This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacker

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Friends computer, has no virus protection. Windows XP operating system.

On boot-up, get "16 bit MS-DOS Subsystem" box. Message in box says "c:\fadjad.exe, C:\WINDOWS\SYSTEM32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose close to terminate the application."

Multiple IE browser sessions also open on boot, web address is http://amateur.freegayspace.com/leetage/nauf.html, browser window is blank.

Cannot get to internet to download virus protection software. When attempt to open browser, most of the time get "page cannot be displayed." Any address entered into browser also gives "page cannot be displayed."

When Spybot is run, finds "DSO Exploit" with 5 entries. Fix problems, reboot, "DSO Exploit" is back.

Turned off restore, no help.

Ad-Aware does not find any problems. Cannot access internet to download virus protection.

Logfile of HijackThis v1.99.0
Scan saved at 12:57:12 AM, on 12/29/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\mssams.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Documents and Settings\Owner\Application Data\wtta.exe
C:\WINDOWS\system32\d?dplay.exe
C:\Program Files\Digital Image\Monitor.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us6.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://us6.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {20B9EF5F-5DBF-2864-9868-29A71F3C96C2} - C:\WINDOWS\system32\byvxehnv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Microsoft Update] wserv32.exe
O4 - HKLM\..\Run: [RCScheduleCheck] C:\Program Files\VCOM\Recovery Commander\RCSCHED.EXE -CHECK
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eiGAaHcs] C:\WINDOWS\vhfenx.exe
O4 - HKLM\..\Run: [Security Agent Manager] mssams.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\RunServices: [Microsoft Update] wserv32.exe
O4 - HKLM\..\RunServices: [Windows Registry Scan] regscan32.exe
O4 - HKLM\..\RunServices: [ScManager] scman.exe
O4 - HKLM\..\RunServices: [Internet Explorer] IEXPLORE.EXE
O4 - HKLM\..\RunServices: [Security Agent Manager] mssams.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\wtta.exe
O4 - HKCU\..\Run: [Security Agent Manager] mssams.exe
O4 - HKCU\..\Run: [Atuipas] C:\WINDOWS\system32\d?dplay.exe
O4 - HKCU\..\RunServices: [Security Agent Manager] mssams.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0a\aoltray.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\Digital Image\Monitor.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: JT's Blocks - http://download.games.yahoo.com/games/clients/y/blt1_x.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O23 - Service: McAfee Framework Service - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Thanks, Neo
Hello Neo, I wish you to know I am looking at this log, and because you can't get online I am going to attempt to do the cleaning with manual tools and this is not the way it should be done. If you have managed to fix the situation already, I would appreciate it if you would post in this thread and let me know so I will not continue working on the log. Because of the extensive removals I wish to clear them through experts and this will slow down the post a little. Thanks for your understanding. Thanks…pskelley TomCoyote forum Classroom Advanced
Hello Neo, Welcome to TomCoyote forum. You do have some nasty stuff on this computer and I would usually run online tools to locate and remove these items. Since you appear to not be able to get online, I will give it a try with manual tools and hope for success. Online search of your items like: fadjad.exe, returns lots of information.

I first need to say that it is explained in SP2 that all malware must be removed before it is installed and it seems this did not occur. If it will have to be removed and reinstalled remains to be seen. Here is some information that might prove handy:
SP2 CD
http://www.microsoft.com/windowsxp/downloa…us/default.mspx
What you should know
http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx

Before we start, we must have HijackThis.exe in a safe permanent folder where it can store backups that may be needed and the logfiles we will create. It is still in a zip file in a temporary directory and this is not safe. Open MyComputer, then the C drive, right click on a blank spot and choose NEW then FOLDER. Move the HJT.exe into that folder then delete what is not in the folder. Here is a tutorial if you need it:
http://russelltexas.com/malware/faqhijackthis.htm
Please do this before you proceed.

I believe this is our culprint:
C:\WINDOWS\system32\mssams.exe
http://computercops.biz/postt94098.html
http://computercops.biz/print-1-94098.html

But these are also items that need to be removed:

This first one you must be very careful with.
C:\WINDOWS\system32\d?dplay.exe
This information comes from one of our experts:
warn himthat the use of a '?' is normally a wildcard, and to be careful while deleting. IE a file dvdplay.exe would be legit. It must have that question mark, not just any character. You must be careful that you delete only a bad item, check the properties of the item to be sure it is not a valid file.

C:\Documents and Settings\Owner\Application Data\wtta.exe
http://answers.google.com/answers/threadview?id=440181

(Please read about this item below it, I will remove it also.)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
http://computercops.biz/startuplist-180.html

This is what we need to tackle first:
C:\WINDOWS\system32\mssams.exe
C:\Documents and Settings\Owner\Application Data\wtta.exe
C:\WINDOWS\system32\d?dplay.exe <<< Caution

Let's hope they go without too much effort, the automated tools are what is needed, and as soon as you can update the AV software, I would do so and run it to see if it locates anything remaining we can't remove manually. I will also provide two additional free online scans you should run. I suggest these instruction be printed as we will be using the safe mode and you will not be able to view them. I will list the methods in numerical order.

1) Use these instruction to enable hidden files for this Operating System:
http://www.bleepingcomputer.com/forums/ind…showtutorial=62

2) These items must not be running, so use these instructions to enter Safe Mode:
http://www.bleepingcomputer.com/forums/ind…torial=61#winxo

3) Scan with HijackThis and check each of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us6.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {20B9EF5F-5DBF-2864-9868-29A71F3C96C2} - C:\WINDOWS\system32\byvxehnv.dll
O4 - HKLM\..\Run: [Microsoft Update] wserv32.exe
O4 - HKLM\..\Run: [eiGAaHcs]
O4 - HKLM\..\Run: [Security Agent Manager] mssams.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\RunServices: [Microsoft Update] wserv32.exe
O4 - HKLM\..\RunServices: [Windows Registry Scan] regscan32.exe
O4 - HKLM\..\RunServices: [ScManager] scman.exe
04 - HKLM\..\RunServices: [Internet Explorer] IEXPLORE.EXE
O4 - HKLM\..\RunServices: [Security Agent Manager] mssams.exe
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\wtta.exe
O4 - HKCU\..\Run: [Security Agent Manager] mssams.exe
O4 - HKCU\..\Run: [Atuipas] C:\WINDOWS\system32\d?dplay.exe
O4 - HKCU\..\RunServices: [Security Agent Manager] mssams.exe

Close all programs except HJT and all browser windows then click on "Fix Checked"

RIGHT click on Start then click on Explore. Locate and Delete these files.

C:\Documents and Settings\Owner\Application Data\wtta.exe

C:\WINDOWS\system32\d?dplay.exe >>make sure you have the bad file

C:\WINDOWS\system32\mssams.exe

C:\WINDOWS\system32\byvxehnv.dll

C:\WINDOWS\vhfenx.exe

Run Cleanmgr: Start, Run type "cleanmgr" without the quotes then ok. Check and remove anything windows locates. Empty the recycle bin and restart the computer. Use the follow two links to keep in the same thread, then post a new log, please include any feedback you think we should have.
When replying to your topic, please use the
http://forums.tomcoyote.org/style_images/1/t_reply.gif
button NOT the
http://forums.tomcoyote.org/style_images/1/t_new.gif
button.

If you can get online at this point, please run these two free online scans:
http://www.windowsecurity.com/trojanscan/
http://housecall.trendmicro.com/housecall/start_corp.asp

Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you get help here consider a donation:
http://tomcoyote.com/donate.php
Thanks, pskelley, but I have already worked through the problems. I was up all night after I posted working on the problems, and using information I found on a website by Mike Healan, I managed to get to a point where I could get on line and downloaded some virus software. Once I had some good virus software to root out the Trojans, it was not much of a problem. I appreaciate all the information that you guys have posted out there in various websites. Neo
Hi Neo, Glad to hear you managed to work out the problems, that was a tough fix no doubt about. Mike is a great guy and you will find him at http://forums.spywareinfo.com/index.php?b=1 where they have BootCamp.
My problem was getting you clean enough to get you online to those tools. The first thing I do is have Ad-aware and Spybot downloaded to get rid of adware then I list a variety of free online scans depending on the trojan/virus I am trying to remove. Since your problem has been worked out, I will close the link but not before wishing you a Happy New Year, and giving you some valuable information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online.

http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://www.cjwd.demon.co.uk/compsafetyonline.html
http://www.bleepingcomputer.com/forums/topict2520.html

Thanks…pskelley
TomCoyote forum
Classroom Advanced
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI