This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log Analysis Please

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 10:13:59 AM, on 4/22/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON INTERNET SECURITY\NISSERV.EXE
C:\PROGRAM FILES\NORTON INTERNET SECURITY\IAMAPP.EXE
C:\PROGRAM FILES\NORTON INTERNET SECURITY\NISUM.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\PHISON\SHICON98.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://www.find-itnow.com/panel_search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v43/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {3CA6DFF6-C6B0-11D4-8035-0050BF0BA18C} (BMSPX Control) - http://221.161.48.135/bmspx.cab
O16 - DPF: {0DA29600-5585-11D8-B5A3-000475C0E61A} (CodeBabyObject Object) - http://2003.quicktaxweb.ca/codebaby/codebaby.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/175052e029c64d…ip/RdxIE601.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://map.ulsan.go.kr/eng/Control/IPIXX_C…2,0,5/IPIXX.cab
O16 - DPF: {6613AE96-E2FE-4651-9185-9271F9E056AB} (Ims24 Control) - http://map.ulsan.go.kr/eng/Control/IMS_Cab…,1018/IMS24.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.telusgeomatics.com/tgpub/tgutil…s/mgaxctrl6.cab
Hello sillvver, Welcome to TomCoyote forum. You do have some issues, if you want my help please follow these directions.

1) C:\WINDOWS\TEMP\HIJACKTHIS.EXE is running from a TEMP folder, we need a permanent folder to store HJT. logs and backups for safety. To fix this return to C:\Windows and RIGHT click your mouse on a blank spot and make a new folder called HJT. Then move HJT.exe into that Folder and look like this: C:\Windows\HJT\HIJACKTHIS.EXE. Once you have it moved you may delete everything in the TEMP folder, NOT THE FOLDER just the contents.
http://www.personal-computer-tutor.com/deletingtempfiles.htm

2) My scan indicated the possible presence of CoolWebSearch and we must remove it if it is there. Download the free version of CWShredder from the following link. Update it first then choose FIX not scan, allow it to remove anything it locates. Please tell me what it found in your next post.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

3) Download CCleaner from this link: http://www.ccleaner.com/ Take the time to review the instructions on the download page so that when I ask you to run it you will know what you are doing.

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(next one: http://www.doxdesk.com/parasite/CoolWebSearch.html )
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://www.find-itnow.com/panel_search.html
(The next item is missing a file and not working correctly. If you wish to use it you will need to download it again after we finish)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL (file missing)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/175052e029c64d…ip/RdxIE601.cab
Netster/nasty
(if you know the next two lines you may leave them)
O16 - DPF: {6613AE96-E2FE-4651-9185-9271F9E056AB} (Ims24 Control) - http://map.ulsan.go.kr/eng/Control/IMS_Cab…,1018/IMS24.cab
O16 - DPF: {6613AE96-E2FE-4651-9185-9271F9E056AB} (Ims24 Control) - http://map.ulsan.go.kr/eng/Control/IMS_Cab…,1018/IMS24.cab

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Run CCleaner then restart the computer and post a new log in this same thread along with any feedback you have. Let us know how you are running.

Thanks…pskelley
TomCoyote forum
Slyware Warrior

PURGE SYSTEM RESTORE
When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instruction:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam
Hi and thank you very much for taking the time to reply. This is all on my computer at work. I will print out the instructions and do what you have suggested. I will not be able to contact you again until Monday/Tuesday. I will go as far as I can with your directions and let you know what I was able to do. Again, thank you. sillvver
That is absolutely no problem. :) If you look around the forum you will see I have plenty to keep me busy. :lol: I will be notified via email when you post again and get back to you as fast as EST allows. pskelley
I have not heard from you about this issue for two weeks. I will close this thread in 48 hours assuming you resolved the issue. Thanks…pskelley
Hi, I am sorry that I have not gotten back to you on this. I am just not able to devote any time to this right now, circumstances do not allow. Thank you for your time and your effort. I will try this again when I am able to sit at the computer for a few hours.
Members comments in their last post explains, they will repost when they have the time to work through the issues.
Thanks…pskelley

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI