This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijacked this log

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I have been getting virtual memory low messages, so I got more ram (went from 96 to 256MB) and although things are running better it seems, its not by much and I have seen a virtual memory low message since then as well. I'd like things to be a little faster if they can be and clean up any riff raff on my PC as well. Thanks,

Jared

I followed the "before you post" instructions, here are my logs:

Logfile of HijackThis v1.98.2
Scan saved at 2:30:34 PM, on 1/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ja\Desktop\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.screenname.aol.com/_cqr/login/lo…f&authLev;=2
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "D:\Stuff\Programs\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "D:\Stuff\Programs\qttask.exe" -atboottime
O4 - HKLM\..\Run: [a-squared] "D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL; Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 2:03:05 PM 1/25/2007

+ Scan result:



C:\System Volume Information\_restore{F5E3F6EC-BDA5-4E88-B9D0-EC132142AFCF}\RP775\A0070727.dll -> Adware.Aws : Cleaned.
D:\Stuff\Programs\burner\Alcohol 120\ALCOHOL 120% v1.4.7.1005 CRACKED(5).zip/cr-al147.exe -> Logger.Banker.zn : Cleaned.
D:\Stuff\Programs\burner\Alcohol 120\ALCOHOL 120% v1.4.7.1005 CRACKED(5)\cr-al147.exe -> Logger.Banker.zn : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Adocean : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@adorigin[1].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][5].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][7].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Euniverseads : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Euniverseads : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Euniverseads : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@ivwbox[2].txt -> TrackingCookie.Ivwbox : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@starware[3].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][3].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@tfag[2].txt -> TrackingCookie.Tfag : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@login.tracking101[3].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@webstat[4].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yadro[3].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yadro[4].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yadro[5].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][4].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Ja\Cookies\[removed][5].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Ja\Cookies\ja@yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end
Magicjared :D

Welcome to the forum, you are using a very outdated version of HJT and it's not showing us the whole picture, lets do this.

Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Go to where you currently have HJT installed and delete the whole folder.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use the [external image: Posted Image] Button and not the New Topic Button
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
thanks, here's the new log:
Logfile of HijackThis v1.99.1
Scan saved at 6:58:22 PM, on 1/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe
D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.screenname.aol.com/_cqr/login/lo…f&authLev=2
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "D:\Stuff\Programs\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "D:\Stuff\Programs\qttask.exe" -atboottime
O4 - HKLM\..\Run: [a-squared] "D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Good Morning, :D

Viewpoint is a program that is not malicious in its self but installs without your knowledge or consent and does use some system resources and is not needed…So go to your Add-Remove Programs in the Control Panel and uninstall anything associated with Viewpoint

All AVG found where cookies so nothing there to worry about. :thumbup:


Download the Stand Alone Version of CWShredder to your desktop.
  • Open CWShredder
  • Check for Updates
  • Close out the program. <– Dont run it yet



    Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank

    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe





    Boot into Safemode
    • Go to Start> Shut off your Computer> Restart
    • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
      this will bring up a menu.
    • Use the Up and Down Arrow Keys to scroll up to Safemode
    • Then press the Enter Key on your Keyboard
    Tutorial if you need it How to boot into Safemode



    Open CWShredder
  • Double-click on CWShredder.exe.
  • Click Fix and click OK at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click Next and then Exit .



Reboot normally and run this system cleaner.


If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



FYI, 256mb of ram in not a whole log for Windows XP, you should have at least 512 to have your system run more efficiently. You can go here and plug in the make and model of your system and they have a tool that will scan your system and let you know what you can upgrade to .

Crucial


Let me see a new HJT lot and let me know if any of this helped
Great thanks for helping me out. I'm not sure yet just how much it helped but it definatly cleared up a lot of unecessary stuff. I didnt have anything come up with the cwshredder, but the cclean cleared up around 250mb and 420 something issues.

I currently have the maximum amount of ram that my computer will hold. Although I would like more, I typically don't use that much memory with my regular computer usage.

New log:
Logfile of HijackThis v1.99.1
Scan saved at 3:24:26 PM, on 1/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe
D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.screenname.aol.com/_cqr/login/lo…f&authLev=2
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "D:\Stuff\Programs\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "D:\Stuff\Programs\qttask.exe" -atboottime
O4 - HKLM\..\Run: [a-squared] "D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
Magicjared :D

Your HJT log looks fine :thumbup: but lets do a few more things.

  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment (JRE) 5.0 Update 11 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future




Lets run a free online virus checker from Panda, if the scan comes up clean than I can direct you to some windows support sites that may be better equipped to help you.

Run Panda's ActiveScan from here and perform a full system scan.

1. Once you are on the Panda site click the "Scan your PC" button
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
Since you are on a slow connection it will take about 15 minuites for the scanner to load.
10. Click on "Local Disks" to start the scan
11. Once scan is done, click "see report" then "save report"
Save the log someplace.
12. reboot
13. Post Panda scan results in your next reply

Let me see the Panda report please
hmm…Still not all clear: Incident Status Location Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Ja\Cookies\ja@atwola[1].txt Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Ja\Cookies\[removed][1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Ja\Cookies\[removed][2].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Ja\Cookies\ja@target[2].txt Potentially unwanted tool:Application/KillApp.B Not disinfected C:\EasyDivX\softs\ck.exe Adware:Adware/Gator Not disinfected D:\Stuff\Programs\codecs\Gordian.Knot.Codec.Pack.1.7.Setup.exe[DivXPro511Adware.exe][Gain_Trickler.exe]
Yep, there could be some problems that are not showing up on your log.

Open Hijackthis
  • Go to Misc Tools> Open Uninstall Manager.
  • Click on Save List.
  • The list will open in Notepad.
  • Copy and Paste the List into this thread
Here it is: AC3Filter (remove only) Ad-Aware SE Personal Adobe Acrobat 4.0 Adobe Bridge 1.0 Adobe Common File Installer Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Shockwave Player Adobe Stock Photos 1.0 ADS Tech Camera View Alcohol 120% All To MP3 Converter 1.55 AOL Instant Messenger a-squared Anti-Malware 2.1 a-squared Free 2.1 AVG Anti-Spyware 7.5 BitComet 0.57 burnatonce Canon Camera WIA Driver 6.3 CCleaner (remove only) CD/DVD-ROM Generator 1.20 Direct Show Ogg Vorbis Filter (remove only) DivX DustBuster 2.6.2 DVD Decrypter (Remove Only) DVD Region Killer DVD Shrink 3.2 DVDInfoPro EasyDivX v0.820 Lite EZF-AdvanceIII Uninstall ffdshow (remove only) FLV Player 1.3.3 HHD Software Hex Editor Hijackthis 1.99.1 HijackThis 1.99.1 Huffyuv AVI lossless video codec (Remove Only) IsoBuster 1.6 J2SE Development Kit 5.0 Update 11 J2SE Runtime Environment 5.0 Update 11 LiveAdvisor (Symantec Corporation) LiveUpdate Macromedia Flash Player 8 Magic ISO Maker v4.7 (build 0132) MGI PhotoSuite 4 (Remove Only) Microsoft Office Excel Viewer 2003 Microsoft Office XP Professional with FrontPage Nero Media Player Nero OEM NeroVision Express 2 Nikon Message Center Norton AntiVirus 2000 Panda ActiveScan PictureProject PictureProject In Touch Downloader 1.0 PowerDVD QuickTime QuickTime Alternative 1.33 QuickTime for Windows (32-bit) RealPlayer Basic Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB929969) SouthPark Mario Bros 2 - Last Edition Spybot - Search & Destroy 1.3 Subtitle Workshop 2.51 TMPGEnc DVD Author 1.5 TMPGEnc Plus 2.5 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Version 0.65 VobSub v2.23 (Remove Only) Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 WinRAR archiver WinZip XviD MPEG-4 Video Codec
Two things I would do , first is to remove the BitComet program via the Add-Remove Programs in the Control Panel. But this is your call, most file sharing programs are bad news.


You have a lot of video codecs installed, the ones you have seem legit but you have to be extremely careful as there are bad infections going around posing as legit codecs that you need to install. Sometimes codecs come with spyware and worse.

This is spyware that came with this codec.
D:\Stuff\Programs\codecs\Gordian.Knot.Codec.Pack.1.7.Setup.exe[DivXPro511Adware.exe][Gain_Trickler.exe]

Go to this site and download the tool to remove Claria that is related to Gain_Trickler.
http://www.spywareremove.com/removeClaria.html


Post a new HJT log when your done and let me know if this helped at all.
That removal program says it is only a scan, it says to remove the files I need to purchase the full version. It did come up with 49 issues though. There are four spyware cookies: ad.yieldmanager.com adbureau addynamix atwola 6 instances of anti leech plugins and 38 issues named "wildtangent" which do not have a definition and 1 issue named "addynamix" that also doesnt have a definition They do give instructions on how to manually remove "parasite programs", should I do this?
This is a free program that is yours to keep and it will remove it also.


You can use the links in my signature to download and install Spybot Search and Destroy 1.4

If you have the older version 1.3, remove it via the Add-Remove Programs in the Control Panel.

  • During Installation, just follow all the defaults.
  • Go to Mode and click on Advanced Mode
  • Then to Updates Search for Updates
  • If you get a Bad Checksum Error, just choose a different download location.
  • Then to Settings/ File Sets and take the checkmark out of Usage Tracks
  • Then to Tools/ Hosts Files click on Add Spybot S&D Hosts Files.
  • Then to Tools/ IE Tweeks and put a checkmark in Lock the Hosts Files
  • Then to Immunize. Up at the top by the GREEN SIGN, click on Immunize.
  • Then to Search and Destroy/ Check for Problems
  • Let it scan your system
  • Then to Fix Problems and fix all it finds.
  • Reboot your computer.

Then remove this
D:\Stuff\Programs\codecs\Gordian.Knot.Codec.Pack.1.7.Setup.exe
alright, I ran spy bot and it cleared up some issues and then deleted that codec. Here is a new log:

Logfile of HijackThis v1.99.1
Scan saved at 8:59:26 PM, on 2/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe
D:\Stuff\Programs\a-squared Anti-Malware\a2scan.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.screenname.aol.com/_cqr/login/lo…f&authLev=2
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "D:\Stuff\Programs\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "D:\Stuff\Programs\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [a-squared] "D:\Stuff\Programs\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
Good Morning :D

Your log looks fine :thumbup:


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI