This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help With Hijack Log Please

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've got some strange websites popping up regularly for some reason. Hope you can help me.


Logfile of HijackThis v1.99.0
Scan saved at 14:26:21, on 25-1-2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\IP INSIGHT\ARMON32A.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\OPLIMIT\OCRAWARE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\OPLIMIT\OCRAWR32.EXE
C:\Program Files\HP OfficeJet 600-serie\register\remind.exe
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\CPQMLDET.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\STARTEAK.EXE
C:\COMPAQ\EAKDRV\EAUSBKBD.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\HP OFFICEJET 600-SERIE\BIN\HPOSTART.EXE
C:\PROGRAM FILES\HP OFFICEJET 600-SERIE\BIN\HPOJVDIX.EXE
C:\WINDOWS\SYSTEM\HPOMLCH.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\SHAREAZA\SHAREAZA.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirec…=search&ap=b204
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F1 - win.ini: load=c:\oplimit\ocraware.exe c:\progra~1\hpoffi~1\register\remind.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [WCOLOREAL] C:\Program Files\COMPAQ\COLOREAL\COLOREAL.EXE
O4 - HKLM\..\Run: [Digital Dashboard] C:\Program Files\Compaq\Digital Dashboard\CPQMLDET.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [AccessRampMonitor 01] "C:\PROGRAM FILES\IP INSIGHT\ARMon32a.exe"
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Microsoft Works Agenda-herinneringen.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Opstartprocedure HP OfficeJet 600-serie.lnk = C:\Program Files\HP OfficeJet 600-serie\bin\HPOstart.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.planet.nl
O15 - Trusted Zone: http://*.69sexsearch.com
O15 - Trusted Zone: http://*.0texkax7c6hzuidk.com
O15 - Trusted Zone: http://*.093qpeuqpmz6ebfa.com
O15 - Trusted Zone: http://*.rapid-pass.net
O15 - Trusted Zone: http://*.afendis.de
O16 - DPF: {F0BC061F-DAF9-4533-8011-53BCB4C10307} (Installations Assistent) - http://install.gif-bereich.de/InstallationsAssistent.ocx
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup…p1/imloader.cab
Hello Raistlyn, and Welcome to Tom Coyote,

I am going to review your log and get back to you as soon as possible.

In the meantime, please do the following,

* Go to MY CONTROLS > EMAIL SETTINGS > and ENABLE EMAIL NOTIFICATIONS.

* At the top of this post, click on TRACK THIS TOPIC ( then if you can't find this thread, go to MY CONTROLS > VIEW TOPICS and it will be in there.

* Just reply to this post only by posting with the reply button.



Ken545
Raistlyn, It appears that you have a virus and some Maleware on your system. This would explain the pop ups, and weird behavior. What we want to do is to have you run some programs to start the cleanup process. What it dosen't fix, we can do manually after we run the programs, but they could fix it all. After you are clean, then we can install some programs to help stop this garbage from installing in the first place. I see you have Norton Anti-Virus installed, open up that program, go to LIve update and download the latest updates and run a
OOOPPPPSSSS Sorry

Raistlyn,


It appears that you have a virus and some Maleware on your system. This would explain the pop ups, and weird behavior. What we want to do is to have you run some programs to start the cleanup process. What it dosen't fix, we can do manually after we run the programs, but they could fix it all. After you are clean, then we can install some programs to help stop this garbage from installing in the first place.

* I see you have Norton Anti-Virus installed, open up that program, go to LIve update and download the latest updates and run a Full System Scan.

* Please note the links at the bottom of my post, they will take you to some excellent sites to download the tools we will use for your fix.

* After your Norton Scan, go to my link for TRENDMICRO HOUSECALL and run the free online virus scan. It will ask your permission to install Active X componants, say yes, be sure to put a checkmark in the box to Fix all it finds. After it is done, it wouldn't hurt to run the one from PANDA also.

* Then download SPYBOT SEARCH AND DESTROY 1.3. during installation, just folllow all the defaults. Here are some more instructions for running this program.

>Mode/ Advanced Mode

Search For Updates / Download Updates

Immunize / Then Immunize at the top by the Green Plus Sign

Settings / Ignore Products / Checkmark in DSO EXPLOITS)

Settings / File Sets (Checkmark out of USAGE TRACKS)

TOOLS / Hosts File / Add Spybot S&D Host List

Spybot S&D / Check For Problems

Fix Selected Problems

* Re-Boot your computer

* Then download and install AD-AWARE SE PERSONAL 1.05 follow all the defaults during installation. More instructions..

> Ad-Aware SE Personal 1.05

Check for Updates

Checkmark out of SEARCH FOR NEGLIGIBLE RISK ENTRIES

Perform a FULL SYSTEM SCAN

Right click to SELECT ALL / NEXT to delete all entries

* Re-Boot your computer

Then when your done with running all these programs, please run HJT and post a new log and we can see where we stand.


Ken545

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI