This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My HijackThis Log File

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

MyLog File: Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe C:\WINDOWS\bWlrZQ\command.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\hijackthis\HijackThis.exe R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [tSdURg2] "C:\WINDOWS\System32\fhsxc.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE O4 - HKCU\..\Run: [Trpp] "C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe" -vt ndrv O18 - Filter: text/html - {F8D76886-FA88-4DF6-8FBD-C02CF8C91C94} - C:\WINDOWS\System32\ubbv.dll O20 - AppInit_DLLs: wowexec.dll O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\k0js0a17ed.dll O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bWlrZQ\command.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory

MSWINSCK.OCX

Please post the ENTIRE HijackThis! log.

The last one was missing the "header" info.

There will be other things to remove.
:)
This is my log file after i used Look2me Destroyer, i am still having popup problems also. Any help is much appreciated, thanks Logfile of HijackThis v1.99.1 Scan saved at 5:29:43 PM, on 8/29/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\alg.exe C:\WINDOWS\bWlrZQ\command.exe C:\WINDOWS\System32\wdfmgr.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}\Update.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\hijackthis\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\wuauclt.exe R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [tSdURg2] "C:\WINDOWS\System32\fhsxc.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE O4 - HKCU\..\Run: [Trpp] "C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe" -vt ndrv O18 - Filter: text/html - {F8D76886-FA88-4DF6-8FBD-C02CF8C91C94} - C:\WINDOWS\System32\ubbv.dll O20 - AppInit_DLLs: wowexec.dll O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bWlrZQ\command.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O4 - HKLM\..\Run: [tSdURg2] "C:\WINDOWS\System32\fhsxc.exe"

O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE

O4 - HKCU\..\Run: [Trpp] "C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe" -vt ndrv

O18 - Filter: text/html - {F8D76886-FA88-4DF6-8FBD-C02CF8C91C94} - C:\WINDOWS\System32\ubbv.dll

O20 - AppInit_DLLs: wowexec.dll

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bWlrZQ\command.exe

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column look for:

Command Service

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\bWlrZQ\command.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\mike\application data\ppatch~2 <— FOLDER

c:\windows\bwlrzq <— FOLDER

c:\windows\racle~1 <— FOLDER

c:\windows\system32\fhsxc.exe <— file

c:\windows\system32\ubbv.dll <— file

c:\windows\system32\wowexec.dll <— file
(DO NOT DELETE WOWEXEC.EXE !!!)

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread.
Please use the [external image: Posted Image] button, and do not start a new thread.

There is at least one other item left to take care of, even if your endeavors on these items are successful.
:)
Here is my new HiJack Log File: Logfile of HijackThis v1.99.1 Scan saved at 6:27:47 PM, on 8/29/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}\Update.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\System32\devldr32.exe C:\WINDOWS\System32\syshost.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Webroot\Spy Sweeper\SSU.EXE C:\WINDOWS\system32\srshost.exe C:\Program Files\hijackthis\HijackThis.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKLM\..\Run: [Microsoft Windows System] syshost.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\RunServices: [Microsoft Windows System] syshost.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE O4 - HKCU\..\Run: [srshost.exe] C:\WINDOWS\system32\srshost.exe O4 - Global Startup: Wincbr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [Microsoft Windows System] syshost.exe

O4 - HKLM\..\RunServices: [Microsoft Windows System] syshost.exe

O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE

O4 - HKCU\..\Run: [srshost.exe] C:\WINDOWS\system32\srshost.exe

O4 - Global Startup: Wincbr.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\windows\racle~1 <— FOLDER

c:\windows\system32\srshost.exe <— file

c:\windows\system32\syshost.exe <— file

wincbr.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread.

You need a firewall - ASAP!!!

Free ones are located here:

Securing Your PC After An Attack

Or find one of your own choosing.
While your there looking at links, think about an antivirus as well.

You'll need one of those as well.

DON'T INSTALL ANY ANTIVIRUS JUST YET!
Thank you for all your help! Logfile of HijackThis v1.99.1 Scan saved at 7:29:02 PM, on 8/29/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\savedump.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}\Update.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\hijackthis\HijackThis.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Unless something new shows up, only 1 "bad boy" left. :thumbup:

Please download/unzip this:

Registry Search 2.0 by Bobbi Flekman © 2005

on regsearch.exe, and search for this:

{3829BA0F-015E-1033-0303-000723980001}

[external image: Posted Image] Make sure ALL the boxes are checked under "Search".

It may take a while to run, so be patient. When finished, the search results will appear in your text editor,

Paste the contents of the search results into your next post.
:)
REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 8/29/2006 7:57:05 PM for strings: ; '{3829ba0f-015e-1033-0303-000723980001}' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_USERS\S-1-5-21-2025429265-436374069-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "{3829BA0F-015E-1033-0303-000723980001}"="\"C:\\Program Files\\Common Files\\{3829BA0F-015E-1033-0303-000723980001}\\Update.exe\" mc-110-12-0000103" ; End Of The Log…
Copy and paste the contents of the quote box below into notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[HKEY_USERS\S-1-5-21-2025429265-436374069-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"{3829BA0F-015E-1033-0303-000723980001}"=-


Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Reboot.

Delete this FOLDER:

C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}

Reboot and post a new HijackThis! log.

Unless something new appears, this should take care of things.

If the log looks good, I'd like for you to try at least one of these online virus scans:

Trend-Micro Housecall
Put on 'Autoclean' and delete what it can't clean.

Etrust Security Advisor
Choose 'Cure' whatever is found, then delete if unsuccessful.

Bitdefender

If they find something they can't fix, or delete, let me know.

As soon as all the "bugs" are fixed, choose a firewall and an antivirus.

Some free ones can be found here:

Securing Your PC After An Attack

Without a firewall/antivirus, you're an infection just waiting to happen….
:oops:
Thanks again, Logfile of HijackThis v1.99.1 Scan saved at 8:33:48 PM, on 8/29/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\System32\devldr32.exe C:\Documents and Settings\mike\Local Settings\Temp\Temporary Directory 8 for hijackthis.zip\HijackThis.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI