This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Hijackthis Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help. My homepage has been set to About.blank and I am unable to reset this. It prevents me from using yahoo. Also, I am unable to do a system restore.
Thank you in advance for your help.

Logfile of HijackThis v1.98.2
Scan saved at 2:18:52 PM, on 11/14/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Ryan\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/1/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/1/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {E6A2278A-7669-408B-89BF-2073C15599B9} - C:\WINDOWS\system32\oha.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [ktktksmjtabh] C:\WINDOWS\system32\iedclcmf.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…b?rand=20035520
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
O18 - Filter: text/html - {CB360A6C-471B-47FF-8D6A-67C370DD4C5A} - C:\WINDOWS\system32\oha.dll
O18 - Filter: text/plain - {CB360A6C-471B-47FF-8D6A-67C370DD4C5A} - C:\WINDOWS\system32\oha.dll
Download FxAgentB.exe from HERE and save it to your desktop. After downloading, double-click the FxAgentB file to run it and the program will scan your entire hard drive - this may take a while. When it is done, it will generate a log file called FxAgentB.log - save that information as you will need to paste it here later. Reboot when done.

Next click HERE to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. If you already have CWShredder, click 'Check for update' and make sure you are running version 1.59.1. Reboot when done.

Then click HERE to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done, rescan with HijackThis and post a new log here, together with the FxAgentB log.
I did what you said. Here are the two new logs. Thank you so much for your help.

HiJackThis Log

Logfile of HijackThis v1.98.2
Scan saved at 1:36:43 AM, on 11/15/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ryan\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/1/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/1/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [ktktksmjtabh] C:\WINDOWS\system32\iedclcmf.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…b?rand=20035520
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab

FxAgentB log

Symantec Backdoor.Agent.B Removal Tool 1.0.1.2

process: winlogon.exe, thread: 00000298 (terminated)
process: services.exe, thread: 00000308 (terminated)
process: lsass.exe, thread: 00000304 (terminated)
process: svchost.exe, thread: 000003B4 (terminated)
process: svchost.exe, thread: 00000424 (terminated)
process: svchost.exe, thread: 000004D8 (terminated)
process: svchost.exe, thread: 0000058C (terminated)
process: svchost.exe, thread: 000005E0 (terminated)
process: LEXBCES.EXE, thread: 00000660 (terminated)
process: spoolsv.exe, thread: 000006A0 (terminated)
process: KodakCCS.exe, thread: 00000798 (terminated)
process: mcvsrte.exe, thread: 000007E4 (terminated)
process: ScsiAccess.EXE, thread: 000000C8 (terminated)
process: svchost.exe, thread: 00000184 (terminated)
process: wdfmgr.exe, thread: 000001A0 (terminated)
process: McShield.exe, thread: 000002D8 (terminated)
process: alg.exe, thread: 00000458 (terminated)
process: wscntfy.exe, thread: 00000804 (terminated)
process: explorer.exe, thread: 00000838 (terminated)
process: hkcmd.exe, thread: 00000910 (terminated)
process: mcagent.exe, thread: 00000920 (terminated)
process: Directcd.exe, thread: 00000A80 (terminated)
process: mcvsshld.exe, thread: 000008D8 (terminated)
process: lxbbbmgr.exe, thread: 00000AAC (terminated)
process: qagent.exe, thread: 000001BC (terminated)
process: realsched.exe, thread: 00000190 (terminated)
process: lxbbbmon.exe, thread: 00000B34 (terminated)
process: LEXPPS.EXE, thread: 000007A0 (terminated)
process: DLG.exe, thread: 00000C4C (terminated)
process: EasyShare.exe, thread: 00000DDC (terminated)
process: mrtMngr.exe, thread: 00000D0C (terminated)
process: FxAgentB.exe, thread: 00000564 (terminated)

registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: AppInit_DLLs (value set to "")

C:\Documents and Settings\Cori: (not scanned)
C:\Documents and Settings\Ryan\Local Settings\Temp\science_ob=ArticleURL&_udi=B6T80-43TNX68-6&_user=2139826&_handle=W-WA-A-A-WU-MsSAYZA-UUW-AUZZADYZCA-BYBEUZZV-WU-U&_fmt=full&_coverDate=09%2F30%2F2001&_rdoc=6&_orig=browse&_srch=%23toc%235072%232001%23999709996.htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Ryan\Local Settings\Temp\science_ob=MImg&_imagekey=B6T80-3Y6Y71F-4-1&_cdi=5072&_orig=browse&_coverDate=01%2F31%2F2000&_sk=999739998&view=c&wchp=dGLbVtb-zSkzV&_acct=C000054278&_version=1&_userid=2139826&md5=433656dcac8df45af3a04f30501f4d85&ie=f (2).pdf (WARNING: not scanned, path to long)
C:\Documents and Settings\Ryan\Local Settings\Temp\science_ob=MImg&_imagekey=B6T80-3Y6Y71F-4-1&_cdi=5072&_orig=browse&_coverDate=01%2F31%2F2000&_sk=999739998&view=c&wchp=dGLbVtb-zSkzV&_acct=C000054278&_version=1&_userid=2139826&md5=433656dcac8df45af3a04f30501f4d85&ie=f.pdf (WARNING: not scanned, path to long)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc10.jpi_cache: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc11.java: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc15: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc16: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc17: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc18: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc19: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc20: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc21: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc22: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc23: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc24: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc25: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc27: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc28: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc29: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc30: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc31: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc32: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc33.tmp: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc34.tmp: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc35.tmp: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc36.tmp: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc37.tmp: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc38.tmp: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc39.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc40.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc41.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc42.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc43.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc44.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc45.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc46.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc47.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc48.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc49.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc50.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc51.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc52.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc53.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc54.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc55.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc56.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc57.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc58.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc59.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc60.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc61.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc62.TMP: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc63.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc64.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc65.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc66.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc67.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc68.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc69.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc70.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc71.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc72.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc73.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc74.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc75.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc76.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc77.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc78.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc79.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc80.dir00: (not scanned)
C:\RECYCLER\S-1-5-21-1682794295-2924537-2588506418-1007\Dc81.dir00: (not scanned)
C:\WINDOWS\SYSTEM32\msmkbo.dll: (will be deleted on next reboot)

The Backdoor.Agent.B removal was successful.
The system will delete 1 Backdoor.Agent.B files from your PC on next reboot.

Here is the report:

1 file(s) could not be deleted.
They will be deleted on next reboot.

The total number of the scanned files: 53732
The number of deleted files: 0
The number of viral processes terminated: 0
The number of viral threads terminated: 32
The number of registry entries fixed: 1

The tool initiated a system reboot.
Please boot to asfe mode (tap f8 while bios laods) then scan with hijackthis and put a check beside these lines and choose FIX.

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/1/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/1/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.searchv.com/1/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;

O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [ktktksmjtabh] C:\WINDOWS\system32\iedclcmf.exe
O4 - Global Startup: Digital Line Detect.lnk = ?

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…b?rand=20035520

Then while still in safe mode delete these files

c:\program files\180solutions<< C:\WINDOWS\system32\iedclcmf.exe<<
Then reboot and post a new log.
I did the hijackthis FIX in safemode, but was not able to find

c:\program files\180solutions<< C:\WINDOWS\system32\iedclcmf.exe<<
after that to delete. Here is my new log. Thank you again.

Logfile of HijackThis v1.98.2
Scan saved at 10:14:31 PM, on 11/15/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Ryan\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
Glad we could help.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for e-mail)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI