This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help On My Hijackthis Log

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My homepage keeps resetting to "Search For" page and pop ups keep coming up telling me I have spyware on my computer (duh?). Also I have scanned with Adware, Prevx and Spybot. Any help would be great.

Here ia my HijackThis Log :

Logfile of HijackThis v1.99.1
Scan saved at 10:07:48 PM, on 4/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\PREVX\Prevx Home\SAGUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {97F06520-C055-4F61-9A05-B2EE3E3FA11C} - C:\WINDOWS\system32\eof.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\PREVX\Prevx Home\SAGUI.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…64/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/010d151c693227…ip/RdxIE601.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D5084B9-47E7-4B21-A9C1-C624B36A6C47}: NameServer = 151.164.1.8,206.13.28.12
O18 - Filter: text/html - {A39673B8-35FC-4072-9EEE-87962EBD79CD} - C:\WINDOWS\system32\eof.dll
O18 - Filter: text/plain - {A39673B8-35FC-4072-9EEE-87962EBD79CD} - C:\WINDOWS\system32\eof.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\PREVX\Prevx Home\PXAgent.exe" -f (file missing)

Thanks in Advance!
Hello pleasefix and welcome to TomCoyote. :wavey:

You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Prepare CWShredder for use:
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare SpSeHjfix
    • Download SpSeHjfix from here.
    • Unzip the contents of SpSeHjfix112.zip.
    • Please do not do anything with it yet.
  • Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.

Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.
To return to normal mode just restart your computer as you normally would.
  • Disconnect from the Internet and Close ALL OPEN PROGRAMS.
    • Run 'SpSeHjfix'. and click on "Start Disinfection".
    • When it's finished it will reboot your machine to finish the cleaning process.
    • The tool creates a log of the fix which will appear in the folder.
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Reboot and repeat the process above.
  • Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.
Thanks here is the log for SPSeHjFix:


(5/2/05 10:28:30 PM) SPSeHjFix started v1.1.2
(5/2/05 10:28:30 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/2/05 10:28:30 PM) Language: english
(5/2/05 10:28:30 PM) Win-Path: C:\WINDOWS
(5/2/05 10:28:30 PM) System-Path: C:\WINDOWS\system32
(5/2/05 10:28:30 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/2/05 10:28:37 PM) Disinfection started
(5/2/05 10:28:37 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\sp.dll
(5/2/05 10:28:37 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\system32\eof.dll
(5/2/05 10:28:37 PM) Searchassistant Uninstaller - Keys Deleted
(5/2/05 10:28:37 PM) UBF: 6 - UBB: 2 - UBR: 19
(5/2/05 10:28:37 PM) FilterKey: HKCR\text/html (deleted)
(5/2/05 10:28:37 PM) FilterKey: HKCR\CLSID\{A39673B8-35FC-4072-9EEE-87962EBD79CD} (deleted)
(5/2/05 10:28:37 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(5/2/05 10:28:37 PM) FilterKey: HKCR\text/plain (deleted)
(5/2/05 10:28:37 PM) FilterKey: HKCR\CLSID\{A39673B8-35FC-4072-9EEE-87962EBD79CD} (error while deleting)
(5/2/05 10:28:37 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(5/2/05 10:28:37 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97F06520-C055-4F61-9A05-B2EE3E3FA11C} (deleted)
(5/2/05 10:28:37 PM) BHO-Key: HKCR\CLSID\{97F06520-C055-4F61-9A05-B2EE3E3FA11C} (deleted)
(5/2/05 10:28:37 PM) UBF: 4 - UBB: 1 - UBR: 19
(5/2/05 10:28:37 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\sp.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\sp.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/2/05 10:28:38 PM) Stealth-String not found
(5/2/05 10:28:38 PM) File added to delete: c:\windows\system32\eof.dll
(5/2/05 10:28:38 PM) Reboot


(5/2/05 10:35:10 PM) SPSeHjFix started v1.1.2
(5/2/05 10:35:10 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/2/05 10:35:10 PM) Language: english
(5/2/05 10:35:10 PM) Win-Path: C:\WINDOWS
(5/2/05 10:35:10 PM) System-Path: C:\WINDOWS\system32
(5/2/05 10:35:10 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/2/05 10:35:11 PM) Disinfection started
(5/2/05 10:35:11 PM) Bad-Dll(IEP): (not found)
(5/2/05 10:35:11 PM) Bad-Dll(IEP) in BHO: (not found)
(5/2/05 10:35:11 PM) UBF: 4 - UBB: 1 - UBR: 20
(5/2/05 10:35:11 PM) UBF: 4 - UBB: 1 - UBR: 20
(5/2/05 10:35:11 PM) Bad IE-pages: (none)
(5/2/05 10:35:12 PM) Stealth-String not found
(5/2/05 10:35:12 PM) Not infected->END


(5/2/05 10:37:45 PM) SPSeHjFix started v1.1.2
(5/2/05 10:37:45 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/2/05 10:37:45 PM) Language: english
(5/2/05 10:37:45 PM) Win-Path: C:\WINDOWS
(5/2/05 10:37:45 PM) System-Path: C:\WINDOWS\system32
(5/2/05 10:37:45 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\


Here is the new log for hijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 11:04:41 PM, on 5/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\PREVX\Prevx Home\PXAgent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\PREVX\Prevx Home\SAGUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\PREVX\Prevx Home\SAGUI.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…64/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/010d151c693227…ip/RdxIE601.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D5084B9-47E7-4B21-A9C1-C624B36A6C47}: NameServer = 151.164.1.8,206.13.28.12
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\PREVX\Prevx Home\PXAgent.exe" -f (file missing)

Thanks for the help. Currently IE does not run. I am using firefox to post this.

Thanks!
To repair Internet Explorer in Windows XP, complete the following procedure while you are logged on as an administrator:

Use the System File Checker tool to scan all of the protected files on your computer:

Click Start, and then click Run.
In the Open box, type sfc /scannow, and then click OK.

Two links to look at:
Additional Info
Additional Info


Open HijackThis, run a scan, then check the following:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/010d151c693227…ip/RdxIE601.cab


With all other programs and browsers closed, click fix checked.


Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
Thanks my IE is now working adn here is the new HiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:46:36 PM, on 5/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\PREVX\Prevx Home\PXAgent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\PREVX\Prevx Home\SAGUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\PREVX\Prevx Home\SAGUI.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…64/mcinsctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D5084B9-47E7-4B21-A9C1-C624B36A6C47}: NameServer = 151.164.1.8,206.13.28.12
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\PREVX\Prevx Home\PXAgent.exe" -f (file missing)


The only thing is that I cannot set my homepage it continually is set to about:blank.

Thanks again!
Just want to make sure I am clear on what you are saying. Is this the same About:Blank ("Search For") pages you had before or is it a blank page that shows About:Blank in the address bar?
It is just a blank page (allwhite no more Search for page) with the address that says about:blank. I've tried going into the tools to internet options and typing in a new address but I stays about:blank. Thanks
Open Microsoft Antispyware and click Tools < Advanced Tools < System Explorers. In the left pane under Internet Explorer, click IE Settings. Click Restore all IE default settings. Now click Change URL/page and enter the home page you would like for Internet Explorer and click OK.
Let us know if this helps.

Do you have any items unchecked in msconfig or stopped from starting with a start-up manager?
Hi I started up my computer and found that Search Assist was trying to install back on my computer. Not sure why since I don't really use IE anymore I use Fire Fox. But I ran a new HiJachThis Log and here it is:

Logfile of HijackThis v1.99.1
Scan saved at 10:00:23 PM, on 5/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {1D94898F-8C28-4FD3-916B-4ED94B489B66} - C:\WINDOWS\system32\kgc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll,DllInstall
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…64/mcinsctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D5084B9-47E7-4B21-A9C1-C624B36A6C47}: NameServer = 151.164.1.8,206.13.28.12
O18 - Filter: text/html - {6B89EC1F-4741-4DAC-B057-C3EDA31A4261} - C:\WINDOWS\system32\kgc.dll
O18 - Filter: text/plain - {6B89EC1F-4741-4DAC-B057-C3EDA31A4261} - C:\WINDOWS\system32\kgc.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Any help would be great thanks again.
This infection does have a habit of returning. We'll need to go back to the original fix again.

You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Prepare CWShredder for use:
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare SpSeHjfix
    • Download SpSeHjfix from here.
    • Unzip the contents of SpSeHjfix112.zip.
    • Please do not do anything with it yet.
  • Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.

Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.
To return to normal mode just restart your computer as you normally would.
  • Disconnect from the Internet and Close ALL OPEN PROGRAMS.
    • Run 'SpSeHjfix'. and click on "Start Disinfection".
    • When it's finished it will reboot your machine to finish the cleaning process.
    • The tool creates a log of the fix which will appear in the folder.
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Reboot and repeat the process above.

    Repeat the process above until you get a log like this - 'not infected'

    3-26-05 18:08:05) SPSeHjFix started v1.1.0
    (3-26-05 18:08:05) OS: Win (4.10.2222)
    (3-26-05 18:08:05) Language: svenska
    (3-26-05 18:08:07) Disinfect started
    (3-26-05 18:08:07) Bad-Dll(IEP): (not found)  <——
    (3-26-05 18:08:07) Bad-Dll(IEP) in BHO: (not found) <——
    (3-26-05 18:08:07) UBF: 4
    (3-26-05 18:08:07) UBB: 2
    (3-26-05 18:08:07) UBR: 17
    (3-26-05 18:08:07) Bad IE-pages:
    (3-26-05 18:08:07) Stealth-String not found:  <——
    (3-26-05 18:08:07) Not infected->END  <——

  • Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix' as a reply to this thread.
Hi I Followed the directions and this time. When I ran cshredder in safe mode the graphics on my screen was messed up after it ran. But I was still able to click restart from the start menu. Afterwards the computer restarted but got stuck showing nthing on the screen and it had no mouse or keyboard input. I did a hard restart and now I hear the computer on but there is nothing on the screen and no mouse or keyboard action. Also I tried restarting with the window XP CD and nothing happen either? Any help? Thanks pleasefix
Boot into the Recovery Console by following these steps: 1. Insert the Windows CD and restart your computer. Follow your computer's prompts to boot from the CD. (You might need to adjust settings in the computer's BIOS to enable the option to boot from a CD.) 2. Follow the setup prompts to load the basic Windows startup files. At the Welcome To Setup screen press R to start the Recovery Console. 3. Enter the number of the Windows installation you want to access from the Recovery Console. 4. When prompted, type the Administrator password. If you're using the Recovery Console on a system running Windows XP Home Edition, this password is blank by default, so just press Enter.
Thanks I reinstalled the video card back into the mother board. So Here is the SPSeHjFix log:


(5/7/05 9:39:21 PM) SPSeHjFix started v1.1.2
(5/7/05 9:39:21 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/7/05 9:39:21 PM) Language: english
(5/7/05 9:39:21 PM) Win-Path: C:\WINDOWS
(5/7/05 9:39:21 PM) System-Path: C:\WINDOWS\system32
(5/7/05 9:39:21 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/7/05 9:39:24 PM) Disinfection started
(5/7/05 9:39:24 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/7/05 9:39:24 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\system32\feh.dll
(5/7/05 9:39:24 PM) Searchassistant Uninstaller - Keys Deleted
(5/7/05 9:39:24 PM) UBF: 6 - UBB: 2 - UBR: 18
(5/7/05 9:39:24 PM) FilterKey: HKCR\text/html (deleted)
(5/7/05 9:39:24 PM) FilterKey: HKCR\CLSID\{E8B65B8F-2B44-4E88-A3D5-D8725571FD0B} (deleted)
(5/7/05 9:39:24 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(5/7/05 9:39:24 PM) FilterKey: HKCR\text/plain (deleted)
(5/7/05 9:39:24 PM) FilterKey: HKCR\CLSID\{E8B65B8F-2B44-4E88-A3D5-D8725571FD0B} (error while deleting)
(5/7/05 9:39:24 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(5/7/05 9:39:24 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E63ED8F-9D43-4058-8327-8C45EB9DA1D8} (deleted)
(5/7/05 9:39:24 PM) BHO-Key: HKCR\CLSID\{0E63ED8F-9D43-4058-8327-8C45EB9DA1D8} (deleted)
(5/7/05 9:39:24 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll,DllInstall (deleted)
(5/7/05 9:39:24 PM) UBF: 4 - UBB: 1 - UBR: 17
(5/7/05 9:39:24 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/7/05 9:39:24 PM) Stealth-String not found
(5/7/05 9:39:24 PM) File added to delete: c:\windows\system32\feh.dll
(5/7/05 9:39:24 PM) File added to delete: c:\docume~1\owner\locals~1\temp\se.dll
(5/7/05 9:39:24 PM) Reboot


(5/7/05 9:45:53 PM) SPSeHjFix started v1.1.2
(5/7/05 9:45:53 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/7/05 9:45:53 PM) Language: english
(5/7/05 9:45:53 PM) Win-Path: C:\WINDOWS
(5/7/05 9:45:53 PM) System-Path: C:\WINDOWS\system32
(5/7/05 9:45:53 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/7/05 9:45:59 PM) Disinfection started
(5/7/05 9:45:59 PM) Bad-Dll(IEP): (not found)
(5/7/05 9:45:59 PM) Bad-Dll(IEP) in BHO: (not found)
(5/7/05 9:45:59 PM) UBF: 4 - UBB: 1 - UBR: 18
(5/7/05 9:45:59 PM) UBF: 4 - UBB: 1 - UBR: 18
(5/7/05 9:45:59 PM) Bad IE-pages: (none)
(5/7/05 9:46:00 PM) Stealth-String not found
(5/7/05 9:46:00 PM) Not infected->END


(5/8/05 12:52:23 AM) SPSeHjFix started v1.1.2
(5/8/05 12:52:23 AM) OS: WinXP Service Pack 2 (5.1.2600)
(5/8/05 12:52:23 AM) Language: english
(5/8/05 12:52:23 AM) Win-Path: C:\WINDOWS
(5/8/05 12:52:23 AM) System-Path: C:\WINDOWS\system32
(5/8/05 12:52:23 AM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/8/05 12:52:25 AM) Disinfection started
(5/8/05 12:52:25 AM) Bad-Dll(IEP): (not found)
(5/8/05 12:52:25 AM) Bad-Dll(IEP) in BHO: (not found)
(5/8/05 12:52:25 AM) UBF: 4 - UBB: 1 - UBR: 18
(5/8/05 12:52:25 AM) UBF: 4 - UBB: 1 - UBR: 18
(5/8/05 12:52:26 AM) Bad IE-pages: (none)
(5/8/05 12:52:26 AM) Stealth-String not found
(5/8/05 12:52:26 AM) Not infected->END


(5/8/05 12:55:08 AM) SPSeHjFix started v1.1.2
(5/8/05 12:55:08 AM) OS: WinXP Service Pack 2 (5.1.2600)
(5/8/05 12:55:08 AM) Language: english
(5/8/05 12:55:08 AM) Win-Path: C:\WINDOWS
(5/8/05 12:55:08 AM) System-Path: C:\WINDOWS\system32
(5/8/05 12:55:08 AM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/8/05 12:55:22 AM) Disinfection started
(5/8/05 12:55:22 AM) Bad-Dll(IEP): (not found)
(5/8/05 12:55:22 AM) Bad-Dll(IEP) in BHO: (not found)
(5/8/05 12:55:22 AM) UBF: 4 - UBB: 1 - UBR: 18
(5/8/05 12:55:22 AM) UBF: 4 - UBB: 1 - UBR: 18
(5/8/05 12:55:22 AM) Bad IE-pages: (none)
(5/8/05 12:55:22 AM) Stealth-String not found
(5/8/05 12:55:22 AM) Not infected->END


(5/8/05 12:58:42 AM) SPSeHjFix started v1.1.2
(5/8/05 12:58:42 AM) OS: WinXP Service Pack 2 (5.1.2600)
(5/8/05 12:58:42 AM) Language: english
(5/8/05 12:58:42 AM) Win-Path: C:\WINDOWS
(5/8/05 12:58:42 AM) System-Path: C:\WINDOWS\system32
(5/8/05 12:58:42 AM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\


Also here is the hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 12:59:43 AM, on 5/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…64/mcinsctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D5084B9-47E7-4B21-A9C1-C624B36A6C47}: NameServer = 151.164.1.8,206.13.28.12
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Thanks again. I hope this helps.
Glad to hear it was just the video card. Just some basic clean-up remaining. Cross your fingers and hopefully it will stay away now.

Step 1
We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft AntiSpyware.
  • Click on Tools, Settings.
  • In the left pane, click on Real-time Protection.
  • Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
  • Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
  • After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
  • Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.


Step 2
Open HijackThis, run a scan, then check the following:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


With all other programs and browsers closed, click fix checked.


Step 3
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
Thanks for the help again. Here is my new HiJachThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 1:02:31 PM, on 5/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…64/mcinsctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D5084B9-47E7-4B21-A9C1-C624B36A6C47}: NameServer = 151.164.1.8,206.13.28.12
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe


I'll leave my computer on for a while and see if anything else comes back.

Crossing my Fingers!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI