This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New Hijack This Log

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Need help to check this HijackThis Log.
Logfile of HijackThis v1.99.1
Scan saved at 3:28:05 PM, on 27-Jun-05
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firewall\Sygate\SSA\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\Program Files\Compaq\EAB\EABSERVR.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\WINDOWS\System32\ltmsg.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\MIAF83~1\GCASDT~1.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\CENTURY\WTERM\WTERM32.EXE
C:\WINDOWS\explorer.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Hewlett-Packard
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Firewall\Sygate\SSA\smc.exe -startgui
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://ie.config.asia.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.eur.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.im.hou.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.jp.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.ecom.dec.com (HKLM)
O15 - Trusted Zone: http://ie.config.tandem.com (HKLM)
O16 - DPF: {4E7BD74F-2B8D-469E-D7EE-FE6FA781BF33} (Netscape) - http://downloads.netscape.com/search/toolbar/netscape.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097736558997
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O17 - HKLM\System\CS6\Services\Tcpip\Parameters: Domain = asiapacific.cpqcorp.net
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: Domain = asiapacific.cpqcorp.net
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Hibernation - Unknown owner - C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe
O23 - Service: HP Sygate Icon Control (HPSygControl) - Unknown owner - C:\PROGRA~1\Sygate\SSA\syg_hp.exe (file missing)
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
Hello , welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.
Yes, still need help to check my HijackThis log file.


Logfile of HijackThis v1.99.1
Scan saved at 4:45:11 PM, on 18-Jul-05
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firewall\Sygate\SSA\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compaq\EAB\EABSERVR.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\WINDOWS\System32\ltmsg.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\MIAF83~1\GCASDT~1.EXE
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\CENTURY\WTERM\WTERM32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Hewlett-Packard
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Firewall\Sygate\SSA\smc.exe -startgui
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://ie.config.asia.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.eur.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.im.hou.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.jp.compaq.com (HKLM)
O15 - Trusted Zone: http://ie.config.ecom.dec.com (HKLM)
O15 - Trusted Zone: http://ie.config.tandem.com (HKLM)
O16 - DPF: {4E7BD74F-2B8D-469E-D7EE-FE6FA781BF33} (Netscape) - http://downloads.netscape.com/search/toolbar/netscape.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097736558997
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O17 - HKLM\System\CS6\Services\Tcpip\Parameters: Domain = asiapacific.cpqcorp.net
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: Domain = asiapacific.cpqcorp.net
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Hibernation - Unknown owner - C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe
O23 - Service: HP Sygate Icon Control (HPSygControl) - Unknown owner - C:\PROGRA~1\Sygate\SSA\syg_hp.exe (file missing)
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
Hi Cilla

Before we start any cleanup I have some questions.

1. What are the problems that you have with the ccomputer.

2. To me it looks as you have a very close connection to Compaq-HP and seem to be on their net work in Asia via Alta Vista. Is that correct?

3. You have Sygate firewall installed on your computer. Do you know if it it is a version customisied for HP?

4. Have you or an administrator set any policies or did you activate the 'Lock homepage from changes' option in some kind of anti-spyware tool?

Now lets get rid of what is clearly Slyware.

Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button instead of "Do a System Scan Only" that is OK. In that case click "Scan".) When the scan is finished put a check mark by the items that are listed in bold below. If you can not find an item, that is OK. Just continue but inform me with your next post. Do not click fix until instructed to do so:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - Default URLSearchHook is missing


This is optional but you could also have HijackThis fix these entries as they are not needed and they can slow down your PC when starting up
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
This program places an icon in the system tray for quick access to Apple QuickTime. It is not necessary since QuickTime may be run manually even without the tray icon. If you choose to remove it, you will also have to disable it from within QuickTime, in the following manner:

1) Run QuickTime from the Start -> Programs menu
2) Click on the Edit menu, then Preferences
3) Select QuickTime Preferences from the right-hand side menu
4) Uncheck the box next to "QuickTime System Tray Icon", and click OK.


Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button that is OK.) When the scan is finished put a check mark by the items that are listed in below. If you can not find an item just continue but inform me with your next post. Do not click fix until instructed to do so:


Close all open windows except HijackThis and then click the "Fix checked" button.

Please run a new HijackThis Scan and post the log together with the answers to my questions.

E :)
Hi Elrond,

Thanks for the previous advice. Attached is the latest HiJackThis log file.

1. The problem was the internet and other programs were slow. Another problem
was in my Local Area Connection, the packets sent are billions compared to
pachets received are only a few thousand. I suspected problems due to
spyware/adware. I already scanned using Lavasoft and Spybot but scan results
were clean.
2. Yes. Already added these to the ignore checklist.
3. Sysgate version is as per HP's.
4. Yes, I locked the homepage because previously even though when I set the
homepage as blank in the Internet Options, it'll still show the msn website when
I open IE.

Latest HIJackThis log
Logfile of HijackThis v1.99.1
Scan saved at 8:37:10 AM, on 26-Jul-05
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Firewall\Sygate\SSA\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\mnmsrvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compaq\EAB\EABSERVR.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\WINDOWS\System32\ltmsg.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\MIAF83~1\GCASDT~1.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\CENTURY\WTERM\WTERM32.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.altavista.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EABSERVR.EXE /Start
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4E7BD74F-2B8D-469E-D7EE-FE6FA781BF33} (Netscape) - http://downloads.netscape.com/search/toolbar/netscape.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097736558997
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Hibernation - Unknown owner - C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe
O23 - Service: HP Sygate Icon Control (HPSygControl) - Unknown owner - C:\PROGRA~1\Sygate\SSA\syg_hp.exe (file missing)
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
Hi cilla
  • I would like you to open HiJackThis
  • Click Open the Misc Tools Section
  • Click Open process manager
  • Highlight C:\PROGRA~1\MIAF83~1\GCASDT~1.EXE
  • Click the checkbox for Show DLLs
  • Click the Floppy Disk Icon next to "Show DLLs" and save the file in a place where you can find it. Post it in your next post.
We need to see the hidden files.
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under "Hidden files and folders" select Show hidden files and folders.
Uncheck Hide file extensions for known file types.
Click OK

Next I would like you to use Exlorer to find the following folder in C:\Program Files:
MIAF83~1 (The name starts with MIAF83 and is longer than eight characters.
Let me know what files are in that folder.
See if you can find the following file in the folder: GCASDT~1.EXE. (The same rules as for the folder are valid. My guess is that the name is gcasDtServ.exe)

If you find it please right click it and select Properties.
Click the version tab and let me know what it says. I am especially interested in the copyright.

Post the log and tet me know the information about the folder and the file.


E :)
Hi Elrond, Here's the DLL file :- Process list saved on 9:16:17 AM, on 28-Jul-05 Platform: Windows XP SP1 (WinNT 5.01.2600) [pid] [full path to filename] [file version] [company name] 1500 C:\WINDOWS\System32\smss.exe 5.1.2600.1106 Microsoft Corporation 1604 C:\WINDOWS\system32\winlogon.exe 5.1.2600.1557 Microsoft Corporation 1648 C:\WINDOWS\system32\services.exe 5.1.2600.0 Microsoft Corporation 1660 C:\WINDOWS\system32\lsass.exe 5.1.2600.1106 Microsoft Corporation 1836 C:\WINDOWS\System32\Ati2evxx.exe 6.14.10.4099 1880 C:\WINDOWS\system32\svchost.exe 5.1.2600.0 Microsoft Corporation 188 C:\WINDOWS\System32\svchost.exe 5.1.2600.0 Microsoft Corporation 360 C:\Program Files\Sygate\SSA\smc.exe 5.5.0.2312 Sygate Technologies, Inc. 1028 C:\WINDOWS\system32\spoolsv.exe 5.1.2600.0 Microsoft Corporation 1296 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe 2.2.1.4 Symantec Corporation 1308 C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe 5.0.9.1 Hewlett-Packard Company 1336 C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe 5.0.9.1 Hewlett-Packard Company 1352 C:\Program Files\Symantec AntiVirus\DefWatch.exe 9.0.2.1000 Symantec Corporation 1384 C:\PROGRA~1\HPQ\CUSTOM~1\hibserv.exe 4.10.6.3 1436 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe 7.0.9064.9150 Microsoft Corporation 1476 C:\WINDOWS\System32\mnmsrvc.exe 4.4.0.3400 Microsoft Corporation 1516 C:\Program Files\Symantec AntiVirus\SavRoam.exe 9.0.2.1000 symantec 1524 C:\WINDOWS\System32\rundll32.exe 5.1.2600.0 Microsoft Corporation 1560 C:\Program Files\Symantec AntiVirus\Rtvscan.exe 9.0.2.1000 Symantec Corporation 180 C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe 2.0.0.54 Intel 252 C:\Program Files\Common Files\ActivCard\acautoreg.exe 1.0.6.0 ActivCard S.A. 420 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe 2.2.1.4 Symantec Corporation 832 C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe 5.0.9.1 Compaq Computer Corporation 3104 C:\WINDOWS\Explorer.EXE 6.0.2800.1106 Microsoft Corporation 2904 C:\Program Files\Compaq\EAB\EABSERVR.EXE 3.0.4.1 Compaq 3992 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe 5.3.2.34 Roxio 2372 C:\Program Files\Hewlett-Packard\PC COE\IDA.EXE 1.0.0.86 Hewlett-Packard Company 676 C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe 1.7.9.0 ActivCard S.A. 1140 C:\WINDOWS\System32\ltmsg.exe 3.0.0.2 LUCENT TECHNOLOGIES 376 C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE 5.0.9.1 Hewlett-Packard Company 2012 C:\Program Files\Compaq\Hotkey Software\hkss.exe 1.1.-27.1 Compaq Computer Corporation 4028 C:\Program Files\Common Files\Symantec Shared\ccApp.exe 2.2.1.4 Symantec Corporation 4068 C:\PROGRA~1\SYMANT~1\VPTray.exe 9.0.2.1000 Symantec Corporation 4088 C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe 6.41.22.3 Nokia 1896 C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE 6.41.85.8 Nokia Mobile Phones Ltd. 400 C:\Program Files\Microsoft AntiSpyware\gcasServ.exe 1.0.0.509 Microsoft Corporation 2000 C:\Program Files\Support.com\bin\tgcmd.exe 5.5.482.0 Support.com, Inc. 1968 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe 3.0.0.40 Adobe Systems Incorporated 2084 C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE 6.41.20.0 Nokia. 1832 C:\Program Files\WinZip\WZQKPICK.EXE 1.0.0.0 WinZip Computing, Inc. 3692 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe 2596 C:\PROGRA~1\MIAF83~1\GCASDT~1.EXE 1.0.0.509 Microsoft Corporation 3392 C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE 10.0.6626.0 Microsoft Corporation 3396 C:\WINDOWS\system32\ntvdm.exe 5.1.2600.1564 Microsoft Corporation 3764 C:\WINDOWS\System32\ctfmon.exe 5.1.2600.1106 Microsoft Corporation 3648 C:\CENTURY\WTERM\WTERM32.EXE 3.3.6.0 Century Software, Inc. 692 C:\PROGRA~1\MIAF83~1\GIANTAntiSpywareMain.exe 1.0.0.509 Microsoft Corporation 2888 C:\Program Files\Windows Media Player\wmplayer.exe 10.0.0.3646 Microsoft Corporation 3964 C:\Program Files\Internet Explorer\IEXPLORE.EXE 6.0.2800.1106 Microsoft Corporation 872 C:\Program Files\Microsoft Office\Office10\WINWORD.EXE 10.0.6612.0 Microsoft Corporation 2924 C:\Program Files\HijackThis\HijackThis.exe 1.99.0.1 Soeperman Enterprises Ltd. DLLs loaded by process C:\PROGRA~1\MIAF83~1\GCASDT~1.EXE: [full path to filename] [file version] [company name] C:\WINDOWS\System32\ntdll.dll 5.1.2600.1217 Microsoft Corporation C:\WINDOWS\system32\kernel32.dll 5.1.2600.1560 Microsoft Corporation C:\WINDOWS\System32\MSVBVM60.DLL 6.0.92.37 Microsoft Corporation C:\WINDOWS\system32\USER32.dll 5.1.2600.1634 Microsoft Corporation C:\WINDOWS\system32\GDI32.dll 5.1.2600.1561 Microsoft Corporation C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.1361 Microsoft Corporation C:\WINDOWS\system32\ole32.dll 5.1.2600.1619 Microsoft Corporation C:\WINDOWS\system32\OLEAUT32.dll 3.50.5016.0 Microsoft Corporation C:\WINDOWS\system32\MSVCRT.DLL 7.0.2600.1106 Microsoft Corporation C:\WINDOWS\System32\uxtheme.dll 6.0.2800.1106 Microsoft Corporation C:\WINDOWS\System32\CLBCATQ.DLL 2001.12.4414.53 Microsoft Corporation C:\WINDOWS\System32\COMRes.dll 2001.12.4414.42 Microsoft Corporation C:\WINDOWS\system32\VERSION.dll 5.1.2600.0 Microsoft Corporation C:\WINDOWS\System32\SSSensor.dll 5.5.0.5 Sygate Technologies, Inc. C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll 1.0.0.509 Microsoft Corporation C:\WINDOWS\System32\GCCollection.dll 1.0.0.509 Microsoft Corporation C:\WINDOWS\system32\SHLWAPI.dll 6.0.2800.1612 Microsoft Corporation C:\WINDOWS\System32\SXS.DLL 5.1.2600.1579 Microsoft Corporation C:\WINDOWS\System32\msi.dll 3.1.4000.2435 Microsoft Corporation C:\WINDOWS\system32\shell32.dll 6.0.2800.1643 Microsoft Corporation C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1643_x-ww_7c3a9bc6\comctl32.dll 6.0.2800.1643 Microsoft Corporation C:\WINDOWS\system32\comctl32.dll 5.82.2800.1106 Microsoft Corporation C:\WINDOWS\System32\netapi32.dll 5.1.2600.1562 Microsoft Corporation C:\WINDOWS\System32\SETUPAPI.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\appHelp.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\urlmon.dll 6.0.2800.1485 Microsoft Corporation C:\WINDOWS\System32\Secur32.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\rasapi32.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\rasman.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\WS2_32.dll 5.1.2600.0 Microsoft Corporation C:\WINDOWS\System32\WS2HELP.dll 5.1.2600.0 Microsoft Corporation C:\WINDOWS\System32\TAPI32.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\rtutils.dll 5.1.2600.0 Microsoft Corporation C:\WINDOWS\System32\WINMM.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\MSCTF.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\ShFolder.dll 6.0.2800.1106 Microsoft Corporation C:\WINDOWS\system32\imagehlp.dll 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\System32\PSAPI.DLL 5.1.2600.1106 Microsoft Corporation C:\WINDOWS\system32\wininet.dll 6.0.2800.1505 Microsoft Corporation C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.1123 Microsoft Corporation C:\WINDOWS\system32\MSASN1.dll 5.1.2600.1362 Microsoft Corporation C:\WINDOWS\System32\wsock32.dll 5.1.2600.0 Microsoft Corporation C:\WINDOWS\System32\IPhlpAPI.dll 5.1.2600.2 Microsoft Corporation C:\WINDOWS\System32\hashlib.dll 1.0.0.509 Microsoft Corporation For your second request :- File version : 1.0.0.509 Description : Microsoft AntiSpyware Data Service Copyright : Copyright©2004-2005 MIcrosoft Corperation.
Hi cilla
Congratulations. Your log looks clean. :)


This is IMPORTANT: You need to update your Windows. It is out of date. The version you should have at this time is Windows XP with SP2.

If you have a high-speed internet connection, go to”Start”> "Tools" menu > "Windows Update" or go to Microsoft Windows and Internet Explorer Updates to get the critical updates including SP2.

However if you have a dialup connection I would advise you to order the CD as the download is large and will take a VERY long time to download.
You can get the CD here .
Please inform me if you had any problems with the upgrade.


Now I want you to clean up some loose ends and take some precautions to avoid being re-infected
  • Clean out Temporary Files etc. Download System Security Suite from http://www.igorshpak.net/software/3ssetup104.zip. Extract it from the zip file into a folder and double click on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. Reboot when prompted. It is a good idea to do this every few weeks as a lot of junk collects there over time.


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
    Also see the following: Internet Explorer Privacy & Security Settings
    Working with Internet Explorer 6 Security
    Many exploits are directed at Internet Explorer, you don't have to use it. Try a different browser like
    Firefox . It is also worth trying Thunderbird for controlling spam in your e-mail.


  • Always use a anti-virus program and KEEP IT UPDATED
    It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
    This alone can save you a lot of trouble with malware in the future.


  • Always use a firewall.
    I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen to often with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    Be restrictive with granting access to the internet. If you are unsure if the program really needs the access, test it by denying the access and see if this has any negative effects. If not, make the block permanent.


  • Never run two Antivirus programs or two Firewalls at the same time. They can interfere with each other and cause problems.


  • MOST IMPORTANT : You Need to keep “Windows” and "Internet Explorer” updated. Open ‘Internet Explorer” and go to”Start”> "Tools" menu > "Windows Update" or go to Microsoft Windows and Internet Explorer Updates to get the critical updates.


  • If you are running Microsoft Office, or any portion thereof you must keep it updated as well. Go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed. Update MS Office here.


  • You will find more about how to protect yourself as well as suggested programs for this purpose HERE.
    PLEASE READ IT AND FOLLOW THE RECOMMENDATIONS TO PROTECT YOURSELF.



  • Update all these programs regularly - Make sure you update all the the protection programs regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.


  • It is worth while to take a look at "So how did I get infected in the first place? for some good advice.

Follow this list and your potential for being infected again will reduce dramatically.


I am glad if I was able to help.


E :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI