This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

after About Buster, here's my hjt log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been trying to clean this computer up, and I've installed Norton Internet Security 2005, and Ad Aware and run scans and deleted a bunch of stuff.

I also ran About Buster and it removed Home Search Assistent.

Here's my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 11:48:04 PM, on 5/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Larry Whitson\Desktop\malware tools\hijackthis\HijackThis.exe

O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

I appreciate any help.

larryw
Hi Larry, Welcome to TomCoyote forum. Great job :thumbup: this log is clean. How's it running? If you need one this is a great little utility that does a heck of a job cleaning: http://www.ccleaner.com/ even has it's own free forum if you have questions. Since you are clean, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Good luck and safe surfing

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Thanks, I've since also run Spybot and ccleaner and deleted a bunch more stuff and uninstalled a bunch of unnecessary programs.

New hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 9:51:55 PM, on 6/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Larry Whitson\Desktop\malware tools\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Seems to be running very good (wildly better than a week ago :P ).

Ad Aware comes up clean.

Spybot keeps finding Wild Tangent and when I expand the entry (before fixing) here's what it shows:

WildTangent: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\ClassPath=…;C:\WINDOWS\wt\webdriver\wtdmmp.jar…

Then when I "fix" it Spybot says it was successful, but when I restart, and run Spybot again it finds the exact same thing.


In my add/remove programs list, I have these showing up (which I have not tried to uninstall):


Java 2 Runtime Environment Standard Edition v1.3.1 (29.4 MB)

Java Web start (1.69 MB)

Java 2 Runtime Environment, SE v1.4.1_01 (1.64 MB)

Java 2 Runtime Environment, SE v1.4.0_01 (1.63 MB)


In C:\Program Files, I have these Java folders:

Java (70.9 MB)

Java Web Start (1.87 MB)

JavaSoft (21.9 MB)



Are all those legit? Necessary? I got suspicious when I saw Java VM in the info from Spybot for wildtangent.

Thanks for looking again, I really appreciate your time,

Larry W
Here is some information about Java, I understand that many of your virtual tools, etc. will not work without it. I am not real strong in understanding this but If I remember correctly Microsoft used is for a long time as a third party then Microsoft came up with their own version here: http://www.microsoft.com/mscorp/java/ and booted Java by Sun. Then the courts got involved and the M word was spoken (monopoly) and Microsoft was forced to make their software so it could use the Java product also, and it appears there is still controversy over which is best. Don't quote me on this, I suggest you do some research before making any decisions about removing any of that Java you posted. I does look to me like different versions and perhaps an update to the newest version would allow removing to old ones but I am not sure of this. Perhaps the links below will provide the information. Here are some faqs from Microsoft: http://www.microsoft.com/mscorp/java/faq.asp
Here are some blogs about the Sun Java technology: http://java.sun.com/developer/blogs/index.html
http://java.sun.com/
http://java.sun.com/docs/books/tutorial/
http://www.java.com/en/

In summation, I would not advise removing any of the Java software until you know more about what it is.

WildTangent: http://www.pchell.com/support/wildtangent.shtml
Now this one is explained above but I routinely remove it because it appears it collects information about the user that it really has no business collecting.
There are many opinions, so here is the information Google provides and you can make up your own mind. I would not have it install of my computers and I have heard it is not needed for any of the games it is installed with to work?
http://www.google.com/search?hl=en&rls;=GGL…Tangent&spell;=1

I have no WT in the log or I would have removed it, you will have to search if you wish it gone and edit your registry to get rid of it. If you consider this, make sure you backup the registry in the event of an error. Since it is not running I would probably leave it alone.

I will also mention that free training opportunities are available if you ever want to learn more about this process. There are many A:B infections waiting because of the lack of trained folks to remove them. :(

Hope this helps…Phil
Thanks for the link to the WT remover. Quick and easy. I'm pretty confident about my set up now, how's this sound to you for general security– Norton Internet Security 2005 (clean scan) I'm using the Norton Firewall, so I have the XP firewall turned off Ad Aware SE Pro (clean scan) Spybot (clean scan) HiJack This (log clean as above) I have things all set to auto-update. I have my active x controls to "prompt" for both signed/unsigned. Computer is now flying!! I thought I was going to have to ditch this 'ole thing! I'm still reviewing some of the other online safety links you listed above. I really appreciate you helping me verify my logs, etc. Thanks again, larry w
Hi Larry, Sounds like you are ready for business. I might as well make sure you have these tools:
http://www.pcpitstop.com/ They have an excellant free forum available also.

http://www.grc.com/x/ne.dll?rh1dkyd2 Steve Gibson.s free tool for checking the integrity of your ports, and lots more.

In case you are not aware both Ad-aware and Spybot just released upgrades. You should be on Ad-aware SE Personal 1.06 and Spybot S&D 1.04.
http://tomcoyote.org/aawsb.php

You will see these mentioned and I run all three on two computers and Tea timer on the thired. General thought is that if you run TeaTimer you don't need SpywareGuard as they perform the same function.

SpywareBlaster
http://www.bleepingcomputer.com/forums/tutorial49.html
SpywareGuard:
http://www.bleepingcomputer.com/forums/tutorial50.html
IE-Spyad
http://www.bleepingcomputer.com/forums/tutorial53.html

Here is a nice library of "Do it yourself tutorials" if you ever need them:
http://forum.malwareremoval.com/viewforum.php?f=4

Safe surfing to you sir…Phil
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI