\temp\0K.exe]<< C:\WINDOWS\System32\ATIVPEAG.exe]<< C:\Documents and Settings\Blevins\Application Data\brwe.exe]<< C:\WINDOWS\System32\w?nlogon.exe]<<

C:\Program Files\Viewpoint

(do a search for this one. It'll probably be in c:\windows or c:\windows\system32.)

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Thanks, I will do all of this when I get back tonight - however as of right now, the only problem I am having is that AIM won't stay logged in - but AOL is evil.
Please read through the ideas and free software listed below that will help to keep your computer clean.
Some of these you may already have installed or may have done already.

Install a firewall.ZoneAlarm FREE

Ensure that an Antivirus is updated weekly and running. You only need one.
AVG antivirus from Grisoft is a very good FREE antivirus program.

Make sure you have the latest critical updates from windows update.

SpywareBlaster will prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.

IE-SPYAD puts over 4000 known 'bad' sites into your IE restricted zone so that they cannot install malware on your PC.

Google toolbar has a very good built in popup blocker with a nice search bar. To provide privacy, select disable advanced features when installing.

Check your system for latest virus definitions with an online virus scan every week or two.
TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan

Check your system for latest trojan definitions with an Online trojan scan also every week or two.

And also see this link for additional security information.
So how did I get infected in the first place?

Please consider using Firefox
http://texturizer.net/firefox/index.html

Please read this




Due to inactivity this topic will be closed.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI