This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hjt Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My husband's computer is driving me to drink! Please help.

He has a Microsoft keyboard that has programmable buttons, and the buttons aren't working right. Within the Microsoft setup program everything is still set up right, but the buttons don't function as they are programmed to. He has tried uninstalling and reinstalling the keyboard with no improvement. As an example while I was running some preliminary tests before running HJT I pressed the calculator key, which is supposed to open up the Windows calculator, and instead it closed the active Firefox window. He's even had times when non-programmable keys do the wrong thing, like the capslock key closing Firefox. I have the same keyboard at work and it hasn't given me one problem.

Lately he's been having trouble with programs trying to dial the modem, which isn't hooked up to anything. He's been having all kinds of connection and networking issues, only on his computer, everything is working fine on mine, so I assume there's nothing wrong with our router. When I go to My Network Places on my computer I can see his computer but I can't access it. However, I was able to map a network drive to the shared folder on his computer. He can access the shared folders on my computer from his. He had trouble last night with Winamp not connecting to the internet, and when it couldn't get a connection it tried dialing the modem. Today it's working fine. We have a cable modem run through the router, and I'm not having any trouble with it from my computer. Our Tivo isn't having any trouble with it either. So I figure it's got to be his computer, not the router or cable modem.

There are two windows updates that won't run on his computer, Security Update for Microsoft.NET Framework, Version 2.0 (KB928365) and Version 1.1 Service Pack 1 (KB928366). The other night I ran Housecall and it noticed he was missing a couple of updates (I haven't been keeping track, not sure if it's the same ones) and there was a link to Microsoft's website, where I was supposed to download and install like 3 different files. None of them would install, they all basically said that they were updates to a program I didn't have, so they couldn't install.

He's also having trouble with the screen blinking every once in a while, and that's obviously a problem with the graphics hardware. It's the same blink you would get when you hit apply after changing screen settings. It does it a lot less when he's not running a video game. He used to play Bejeweled a lot, the version that runs on the computer not online, and it happened a lot more when he was playing, so he stopped. But the problem hasn't gone away completely.

Help!!! Here's the HJT log that he got yesterday morning:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:06:08 AM, on 8/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Norton CleanSweep\QDCSFS.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Wallpaper Master\Wallpaper.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\Program Files\TiVo\Desktop\TiVoServer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Citrix\ICA Client\Wfcrun32.exe
C:\PROGRA~1\Citrix\ICACLI~1\WFICA32.EXE
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\Citrix\ICACLI~1\WFICA32.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f556.mail.yahoo.com/dc/launch?ac…mp;YY=587475367
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = What are you looking at?
O1 - Hosts: 203.121.71.128www.celebutopia.net
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {BD1B1D80-D55A-483B-B54F-4F6EF9524E4C} - C:\WINDOWS\system32\wmvemoe2.dll (file missing)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton CleanSweep\QDCSFS.exe /startup /scheduler
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WallpaperChanger] C:\Program Files\Wallpaper Master\Wallpaper.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry /auto:TivoServer
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: AutorunsDisabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Mitch\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O15 - Trusted Zone: *.west.com
O15 - Trusted Zone: *.workathomeagent.com
O15 - Trusted Zone: *.workathomeagent.net
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1149444922706
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149447987062
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D8EE8DC0-F193-11D0-B1E5-08005A885319} (MicroX Persistent Mainframe Display Control) - http://www.workathomeagent.net/walldata/cu…hostexpress.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-832605661009} (Live Collaboration) - http://livenj02.custhelp.com/7530-b327h/rnl/java/RntX.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe

–
End of file - 8704 bytes
Judi, :D

Welcome to the forum, you do have some issues going on but none that I can see are malware.

Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: (no name) - {BD1B1D80-D55A-483B-B54F-4F6EF9524E4C} - C:\WINDOWS\system32\wmvemoe2.dll (file missing)

O4 - Global Startup: AutorunsDisabled


If you want these in your trusted zone than keep them
O15 - Trusted Zone: *.west.com
O15 - Trusted Zone: *.workathomeagent.com
O15 - Trusted Zone: *.workathomeagent.net


Is this your ISP???

203.121.64.0 - 203.121.127.255
TIME Telecommunications Sdn Bhd
Kuala Lumpur

Azmy Mohamad Yusof
[removed]
[removed]
TIMEdotNet Bhd
Level 3, Lot 14 Jalan U1/26 Glenmarie HICOM Industrial Park 40000
Shah Alam Selangor Malaysia
[abuse] [removed]
+6-03-50326131
+6-03-50326204



This could be related to your problems, read it and decide if you want to remove it, you may want to give them a call and ask for help.
http://www.skymovies.com/skybybroadband/articles/article04


Please download CCleaner
Save it to the Desktop:
  • Run the CCleaner installer.
  • During installation process, uncheck: Add CCleaner Yahoo! Toolbar and use CCleaner from within IE
  • Once installed, run CCleaner and click the Windows tab
  • Scroll to the Advanced section:

  • Check only: Old Prefetch data

  • In the left pane, click Options
  • Select Cookies

  • Move the ones you want to keep to the Cookies to keep section (on the right), by highlighting and using the middle arrows. (Otherwise your login password to certain sites is lost.)

  • Select the Advanced button

  • Uncheck: Only delete files in Windows Temp folders older than 48 hours

  • Next, click the Cleaner button in the left pane
  • Click the Run Cleaner button (bottom right)
  • Click OK at the prompt.
  • When done, exit CCleaner.
Caution: Please do not use the Issues button in the left pane. This is a built-in Registry cleaner and may cause irreparable damage to the system if used incorrectly.Aaflac

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!


If any of the above does not help than I suggest you post in a windows forum as this forum is for the removal of malware only.

Windows Tech Support ForumsIt's Not Always MalwareSpeedup WindowsWindows TipsKen :D
Ken, I want to apologize. I tried to contact a moderator yesterday to get my thread deleted. I already got spanked over at bleepingcomputer.com for posting at two different forums. I'm terribly sorry to have taken your time but I'm being helped at bleepingcomputer. Could you please delete this thread? I really am very sorry, I didn't realize it was so frowned upon to post at more than one forum.
[removed] is not our ISP….celebutopia is a website my husband visits…..is this a problem, did celebutopia install something bad on our computer? Please let me know, because he has had major problems with that website, and if it's the root of his computer problems, or related in any way, I want to know. And where would this Kontiki come from? Could it be from a Torrent service, because I know he has at least one of those, and I also know he was having problems getting UTorrent to work….something about when he would forward the port the internet would stop working. Could this Kontiki have anything to do with it?
Hi Judi,

Yes, all these forums are staffed by volunteers and with the amount of infected computers most times we are spread a little thin. If you are being helped at our sister site Bleeping Computer than I will close this one. Let me know please.

Kontiki <– Its not malicious but seems to be installed with Sky Broadband and from what I have been reading it can cause some problems. Thats why I think you should contact SKY and tell them you want to remove it. Its really not needed.

You can reset your hosts files and this will take care of that entry

Download HostsXpert v4
  • Unzip HostXpert to your desktop
  • Open up the HostXpert program.
  • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
  • Click Create Back Up
  • Then click on Restore Microsoft's Host Files
  • Close the HostXpert program

I will leave this thread open for you, but we need to close this one or the one at BC

Ken :D
Poster being helped at Bleeping Computer so this thread is being closed.

How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI