Newbie HJT log (Resolved)
-
Newbie HJT log (Resolved)
Ran spybot and adaware. Here is the log:
Thanks,
Logfile of HijackThis v1.98.0
Scan saved at 11:16:56 AM, on 7/31/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Symantec AntiVirus\DefWatch.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Symantec AntiVirus\Rtvscan.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\SYMANT~1\VPTray.exe
D:\Program Files\QuickTime\qttask.exe
D:\WINDOWS\wovax.exe
D:\WINDOWS\System32\ikthnhcv.exe
D:\WINDOWS\goidr.exe
D:\Program Files\WindUpdates\WinUpdt.exe
D:\Program Files\WindowsSA\omniscient.exe
D:\Program Files\WindUpdates\WinKA.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\AIM\aim.exe
D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
D:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
D:\WINDOWS\System32\wuauclt.exe
D:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
D:\Documents and Settings\Fetterolf\Desktop\Hjt\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} -
(no file)
R3 - URLSearchHook: URLSearch Class -
{965A592F-8EFA-4250-8630-7960230792F1} - D:\WINDOWS\System32\cdsm32.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497 - (no
file)
F2 - REG:system.ini: UserInit=D:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SDWin32 Class - {8BB28480-728F-48C7-8E9B-AA644F7DD60C} -
D:\WINDOWS\System32\zmwks.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [wovax] D:\WINDOWS\wovax.exe
O4 - HKLM\..\Run: [kvhgkgw] D:\WINDOWS\System32\ikthnhcv.exe
O4 - HKLM\..\Run: [goidr] D:\WINDOWS\goidr.exe
O4 - HKLM\..\Run: [aqadcup] D:\WINDOWS\aqadcup.exe
O4 - HKLM\..\Run: [zmwksc] D:\WINDOWS\System32\zmwksc.exe
O4 - HKLM\..\Run: [WindUpdates] D:\Program Files\WindUpdates\WinUpdt.exe
O4 - HKLM\..\Run: [Windows SA] D:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [qvolkt] D:\WINDOWS\qvolkt.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PopUpStopperFreeEdition]
D:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O4 - Startup: Camio Viewer.lnk = D:\Program Files\Sierra Imaging\Image
Expert\IXApplet.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft
Office\Office\OSA9.EXE
O8 - Extra context menu item: &Define - D:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - D:\Program
Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Web Rebates - file://D:\Program
Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: Encarta Encyclopedia -
{2FDEF853-0759-11D4-A92E-006097DBED37} - D:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia -
{2FDEF853-0759-11D4-A92E-006097DBED37} - D:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} -
D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define -
{5DA9DE80-097A-11D4-A92E-006097DBED37} - D:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program
Files\AIM\aim.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_fi...87ac90b54afcc1
8827f4e0c2e1af8d6b2139a6d78fa1ba96d9d848d38af6822d 00ec9f99362db9dd3db34d4b55
fa34a893c9a5b532161d5cd35:316ec1697e4766858480d3e8 0deecaa8
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite...ITDetector.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{7E54329E-6961-4ACA-BE22-92D91E5EE8C1}:
NameServer = 66.212.32.1 66.212.32.2
-
Forget to mention that I am getting a lot of popups and computer freezes. Some stuff keeps coming back when I run adaware. Is there anything I should remove in the above log?
Thanks
-
Hello,
Please close all browser windows, restart hijack this and put a checkmark next to the following entries:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} -
(no file)
R3 - URLSearchHook: URLSearch Class -
{965A592F-8EFA-4250-8630-7960230792F1} - D:\WINDOWS\System32\cdsm32.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497 - (no
file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: SDWin32 Class - {8BB28480-728F-48C7-8E9B-AA644F7DD60C} -
D:\WINDOWS\System32\zmwks.dll
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [wovax] D:\WINDOWS\wovax.exe
O4 - HKLM\..\Run: [kvhgkgw] D:\WINDOWS\System32\ikthnhcv.exe
O4 - HKLM\..\Run: [goidr] D:\WINDOWS\goidr.exe
O4 - HKLM\..\Run: [aqadcup] D:\WINDOWS\aqadcup.exe
O4 - HKLM\..\Run: [zmwksc] D:\WINDOWS\System32\zmwksc.exe
O4 - HKLM\..\Run: [WindUpdates] D:\Program Files\WindUpdates\WinUpdt.exe
O4 - HKLM\..\Run: [Windows SA] D:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [qvolkt] D:\WINDOWS\qvolkt.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft
Office\Office\OSA9.EXE
O8 - Extra context menu item: Web Rebates - file://D:\Program
Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_f...687ac90b54afcc1
8827f4e0c2e1af8d6b2139a6d78fa1ba96d9d848d38af6822d 00ec9f99362db9dd3db34d4b55
fa34a893c9a5b532161d5cd35:316ec1697e4766858480d3e8 0deecaa8
Click Fix Checked
Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.
Go to C:\ and delete the following:
installer
Then go to C:\Program Files and delete the following:
WindUpdates
WindowsSA
Then go to C:\Windows and delete the following:
wovax.exe
goidr.exe
aqadcup.exe
Then go to C:\Windows\System32 and delete the following:
ikthnhcv.exe
zmwksc.exe
Reboot and post a fresh log
-
OK, did as you instructed. Here is the new HJT log. Anything else to remove?
Thanks:
Logfile of HijackThis v1.98.0
Scan saved at 3:31:36 PM, on 8/3/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Symantec AntiVirus\DefWatch.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Symantec AntiVirus\Rtvscan.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\SYMANT~1\VPTray.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\SpywareBlaster\spywareblaster.exe
D:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
D:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
D:\WINDOWS\System32\wuauclt.exe
D:\Program Files\Microsoft Office\Office\WINWORD.EXE
D:\WINDOWS\msagent\AgentSvr.exe
D:\Program Files\AIM\aim.exe
D:\Documents and Settings\Fetterolf\Desktop\Hjt\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - D:\Program Files\Panicware\Pop-Up Stopper Basic\CCHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Pa&nicware Pop-Up Stopper Basic - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - D:\Program Files\Panicware\Pop-Up Stopper Basic\popuppro.dll
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Camio Viewer.lnk = D:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: SpywareBlaster (2).lnk = D:\Program Files\SpywareBlaster\spywareblaster.exe
O8 - Extra context menu item: &Define - D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - D:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E54329E-6961-4ACA-BE22-92D91E5EE8C1}: NameServer = 66.212.32.1 66.212.32.2
-
That looking good. Hows it running?
I see you have added SpywareBlaster to startup. This isn't necessary. SpywareBlaster does not need to be constantly running. It makes some tweaks to the registry and various settings and then thats it. It doesn't run in the backgroun or need to run at startup so you can put a checkmark next to this entry:
O4 - Global Startup: SpywareBlaster (2).lnk = D:\Program Files\SpywareBlaster\spywareblaster.exe
and click Fix Checked.
You might want to have a read of this information about preventing it returning. Remember you only need one antivirus program and one firewall 
Preventing it returning
After your problem has been resolved on the forum, it is an absoulute MUST to do the following steps to prevent the problem returning. Click on the link to get access to the software or webpage that I'm referring to.
1. Visit Windows Update
Pay a visit to Windows Update and scan for and download ALL Critical Updates and Service Packs. New updates are usually released monthly so check back to Windows Update every month.
2. Download Antivirus Software-
If you haven't already got Antivirus software, you should download and install AVG Antivirus. It is freeware and is updated nearly every 2 days (sometimes more frequently if there are a lot of new viruses) and in my opinion, is better than some Antivirus software such as Norton. Antivirus software will prevent viruses infecting your system and it is important that you update it every two days or every week at the most.
3. Download a Firewall-
If you haven't already got a firewall, it is Very important that you download one. Firewalls will prevent unauthorised access to your computer and stop data leaking out of your computer. You may think that it won't happen to you, but Hackers don't care who you are, what you do, where you live or what you had for tea last Sunday on your holiday in the Lake District, they want your data. Firewalls will keep these sneaks out and one of the best is Sygate Personal Firewall, which happens to be freeware.
4. Spyware Scanners-
It is important that as well as having real time spyware protection, you have a spyware scanning application. If you have not already been told to download one earlier in this thread, it is a good idea to download Spybot Search And Destroy and Ad-aware. They are both spyware scanners and will search for a remove spyware. It is recommended that you have both, because one will pick up entries that the other misses. It is even a good idea to download these if you have other programs such as ASE, Spysweeper, Pest Patrol, etc, because one spyware scanner will not pick up everything. Please remember to update your spyware scanners weekly/fortnightly.
5. Prevent Spyware slipping through Internet Explorer-
Quite a lot of spyware slips through Internet Explorer if your settings are not tight enough. Spyware Blaster will help you prevent spyware slipping through and installing tracking cookies. Simply run it via Start> Programs> Spyware Blaster and click Enable All Protection and it will protect you. It doesn't even have to be open! Remember to update weekly/fortnightly.
6. Constant Spyware Protection-
It is important to have constant spyware protection. Spyware Guard works like an antivirus program but detects Spyware instead. It will constantly protect your system. Check for updates monthly.
All Of these steps are very important and it is HIGHLY recommended that you download all of the programs mentioned for your own safety. Remember to Update everything (including Windows using Windows Update)! It is also a good idea to perform weekly/fortnightly scans with Spybot S&D, Ad-aware and your antivirus software.
And last of all, please remember, that common sense is your greatest tool. Without it, spyware and other related Malware would rule!
-
It seems to be running good. I didn't know that about spywareblaster. I thought it had to load and then you can close it out. I will fix it and visit the links you posted and post a new log in a couple of days.
Thanks
I am not too familiar with these boards, are there any points to reward or anything?
Thanks again, will talk to you soon
-
I'll mark this thread as resolved then. When you come back for a checkup, just put Hijack This Log Checkup as the subject and me or someone else will take a quick look and hopefully give a clean bill of health 
You can rate the threads in this forum or rate an individual user. To rate a thread, go to the thread in question and at the top click Rate Thread on the Toolbar.
You can also give reputation points to users by clicking the
on the Right hand side above their name. Then you can add a comment and why you approve of their post.