This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is a log of my sister's computer. Please review and advise.
I have cleaned her computer yesterday of 100+ virus infections and numerous spyware programs. I had to reset winsock also to access the internet.
I will get back to your question regarding my computer.
Thank you in advance.


Logfile of HijackThis v1.99.0
Scan saved at 10:17:13 PM, on 2/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\AVPersonal\AVGUARD.EXE
E:\Program Files\AVPersonal\AVWUPSRV.EXE
e:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
e:\PROGRA~1\mcafee.com\vso\mcshield.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files\Startup Mechanic\StartupMonitor.exe
E:\Program Files\AVPersonal\AVGNT.EXE
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
E:\Program Files\Microsoft AntiSpyware\gcasServ.exe
E:\Program Files\PhishGuard\PhishGuard.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R3 - Default URLSearchHook is missing
O2 - BHO: Windows Proxy support DLL - {2DC9D850-144D-11E1-B3C9-10805E499D93} - E:\WINDOWS\system32\winprox.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: PhishGuard.Helper - {8B50176C-DD6E-4C14-A603-727A859337CD} - E:\Program Files\PhishGuard\PhishGuardHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - e:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [qpmU32S] appxmlc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Startup Manager Scanner] E:\Program Files\Startup Mechanic\StartupMonitor.exe
O4 - HKLM\..\Run: [AVGCtrl] E:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [bE58RSe4O] mstesnpn.exe
O4 - Global Startup: PhishGuard.lnk = E:\Program Files\PhishGuard\PhishGuard.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://E:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://E:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://E:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://E:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://E:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - E:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - E:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - E:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: IMAPI CD-Burning COM Service - Roxio Inc. - E:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield - Unknown - e:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - Networks Associates Technology, Inc - E:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - e:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello David, I had a chance to look over your sister's log. I keep getting this message "You are receiving this message because a part of this website is illegally using my bandwidth" can you stop it?

This is what I located about this item as it is also in your sister's log. I am just surprised Google does have more information about it. Looks like it has to do with email? I included some information and I will leave the item alone unless you tell me otherwise.
O2 - BHO: Windows Proxy support DLL - {2DC9D850-144D-11E1-B3C9-10805E499D93} - E:\WINDOWS\system32\winprox.dll
http://www.anti-spy.info/process/winprox.dll.html
mail.ntpcug.org - /sigs/msnetwrk/
http://www.ntpcug.org/

There appears to be two antivirus programs running on this computer at the same time. This is not good policy, as conflictions can occur and one well maintained program will do a better job of protecting you.
e:\PROGRA~1\mcafee.com\vso\mcshield.exe
E:\Program Files\AVPersonal\AVGUARD.EXE
This being the case, I suggest you turn off one of them or uninstall it.

These two items do not identify and as such we consider them random named trojans. Unless you know what they are they should be removed. I will also have you do a double check with a free online scan, and purge your system restore points to make sure these trojans are not backed up and could reinfect her computer if you had to use Systen Restore.
O4 - HKLM\..\Run: [qpmU32S] appxmlc.exe
O4 - HKCU\..\Run: [bE58RSe4O] mstesnpn.exe

Open Task Manager and end process on these items if there:
[qpmU32S] appxmlc.exe
[bE58RSe4O] mstesnpn.exe


Use this link to enable hidden files for this Operating System:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html
Since these files do not identify their location, you will need to search for it so you can delete them later.

If you have any programs running that will prevent the changes we wish to make with HJT, you will need to turn them off now.

Scan with HijackThis and check the box in front of each line item:

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [qpmU32S] appxmlc.exe
O4 - HKCU\..\Run: [bE58RSe4O] mstesnpn.exe
(if you did not set these restrictions you may delete them)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Close all programs but HJT and all browser windows then click on "Fix Checked"

RIGHT click on Start then click on Explore, locate and delete these files:

appxmlc.exe >>> file

mstesnpn.exe >>> file

Clean Like this: Start, Run type "cleanmgr" without the quotes then ok. Check and remove anything windows locates. Empty the recycle bin and restart the computer. Use ADD REPLY to stay in this thread, post a new log along with any feedback you think we should have.

At this point I would like you to update the AV software you have decided to run, then do a complete system scan to make sure no mention of the trojans occur. Then I would like you to run this free online scan as a double check: http://www.pandasoftware.com/activescan/co…n_principal.htm

I will give you this link now, but I DO NOT want you to use it until you have been certified clean of malware. This will purge the System Restore points and clean out anything bad that may be in there:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Opps! I removed the avatar image that resulted in the prompt. I will followup after following the recommendations for my sister's computer. Thank you!
Thank you again for your help. Prior to following your suggestions I attempted to delete mcafee.com files, but this file is protected and I am unable to completely delete.
I am only running the free AntiVir Guard program. I believe the system is clean. The only infected file that I could find, following the extensive search last week, was a remanant of TROJ RVP.D and it has been deleted. The only spyware that I can locate is eacceleration and it has been deleted.
I implemented your recommendations in the order advised. I performed a housecall scan prior to the pandasoftware activescan. Both resulted in a clean scan. Following reboot I checked the system resotre box as directed.
Below is the new HJT log. Please advise and thank you (and my sister thanks you too), David

Logfile of HijackThis v1.99.0
Scan saved at 6:18:07 PM, on 2/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\AVPersonal\AVGUARD.EXE
E:\Program Files\AVPersonal\AVWUPSRV.EXE
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\wdfmgr.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\WINDOWS\System32\alg.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\Program Files\Startup Mechanic\StartupMonitor.exe
E:\Program Files\AVPersonal\AVGNT.EXE
E:\Program Files\PhishGuard\PhishGuard.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
O2 - BHO: Windows Proxy support DLL - {2DC9D850-144D-11E1-B3C9-10805E499D93} - E:\WINDOWS\system32\winprox.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PhishGuard.Helper - {8B50176C-DD6E-4C14-A603-727A859337CD} - E:\Program Files\PhishGuard\PhishGuardHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - e:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] "E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Startup Manager Scanner] E:\Program Files\Startup Mechanic\StartupMonitor.exe
O4 - HKLM\..\Run: [AVGCtrl] E:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - Global Startup: PhishGuard.lnk = E:\Program Files\PhishGuard\PhishGuard.exe
O8 - Extra context menu item: &Google Search - res://E:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://E:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://E:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://E:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://E:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - E:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - E:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - E:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: IMAPI CD-Burning COM Service - Roxio Inc. - E:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello David, I must apologize as we recently went through a merger and a change of software. During this period some notifications were not sent and I was not notified that you posted a new log for your sister that I had requested. I spotted this error during routine check of member's threads to make sure nothing was missed. While I can say the last log you posted was clean, a new version of HJT was released recently 1.99.1. If all is wll, make sure you fix her up with the programs I suggested for you to keep her clean and safe. You do not need to post a new log unless you want to but if you do be sure to update HJT first. I will leave this thread open for 48 hours in the event you need it. Once again, sorry for the technical mixup. Thanks, Phil Skelley
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI