This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HIjack This Report

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Somehow I cannot start cryptographic services, which is preventing my updates from installing and other probs. Integrity of update.fle cannot be verified; downloads give message stating that Windows has found aproblem with this file.
When I try to start it, I get error 1083: the program used to implement the services does not implement it.
Microsoft suggested Hijank This.
Here is the report.
Please help!


Index % of PCs with item Code Data
1 0.0% O10 c:\windows\system32\nwprovau.dll
2 0.0% O16 {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
3 0.0% O16 {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
4 0.0% O16 {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
5 0.0% O16 {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1230480551933
6 0.0% O18 bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
7 0.0% O2 &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
8 0.0% O2 JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
9 0.0% O2 Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
10 0.0% O2 Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
11 0.0% O2 SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
12 0.0% O23 Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
13 0.0% O23 InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
14 0.0% O23 LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
15 0.0% O23 Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
16 0.0% O23 HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
17 0.0% O23 HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
18 0.0% O23 Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe (file missing)
19 0.0% O23 Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
20 0.0% O3 (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
21 0.0% O3 Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
22 0.0% O4 [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
23 0.0% O4 [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
24 0.0% O4 [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
25 0.0% O4 [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User '?')
26 0.0% O4 [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User '?')
27 0.0% O9 Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
28 0.0% O9 Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
29 0.0% O9 Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
30 0.0% O9 (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
31 0.0% O9 (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
32 0.0% O9 @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
33 0.0% P01 C:\WINDOWS\Explorer.EXE
34 0.0% P01 C:\WINDOWS\system32\svchost.exe
35 0.0% P01 C:\WINDOWS\system32\lsass.exe
36 0.0% P01 C:\WINDOWS\system32\winlogon.exe
37 0.0% P01 C:\WINDOWS\system32\services.exe
38 0.0% P01 C:\WINDOWS\System32\smss.exe
39 0.0% P01 C:\WINDOWS\system32\spoolsv.exe
40 0.0% P01 C:\WINDOWS\system32\ctfmon.exe
41 0.0% P01 C:\Program Files\Internet Explorer\iexplore.exe
42 0.0% P01 C:\WINDOWS\system32\wuauclt.exe
43 0.0% P01 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
44 0.0% P01 C:\WINDOWS\System32\dllhost.exe
45 0.0% P01 C:\WINDOWS\System32\HPZipm12.exe
46 0.0% P01 C:\WINDOWS\system32\cisvc.exe
47 0.0% P01 C:\WINDOWS\system32\LEXBCES.EXE
48 0.0% P01 C:\WINDOWS\system32\lexpps.exe
49 0.0% P01 C:\WINDOWS\system32\cidaemon.exe
50 0.0% P01 C:\WINDOWS\System32\tcpsvcs.exe
51 0.0% P01 C:\WINDOWS\system32\mqsvc.exe
52 0.0% P01 C:\WINDOWS\system32\mqtgsvc.exe
53 0.0% P01 C:\WINDOWS\system32\mmc.exe
54 0.0% P01 C:\WINDOWS\System32\dmadmin.exe
55 0.0% P01 C:\WINDOWS\System32\locator.exe
56 0.0% P01 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
57 0.0% P01 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPBOID.EXE
58 0.0% P01 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
59 0.0% P01 C:\Program Files\Java\jre6\bin\jqs.exe
60 0.0% R0 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
61 0.0% R0 HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
62 0.0% R0 HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
63 0.0% R0 HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
64 0.0% R0 HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
65 0.0% R0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f654.mail.yahoo.com/ym/login?.rand=3f6agdap24s0r
66 0.0% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
67 0.0% R1 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
68 0.0% R1 HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
69 0.0% R1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
70 0.0% R1 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
71 0.0% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
72 0.0% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
73 0.0% R1 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
74 0.0% R1 HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
75 0.0% R3 Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
Explanation of the codes
R - Registry, StartPage/SearchPage changes
• R0 - Changed registry value
• R1 - Created registry value
• R2 - Created registry key
• R3 - Created extra registry value where only one should be
F - IniFiles, autoloading entries
• F0 - Changed inifile value
• F1 - Created inifile value
• F2 - Changed inifile value, mapped to Registry
• F3 - Created inifile value, mapped to Registry
N - Netscape/Mozilla StartPage/SearchPage changes
• N1 - Change in prefs.js of Netscape 4.x
• N2 - Change in prefs.js of Netscape 6
• N3 - Change in prefs.js of Netscape 7
• N4 - Change in prefs.js of Mozilla
O - Other, several sections which represent:
• O1 - Hijack of auto.search.msn.com with Hosts file
• O2 - Enumeration of existing MSIE BHO's
• O3 - Enumeration of existing MSIE toolbars
• O4 - Enumeration of suspicious autoloading Registry entries
• O5 - Blocking of loading Internet Options in Control Panel
• O6 - Disabling of 'Internet Options' Main tab with Policies
• O7 - Disabling of Regedit with Policies
• O8 - Extra MSIE context menu items
• O9 - Extra 'Tools' menuitems and buttons
• O10 - Breaking of Internet access by New.Net or WebHancer
• O11 - Extra options in MSIE 'Advanced' settings tab
• O12 - MSIE plugins for file extensions or MIME types
• O13 - Hijack of default URL prefixes
• O14 - Changing of IERESET.INF
• O15 - Trusted Zone Autoadd
• O16 - Download Program Files item
• O17 - Domain hijack
• O18 - Enumeration of existing protocols and filters
• O19 - User stylesheet hijack
• O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys
• O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key
• O22 - SharedTaskScheduler autorun Registry key
• O23 - Enumeration of NT Services
• O24 - Enumeration of ActiveX Desktop Components
Privacy Policy | About Trend Micro | Contact Us
Copyright © 2007 Trend Micro, Inc.
Hi, and Welcome to WhatTheTech :)

Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI