This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unable to run Hijack this.

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I recently downloaded HJT but I am unable to run it. When I click on the icon my hour glass activates for a few seconds and then thats it. I downloaded HJT according to the instructions. Also I have downloaded HJT before in the past and did not have any problems. At the present moment I am having issues with my computer running at a snails pace hence why I downloaded HJT. Any help would be greatly appreciated. Thanks in advance.
Also, I don't know if this helps or not, but here is my log from Startuplist: StartupList report, 5/1/2005, 10:10:35 AM StartupList version: 1.52 Started from : C:\Documents and Settings\Administrator\Local Settings\Temp\StartupList.EXE Detected: Windows 2000 SP4 (WinNT 5.00.2195) Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106) * Using default options ================================================== Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\hidserv.exe C:\WINNT\system32\lsasss.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\winmgt.exe C:\WINNT\Explorer.exe C:\WINNT\System32\USB_Kbd\Versato.exe C:\WINNT\system32\svcl.exe C:\WINNT\system32\urfilename.exe C:\Program Files\Winamp\winampa.exe C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe C:\WINNT\system32\winshost.exe C:\WINNT\system32\aolbeta.exe C:\WINNT\system32\winhus.exe C:\WINNT\system32\msnn.exe C:\WINNT\system32\lsa.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINNT\system32\msint.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\WINNT\system32\spooler.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINNT\system32\winmgr.exe C:\WINNT\system32\ln3w.exe C:\WINNT\system32\MSN32z.EXE C:\WINNT\system32\svcl.exe C:\WINNT\system32\RUNDLL32.EXE C:\WINNT\system32\winshost.exe C:\WINNT\system32\j?vaw.exe C:\Documents and Settings\Administrator\Application Data\ddaa.exe J:\WinZip\WZQKPICK.EXE C:\WINNT\system32\Win9x.exe C:\WINNT\system32\winhost.exe C:\WINNT\system32\winn.scr C:\WINNT\system32\winhost.exe C:\WINNT\system32\MsnPlus.exe C:\WINNT\system32\desktop.exe J:\WINZIP\winzip32.exe C:\Documents and Settings\Administrator\Local Settings\Temp\StartupList.exe ————————————————– Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] WinZip Quick Pick.lnk = J:\WinZip\WZQKPICK.EXE Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE ————————————————– Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINNT\system32\userinit.exe, ————————————————– Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run Synchronization Manager = mobsync.exe /logon Versato = C:\WINNT\System32\USB_Kbd\Versato.exe NvCplDaemon = RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup Service Configuration Loader = svcl.exe nwiz = nwiz.exe /install ur key = urfilename.exe Windows DLL Loader = C:\WINNT\RUNDLL16.EXE WinampAgent = C:\Program Files\Winamp\winampa.exe HPDJ Taskbar Utility = C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe WINDOWS SYSTEM HOST = winshost.exe WINS HOST = winhost.exe WPAConfiguration = lsasss.exe ZQ8N = C:\documents and settings\administrator\local settings\temp\ZQ8N.exe TXXHW.exe = c:\winnt\system32\TXXHW.exe TV Media = C:\Program Files\TV Media\Tvm.exe AOl beta Test = aolbeta.exe WINS HUS SERVICE = winhus.exe MSN = msnn.exe Services = C:\cache.exe Microsoft Msn = msa32.exe LSA = lsa.exe AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe Windows Ocx Driver = msint.exe Windows Tagmsnger = tagmr.exe roflwins = winn.scr iTunesHelper = C:\Program Files\iTunes\iTunesHelper.exe QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime windows32 = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\ntprint.exe Windows32 Net Database = msnd32.exe WKS = wksftpd.exe Windows System Maintenance = spooler.exe Windows Time = winmgr.exe MsProtocol = msnis.exe Services Loader = ln3w.exe System Personal Firewall = MsnPlus.exe MSN32 Z Services = MSN32z.EXE Windows X = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vo.exe Show desktop = desktop.exe Windows Network Controller = Win9x.exe ————————————————– Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce Windows Network Controller = Win9x.exe ————————————————– Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices Service Configuration Loader = svcl.exe ur key = urfilename.exe WINDOWS SYSTEM HOST = winshost.exe WINS HOST = winhost.exe WPAConfiguration = lsasss.exe AOl beta Test = aolbeta.exe WINS HUS SERVICE = winhus.exe MSN = msnn.exe Microsoft Msn = msa32.exe LSA = lsa.exe Windows Ocx Driver = msint.exe Windows Tagmsnger = tagmr.exe roflwins = winn.scr Windows32 Net Database = msnd32.exe WKS = wksftpd.exe Windows System Maintenance = spooler.exe Windows Time = winmgr.exe MsProtocol = msnis.exe Services Loader = ln3w.exe System Personal Firewall = MsnPlus.exe MSN32 Z Services = MSN32z.EXE Show desktop = desktop.exe Windows Network Controller = Win9x.exe ————————————————– Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Service Configuration Loader = svcl.exe NvMediaCenter = RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit ur key = urfilename.exe starter = scvhostingg.exe WINDOWS SYSTEM HOST = winshost.exe WINS HOST = winhost.exe Hyuvhq = C:\WINNT\system32\j?vaw.exe TV Media = C:\Program Files\TV Media\Tvm.exe Windows32 Messenger Service = msmsgv.exe MS Windows CachePath = msnull32.exe AOl beta Test = aolbeta.exe Ms Processe Manager = msproc.exe MSN = msnn.exe Windows Processe Manager = mspn32.exe Microsoft Msn = msa32.exe eZmmod = C:\PROGRA~1\ezula\mmod.exe eZWO = C:\PROGRA~1\Web Offer\wo.exe LSA = lsa.exe Windows Proc Driver = winpsx.exe WindowsRegKey update = hhgazcfohx.exe Microsoft Application HD = mshdi.exe Windows Ocx Driver = msint.exe roflwins = winn.scr Microsoft PCI Manager = mspci.exe Windows32 Net Database = msnd32.exe WKS = wksftpd.exe Windows System Maintenance = spooler.exe Windows Time = winmgr.exe MsProtocol = msnis.exe Services Loader = ln3w.exe System Personal Firewall = MsnPlus.exe Show desktop = desktop.exe Ette = C:\Documents and Settings\Administrator\Application Data\ddaa.exe Windows Network Controller = Win9x.exe ————————————————– Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce Windows Network Controller = Win9x.exe ————————————————– Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices Windows Proc Driver = winpsx.exe MSN = msnn.exe Microsoft Msn = msa32.exe LSA = lsa.exe Windows Ocx Driver = msint.exe roflwins = winn.scr Windows32 Net Database = msnd32.exe WKS = wksftpd.exe MsProtocol = msnis.exe Windows Processe Manager = mspn32.exe ————————————————– Load/Run keys from C:\WINNT\WIN.INI: load=*INI section not found* run=*INI section not found* Load/Run keys from Registry: HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load= HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=NVDESK32.DLL ————————————————– Shell & screensaver key from C:\WINNT\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINNT\system32\ssmaze.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* ————————————————– Enumerating Browser Helper Objects: (no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - C:\WINNT\system32\zdulam.dll (file missing) - {B610895A-6FEB-241F-99DA-33819BCC5F96} (no name) - C:\WINNT\system32\bpo.dll - {C3CE1B59-A6B4-EA49-9D5A-ABC81F852D94} ————————————————– Enumerating ShellServiceObjectDelayLoad items: Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll WebCheck: C:\WINNT\system32\webcheck.dll SysTray: stobject.dll ————————————————– End of report, 10,349 bytes Report generated in 4.110 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only
Hi Willowdale! I'm 'KotaGuy. Welcome to TomCoyote!

See a lot of nastiness in that startup log. Lets see if we can't get HijackThis to run for you.

First thing I would like you to do is try renaming HijackThis.exe to just H.exe.

Once you have it renamed… see if it will run. If it does… please post a HijackThis log, if it doesn't, please let me know.

Thanks!
Thanks, that worked. Here is my log fie, Logfile of HijackThis v1.99.1 Scan saved at 11:22:44 AM, on 5/8/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\csrss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\hidserv.exe C:\WINNT\system32\lsasss.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\winmgt.exe C:\WINNT\System32\USB_Kbd\Versato.exe C:\WINNT\system32\svcl.exe C:\WINNT\system32\urfilename.exe C:\Program Files\Winamp\winampa.exe C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe C:\WINNT\system32\winshost.exe C:\WINNT\system32\aolbeta.exe C:\WINNT\system32\winhus.exe C:\WINNT\system32\msnn.exe C:\WINNT\system32\lsa.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINNT\system32\msint.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\WINNT\system32\spooler.exe C:\WINNT\system32\winmgr.exe C:\WINNT\system32\ln3w.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINNT\system32\MSN32z.EXE C:\WINNT\system32\svcl.exe C:\WINNT\system32\RUNDLL32.EXE C:\WINNT\system32\winshost.exe C:\Documents and Settings\Administrator\Application Data\ddaa.exe J:\WinZip\WZQKPICK.EXE C:\WINNT\system32\Win9x.exe C:\WINNT\explorer.exe C:\WINNT\system32\MsnPlus.exe C:\WINNT\system32\winhost.exe C:\WINNT\system32\winn.scr C:\WINNT\system32\winhost.exe C:\WINNT\system32\j?vaw.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HJT\H.exe.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINNT\system32\SearchBar.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {B610895A-6FEB-241F-99DA-33819BCC5F96} - C:\WINNT\system32\zdulam.dll (file missing) O2 - BHO: (no name) - {C3CE1B59-A6B4-EA49-9D5A-ABC81F852D94} - C:\WINNT\system32\bpo.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\MSDXM.OCX O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [Versato] C:\WINNT\System32\USB_Kbd\Versato.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Service Configuration Loader] svcl.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [ur key] urfilename.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe O4 - HKLM\..\Run: [WINDOWS SYSTEM HOST] winshost.exe O4 - HKLM\..\Run: [WINS HOST] winhost.exe O4 - HKLM\..\Run: [WPAConfiguration] lsasss.exe O4 - HKLM\..\Run: [ZQ8N] C:\documents and settings\administrator\local settings\temp\ZQ8N.exe O4 - HKLM\..\Run: [TXXHW.exe] c:\winnt\system32\TXXHW.exe O4 - HKLM\..\Run: [AOl beta Test] aolbeta.exe O4 - HKLM\..\Run: [WINS HUS SERVICE] winhus.exe O4 - HKLM\..\Run: [MSN] msnn.exe O4 - HKLM\..\Run: [Services] C:\cache.exe O4 - HKLM\..\Run: [Microsoft Msn] msa32.exe O4 - HKLM\..\Run: [LSA] lsa.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [Windows Ocx Driver] msint.exe O4 - HKLM\..\Run: [Windows Tagmsnger] tagmr.exe O4 - HKLM\..\Run: [roflwins] winn.scr O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [windows32] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\ntprint.exe O4 - HKLM\..\Run: [Windows32 Net Database] msnd32.exe O4 - HKLM\..\Run: [WKS] wksftpd.exe O4 - HKLM\..\Run: [Windows System Maintenance] spooler.exe O4 - HKLM\..\Run: [Windows Time] winmgr.exe O4 - HKLM\..\Run: [MsProtocol] msnis.exe O4 - HKLM\..\Run: [Services Loader] ln3w.exe O4 - HKLM\..\Run: [System Personal Firewall] MsnPlus.exe O4 - HKLM\..\Run: [MSN32 Z Services] MSN32z.EXE O4 - HKLM\..\Run: [Windows X] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vo.exe O4 - HKLM\..\Run: [Windows Network Controller] Win9x.exe O4 - HKLM\..\RunServices: [Service Configuration Loader] svcl.exe O4 - HKLM\..\RunServices: [ur key] urfilename.exe O4 - HKLM\..\RunServices: [WINDOWS SYSTEM HOST] winshost.exe O4 - HKLM\..\RunServices: [WINS HOST] winhost.exe O4 - HKLM\..\RunServices: [WPAConfiguration] lsasss.exe O4 - HKLM\..\RunServices: [AOl beta Test] aolbeta.exe O4 - HKLM\..\RunServices: [WINS HUS SERVICE] winhus.exe O4 - HKLM\..\RunServices: [MSN] msnn.exe O4 - HKLM\..\RunServices: [Microsoft Msn] msa32.exe O4 - HKLM\..\RunServices: [LSA] lsa.exe O4 - HKLM\..\RunServices: [Windows Ocx Driver] msint.exe O4 - HKLM\..\RunServices: [Windows Tagmsnger] tagmr.exe O4 - HKLM\..\RunServices: [roflwins] winn.scr O4 - HKLM\..\RunServices: [Windows32 Net Database] msnd32.exe O4 - HKLM\..\RunServices: [WKS] wksftpd.exe O4 - HKLM\..\RunServices: [Windows System Maintenance] spooler.exe O4 - HKLM\..\RunServices: [Windows Time] winmgr.exe O4 - HKLM\..\RunServices: [MsProtocol] msnis.exe O4 - HKLM\..\RunServices: [Services Loader] ln3w.exe O4 - HKLM\..\RunServices: [System Personal Firewall] MsnPlus.exe O4 - HKLM\..\RunServices: [MSN32 Z Services] MSN32z.EXE O4 - HKLM\..\RunServices: [Windows Network Controller] Win9x.exe O4 - HKLM\..\RunOnce: [Windows Network Controller] Win9x.exe O4 - HKLM\..\RunOnce: [AAW] "C:\AdAware\Ad-Aware SE Personal\Ad-Aware.exe" "+b1" O4 - HKCU\..\Run: [Service Configuration Loader] svcl.exe O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit O4 - HKCU\..\Run: [ur key] urfilename.exe O4 - HKCU\..\Run: [starter] scvhostingg.exe O4 - HKCU\..\Run: [WINDOWS SYSTEM HOST] winshost.exe O4 - HKCU\..\Run: [WINS HOST] winhost.exe O4 - HKCU\..\Run: [Hyuvhq] C:\WINNT\system32\j?vaw.exe O4 - HKCU\..\Run: [Windows32 Messenger Service] msmsgv.exe O4 - HKCU\..\Run: [MS Windows CachePath] msnull32.exe O4 - HKCU\..\Run: [AOl beta Test] aolbeta.exe O4 - HKCU\..\Run: [Ms Processe Manager] msproc.exe O4 - HKCU\..\Run: [MSN] msnn.exe O4 - HKCU\..\Run: [Windows Processe Manager] mspn32.exe O4 - HKCU\..\Run: [Microsoft Msn] msa32.exe O4 - HKCU\..\Run: [LSA] lsa.exe O4 - HKCU\..\Run: [Windows Proc Driver] winpsx.exe O4 - HKCU\..\Run: [WindowsRegKey update] hhgazcfohx.exe O4 - HKCU\..\Run: [Microsoft Application HD] mshdi.exe O4 - HKCU\..\Run: [Windows Ocx Driver] msint.exe O4 - HKCU\..\Run: [roflwins] winn.scr O4 - HKCU\..\Run: [Microsoft PCI Manager] mspci.exe O4 - HKCU\..\Run: [Windows32 Net Database] msnd32.exe O4 - HKCU\..\Run: [WKS] wksftpd.exe O4 - HKCU\..\Run: [Windows System Maintenance] spooler.exe O4 - HKCU\..\Run: [Windows Time] winmgr.exe O4 - HKCU\..\Run: [MsProtocol] msnis.exe O4 - HKCU\..\Run: [Services Loader] ln3w.exe O4 - HKCU\..\Run: [System Personal Firewall] MsnPlus.exe O4 - HKCU\..\Run: [Ette] C:\Documents and Settings\Administrator\Application Data\ddaa.exe O4 - HKCU\..\Run: [Windows Network Controller] Win9x.exe O4 - HKCU\..\RunServices: [Windows Proc Driver] winpsx.exe O4 - HKCU\..\RunServices: [MSN] msnn.exe O4 - HKCU\..\RunServices: [Microsoft Msn] msa32.exe O4 - HKCU\..\RunServices: [LSA] lsa.exe O4 - HKCU\..\RunServices: [Windows Ocx Driver] msint.exe O4 - HKCU\..\RunServices: [roflwins] winn.scr O4 - HKCU\..\RunServices: [Windows32 Net Database] msnd32.exe O4 - HKCU\..\RunServices: [WKS] wksftpd.exe O4 - HKCU\..\RunServices: [MsProtocol] msnis.exe O4 - HKCU\..\RunServices: [Windows Processe Manager] mspn32.exe O4 - HKCU\..\RunOnce: [Windows Network Controller] Win9x.exe O4 - Global Startup: WinZip Quick Pick.lnk = J:\WinZip\WZQKPICK.EXE O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: e-DiagTools LAN Configuration Agent (edtlancfg) - Unknown owner - C:\Program Files\HP\e-DiagTools\Service.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: WPAConfiguration (Microsoft Configuration) - Unknown owner - C:\WINNT\system32\lsasss.exe" -service (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe O23 - Service: Windows Security (WinMgt) - Unknown owner - C:\WINNT\system32\winmgt.exe O23 - Service: Windows Services (WinSrv) - Unknown owner - C:\WINNT\System32\scvhost.exe
Thanks for posting the new log.

Ok… I'd like to see if some online scans will clean your log up a bit. Please do scans at lease two of the following online virus scans at Panda ActiveScan, TrendMicro HouseCall, or eTrust AntiVirus WebScanner.

Also do an online Trojan scan from Windows Security

Let them fix anything they find, rebooting your computer between each scan.

Next, download and install Ad-Aware and Spybot S&D. Visit this page for proper configuration of both programs. Run and scan with both, letting them fix whatever they find. Remember to reboot between each scan.

Once that is done… post a new HijackThis log please.
Seems to be working better after that,
here is my new log file.

Logfile of HijackThis v1.99.1
Scan saved at 9:20:13 PM, on 5/8/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\lsasss.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\winmgt.exe
C:\WINNT\System32\USB_Kbd\Versato.exe
C:\WINNT\system32\svcl.exe
C:\WINNT\system32\urfilename.exe
C:\Program Files\Winamp\winampa.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\WINNT\system32\winshost.exe
C:\WINNT\system32\winhost.exe
C:\WINNT\system32\aolbeta.exe
C:\WINNT\system32\winhus.exe
C:\WINNT\system32\msnn.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\system32\msint.exe
C:\WINNT\system32\winn.scr
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\spooler.exe
C:\WINNT\system32\msnis.exe
C:\WINNT\system32\ln3w.exe
C:\WINNT\system32\MsnPlus.exe
C:\WINNT\system32\svcl.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\system32\winshost.exe
C:\WINNT\system32\winhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrator\Application Data\ddaa.exe
J:\WinZip\WZQKPICK.EXE
C:\WINNT\explorer.exe
C:\WINNT\system32\j?vaw.exe
C:\HJT\H.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINNT\system32\SearchBar.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {B610895A-6FEB-241F-99DA-33819BCC5F96} - C:\WINNT\system32\zdulam.dll (file missing)
O2 - BHO: (no name) - {C3CE1B59-A6B4-EA49-9D5A-ABC81F852D94} - C:\WINNT\system32\bpo.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\MSDXM.OCX
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Versato] C:\WINNT\System32\USB_Kbd\Versato.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Service Configuration Loader] svcl.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ur key] urfilename.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [WINDOWS SYSTEM HOST] winshost.exe
O4 - HKLM\..\Run: [WINS HOST] winhost.exe
O4 - HKLM\..\Run: [WPAConfiguration] lsasss.exe
O4 - HKLM\..\Run: [ZQ8N] C:\documents and settings\administrator\local settings\temp\ZQ8N.exe
O4 - HKLM\..\Run: [TXXHW.exe] c:\winnt\system32\TXXHW.exe
O4 - HKLM\..\Run: [AOl beta Test] aolbeta.exe
O4 - HKLM\..\Run: [WINS HUS SERVICE] winhus.exe
O4 - HKLM\..\Run: [MSN] msnn.exe
O4 - HKLM\..\Run: [Services] C:\cache.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Windows Ocx Driver] msint.exe
O4 - HKLM\..\Run: [Windows Tagmsnger] tagmr.exe
O4 - HKLM\..\Run: [roflwins] winn.scr
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [windows32] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\ntprint.exe
O4 - HKLM\..\Run: [WKS] wksftpd.exe
O4 - HKLM\..\Run: [Windows System Maintenance] spooler.exe
O4 - HKLM\..\Run: [MsProtocol] msnis.exe
O4 - HKLM\..\Run: [Services Loader] ln3w.exe
O4 - HKLM\..\Run: [System Personal Firewall] MsnPlus.exe
O4 - HKLM\..\Run: [Windows X] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vo.exe
O4 - HKLM\..\RunServices: [Service Configuration Loader] svcl.exe
O4 - HKLM\..\RunServices: [ur key] urfilename.exe
O4 - HKLM\..\RunServices: [WINDOWS SYSTEM HOST] winshost.exe
O4 - HKLM\..\RunServices: [WINS HOST] winhost.exe
O4 - HKLM\..\RunServices: [WPAConfiguration] lsasss.exe
O4 - HKLM\..\RunServices: [AOl beta Test] aolbeta.exe
O4 - HKLM\..\RunServices: [WINS HUS SERVICE] winhus.exe
O4 - HKLM\..\RunServices: [MSN] msnn.exe
O4 - HKLM\..\RunServices: [Windows Ocx Driver] msint.exe
O4 - HKLM\..\RunServices: [Windows Tagmsnger] tagmr.exe
O4 - HKLM\..\RunServices: [roflwins] winn.scr
O4 - HKLM\..\RunServices: [WKS] wksftpd.exe
O4 - HKLM\..\RunServices: [Windows System Maintenance] spooler.exe
O4 - HKLM\..\RunServices: [MsProtocol] msnis.exe
O4 - HKLM\..\RunServices: [Services Loader] ln3w.exe
O4 - HKLM\..\RunServices: [System Personal Firewall] MsnPlus.exe
O4 - HKLM\..\RunOnce: [AAW] "C:\AdAware\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [Service Configuration Loader] svcl.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ur key] urfilename.exe
O4 - HKCU\..\Run: [starter] scvhostingg.exe
O4 - HKCU\..\Run: [WINDOWS SYSTEM HOST] winshost.exe
O4 - HKCU\..\Run: [WINS HOST] winhost.exe
O4 - HKCU\..\Run: [Hyuvhq] C:\WINNT\system32\j?vaw.exe
O4 - HKCU\..\Run: [Windows32 Messenger Service] msmsgv.exe
O4 - HKCU\..\Run: [MS Windows CachePath] msnull32.exe
O4 - HKCU\..\Run: [AOl beta Test] aolbeta.exe
O4 - HKCU\..\Run: [Ms Processe Manager] msproc.exe
O4 - HKCU\..\Run: [MSN] msnn.exe
O4 - HKCU\..\Run: [Windows Processe Manager] mspn32.exe
O4 - HKCU\..\Run: [Windows Proc Driver] winpsx.exe
O4 - HKCU\..\Run: [WindowsRegKey update] hhgazcfohx.exe
O4 - HKCU\..\Run: [Microsoft Application HD] mshdi.exe
O4 - HKCU\..\Run: [Windows Ocx Driver] msint.exe
O4 - HKCU\..\Run: [roflwins] winn.scr
O4 - HKCU\..\Run: [Microsoft PCI Manager] mspci.exe
O4 - HKCU\..\Run: [WKS] wksftpd.exe
O4 - HKCU\..\Run: [Windows System Maintenance] spooler.exe
O4 - HKCU\..\Run: [MsProtocol] msnis.exe
O4 - HKCU\..\Run: [Services Loader] ln3w.exe
O4 - HKCU\..\Run: [System Personal Firewall] MsnPlus.exe
O4 - HKCU\..\Run: [Ette] C:\Documents and Settings\Administrator\Application Data\ddaa.exe
O4 - HKCU\..\RunServices: [Windows Proc Driver] winpsx.exe
O4 - HKCU\..\RunServices: [MSN] msnn.exe
O4 - HKCU\..\RunServices: [Microsoft Msn] msa32.exe
O4 - HKCU\..\RunServices: [LSA] lsa.exe
O4 - HKCU\..\RunServices: [Windows Ocx Driver] msint.exe
O4 - HKCU\..\RunServices: [roflwins] winn.scr
O4 - HKCU\..\RunServices: [Windows32 Net Database] msnd32.exe
O4 - HKCU\..\RunServices: [WKS] wksftpd.exe
O4 - HKCU\..\RunServices: [MsProtocol] msnis.exe
O4 - HKCU\..\RunServices: [Windows Processe Manager] mspn32.exe
O4 - Global Startup: WinZip Quick Pick.lnk = J:\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: e-DiagTools LAN Configuration Agent (edtlancfg) - Unknown owner - C:\Program Files\HP\e-DiagTools\Service.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: WPAConfiguration (Microsoft Configuration) - Unknown owner - C:\WINNT\system32\lsasss.exe" -service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Windows Security (WinMgt) - Unknown owner - C:\WINNT\system32\winmgt.exe
O23 - Service: Windows Services (WinSrv) - Unknown owner - C:\WINNT\System32\scvhost.exe
Thanks for posting the new log.

Scans didn't fix as much as I would have hoped… we got some work to do :)

Print this out for reference during the fix.

Download and install CCleaner. Don't run it yet.

Download CWShredder. Save it to its own folder. Run the program. Update it. press the Fix button. Exit when done.

Make sure no files are hidden. To do this:

1. Click Start.
2. Open My Computer.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Uncheck the Hide protected operating system files (recommended) option.
7. Click Yes to confirm.
8. Click OK.

Click Start>Run, type in services.msc. Look for these Services:

WPAConfiguration
Windows Security
Windows Services


For each of these Services, do the following:

1. Right click on the Service.
2. Choose Properties
3. Stop the service
4. Change the Startup to Disabled

Exit the Services Console.

Hit Ctrl+alt+Delete to bring up the Task Manager. End Task:

lsasss.exe
winmgt.exe
svcl.exe
urfilename.exe
winshost.exe
winhost.exe
aolbeta.exe
winhus.exe
msnn.exe
msint.exe
winn.scr
msnis.exe
ln3w.exe
MsnPlus.exe
ddaa.exe
j?vaw.exe


Run and scan with HijackThis. With all other browsers and windows closed, place a check beside the following and Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINNT\system32\SearchBar.htm
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {B610895A-6FEB-241F-99DA-33819BCC5F96} - C:\WINNT\system32\zdulam.dll (file missing)
O2 - BHO: (no name) - {C3CE1B59-A6B4-EA49-9D5A-ABC81F852D94} - C:\WINNT\system32\bpo.dll
O4 - HKLM\..\Run: [Service Configuration Loader] svcl.exe
O4 - HKLM\..\Run: [ur key] urfilename.exe
O4 - HKLM\..\Run: [WINDOWS SYSTEM HOST] winshost.exe
O4 - HKLM\..\Run: [WINS HOST] winhost.exe
O4 - HKLM\..\Run: [WPAConfiguration] lsasss.exe
O4 - HKLM\..\Run: [ZQ8N] C:\documents and settings\administrator\local settings\temp\ZQ8N.exe
O4 - HKLM\..\Run: [TXXHW.exe] c:\winnt\system32\TXXHW.exe
O4 - HKLM\..\Run: [AOl beta Test] aolbeta.exe
O4 - HKLM\..\Run: [WINS HUS SERVICE] winhus.exe
O4 - HKLM\..\Run: [MSN] msnn.exe
O4 - HKLM\..\Run: [Services] C:\cache.exe
O4 - HKLM\..\Run: [Windows Ocx Driver] msint.exe
O4 - HKLM\..\Run: [Windows Tagmsnger] tagmr.exe
O4 - HKLM\..\Run: [roflwins] winn.scr
O4 - HKLM\..\Run: [windows32] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP\ntprint.exe
O4 - HKLM\..\Run: [WKS] wksftpd.exe
O4 - HKLM\..\Run: [Windows System Maintenance] spooler.exe
O4 - HKLM\..\Run: [MsProtocol] msnis.exe
O4 - HKLM\..\Run: [Services Loader] ln3w.exe
O4 - HKLM\..\Run: [System Personal Firewall] MsnPlus.exe
O4 - HKLM\..\Run: [Windows X] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\vo.exe
O4 - HKLM\..\RunServices: [Service Configuration Loader] svcl.exe
O4 - HKLM\..\RunServices: [ur key] urfilename.exe
O4 - HKLM\..\RunServices: [WINDOWS SYSTEM HOST] winshost.exe
O4 - HKLM\..\RunServices: [WINS HOST] winhost.exe
O4 - HKLM\..\RunServices: [WPAConfiguration] lsasss.exe
O4 - HKLM\..\RunServices: [AOl beta Test] aolbeta.exe
O4 - HKLM\..\RunServices: [WINS HUS SERVICE] winhus.exe
O4 - HKLM\..\RunServices: [MSN] msnn.exe
O4 - HKLM\..\RunServices: [Windows Ocx Driver] msint.exe
O4 - HKLM\..\RunServices: [Windows Tagmsnger] tagmr.exe
O4 - HKLM\..\RunServices: [roflwins] winn.scr
O4 - HKLM\..\RunServices: [WKS] wksftpd.exe
O4 - HKLM\..\RunServices: [Windows System Maintenance] spooler.exe
O4 - HKLM\..\RunServices: [MsProtocol] msnis.exe
O4 - HKLM\..\RunServices: [Services Loader] ln3w.exe
O4 - HKLM\..\RunServices: [System Personal Firewall] MsnPlus.exe
O4 - HKCU\..\Run: [Service Configuration Loader] svcl.exe
O4 - HKCU\..\Run: [ur key] urfilename.exe
O4 - HKCU\..\Run: [starter] scvhostingg.exe
O4 - HKCU\..\Run: [WINDOWS SYSTEM HOST] winshost.exe
O4 - HKCU\..\Run: [WINS HOST] winhost.exe
O4 - HKCU\..\Run: [Hyuvhq] C:\WINNT\system32\j?vaw.exe
O4 - HKCU\..\Run: [Windows32 Messenger Service] msmsgv.exe
O4 - HKCU\..\Run: [MS Windows CachePath] msnull32.exe
O4 - HKCU\..\Run: [AOl beta Test] aolbeta.exe
O4 - HKCU\..\Run: [Ms Processe Manager] msproc.exe
O4 - HKCU\..\Run: [MSN] msnn.exe
O4 - HKCU\..\Run: [Windows Processe Manager] mspn32.exe
O4 - HKCU\..\Run: [Windows Proc Driver] winpsx.exe
O4 - HKCU\..\Run: [WindowsRegKey update] hhgazcfohx.exe
O4 - HKCU\..\Run: [Microsoft Application HD] mshdi.exe
O4 - HKCU\..\Run: [Windows Ocx Driver] msint.exe
O4 - HKCU\..\Run: [roflwins] winn.scr
O4 - HKCU\..\Run: [Microsoft PCI Manager] mspci.exe
O4 - HKCU\..\Run: [WKS] wksftpd.exe
O4 - HKCU\..\Run: [Windows System Maintenance] spooler.exe
O4 - HKCU\..\Run: [MsProtocol] msnis.exe
O4 - HKCU\..\Run: [Services Loader] ln3w.exe
O4 - HKCU\..\Run: [System Personal Firewall] MsnPlus.exe
O4 - HKCU\..\Run: [Ette] C:\Documents and Settings\Administrator\Application Data\ddaa.exe
O4 - HKCU\..\RunServices: [Windows Proc Driver] winpsx.exe
O4 - HKCU\..\RunServices: [MSN] msnn.exe
O4 - HKCU\..\RunServices: [Microsoft Msn] msa32.exe
O4 - HKCU\..\RunServices: [LSA] lsa.exe
O4 - HKCU\..\RunServices: [Windows Ocx Driver] msint.exe
O4 - HKCU\..\RunServices: [roflwins] winn.scr
O4 - HKCU\..\RunServices: [Windows32 Net Database] msnd32.exe
O4 - HKCU\..\RunServices: [WKS] wksftpd.exe
O4 - HKCU\..\RunServices: [MsProtocol] msnis.exe
O4 - HKCU\..\RunServices: [Windows Processe Manager] mspn32.exe
O23 - Service: WPAConfiguration (Microsoft Configuration) - Unknown owner - C:\WINNT\system32\lsasss.exe" -service (file missing)
O23 - Service: Windows Security (WinMgt) - Unknown owner - C:\WINNT\system32\winmgt.exe
O23 - Service: Windows Services (WinSrv) - Unknown owner - C:\WINNT\System32\scvhost.exe


Boot into Safe Mode. To do this:

1. Reboot your computer.
2. Tap the F8 button as your computer is booting to bring you to the Advanced Options Menu.
3. Select Safe Mode and press Enter.

Search for and delete this folder:

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IXP000.TMP

Search for and delete these files:

C:\Documents and Settings\Administrator\Application Data\ddaa.exe
C:\documents and settings\administrator\local settings\temp\ZQ8N.exe
C:\documents and settings\administrator\local settings\temp\vo.exe
C:\WINNT\system32\SearchBar.htm
C:\WINNT\system32\lsasss.exe
C:\WINNT\system32\winmgt.exe
C:\WINNT\system32\svcl.exe
C:\WINNT\system32\urfilename.exe
C:\WINNT\system32\winshost.exe
C:\WINNT\system32\winhost.exe
C:\WINNT\system32\aolbeta.exe
C:\WINNT\system32\winhus.exe
C:\WINNT\system32\msnn.exe
C:\WINNT\system32\msint.exe
C:\WINNT\system32\winn.scr
C:\WINNT\system32\spooler.exe
C:\WINNT\system32\msnis.exe
C:\WINNT\system32\ln3w.exe
C:\WINNT\system32\MsnPlus.exe
c:\winnt\system32\TXXHW.exe
C:\WINNT\system32\j?vaw.exe
C:\WINNT\System32\scvhost.exe
C:\cache.exe
tagmr.exe
wksftpd.exe
ln3w.exe
scvhostingg.exe
msmsgv.exe
msnull32.exe
msproc.exe
mspn32.exe
winpsx.exe
hhgazcfohx.exe
mshdi.exe
mspci.exe
msa32.exe
lsa.exe
msnd32.exe
msnis.exe


NOTE!! When searching for C:\WINNT\System32\scvhost.exe, be sure to delete only C:\WINNT\System32\scvhost.exe and not C:\WINNT\System32\svchost.exe as it is a valid file. Take notice of the "c" and "v" in each file as they are reversed. Delete ONLY C:\WINNT\System32\scvhost.exe.

The same can be said for C:\WINNT\system32\lsasss.exe. There is a legit file C:\WINNT\system32\lsass.exe, notice "ss" at the end instead of "sss". Do not delete C:\WINNT\system32\lsass.exe, delete only C:\WINNT\system32\lsasss.exe.

Also, take care when searching for C:\WINNT\system32\j?vaw.exe. Because it has the "?" in the name, you may get multiple files returned when searching for it. If in doubt, right click on the files, choose Properties. Check the vendor info, if it says it is from Microsoft, Do not delete it!

Browse to your C:\Windows\Prefetch folder. Delete all the files in the folder, do not delete the folder itself. Empty your Recycle Bin. Run CCleaner.

Reboot Windows normally and post a new HijackThis log please.
So far I have downloaded the CCleaner program. Downloaded and raun the CW Shresser program, no problems found with CW Shredder. And I stopped and disabled the following services: WPAConfiguration Windows Security Windows Services My next problem is I cannot bring up my task manager. When I hit cntl, alt, delete and select tack manager, the task manager comes up for a split second and closes. I am unable to select anything. Thanks.
OK… instead of End Tasking them with Task Manager… open up HijackThis. Press the Open the Misc Tools button. Press open Process Manager button. End Task the files from there. Let me know how it goes! :)
My ip provider kicked me off the net due to the problems with my computer.
Sorry for the delay.
Luckily I printed out your last set of instructions and followed them.

THANKS.


Here is my current log file:

Logfile of HijackThis v1.99.1
Scan saved at 11:39:44 AM, on 5/20/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\USB_Kbd\Versato.exe
C:\Program Files\Winamp\winampa.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\RUNDLL32.EXE
J:\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\H.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13A5A7FD-1E12-06BD-3D80-16837BB5F8C8} - C:\WINNT\system32\odsrc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\S&D\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\MSDXM.OCX
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Versato] C:\WINNT\System32\USB_Kbd\Versato.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: WinZip Quick Pick.lnk = J:\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: e-DiagTools LAN Configuration Agent (edtlancfg) - Unknown owner - C:\Program Files\HP\e-DiagTools\Service.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
Thanks for posting the new log.

One last entry to get rid of…

Run and scan with HijackThis. With all other browsers and windows closed, place a check beside the following and fix:

O2 - BHO: (no name) - {13A5A7FD-1E12-06BD-3D80-16837BB5F8C8} - C:\WINNT\system32\odsrc.dll

Reboot and post a new HijackThis log please.

Thanks!
Thansk again here is the log file.

Logfile of HijackThis v1.99.1
Scan saved at 1:43:32 PM, on 5/20/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\USB_Kbd\Versato.exe
C:\Program Files\Winamp\winampa.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\RUNDLL32.EXE
J:\WinZip\WZQKPICK.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\H.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\S&D\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\MSDXM.OCX
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Versato] C:\WINNT\System32\USB_Kbd\Versato.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb01.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: WinZip Quick Pick.lnk = J:\WinZip\WZQKPICK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: e-DiagTools LAN Configuration Agent (edtlancfg) - Unknown owner - C:\Program Files\HP\e-DiagTools\Service.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
Now that your computer is clean, I recommend doing a few more scans to clean up any remnants we might not have been able to get at with HijackThis. Do scans at Panda and TrendMicro as before. Scan with Ad-Aware and Spybot as well. Let them fix anything they find. Reboot between each scan.

If you don't have one, I recommend installing a Firewall. I'm sure you've heard of ZoneAlarm.

I am closing this this topic as it has been resolved.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI