This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another Hijackthis Log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

They are just fragments - can't harm you but it would still be better to remove them.

Please go to http://www.billsway.com/vbspage/ and scroll down to Registry Search Tool. Download, unzip and run RegSrch.vbs (you may need to enable your antivirus program to run the file).

Copy and paste this in the dialog box: 1E8B267B-E051-7189-3573-4FAE56717A61

After a while a prompt will come up. Click OK to write the results to wordpad and post them.

Repeat for:

9642AAEE-ADF9-B6AF-287A-6D3802ACCC2A
B5FB2470-E99F-25B2-39AA-D8E94323B645
E8450C1F-806D-9812-8DFD-5A8D7D2A16F9
Sorry for the delay. I kept checking for your response but wasn't looking on the 2nd page. I downloaded, unzipped and tried to run the Regsrch.vbs file but the computer doesn't seem to recognize it. Is it supposed to be opened with a specific piece of software? You mentioned that I might need to enable my AV software to run the file, but I guess I don't know what you mean by that. Thanks for your help.
No, I'm not getting an error message, it's just that when I double-click the Regsrch.vbs file, the computer just treats it like a text file and opens it using notepad. Nothing happens after that.
Click Start>Settings>Control Panel>Folder Options>File Types Scroll down to VBS and check it is associated with VBSScript Script File. Highlight it and let me know what it opens with.
I couldn't find anything like that on my computer. I went to the windows dowload site and found something called Windows Script 5.6. I downloaded the file called scripten.exe, and ran it. It said it was installing the program, but when it was done, I couldn't find whatever program it supposedly installed.
Click Start>Settings>Control Panel>Folder Options>File Types Scroll down to VBS and click it. Against the Opens with click Change and scroll to find Microsoft ® Windows Based Script Host and OK it. Failing that, from the File Types window, click Advanced>Open>Edit and paste this into the 'application used to perform action' box: C:\WINDOWS\System32\WScript.exe "%1" %* OK/Apply your way out and let me know if it works now.
OK, it worked. I went back to your original instructions and ran the register search against the four suspect strings. Here are the results: REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "9642AAEE-ADF9-B6AF-287A-6D3802ACCC2A" 12/27/2004 8:37:41 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9642AAEE-ADF9-B6AF-287A-6D3802ACCC2A}] [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9642AAEE-ADF9-B6AF-287A-6D3802ACCC2A}\iexplore] REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "B5FB2470-E99F-25B2-39AA-D8E94323B645" 12/27/2004 8:38:50 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B5FB2470-E99F-25B2-39AA-D8E94323B645}] [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B5FB2470-E99F-25B2-39AA-D8E94323B645}\iexplore] REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "E8450C1F-806D-9812-8DFD-5A8D7D2A16F9" 12/27/2004 8:41:21 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8450C1F-806D-9812-8DFD-5A8D7D2A16F9}] [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8450C1F-806D-9812-8DFD-5A8D7D2A16F9}\iexplore] REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "1E8B267B-E051-7189-3573-4FAE56717A61" 12/27/2004 8:44:45 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E8B267B-E051-7189-3573-4FAE56717A61}] [HKEY_USERS\S-1-5-21-1709136994-1037202297-1567011825-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E8B267B-E051-7189-3573-4FAE56717A61}\iexplore]
Click here to download bhofix1.zip. Extract bhofix1.reg from the zip file and save it to the desktop. When done, double click the bhofix1.reg and when asked to merge say yes.

Post a new HJT log.
OK, Here is the latest HJT log:

Logfile of HijackThis v1.98.2
Scan saved at 7:02:00 PM, on 12/28/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\QUICKENW\QAGENT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
C:\Program Files\Desktop Master Chief\skinkers.exe
C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\lotus\wordpro\ltsstart.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\lotus\register\remind32.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.greenmountainaccess.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.greenmountainaccess.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.greenmountainaccess.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {1E8B267B-E051-7189-3573-4FAE56717A61} - (no file)
O2 - BHO: (no name) - {9642AAEE-ADF9-B6AF-287A-6D3802ACCC2A} - (no file)
O2 - BHO: (no name) - {B5FB2470-E99F-25B2-39AA-D8E94323B645} - (no file)
O2 - BHO: (no name) - {E8450C1F-806D-9812-8DFD-5A8D7D2A16F9} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HP\Games\ActiveMenu.exe
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [Halo2Cluster] C:\Program Files\Desktop Master Chief\skinkers.exe
O4 - Startup: Download Plus.lnk = C:\Documents and Settings\Owner\Application Data\DownloadPlus.exe
O4 - Startup: Lotus SmartSuite 97 Registration.lnk = C:\lotus\register\remind32.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Lotus QuickStart.lnk = C:\lotus\wordpro\ltsstart.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://sc.communities.msn.com/controls/chat/msnchat45.cab

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI