This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis V1.99 Log File

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello to the now legendary staffers, (PC World Jan 2005). This is my first post here, so please be fragile ;)

BACKGROUND:
So, here's my scenario: My friend got a "new" used computer and had me reformat it and reinstall everything. No problems. After I used the PC's included restore discs ect to setup his PC, I told him to download and install updates for WinXP. Of course, he didn't :(

Anyway, the other night, he and his fiancée were fighting over whether or not the female wrestler China was really a man or woman, (oh to be in love). His fiancée promptly googled stuff and came across some "interesting" websites - specifically about transvestites. :rofl:

After his entire PC was overrun with Spyware, we ran Ad-Aware and Spybot: Search & Destroy. It found a lot of crap. However, it failed to do anything about it. Having some knowledge in this field, I had him download and run a logfile for Hijack This with version 1.99. He did and I had him remove several things. His PC is almost completely fine - except….

Before I had him disable "AutoComplete" in Internet Explorer, some of the more malicious websites were still visible in his address bar's drop-down list. For example, if he were typing in "google.com" after the letter "g", his address bar would show everything with that beginning. Specifically, a site addressed: gosex.com. All this despite wiping everything clean - manually!
Also, the other issue is a malicious file in his System32 folder in the Windows Directory. I am not too sure what the file is exactly, but even in safe mode, he cannot delete it.

So, after doing everything I can, I had him run another logfile. Below are the results. Please note, he isn't necessarily in "danger" of having his computer overrun again. That is, he seems to be able to do everything perfectly fine and after re-enabling IE's AutoComplete feature, he no longers even sees those aforementioned sights.

Any suggestions/help would be GREATLY appreciated!

SYMPTOMS: Home Page = ToonComics.com
iGuard Program running in background. Redirected web links. In ability to view/download popular anti-spy websites.
Specific: http://www.richardthelionhearted.com/~merijn/cwschronicles.html#tooncomics

LOG:
Logfile of HijackThis v1.99.0
Scan saved at 7:57:35 PM, on 2/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tony\Desktop\virus\HijackThis.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: winlogin.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE66EDBB-9F78-49ED-8ACF-31A6FA0B51AD}: NameServer = 204.255.212.14 206.66.216.8
O20 - AppInit_DLLs: r7vfr13284spupll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

*We thought we selected a disabled line O20… :blink:

Notes: He is using WindowsXP Professional Edition without any updates . Also, his Norton AntiVirus is worthless since his subscription has expired and hasn't been updated for ages. And lastly, for what it's worth, both he and his girl have different user accounts at the logon screen. I don't know if that matters, but I would rather not forget anything that could be important. B)

Again, any help is appreciated!

Thanks a bunch!
:D

</Novel Over>
Sorry to be one of those annoying people who think their problem is the most important problem, but does anyone know what I may do? Thanks! :D
Hello JoeyRoland, welcome to the TC.

Be sure that all windows are closed. Click on START-> RUN. Copy paste the following as it is and click OK.

regsvr32.exe /U r7vfr13284spupll.dll

You should get a message that it has been uninstalled succesfully.
Then be sure that all windows are still closed. Run hijackthis. Hit None of the above, just start the program button. .Put a check mark on these entries.Hit FIX CHEKED button.

O4 - Global Startup: winlogin.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O20 - AppInit_DLLs: r7vfr13284spupll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll




Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Search for and delete these files if listed:
winlogin.exe Be careful: make sure you delete winlogin NOT winlogon.
r7vfr13284spupll.dll


Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED Profile USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI