My hijack log
59 min read
Hi
I need you to boot into safemode and run rest of fix if you hadn't yet.
I need to know.
Please do not try to fix anything own your own.
We will deal with the popup messages.
Can you not boot into safe mode?
Yes i am just running the panda scan now i will post everything in a moment
Scan saved at 10:22:55 PM, on 1/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Updater.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\LiveUpdate\LiveUpdate.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\hijack this\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BTCLiveUpdate] "C:\Program Files\LiveUpdate\LiveUpdate.exe" /autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168141373265
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Use Explorer to navigate to and delete the following file (if it is present) just what is in red:
Files:
* C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe <<<< Maybe C:\ProgramFiles\SYMNET << Folder Starting with these letters.
If you can not find SNDMon.exe move to next step.
I don't know what Explorer is but i went into search and typed in SNDMon.exe and nothing popped up and i don't have a SYMNET folder in my program files.
Thanks for posting logs now we are getting some where got rid of some infection much more to go.
i looked up the service and controller thing and i kept getting information about something called sasser or sasser worm you think i have this??? it doesn't make sense, apparently if i press send or don't send my computer will come up with that thing again about shutting itslef off because of system.exe??
If you had sasser worm it should have show up in Panda online scan.
Once we get rid of all this infected files we will see if this error message stops.
I will need you to boot into safe more to carry this out.
Reboot your computer in Safe Mode.
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
- Login on your usual account.
Start Killbox place a tick next to [x]Delete on reboot Press the ALL Files button <<< Very important to hit the all files button
Copy this whole list into the windows clipboard, all the Bold below.
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
C:\Program Files\MSN Messenger\riched20.dll
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\ib35jrtp.exe
C:\WINDOWS\dljgmqgA.exe
C:\WINDOWS\websk.exe
c:\windows\system32\bdkybh.exe
C:\WINDOWS\mhav.exe
C:\WINDOWS\system32\ggkgwm.exe
C:\WINDOWS\win32073991086372.exe
c:\windows\system32\izopei.exe
C:\WINDOWS\ydcbyf.exe
C:\WINDOWS\system32\zmppnu.exe
C:\winsysupd11.exe
C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe
C:\WINDOWS\SYSC00.exe
C:\Program Files\Symantec\SNDMon.exe
C:\Program Files\SurfSideKick 3\Ssk.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\Program Files\Common Files\roii\roiim.exe
C:\Program Files\MyWebSearch\bar\2.bin\mwsoemon.exe
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
C:\Program Files\Media Access\MediaAccK.exe
C:\windows\system32\elitehof32.exe
C:\gimmygames11.exe
C:\WINDOWS\dinst.exe
C:\WINDOWS\system32\canada.exe
Back in Killbox go to > file > paste from clipboard.
Next, click the red highlighted X button and say NO to the prompt to restart the pc.
Now, exit Killbox and restart Your PC. You will have to reboot back into Safemode
—————————————————————
Use Windows Explorer to navigate to and delete the following folders (if it is present) just what is in red:
Folders:
C:\Program Files\WeirdOnTheWeb
This is how you find it:
1. click start > then click My Computer
2. Double click on C; Drive to open
now we are looking for this part of line that I had above
\Program Files\WeirdOnTheWeb
3. look for and double click on Program Files folder to open.
4. Now look for WeirdOnTheWeb when found right on it and choose delete.
Now repeat steps above all these folders and delete them too.
C:\Program Files\Symantec
C:\Program Files\SurfSideKick
C:\Program Files\Common Files\roii
C:\Program Files\MyWebSearch
C:\Program Files\Media Access
C:\WINDOWS\uniq
If you can not find some continue with fix don't stop here. still in safemode go to next step.
_____________________________________________________________
proper regfix to clear that entries: .
1. Please do this:
- Copy the contents of the Quote Box below to Notepad make sure to just copy what is inside box nothing outside of it. (not Wordpad)
- On file menu click Save as
- Name the file as regfix.reg <<<< You must type exactly as shown period and all
- Change the Save as Type to All Files (NOT as a txt file)
- and Save it on the desktop
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysupd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysban]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roii]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gimmygames]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASDPLUGIN]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ib35jrtp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dljgmqgA]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6JceYY45c]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mhav]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ongsnah]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svgbwr]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\win32073991086372]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwrrakq]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ydcbyf]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjdtsar]
Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.
2. Then double-click on the regfix.reg file icon should look like this [external image: Posted Image], that is on your desktop and when it prompts to merge say yes.
——————————————————————————————————–
Now rerun Ccleaner here still in safe mode.
——————————————————————————
Now reboot into normal mode here
———————————————————
Rerun combofix again here.
———————————————————
This show will show things other done YOU have do use Internt Explorer browser for this not FireFox
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
- The program will launch and then start to download the latest definition files.
- Once the scanner is installed and the definitions downloaded, click Next.
- Now click on Scan Settings
- In the scan settings make sure that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (If available otherwise Standard)
- Scan Options:
- Scan Archives
- Scan Mail Bases
[*]Now under select a target to scan select My Computer
[*]The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
[*]Now click on the Save as Text button
[*] Save the file to your desktop.
[*]Copy and paste that information in your next post.
————————————————————–
Please post logs:
combofix log
kaspersky report
New HJT log
i went into safemod and i opened up kill box i copied all the files and i went into killbox and pressed file paste from clipboard and delete after reboot and all files the only things that should up in the lil box was
C:\program files\mozilla firefox\plugins\npmywebs.dll
C:\program files\msn messenger\richard20.dll
C:\windows\system32\f3pssavr.scr
Other then that i didn't see any other files i copied show up??
So i came back and didn't go through with it yet, i wanted to know if they would all show up or just thses ones!
It seems i can only do three at a time maybe??
Use Windows Explorer to navigate to and delete the following folders (if it is present) just what is in red:
Folders:
C:\Program Files\WeirdOnTheWeb
This is how you find it:
1. click start > then click My Computer
2. Double click on C; Drive to open
now we are looking for this part of line that I had above
\Program Files\WeirdOnTheWeb
3. look for and double click on Program Files folder to open.
4. Now look for WeirdOnTheWeb when found right on it and choose delete.
Now repeat steps above all these folders and delete them too.
C:\Program Files\Symantec
C:\Program Files\SurfSideKick
C:\Program Files\Common Files\roii
C:\Program Files\MyWebSearch
C:\Program Files\Media Access
C:\WINDOWS\uniq
If you can not find some continue with fix don't stop here. still in safemode go to next step.
_____________________________________________________________
proper regfix to clear that entries: .
1. Please do this:
- Copy the contents of the Quote Box below to Notepad make sure to just copy what is inside box nothing outside of it. (not Wordpad)
- On file menu click Save as
- Name the file as regfix.reg <<<< You must type exactly as shown period and all
- Change the Save as Type to All Files (NOT as a txt file)
- and Save it on the desktop
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysupd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysban]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roii]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gimmygames]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASDPLUGIN]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ib35jrtp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dljgmqgA]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6JceYY45c]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mhav]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ongsnah]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svgbwr]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\win32073991086372]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwrrakq]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ydcbyf]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjdtsar]
Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.
2. Then double-click on the regfix.reg file icon should look like this [external image: Posted Image], that is on your desktop and when it prompts to merge say yes.
——————————————————————————————————–
Now rerun Ccleaner here still in safe mode.
——————————————————————————
Now reboot into normal mode here
———————————————————
Rerun combofix again here.
———————————————————
This show will show things other done YOU have do use Internt Explorer browser for this not FireFox
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
- The program will launch and then start to download the latest definition files.
- Once the scanner is installed and the definitions downloaded, click Next.
- Now click on Scan Settings
- In the scan settings make sure that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (If available otherwise Standard)
- Scan Options:
- Scan Archives
- Scan Mail Bases
[*]Now under select a target to scan select My Computer
[*]The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
[*]Now click on the Save as Text button
[*] Save the file to your desktop.
[*]Copy and paste that information in your next post.
————————————————————–
Please post logs:
combofix log
kaspersky report
New HJT log
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI