This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tried all kinds of stuff (Hijak This Log Attached)

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About a week and a half ago I accidently clicked a banner that downloaded some file to my system and began to run it before I had a chance to cancel it. Before I knew it I had pop-ups everywhere explorer.exe kept crashing.

I WAS using Zonealarm but after the bomb was dropped on my computer it basically allowed everything into my computer no matter what my settings were. I downloaded AVG and scanned my system and removed about a dozen trojans, I ran Lavasoft's Adaware, Spybot S&D, The Pccillin online scanner, and ewido.

All of them found stuff that the others had not located but after about a week and a half I have been running the scanners each day always find new trojans and/or pop-up carp**.

AFAIK Windows is fully up to date (it ain't telling me there are more updates to get), I changed my firewall to Comodo, and run my spyware scanners and AVG daily. I still find trojans and stuff every day. AVG no longer ever detects anything, nor does spybot S&D really either. They mostly find a few tracking cookies and thats it. It is PcCillin that finds the trojans all the time.

Anyway, Here is the Hijackthis log.

Thanks in advance

Dennis

Logfile of HijackThis v1.99.1
Scan saved at 1:03:33 AM, on 9/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\SBAudigy4\DVDAudio\CTDVDDET.EXE
D:\SBAudigy4\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\Grisoft\AVG7\avgcc.exe
D:\ewido anti-spyware 4.0\ewido.exe
D:\Comodo\Firewall\CPF.exe
D:\Creative\MediaSource\Detector\CTDetect.exe
d:\Grisoft\AVG7\avgamsvr.exe
d:\Grisoft\AVG7\avgupsvc.exe
d:\Grisoft\AVG7\avgemc.exe
D:\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
d:\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\HiJack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,qsanyas.exe
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ManualRun] "E:\AUTORUN\AutoRun"
O4 - HKLM\..\Run: [CTDVDDET] d:\SBAudigy4\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTSysVol] "d:\SBAudigy4\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] "d:\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [!ewido] "D:\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Comodo Firewall] "D:\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "d:\Creative\MediaSource\Detector\CTDetect.exe" /R
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{905AF475-90C7-4F07-A558-E7FB5DAF7BC2}: NameServer = 68.94.156.1,68.94.157.1
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - d:\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - d:\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - d:\Grisoft\AVG7\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - D:\Comodo\Firewall\cmdagent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - d:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
drseuss620 :D

Welcome to Tom Coyote, sorry for the delay, the forums are very busy.


Open HJT Scan Only , close your browser and all open windows, tick this entry and click on Fix Checked

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,qsanyas.exe


The rest of your log is looking fine :thumbup: But lets run this free Online Virus scanner from Panda, it won't clean anything but I need to see the report.

Panda ActiveScan <—-Accept default settings

Ken :D
The scan from Panda turned up spyware but no trace of trojans or viruses. Incident Status Location Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@advertising[1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@atdmt[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@doubleclick[2].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Dennis\Cookies\dennis@mediaplex[2].txt Thanks for your reply!
Hello,

All Panda found where cookies, :thumbup: if there was something bad on your system, Panda would have found it.

Run this system cleaner.
Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

Lets run one last scan that searches for hidden files that could be bad.. If nothing turns up then I would say you are ok.

Download and Save Blacklight to your desktop:
  • Double-click blbeta.exe
  • Then accept the agreement
  • leave [X]scan through Windows Explorer checked.
  • Click > scan then > next
  • You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
  • Copy and paste this log in your next reply.
  • Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"

Post the Blacklight report and a new HJT log as your original log is about 8 days old.

Ken :D
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI