This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help! This is my log file.

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 10:13:27 PM, on 12/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Maximus\Desktop\Yanto\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Maximus\Application Data\Mozilla\Profiles\default\d5kat0j1.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [sysxp] C:\DOCUME~1\Maximus\LOCALS~1\Temp\bfxtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123565748359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123565731734
O16 - DPF: {DD85FDB7-9363-4873-B50C-CC46F3E4B704} (IGOLauncher6 Control) - http://vitalsign.igamesasia.com.sg/activex/IGOLauncher6.cab
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\YAMAHA\MidRadio Player\midradio.ocx
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\system32\catsrvut.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe



I am getting crazy latency problem when I am playing CS Source. The ping shows I am having good connection but it lags when I engage with another player.Please help me out.
Close all programs leaving only HijackThis running. Place a check against each of the following,
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [sysxp] C:\DOCUME~1\Maximus\LOCALS~1\Temp\bfxtray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)

Click on Fix Checked when finished and exit HijackThis.


Download and run - ATF Cleaner instructions here.

Download and install AVG Anti-Spyware (ewido). Then scan and post the report here.
Instructions and download link can be found here.
Hello Little Eagle, I have followed the instructions you had given. Although the AVG software that I downloaded from the link is different from the pictures illustrated in your guide.Here are the test result after the scanning by AVG Anti-Malware ver 7.5 software. Object Result Status E:\Mozilla\Profiles\rudy\5bdvszij.slt\Mail\pacific.net.sg\Trash Deleted E:\New Drivers & Software\Netscape\Mozilla\Profiles\rudy\5bdvszij.slt\Mail\pacific.net.sg\Trash Deleted E:\New Drivers & Software\Netscape\Profiles\rudy\5bdvszij.slt\Mail\pacific.net.sg\Trash Deleted E:\Documents and Settings\Maximus\Application Data\Mozilla\Profiles\RUDY\QCG2IXSW.SLT\Mail\pacific.net.sg\Trash Deleted E:\qcg2ixsw.slt\Mail\pacific.net.sg\Trash Deleted Object Result Status C:\Documents and Settings\All Users\Documents\DAP[1].v7.2.rar:\DAP.exe Adware Generic.GOP Potentially Unwanted Program, Embedded object, Deleted Not-A-Virus.VirTool.Win32.AvSpoffer.a Family Not-A-Virus.VirTool.Win32.AvSpoffer.a Spyware Family E:\New Drivers & Software\Video\Video splitters\AVI_Splitter_v2.1.zip:\avisplit.2.1.patch\avisplit.2.1.patch.exe Not-A-Virus.VirTool.Win32.AvSpoffer.a Potentially Unwanted Program, Deleted E:\My Documents\CRACK-LOCATOR.COM-GoldWave_4.26.zip:\GoldWave 4.26 Crack.exe Not-A-Virus.VirTool.Win32.AvSpoffer.a Potentially Unwanted Program, Deleted E:\Documents and Settings\Maximus\My Documents\CRACK-LOCATOR.COM-GoldWave_4.26.zip:\GoldWave 4.26 Crack.exe Not-A-Virus.VirTool.Win32.AvSpoffer.a Potentially Unwanted Program, Deleted TrackingCookie.Webtrendslive Family TrackingCookie.Webtrendslive Spyware Family TrackingCookie.Popuptraffic Family TrackingCookie.Popuptraffic Spyware Family E:\Documents and Settings\All Users\Documents\DAP[1].v7.2.rar:\DAP.exe Adware Generic.GOP Potentially Unwanted Program, Embedded object, Deleted Adware.NewDotNet Family Adware.NewDotNet Spyware Family System registry HKU\S-1-5-18\Software\New.net Adware.NewDotNet Potentially Unwanted Program C:\Documents and Settings\All Users\Documents\DAP[1].v7.2.rar Potentially Unwanted Program, Moved to Vault, Archive C:\Documents and Settings\All Users\Documents\DAP[1].v7.2\DAP.EXE Potentially Unwanted Program, Moved to Vault C:\Program Files\Warcraft III\JOJ_War3.exe Potentially Unwanted Program, Moved to Vault C:\Program Files\Warcraft III\JOJ_WorldEdit.exe Potentially Unwanted Program, Moved to Vault E:\Mozilla\Profiles\rudy\5bdvszij.slt\cookies.txt Potentially Unwanted Program, Moved to Vault E:\New Drivers & Software\Video\Video splitters\AVI_Splitter_v2.1.zip Potentially Unwanted Program, Moved to Vault, Archive E:\New Drivers & Software\Netscape\Mozilla\Profiles\rudy\5bdvszij.slt\cookies.txt Potentially Unwanted Program, Moved to Vault E:\New Drivers & Software\Netscape\Profiles\rudy\5bdvszij.slt\cookies.txt Potentially Unwanted Program, Moved to Vault E:\My Documents\CRACK-LOCATOR.COM-GoldWave_4.26.zip Potentially Unwanted Program, Moved to Vault, Archive E:\My Documents\GoldWave 4.26 Crack.exe Potentially Unwanted Program, Moved to Vault E:\Documents and Settings\Maximus\My Documents\CRACK-LOCATOR.COM-GoldWave_4.26.zip Potentially Unwanted Program, Moved to Vault, Archive E:\Documents and Settings\Maximus\My Documents\GoldWave 4.26 Crack.exe Potentially Unwanted Program, Moved to Vault E:\Documents and Settings\Maximus\Start Menu\Programs\Startup\PowerReg Scheduler.exe Potentially Unwanted Program, Moved to Vault E:\Documents and Settings\All Users\Documents\DAP[1].v7.2.rar Potentially Unwanted Program, Moved to Vault, Archive E:\Documents and Settings\All Users\Documents\DAP[1].v7.2\DAP.EXE Potentially Unwanted Program, Moved to Vault E:\qcg2ixsw.slt\cookies.txt Potentially Unwanted Program, Moved to Vault System registry HKU\.DEFAULT\Software\New.net Potentially Unwanted Program, Moved to Vault

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI