This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis.log

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is constantly plagued with popups that I can't stop. I have run adaware, cwshredder, and spybot and spyblaster. I would appreciate any assistance you can offer. The following is my HijackThis Log. Thanks

Logfile of HijackThis v1.99.0
Scan saved at 1:24:27 PM, on 2/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\nutsrv4.exe
C:\WINNT\system32\nvsvc32.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\kwqvgi.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\wsxsvc\wsxsvc.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\webshots.scr
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Sparx Systems\EA\EA.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ntechin] C:\WINNT\system32\n20050308.exe
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/185dc8a25c8153…ip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O23 - Service: ASF Agent - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Rational ClearQuest Mail Service - Unknown - C:\Program Files\Rational\ClearQuest\mailservice.exe
O23 - Service: MySQL - Unknown - C:\Program.exe (file missing)
O23 - Service: Intel NCS NetService - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NuTCRACKERService - DataFocus, Inc. - C:\WINNT\system32\nutsrv4.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: ProxyServer Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpxsr.exe
O23 - Service: Rational ProjectConsole Report Server - Unknown - C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
O23 - Service: Rational Test Agent Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpsvc.exe
O23 - Service: WinTools for IE service - Unknown - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
hello Hope,

to start lets try this: we will uninstall a file, use hjt,boot to safe mode, delete some files.
i would print this out or copy it to a text file so you can find it, as we will be in safe mode:
first look in add/remove programs panel and uninstall MyWebSearch

next make sure files are set to show:

Do one of the following:
* In Windows 98/Me/2000, on the Windows desktop, double-click the My Computer icon.
* In Windows XP, on the taskbar, click Start > My Computer.
# Do one of the following:
* In Windows 98, on the View menu, click Folder Options.
* In Windows Me/2000/XP, on the Tools menu, click Folder Options.
# On the View tab, uncheck Hide file extensions for known file types.
# Do one of the following:
* In Windows 98, in the Advanced Settings box, under the "Hidden files" folder, click Show all files.
* In Windows Me/2000/XP, uncheck Hide protected operating system files. Then, under the "Hidden files" folder, click Show hidden files and folders.
# If you see a warning message, click Yes.
# Click Apply.
# Click OK.
———————–
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php

R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)

O4 - HKLM\..\Run: [ntechin] C:\WINNT\system32\n20050308.exe

O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/185dc8a25c8153…ip/RdxIE601.cab


O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab

O23 - Service: WinTools for IE service - Unknown - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
———————-

ok now boot to safe mode by tapping the f8 key at restart, form the options chose safe mode once in safe mode find and delete:
kwqvgi.exe—->delete just that exe located here—>C:\WINNT\system32

same for these also, both in C:\WINNT\system32
n20050308.exe
wsxsvc.exe

also delete these two>>entire folder:
C:\PROGRA~1\MYWEBS~1\ (myweb search)
C:\Program Files\Common Files\WinTools\WToolsS.exe
———————–

still in safe mode:
Click Start>Run then type %temp%
Hit OK. Delete all the files you can.

Empty your Temp folders. Go to Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin
———————-
reboot normally rescan with hjt and post new log……….
Thanks..sorry it took me this long to get back. Some of the items you listed were not present on my computer. I could not locate MyWebSeach thorugh the Add/Remove Utility although I have been successfully able to remove it previously thorugh this method. Access was denied when trying to delete kwqvgi.exe (in safe mode) and also while in safe mode, I could not find C:\PROGRA~1\(mywebsearch) or :\Program Files\Common Files\WinTools\WToolS.exe. I did run cleanmgr and clean up the areas you specified, rebooted the machine and attached is the latest HJT.log

Logfile of HijackThis v1.99.0
Scan saved at 1:59:30 PM, on 2/10/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\nutsrv4.exe
C:\WINNT\system32\nvsvc32.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\kwqvgi.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\webshots.scr
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: ASF Agent - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Rational ClearQuest Mail Service - Unknown - C:\Program Files\Rational\ClearQuest\mailservice.exe
O23 - Service: MySQL - Unknown - C:\Program.exe (file missing)
O23 - Service: Intel NCS NetService - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NuTCRACKERService - DataFocus, Inc. - C:\WINNT\system32\nutsrv4.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: ProxyServer Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpxsr.exe
O23 - Service: Rational ProjectConsole Report Server - Unknown - C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
O23 - Service: Rational Test Agent Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpsvc.exe
hello Hope,

no problem, some posters never post back. log is looking better.
we will do two things, first use LSPFix– then try to delete that file.

First click here to download LSPFix. http://www.cexx.org/LSPFix.exe

Run it, make sure you click the "I know what I'm doing" button. Select calsp.dll and using the right-pointing 'arrows' move all instances of calsp.dll it mentions and –>nothing else<–to the Remove side but leave everything else (it might already be over there when you open LSPFix). Click the 'Finished' button (if you exit with the X at top right nothing happens).

ok now reboot computer into safe mode again by tapping the f8 key at restart.
once in safe mode. from the desk top hit these 3 keys:

crtl alt delete, select task manager , under the process tab look for —>kwqvgi.exe
if its present select it and then select end process, then close task manager.

next still in safe mode find the file in explorer:
C:\WINNT\system32\kwqvgi.exe
right click on it and select properties and check to see
if the read only attribute is checked. if it is- uncheck it and try again to delete it.
———————–
reboot normally– if still wont delete we will try something else.
rescan with hjt, post new log……..
Hi again,

Still unable to delete the kwqvgi.exe file with same error as before —- it was not listed in the processes in Task Manager and so I tried to delete it manually through explorer. I rebooted and preformed another HiJackThis. The new log follows:

Thanks


Logfile of HijackThis v1.99.0
Scan saved at 8:35:13 AM, on 2/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\nutsrv4.exe
C:\WINNT\system32\nvsvc32.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\system32\kwqvgi.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\webshots.scr
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: ASF Agent - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Rational ClearQuest Mail Service - Unknown - C:\Program Files\Rational\ClearQuest\mailservice.exe
O23 - Service: MySQL - Unknown - C:\Program.exe (file missing)
O23 - Service: Intel NCS NetService - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NuTCRACKERService - DataFocus, Inc. - C:\WINNT\system32\nutsrv4.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: ProxyServer Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpxsr.exe
O23 - Service: Rational ProjectConsole Report Server - Unknown - C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
O23 - Service: Rational Test Agent Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpsvc.exe
Ok, here are the results from the scan: RAV AntiVirus command line for Linux i386. Version: 8.4.3. Copyright © since 1995 GeCAD The Software Company. All rights reserved. Scan engine 8.11 for i386. Last update: Sun, 13 Feb 2005 22:41:04 +0200 Scanning for 113049 malwares (viruses, trojans and worms). Scan started on Tue Feb 15 14:26:14 2005 kwqvgi.exe is infected with TrojanDropper:Win32/Qoologic.C Scan ended on Tue Feb 15 14:26:14 2005 Scan results: Time: 0 second(s). Objects scanned: 1. New objects: 1 Infected: 1. Different virus bodies: 1. Files: 1. Directories: 0. Archives: 0. Packed: 0. Mail files: 0. Warnings: 0. Thanks.
this is the results from the second scan. Service load: 0% 100% File: kwqvgi.exe Status: INFECTED/MALWARE Packers detected: ASPACK AntiVir TR/Dldr.Qoologic.F (0.68 seconds taken) Avast No viruses found (3.10 seconds taken) AVG Antivirus Downloader.Qoologic.L (3.02 seconds taken) BitDefender No viruses found (2.08 seconds taken) ClamAV Trojan.Qooloc-5 (1.83 seconds taken) Dr.Web Trojan.MulDrop.1400 (3.78 seconds taken) F-Prot Antivirus W32/Downloader.AAQ (0.26 seconds taken) Fortinet No viruses found (1.25 seconds taken) Kaspersky Anti-Virus Trojan-Downloader.Win32.Qoologic.f (1.23 seconds taken) mks_vir Trojan.Downloader.Qoologic.F (0.21 seconds taken) NOD32 No viruses found (1.67 seconds taken) Norman Virus Control W32/Qoolaid.2_74 (0.45 seconds taken) Statistics Last piece of malware found was W32/Bifrose.E in sarah_michele_gellar2.scr, detected by:
And finally the results from the 3rd scan: Server response Results of a file scan This is the report of the scanning done over "kwqvgi.exe" file that VirusTotal processed on 02/15/2005 at 20:20:15 (GMT+1). Antivirus Version Update Result AntiVir 6.29.0.14 02.15.2005 TR/Dldr.Qoologic.F AVG 718 02.14.2005 Downloader.Qoologic.L BitDefender 7.0 02.15.2005 Trojan.Downloader.Qoologic.F ClamAV devel-20050130 02.14.2005 Trojan.Qooloc-5 DrWeb 4.32b 02.15.2005 Trojan.MulDrop.1400 eTrust-Iris 7.1.194.0 02.15.2005 no virus found eTrust-Vet 11.7.0.0 02.15.2005 no virus found Fortinet 2.51 02.15.2005 no virus found F-Prot 3.16a 02.15.2005 security risk named W32/Downloader.AAQ Kaspersky 4.0.2.24 02.15.2005 Trojan-Downloader.Win32.Qoologic.f NOD32v2 1.998 02.12.2005 no virus found Norman 5.70.10 02.15.2005 W32/Qoolaid.2_74 Panda 8.02.00 02.15.2005 Adware/QoolAid Sybari 7.5.1314 02.15.2005 Trojan-Downloader.Win32.Qoologic.f Symantec 8.0 02.14.2005 no virus found VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about abailability and continuity of this service. Even when the detection rate given by the use of multiple antivirus engines is far superior to the one offered by only one product, this results DO NOT guarantee the harmlessness of a file. There is no such a solution that can offer a 100% rate of efectiveness recognizing virus and malware. > Go to: Home Contact En Español www.virustotal.com :: @ Hi spasec Sistemas 2004 :: e-mail [removed] Thanks
hello Hope,

ok good. we can try two things.
1) pocket killbox
2) some online scans ( try 2 or 3)
———————————–

online scanners here:
http://www.bitdefender.com/scan/licence.php

http://security.symantec.com/sscv6/default…id=ie&venid=sym

http://www.mwti.net/antivirus/free_utilities.asp

http://www.pandasoftware.com/activescan/co…n_principal.htm

http://housecall.trendmicro.com/housecall/start_corp.asp
———————————-
pocket killbox:

go here:

http://www.subratam.org/

clink on Removal Tool link to left and download Killbox. unzip it somewhere. run it and browse for the file below using the folder icon to the right of the window, select delete on reboot. you should get a conformation message and a second msg to reboot now?
select yes to reboot, cross fingers.

C:\WINNT\system32\kwqvgi.exe
————————————-

afterwards rescan and post new hjt log……………
Hi,

Ok so i was actually able to delete the file with the killbox utility (!). Then I performed the bitdefender search which found nothing. I then performed the pandasoft search which found the following:


Incident Status Location

Adware:Adware/QoolAid No disinfected C:\WINNT\system32\aesino.dll
Adware:Adware/eZula No disinfected C:\Program Files\Web Offer
Spyware:Spyware/BargainBuddy No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\Temp\FLEOK
Adware:Adware/KeenValue No disinfected C:\WINNT\system32\drivers\etc\hosts.bho
Adware:Adware/SAHAgent No disinfected Windows Registry
Adware:Adware/CWS No disinfected C:\WINNT\Downloaded Program Files\ATPartners.inf
Adware:Adware/FunWeb No disinfected Windows Registry
Adware:Adware/NetPals No disinfected C:\WINNT\system32\ATPartners.dll
Adware:Adware/WinTools No disinfected Windows Registry
Adware:Adware/DelFinMedia No disinfected C:\keys.ini
Adware:Adware/MediaTickets No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\WINNT\alchem.???
Adware:Adware/SearchExe No disinfected C:\Program Files\se
Adware:Adware/Look2Me No disinfected C:\WINNT\system\UpdInstall.exe
Adware:Adware/Twain-Tech No disinfected C:\WINNT\inf\twaintec.inf
Adware:Adware/EliteBar No disinfected C:\WINNT\EliteSideBar
Adware:Adware/Beginto No disinfected C:\WINNT\system32\dsktrf.dll
Adware:Adware/MyWebSearch No disinfected Windows Registry
Spyware:Spyware/Virtumonde No disinfected C:\WINNT\system32\Aklsp.dll
Adware:Adware/SuperSpider No disinfected Windows Registry
Spyware:Spyware/Bundleware No disinfected C:\WINNT\downloaded program files\ds3.dll
Spyware:Spyware/CouponAge No disinfected C:\WINNT\system32\calsp.dll
Adware:Adware/CWS.Searchmeup No disinfected Windows Registry
Spyware:Spyware/Virtumonde No disinfected C:\Documents and Settings\Jacqueline Witczak\Local Settings\Temporary Internet Files\Content.IE5\O50B8RO3\minst[1].exe
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Jacqueline Witczak\Local Settings\Temporary Internet Files\Content.IE5\O50B8RO3\prompt[1].php
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Jacqueline Witczak\Local Settings\Temporary Internet Files\Content.IE5\O50B8RO3\WinAdAlt[1].exe
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Jacqueline Witczak\Local Settings\Temporary Internet Files\Content.IE5\O50B8RO3\WinAdCtl[1].exe
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Jacqueline Witczak\Local Settings\Temporary Internet Files\Content.IE5\O50B8RO3\WinAdShift[1].dll
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\Jacqueline Witczak\WrapperOuter.exe
Adware:Adware/EliteBar No disinfected C:\pop.exe
Adware:Adware/EliteBar No disinfected C:\prot.exe
Adware:Adware/EliteBar No disinfected C:\sidebDD.exe
Adware:Adware/EliteBar No disinfected C:\silent093.exe
Adware:Adware/nCase No disinfected C:\Temp\salm.exe_tobedeleted
Adware:Adware/nCase No disinfected C:\Temp\salmhook.dll
Adware:Adware/NetPals No disinfected C:\WINNT\Downloaded Program Files\ATPartners.inf
Adware:Adware/Look2Me No disinfected C:\WINNT\Downloaded Program Files\DS3.dll
Adware:Adware/Envolo No disinfected C:\WINNT\ecpwy.exe
Adware:Adware/EliteBar No disinfected C:\WINNT\EliteSideBar\EliteSideBar 07.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\EliteSideBar\EliteSideBar 08.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\EliteToolBar\EliteToolBar version 58.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\EliteToolBar\EliteToolBar version 59.dll
Adware:Adware/IPInsight No disinfected C:\WINNT\INF\alchem.inf
Adware:Adware/Twain-Tech No disinfected C:\WINNT\INF\twaintec.inf
Virus:Trj/Downloader.GK Disinfected C:\WINNT\polmx.exe
Virus:Trj/Downloader.GK Disinfected C:\WINNT\poltt.exe
Possible Virus. No disinfected C:\WINNT\QBAux.exe
Adware:Adware/EliteBar No disinfected C:\WINNT\sideb.exe
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM\UpdInstall.exe
Spyware:Spyware/Virtumonde No disinfected C:\WINNT\SYSTEM32\akcore.dll
Spyware:Spyware/Virtumonde No disinfected C:\WINNT\SYSTEM32\aklsp.dll
Spyware:Spyware/Virtumonde No disinfected C:\WINNT\SYSTEM32\akrules.dll
Spyware:Spyware/Virtumonde No disinfected C:\WINNT\SYSTEM32\akupd.dll
Adware:Adware/NetPals No disinfected C:\WINNT\SYSTEM32\ATPartners.dll
Spyware:Spyware/CouponAge No disinfected C:\WINNT\SYSTEM32\calsp.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\SYSTEM32\doolsav.dat
Adware:Adware/Beginto No disinfected C:\WINNT\SYSTEM32\dsktrf.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\enj6l11s1.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\enr0l19m1.dll
Adware:Adware/FunWeb No disinfected C:\WINNT\SYSTEM32\f3pssavr.scr
Virus:Trj/Multidropper.MM Disinfected C:\WINNT\SYSTEM32\in10b6s.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\SYSTEM32\kalvckf32.exe
Adware:Adware/EliteBar No disinfected C:\WINNT\SYSTEM32\kalvwvx32.exe
Adware:Adware/EliteBar No disinfected C:\WINNT\SYSTEM32\kalvyel32.exe
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\kt42l7ho1.dll
Virus:Trj/Krico.A Disinfected C:\WINNT\SYSTEM32\kwqvci.exe
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\lvpu0979e.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\m0po0a73ed.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\o866lijs18o6.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\o8pq0i75e8.dll
Virus:Trj/Krico.A Disinfected C:\WINNT\SYSTEM32\pcilqw.dll
Adware:Adware/QoolAid No disinfected C:\WINNT\SYSTEM32\pcilqy.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\SYSTEM32\r4p80e7ueh.dll
Virus:Trj/Krico.A Disinfected C:\WINNT\SYSTEM32\vpgwka.dat
Adware:Adware/DelFinMedia No disinfected C:\WINNT\SYSTEM32\wsxsvc\wsx.dll
Adware:Adware/DelFinMedia No disinfected C:\WINNT\SYSTEM32\wsxsvc\wsx.ocx
Adware:Adware/SAHAgent No disinfected C:\WINNT\SYSTEM32\xmlparse.dll
Adware:Adware/SAHAgent No disinfected C:\WINNT\SYSTEM32\xmltok.dll
Adware:Adware/EliteBar No disinfected C:\WINNT\Temp\12535218.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\Temp\bw2.com
Adware:Adware/SAHAgent No disinfected C:\WINNT\Temp\f70206312.exe
Spyware:Spyware/Overpro No disinfected C:\WINNT\Temp\nsdtmp09.dll
Adware:Adware/SearchExe No disinfected C:\WINNT\Temp\se.exe
Adware:Adware/EliteBar No disinfected C:\WINNT\Temp\suicidetb.exe
Adware:Adware/QoolAid No disinfected C:\WINNT\Temp\wtmp.exe

then i did a rescan and the new hjt log is :

Logfile of HijackThis v1.99.0
Scan saved at 3:29:26 PM, on 2/16/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\nutsrv4.exe
C:\WINNT\system32\nvsvc32.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nhfkiu.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\webshots.scr
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: ASF Agent - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Rational ClearQuest Mail Service - Unknown - C:\Program Files\Rational\ClearQuest\mailservice.exe
O23 - Service: MySQL - Unknown - C:\Program.exe (file missing)
O23 - Service: Intel NCS NetService - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NuTCRACKERService - DataFocus, Inc. - C:\WINNT\system32\nutsrv4.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: ProxyServer Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpxsr.exe
O23 - Service: Rational ProjectConsole Report Server - Unknown - C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
O23 - Service: Rational Test Agent Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpsvc.exe


Thanks for your ongoing help!

Hope
hello Hope,

latest log is looking good, how are things on that end?
do you have ad aware? if not go to there web site and get it and also the vx2 plug in. instructions on how to run the plugin it on there web site:

ad aware SE personal edition:
http://www.lavasoft.de/

afterwards rescan with htj and post new hjt log……..
hi, things are much better. I can't thank you enough!!!
the latest hjt.log is:

Logfile of HijackThis v1.99.0
Scan saved at 10:50:30 AM, on 2/18/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\pds.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\nutsrv4.exe
C:\WINNT\system32\nvsvc32.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\cba\xfr.exe
C:\WINNT\system32\MsgSys.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\webshots.scr
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Internat.exe] internat.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: ASF Agent - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINNT\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\cba\pds.exe
O23 - Service: Rational ClearQuest Mail Service - Unknown - C:\Program Files\Rational\ClearQuest\mailservice.exe
O23 - Service: MySQL - Unknown - C:\Program.exe (file missing)
O23 - Service: Intel NCS NetService - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NuTCRACKERService - DataFocus, Inc. - C:\WINNT\system32\nutsrv4.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: ProxyServer Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpxsr.exe
O23 - Service: Rational ProjectConsole Report Server - Unknown - C:\Program Files\Rational\ProjectConsole\bin\ReportServer.exe
O23 - Service: Rational Test Agent Service - Rational Software - C:\Program Files\Rational\Rational Test\rtpsvc.exe

I still get a few pop-ups but nothing like before.

Hey, would you please help me with another computer. My conputer at home is even worse if you can believe it!?

Thanks.
Hope

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI