This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hijackthis log

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am posting a Hij. This log for removal advice. Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 12:48:52 PM, on 5/11/05
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\S3apphk.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\Program Files\Browser Mouse\mouse32a.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Reference\Bookshelf 2000\qshelf2k.exe
C:\Program Files\KEPware\KEPDDE\kepdde.exe
C:\WINNT\system32\ntvdm.exe
C:\Program Files\Rockwell Software\RSView\RSViewrt32.exe
C:\Program Files\Rockwell Software\RSView\SPTLGSSV32.EXE
C:\Program Files\Rockwell Software\RSView\SPTSETSV32.EXE
C:\Program Files\Rockwell Software\RSView\ICECPRSV32.EXE
C:\Program Files\Rockwell Software\RDM\CMEMEM32.EXE
C:\Program Files\Rockwell Software\RDM\CMESYS32.EXE
C:\Program Files\Rockwell Software\RDM\CMEDDE32.EXE
C:\Program Files\Rockwell Software\RDM\CMEDEV32.EXE
C:\Program Files\Rockwell Software\RDM\CMEOPC32.EXE
C:\Program Files\Rockwell Software\RDM\RDMBTM32.EXE
C:\WINNT\system32\rtdsk40.exe
C:\Program Files\Rockwell Software\RSView\SHDE32.EXE
C:\Program Files\Rockwell Software\RSView\SPTCMDSV32.EXE
C:\PROGRA~1\ROCKWE~1\RSView\sptvbs32.exe
C:\Program Files\Rockwell Software\RSView\SPTCOMST32.EXE
C:\Program Files\Rockwell Software\RSView\SPTDDSSV32.EXE
C:\Program Files\Rockwell Software\RSView\SPTEDS32.EXE
C:\Program Files\Rockwell Software\RSView\SPTALQ32.EXE
C:\Program Files\Rockwell Software\RSView\DLGRT32.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISengine.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: & IntelliStopper - {21C32A07-0176-4FFE-BCDA-65D4A24F4303} - C:\PROGRA~1\INTELL~1\INTELL~1.DLL (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKLM\..\Run: [vdsadasw] C:\WINNT\SYSTEM32\anukem.exe
O4 - HKLM\..\Run: [eEjerik] pohapereq.exe
O4 - HKLM\..\RunServices: [eEjerik] pohapereq.exe
O4 - HKCU\..\Run: [AIE] C:\Program Files\Advanced Internet Eraser\AIE.exe
O4 - HKCU\..\Run: [eEjerik] pohapereq.exe
O4 - Startup: QuickShelf 2000.lnk = C:\Program Files\Microsoft Reference\Bookshelf 2000\qshelf2k.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
Hi dkv

I am known as Elrond. I will do my best to help you get rid of the malware you have on your computer.

Please note that RED or UNDERLINED or sometimes different colored words are links that can be clicked to get to a website.

To be sure that you can find this topic again:
1. Go to the Tom Coyote Forums http://forums.tomcoyote.org/index.php? .
Click on My Controls near the top middle of the window (make sure you have signed in first).
On the left hand column, click "view topics".
If you click on the title of your post, you will be taken there.
2. Also, while at that place in control panel, check the box to the right of your post and then scroll down.
Where it says "unsubscribe" click the pull-down menu and select "immediate email notification", By doing this, you will be notified as soon as I have posted a reply to your log.

HOW TO Instructions:
Reboot in safe mode. If you have a keyboard with a "F Lock" key click it so that the "F" light above it is on when you start tapping the "F8" key.
How to print the fix instructions
How to Copy, Cut, and Paste
Click the red links above.

How to unzip a downloaded zip file.
Place the zip file in the folder where you want the unzipped program to be.
If you are running Windows XP you simply right click the zip file and select "Extract Files".
For the other versions of Windows you will need a program like 7-Zip . If you decide to use 7-Zip down load the newest version that is not a beta version.
Open 7-Zip. Navigate to to the downloaded zip file and highlight it. Right click and select "Extract Here"

How to post a new HijackThis log
Close all windows and browsers.
Find the HijackThis folder. Open it and double click "HijackThis.exe". Click "Do a system scan" and save a "logfile". (If Hijack this shows you a "Scan" button it is OK.)
When the "Scan" button changes into a "Save Log" button click it. Click "Ctrl-A" (the "Ctrl" key and the "A" key at the same time) to highlight the whole log. Now click "Ctrl-C" to copy the text. Open this topic and click the "Add Reply" ("Post Reply") button at the bottom of the page. Paste the log into the window that opens up by clicking "Ctrl-V".
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL INSTRUCTED TO DO SO. SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH


1. Please copy the instructions to a notepad or preferably print them.

2. Make sure to work through the fixes exactly as given and in the exact order they are mentioned below.

3. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

4. Configure Windows to show all files. Showing hidden files and folders in Windows. if you need help with this.

5. Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button that is OK.) When the scan is finished put a check mark by the items that are listed in below. If you can not find an item just continue but inform me with your next post. Do not click fix until instructed to do so:
O2 - BHO: (no name) - {BA25708B-154D-4D40-8607-67AA5190C395} - C:\PROGRA~1\INTELL~1\ISengine.dll (file missing)
O3 - Toolbar: & IntelliStopper - {21C32A07-0176-4FFE-BCDA-65D4A24F4303} - C:\PROGRA~1\INTELL~1\INTELL~1.DLL (file missing)
O4 - HKLM\..\Run: [vdsadasw] C:\WINNT\SYSTEM32\anukem.exe
O4 - HKLM\..\Run: [eEjerik] pohapereq.exe
O4 - HKLM\..\RunServices: [eEjerik] pohapereq.exe
O4 - HKCU\..\Run: [eEjerik] pohapereq.exe
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?

This optional. It is a resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required anyway.
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

Close all open windows except HijackThis and then click the "Fix checked" button.

6.Reboot into Safe Mode: see the How to section if you are not sure.

7. Using Windows Explorer, locate the following file and delete it:
C:\WINNT\SYSTEM32\anukem.exe
Exit Explorer.

8. Please do a search:
"Run "Start">"Search">"All Files and Folders"> enter pohapereq.exe in "All or part of file name". Select "More advanced options". Check-mark "Search System Folders", "Search hidden files and folders", and "Search subfolders". Click "Search". Right click the file when found and left click delete.

9. Reboot in normal mode.

10. * Close ALL windows except "HijackThis"
* SCAN with "HijackThis"
* POST the new log in this thread.

E :)
Elrond, Thanks so much for your time and help.
The files you asked me to delete in safe mode, C:\WINNT\SYSTEM32\anukem.exe and pohapereq.exe, were not present.

Kirk



Logfile of HijackThis v1.99.1
Scan saved at 1:24:35 PM, on 5/17/05
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\S3apphk.exe
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\Program Files\Browser Mouse\mouse32a.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Reference\Bookshelf 2000\qshelf2k.exe
C:\unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKCU\..\Run: [AIE] C:\Program Files\Advanced Internet Eraser\AIE.exe
O4 - Startup: QuickShelf 2000.lnk = C:\Program Files\Microsoft Reference\Bookshelf 2000\qshelf2k.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
Hi again dkv

Congratulations and well done , your log looks clean.

Now I want you to take some precautions to avoid being re-infected.

Settings and maintenance

1. Clean out temporary files etc.
Download and install CleanUp!
a. Click Start > Programs > "CleanUp!" > "CleanUp!".
b. A dialog will appear. Click on the button labeled "CleanUp!".
c. Reboot.
You should do this every few weeks to avoid buildup of unnecessary junk. Run it for each user account on the computer.

2. You reconfigured Windows to show hidden files and you should reset this to its original state using the instructions from here except that
1. Under the "Hidden files and folders" heading put a mark for "Do not show hidden files and folders".
2. Uncheck "Display content of system folders"
3. Check the "Hide protected operating system files (recommended)" option.

3. Make your Internet Explorer more secure

a. Less restrictive but less secure:
Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more in
Internet Explorer Privacy & Security Settings
Working with Internet Explorer 6 Security
Many exploits are directed at Internet Explorer, you don't have to use it. Try a different browser like
Firefox . It is also worth trying
Thunderbird for controlling spam in your e-mail.

b. More secure but very restrictive.
This can be done by following these simple instructions that apply to all "Windows" except "Windows XP with SP2". In SP2 many of those setting are the default settings but check your settings anyhow. The settings can become restrictive but you should use them anyhow. If there are sites that will not show up right with those settings and that you rely on to be free of malware place them in the trusted zone.

1. Click "Start". Open "Control Panel".
2. Select the "Internet Options"
3. Select "Security" Tab and select the following settings.

* ActiveX controls and plug-ins
• Download signed ActiveX controls: Disable
• Download unsigned ActiveX controls: Disable
• Initialize and script ActiveX controls not marked as safe: Disable
• Run ActiveX controls and plug-ins: Disable
• Script ActiveX controls marked safe for scripting: Disable

* Downloads
• Font Download: Disable

* Microsoft VM
• Java permissions: Disable Java

* Miscellaneous
• Allow META REFRESH: Disable
• Display mixed content: Disable
• Drag and drop or copy and paste files: Disable
• Installation of desktop items: Disable
• Launching programs and files in an IFRAME: Disable
• Navigate sub-frames across different domains: Disable
• Software channel permissions: High Safety
• Userdata persistence: Disable

* Scripting
• Active scripting: Disable
• Allow paste operations via script: Disable
• Scripting of Java applets: Disable

* User Authentication
• Logon: Prompt for username and password
4. When all these settings have been made, click on the OK button.
5. If it prompts you as to whether or not you want to save the settings, press the Yes button.
6. Next press the Apply button and then the OK to exit the Internet Properties page.


These are a MUST to protect yourself from malware.
4. Always use a good anti-virus..
KEEP IT UPDATED

5. Always use a good firewall.
I do not see one in your log. Please see the recomendations at the important website below.
Be restrictive with access to the internet. If you are unsure if the program really needs the access, test it by denying the access and see if this has any negative effects. If not make the block permanent.

Never run two Antivirus programs or two Firewalls at the same time. The can interfere with each other and cause problems.

Download and install “SpywareBlaster” and "SpywareGuard".

You will find the addresses for the programs that I recommend at this important website . It is important that you go to there. It is good source of information about computer security. It will give you recommendations for more security tools as well as tips about how to stay clean on the internet. PLEASE FOLLOW THE RECOMENDATIONS TO PROTECT YOURSELF.

7. MOST IMPORTANT for all versions: You Need to keep “Windows” and "Internet Explorer” updated. Open ‘Internet Explorer” and go to”Start”> "Tools" > "Windows Update" or go to Microsoft Windows and Internet Explorer Updates to get the critical updates.

8.If you are running Microsoft Office, or any portion thereof you must keep it updated as well. Go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed. Update MS Office here.

9. Keep your programs updated.

10. I highly recommend downloading and installing the newest versions of “AdAware SE Personal” and “Spybot Search and Destroy”
After installing remember to update the definition files for each program.
I also suggest that you visit this website and follow the instructions on how to configure both programs for best detection. These instructions are the best even though they refer to a cleanup of an infected computer.

11. It is worth while to take a look at "So how did I get infected in the first place? for some good advice.

VERY IMPORTANT. Update all protective programs regularly - Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow these recommendations and your potential for being infected again will be dramatically reduced.

Do you have any problems with your computer? If so please post the details.

It has been a pleasure helping you.

Best of luck and clean computing

Elrond :)
Elrond, again thanks so much. Can you recommend a firewall? Also, can you recommend a donation amount for the sight? I really appreciate it and would like to support it if I can. Kirk
It is difficult to give a recommendation regarding Firewalls. This is a list that I took from the website i recommended:
ZoneAlarm: http://www.zonelabs.com/store/content/cata….jsp?lid=nav_za
Kerio: http://www.kerio.com/kpf_home.html
Outpost : http://www.agnitum.com/download/outpostfree.html.
Sygate: http://www.sygate.com/solutions/centrally_…al_firewall.htm
Norton Personal Firewall: http://www.symantec.com/sabu/nis/npf/

Of those listed, Sygate and Norton tend to be the most powerful. ZoneAlarm tends to be the easiest to use.,
ZoneAlarm, Sygate and Outpost offer a free version for private use.

All of them are powerful. I have seen some problems with Norton and seems to be the least flexible of those I have used. Outpost seems to be the smallest.

Perhaps you can now understand why I can not give a clear answer to your question.

I have no idea how much people donate to the site to keep it going. This will have to be your own decision.

It has been pleasure to to help you and I am sorry I can not help you more with those last questions.

Elrond :D
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI