This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojans - HJT log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

GF's comp got plagued with trojans. Probably from downloading too much porn… Anyway, her comp was a nightmare. Had nearly a dozen anti-virus/spyware programs all running. God only knows what was going on. The malware got in the system restore, so I disabled that. I removed all the questionable programs through the add/remove programs in the control panel. I disabled/deleted every instance of all the different anti-virus/spyware/adware programs so that I can install the professional software we use at my office. So as of now, there is zero protection. Anyway, here's the HJT log. I notice right off that winself is known malware…


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:49:20 PM, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:..WINDOWS..System32..smss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..spoolsv.exe
C:..WINDOWS..winself.exe
C:..WINDOWS..system32..nvsvc32.exe
C:..Program Files..Common Files..New Boundary..PrismXL..PRISMXL.SYS
C:..WINDOWS..System32..snmp.exe
C:..Program Files..Common Files..Symantec Shared..CCPD-LC..symlcsvc.exe
C:..Program Files..Webroot..Spy Sweeper..SpySweeper.exe
C:..WINDOWS..system32..vbpdtvdp.exe
C:..WINDOWS..Explorer.EXE
C:..Program Files..Compact Wireless-G USB Adapter Wireless Network Monitor..WLService.exe
C:..Program Files..Compact Wireless-G USB Adapter Wireless Network Monitor..WUSB54GC.exe
C:..Program Files..Digital Media Reader..shwiconem.exe
C:..WINDOWS..zHotkey.exe
C:..Program Files..Common Files..Real..Update_OB..realsched.exe
C:..WINDOWS..system32..PRISMSVR.EXE
C:..Program Files..Yahoo!..Search Protection..SearchProtection.exe
C:..WINDOWS..RTHDCPL.EXE
C:..Program Files..CyberLink..PowerDVD..PDVDServ.exe
C:..Program Files..QuickTime..qttask.exe
C:..WINDOWS..system32..RUNDLL32.EXE
C:..WINDOWS..system32..accwizz.exe
C:..Program Files..Messenger..msmsgs.exe
C:..WINDOWS..system32..ctfmon.exe
C:..Program Files..2Wire 802.11g Wireless..PRISMCFG.EXE
C:..PROGRA~1..Webshots..webshots.scr
C:..WINDOWS..system32..wuauclt.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe

R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Search Bar = http://us. rd. yahoo. com/customize/ycomp/defaults/sb. r{}*http://www. yahoo. com
R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = C:..WINDOWS..system32..spywarewarning.mht
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = http://go. microsoft. com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Page = http://go. microsoft. com/fwlink/?LinkId=54896
R0 - HKLM..Software..Microsoft..Internet Explorer..Main,Start Page = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKCU..Software..Microsoft..Internet Explorer..SearchURL,(Default) = http://us. rd. yahoo. com/customize/ycomp/defaults/su. r{}


EDIT: sorry about all the explorer stuff at the bottom. I had a bunch of windows open…
[external image: Posted Image]

Sorry about the delay in responding :(

If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI