This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Ive been getting lots of un wanted pop up ads. I have tries running Ad Aware and Spy bot but i still recieve these pop up ads. Neededware is one that seems to come up quite often as wanting to install. Help, Help, please. Here it my hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 2:32:37 PM, on 7/25/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
D:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\WINNT\System32\NMSSvc.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
D:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
D:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
D:\Program Files\Novell\ZENworks\wm.exe
D:\Program Files\Novell\ZENworks\WMRUNDLL.EXE
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\NWTRAY.EXE
D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\??pPatch\chkdsk.exe
D:\Program Files\heda\rccn.exe
C:\Program Files\Gateway Ticketing Systems\Galaxy\Galaxy.exe
C:\NOVELL\GroupWise\GrpWise.exe
C:\NOVELL\GroupWise\Notify.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\jsanchez\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=10.1.1.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = web.sandiegozoo.org;webaccess.sandiegozoo.org;intranet.sandiegozoo.org;quoll.sandiegozoo.org;;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [Client Access Service] "D:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "D:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "D:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "D:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [cdivo] C:\WINNT\system32\cdivo.exe
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [Dwg] C:\WINNT\system32\??pPatch\chkdsk.exe
O4 - HKCU\..\Run: [Pbba] D:\Program Files\heda\rccn.exe
O4 - Global Startup: capture.bat
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - D:\Program Files\Novell\ZENworks\AxNalServer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200411…llInstaller.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O18 - Protocol: nim - {3D206AE2-3039-413B-B748-3ACC562EC22A} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: ShellScrap - C:\WINNT\system32\mtiwave.dll
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINNT\system32\cusrvc.exe
O23 - Service: CWShredder Service - InterMute, Inc. - M:\Batch\! Removal tools\CW Shredder\CWShredder.exe
O23 - Service: DefWatch - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - D:\Program Files\Novell\ZENworks\nalntsrv.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Novell ZfD Wake on LAN Status Agent (Prometheus Wake-On-LAN Status Agent) - Novell Inc. - D:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\WolSerNT.exe
O23 - Service: Novell ZfD Remote Management (Remote Management Agent) - Novell Inc. - D:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
O23 - Service: TL Filter Agent 28 - Timeline, Inc. - D:\Program Files\Timeline Analyst\Shared\TLFSAgt28.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, INC. - D:\Program Files\Novell\ZENworks\wm.exe
Hi jsradiohead;

Well, neededware thought you needed it, since it has placed itself in your Trusted Zone. Guess we will just have to throw it out with the rest of the Internet trash on your PC.

We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make. If you have any additional programs that may interfere, they must also be temporarily disabled.

Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

Please set your computer to show all files.

* Double-click My Computer.
* Click the Tools menu, and then click Folder Options.
* Click the View tab.
* Clear "Hide file extensions for known file types."
* Under the "Hidden files" folder, select "Show hidden files and folders."
* Clear "Hide protected operating system files."
* Click Apply, and then click OK.

Next:
Close all browser windows and RUN HijackThis.
. Click the SCAN button to produce a log.
Place a check mark beside each one of the following entries:


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKCU\..\Run: [Dwg] C:\WINNT\system32\??pPatch\chkdsk.exe
O15 - Trusted Zone: http://www.neededware.com


The following are OPTIONAL fixes:
Search results were inconclusive, so if you know and trust the following, keep them. If not, fix them with Hijack This and delete the files below.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = web.sandiegozoo.org;webaccess.sandiegozoo.org;intranet.sandiegozoo.org;quoll.sandiegozoo.org;;
O4 - HKLM\..\Run: [cdivo] C:\WINNT\system32\cdivo.exe
O4 - HKCU\..\Run: [Pbba] D:\Program Files\heda\rccn.exe
O4 - Global Startup: capture.bat
O18 - Protocol: nim - {3D206AE2-3039-413B-B748-3ACC562EC22A} - (no file)
O20 - Winlogon Notify: ShellScrap - C:\WINNT\system32\mtiwave.dll



Now with all the items selected, delete them by clicking the FIX checked button.


Reboot into Safe Mode:
Additional assistance and alternate methods are available here:
Please use the method described for your particular Operating System.

http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam


Using Windows Explorer, locate the following files/folders shown DARK, and delete them (if they are present):

C:\WINNT\system32\??pPatch The "??" is a wildcard and could be any letters.

The following are in the OPTIONALS. If you know and trust them, keep them. If not delete the file/folder.

C:\WINNT\system32\cdivo.exe

C:\WINNT\system32\mtiwave.dll

If the following is selected to be deleted, it must also be Uninstalled/Removed, in Add/Remove Programs.
D:\Program Files\heda


If you were unable to find, or remove any of the files then please follow these additional instructions:

Download Pocket Killbox and unzip it; save it to your Desktop.

Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.

The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.

Let the system reboot.

If it has not rebooted, please do so now and enable hidden files.

Now lets run a series of scans and Programs, to see if there is any hidden Malware on your PC.

Please use the following links to run one, or more of these online Virus Scanners and let them fix whatever they find.

If you are using any of the browsers listed just below, the following online Virus scanning site is compatable.
http://be.trendmicro-europe.com/consumer/h…call_launch.php
If you are using any of these browsers:
Microsoft Internet Explorer
Netscape (6+)
Mozilla (1+)
Firefox (all)
Opera (7.5+)

Internet Explorer users can also use the following links.

When using Trend Micro, be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the file location, so you can delete it yourself.
Bitdefender and let it delete everything it finds.
TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done.

Next:
Please download, install, update and scan your system with the free version of Ewido trojan scanner:
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack….
  • If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  • When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread, along with a new HijackThis log.

    Then,
    Please download and install Ad-Aware SE and Spybot S&D according to the following instructions. If you already have these programs, please make sure they are the latest version and have been updated today. Then run full systems scans as described below.

    Install and how to use the NEW Ad-aware SE
    http://www.bleepingcomputer.com/forums/ind…showtutorial=48

    Reboot after using Ad-Aware SE.
    Download the VX cleaner plug in for Adaware. Install it, then open Adaware & go to *add-ons* & run the plug-in. If anything is found, select *clean system* & when done, reboot & run Adaware & let it finish the clean-up. Reboot again.


    Would you please download the Spybot S&D program from here Spybot S&D; and install it.
    • Select Search for updates.
    • Then select all available updates that are displayed in the white box.
    • Select a download mirror nearest your location.
    • Then select Download updates .
    • Shut down and restart Spybot.
    • Select the Search and destroy icon and click on Check for Problems.
    • Delete/fix anything that spybot lists In RED.
    .

    Then, please REBOOT, to allow Spybot to finish working

    The following step is important as you may have several malware files in your temp directories.

    Then browse to the C:\documents and settings\Your User Name (repeat for all other user names in documents and settings)\local settings\temp folder and delete all files and folders in it.
    Then browse to the C:\Window\Temp folder and delete all files and folders in it.
    Then in internet explore click tools>internet Options>General. Click on Delete Files make sure you get all offline content as well.


    Reboot and post a fresh Hijack This log in this thread, Using the Post Reply feature, so I will be notified.

    Note: Do not attempt to "Fix" anything in the new log, as we need to see the entire log, without revisions.
Due to lack of response, this topic is closed.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI