This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis Log: PLease Help Diagnose

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 18:44:15, on 12/09/2006
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\cdplayer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\Program Files\Caere\OmniPagePro90\opware32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\ntvdm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\{9C8176F0-02EF-1033-0419-01082799002c}\Update.exe
C:\WINNT\System32\internat.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\OpenOffice.org1.1.2\program\soffice.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\AlanTmp\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.search.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.search.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsoft.com/search/lobby/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.search.msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
F2 - REG:system.ini: UserInit=C:\WINNT\System32\userinit.exe,C:\WINNT\System32\glossary.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [DeluxeCD] C:\WINNT\system32\cdplayer.exe -tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [www.hidro.4t.com ] enbiei.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [Win Processor] wuactul.exe
O4 - HKLM\..\Run: [OmniPage] C:\Program Files\Caere\OmniPagePro90\opware32.exe
O4 - HKLM\..\Run: [Windows Compliant] nkvsku.exe
O4 - HKLM\..\Run: [SysCopy] SysCopy32.exe
O4 - HKLM\..\Run: [Local Procedure Call Mapper] LPC.exe
O4 - HKLM\..\Run: [MSN BETA 0.1] SVCHOSTWIN.exe
O4 - HKLM\..\Run: [bfetsdv9] C:\WINNT\System32\bfetsdv9.exe
O4 - HKLM\..\Run: [MS taskbar] taskbars.exe
O4 - HKLM\..\Run: [Microsoft Network Services Controller] C:\WINNT\System32\mmsvc32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_17.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_17.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_16.exe
O4 - HKLM\..\Run: [saj96f15] RUNDLL32.EXE w003c479.dll,n 00396f120000000a003c479
O4 - HKLM\..\Run: [Windows Update Manager] taskmgr32.exe
O4 - HKLM\..\Run: [RBot v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Server] C:\WINNT\System32\glossary.exe
O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINNT\System32\firewall.exe
O4 - HKLM\..\Run: [FrameWork 2.5] FrameWork.exe
O4 - HKLM\..\Run: [Microsoft DllHost Service] dllhost.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [Win Processor] wuactul.exe
O4 - HKLM\..\RunServices: [Windows Compliant] nkvsku.exe
O4 - HKLM\..\RunServices: [SysCopy] SysCopy32.exe
O4 - HKLM\..\RunServices: [Local Procedure Call Mapper] LPC.exe
O4 - HKLM\..\RunServices: [MSN BETA 0.1] SVCHOSTWIN.exe
O4 - HKLM\..\RunServices: [MS taskbar] taskbars.exe
O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe
O4 - HKLM\..\RunServices: [Windows Update Manager] taskmgr32.exe
O4 - HKLM\..\RunServices: [FrameWork 2.5] FrameWork.exe
O4 - HKLM\..\RunServices: [Microsoft DllHost Service] dllhost.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Windows Compliant] nkvsku.exe
O4 - HKCU\..\Run: [SysCopy] SysCopy32.exe
O4 - HKCU\..\Run: [Local Procedure Call Mapper] LPC.exe
O4 - HKCU\..\Run: [MS taskbar] taskbars.exe
O4 - HKCU\..\Run: [MSN BETA 0.1] SVCHOSTWIN.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [RBot v2 with NetAPI exploit traded with billgates I gave my mother Greetz - OG - Bluehell Irc Server] C:\WINNT\System32\glossary.exe
O4 - Startup: OpenOffice.org 1.1.2.lnk = C:\Program Files\OpenOffice.org1.1.2\program\quickstart.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/plugins/en_US/Dj…ntrol_en_US.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} - http://www1.getmapping.com/ecwplugins/ncs.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/nz.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = procash
O17 - HKLM\System\CCS\Services\Tcpip\..\{4BF3C4B4-1C42-4E97-84D1-5DA8A59679FE}: NameServer = 203.96.152.4,203.96.152.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = procash
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = procash
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Skype\toolbars\Shared\Skype4ComAPI.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Clients Server Runtime Process - Unknown owner - C:\WINNT\csrss.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - C:\Program Files\ewido anti-spyware 4.0\guard.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows DLL Manager - Unknown owner - C:\WINNT\system32\winws.exe (file missing)
O23 - Service: Windows PE Debugger - Unknown owner - C:\WINNT\system32\lviss.exe (file missing)
Hi alanrdry, there is some bad news.

Your computer is heavily infected. Among the infections are what looks like a root kit and some backdoor trojans. :( Please read the following warning.

It appears you have a root kit and some backdoor trojans on your computer. If that is the case your computer is and always will be at risk. I cannot guarantee that we can clean everything and reset all changes that has been done to the computer.
Root kits can be extremely hard to detect, and just as hard to clean out.
You have to think that from this point forward, you can't completely trust your computer. The rootkit could be hiding a backdoor trojan.
It could be that it is possible for someone to secretly steal your financial and other sensitive information and do ANYTHING they want with the computer.
The only way to be SURE that the infections and the changes they have done are removed is to reformat and reinstall.

If that is acceptable to you, not only would it be safer, but it would probably be less time consuming to do a reformat than to clean up the computer.
Please read this article that was published by Robin at Castle Cops and you will understand better why this warning and what to do.
http://castlecops.com/a6511-Identity_Stolen_Now_what.html

Also, you should read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?


When Should I Format, How Should I Reinstall

Further to the articles you are strongly advised to do the following immediately:

1. Disconnect the infected computer from the internet and from any networked computers until the computer can be cleaned.

2. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

3. From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

Also do whatever else that seems appropriate.


Before you decide to reformat you should check that you have all the necessary information and software.

If you decide to continue with a cleanup you should not use this computer for financial or other sensitive transaction.

Let me know what you want to do.
Hi Trojan 1000, Wow! Thanx for that, sortof ;-). This is my father-in-law's PC and I had already removed 150 or so viruses using AVG, 90 odd things with AD-Aware and 50 some with SpyBot and Ewido. As a BHO warning popped up (from SpywareGuard I think) on bootup, I knew we still had issues, but I was hoping it wouldn't be this bad. I will investigate how readily I can do a reinstall but would be quite interested to know what you can point me to in the Hijack log that evidences problem so I can at leasst "give it a try" that way first and see how it looks. I do however take on board what you say about it being potentially untrustworthy going forward and am prepared to reformat. It is just that there may be an issue getting the source disks for all the software he had installed. Many thanx. AlanD
Hi Alan! I'm sorry for the bad news. I'll be glad to help you clean the computer to the best we can. :)

Before we go any futher, I need you to do the following order set below:

First, you need download and install SP3 for Windows 2000. You can get that from here.

Then, you need to download and install SP4 for Windows 2000. You can get that from here.

Important: SP3 should be installed first before installing SP4

Once that is all done, please post a new HijackThis log, along with an Uninstall list by doing the following:
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button. It will open a Notepad file.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Hi Trogan 1000, Sorry for the delay in adding my next bit. I have been incommunicado for a couple of days. First of all, I really appreciate you helping me here, but will probably take a pause at this point for 2 reasons: a) I have to admit I built this PC for my father-in-law (both hardware and software-wise) and the OS "fell off the back of a truck" (if you get what I mean). The serial no entered when installing Win200Pro has stopped me subsequently adding SP's. B) In addition to using AVG and SpyBot, I have over the last week since first raising this tried practically every free or trial version of the various reputable spyware, trojan and root-kit removal tools I could lay hands on (Webroot, Spyware Doctor, Ewido, Trojan Hunter, SpywareGuard, SpywareBlaster UnHackMe …) Now, after removing almost 1000 nasties of various kinds his PC seems to be behaving. We were on the net for about 4 hours total yesterday and all worked well. No popups, no browser hijacking. ZoneAlarm blocked in excess of 200 inbound attempts to connect to it. As he doesn't use it for anything financial or that would include login's and passwords, I have given it back to him to use in his usual way for a week on the basis that it is unlikley to get any worse in that time than it was when it brought it to me 10 days ago. Then, if issues have re-surfaced, we will follow your suggsted course of reformat and re-install (and possibly add a sandbox element!). So again, until next I need help, thanx. Your reaction to what I posted was helpful in terms of the extra digging I did. You guys are great to come to when life gets beyond what we amateur techo's can handle. I am not saying we are necessarily totally out of the woods yet, but I feel good about the progress I have made. Regards, AlanD

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI