Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

HJT log file

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

HJT log file

Unread postby Wiccan Witch » January 5th, 2009, 2:00 pm

ok i really need some help with this. my computer won't let me access certain sites like google and myspace. it just keeps coming up with a microsoft security page that i guess is fake because they have absolutely rubbish grammer ("your computer 'have' been attacked") i ran a scan with hijackthis and this is the log file it came up with. thankyou if you can help

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:37:07, on 05/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Documents and Settings\Val.COMPAQ\Local Settings\Temporary Internet Files\Content.IE5\GBDL7C4O\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: http://www.yahoo.com
O1 - Hosts: http://www.google.com
O1 - Hosts: http://www.google.co.uk
O1 - Hosts: http://www.myspace.com
O1 - Hosts: http://www.youtube.com
O1 - Hosts: http://www.facebook.com
O1 - Hosts: http://www.antispy.com
O1 - Hosts: http://www.yahoo.com
O1 - Hosts: http://www.yahoo.co.uk
O1 - Hosts: http://www.msn.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.gg.com
O1 - Hosts: http://www.ghfhj.com
O1 - Hosts: http://www.cvnbcvnb.com
O1 - Hosts: http://www.1.com
O1 - Hosts: http://www.3.com
O1 - Hosts: http://www.asdf4asdfd.com
O1 - Hosts: http://www.asdfawsdfd.com
O1 - Hosts: http://www.asdfatsdfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.asdfadsdfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.asdfafsdfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.asdfagsdfd.com
O1 - Hosts: http://www.asdfasgdfd.com
O1 - Hosts: http://www.asdfasdhfd.com
O1 - Hosts: http://www.asdfasdfjd.com
O1 - Hosts: http://www.asdfasdfkd.com
O1 - Hosts: http://www.asdfasdfld.com
O1 - Hosts: http://www.asdfasdf,d.com
O1 - Hosts: http://www.asxdfasdfd.com
O1 - Hosts: http://www.asdzfasdfd.com
O1 - Hosts: http://www.asdcfasdfd.com
O1 - Hosts: http://www.asdfvasdfd.com
O1 - Hosts: http://www.asdfabsdfd.com
O1 - Hosts: http://www.asdfasndfd.com
O1 - Hosts: http://www.asdfasdmfd.com
O1 - Hosts: http://www.asdfasdfd.com
O1 - Hosts: http://www.11asdfasdfd.com
O1 - Hosts: http://www.as222dfasdfd.com
O1 - Hosts: http://www.asdfa33sdfd.com
O1 - Hosts: http://www.asdfasd44fd.com
O1 - Hosts: http://www.asdfasdfd5.com
O1 - Hosts: http://www.as66dfasdfd.com
O1 - Hosts: http://www.asdf77asdfd.com
O1 - Hosts: http://www.asdf8asdfd.com
O1 - Hosts: http://www.asdf9asdfd.com
O1 - Hosts: http://www.asdf0asdfd.com
O1 - Hosts: http://www.asdf-asdfd.com
O1 - Hosts: http://www.aqqsdfasdfd.com
O1 - Hosts: http://www.aswwdfasdfd.com
O1 - Hosts: http://www.asdhhfasdfdyy.com
O1 - Hosts: http://www.live.com
O1 - Hosts: http://www.asdwwwfasdfd.com
O1 - Hosts: http://www.asdfeasdfd.com
O1 - Hosts: http://www.asdfrrasdfd.com
O1 - Hosts: http://www.asdfttasdfd.com
O1 - Hosts: http://www.asdfyyasdfd.com
O1 - Hosts: http://www.asdfuuuasdfd.com
O1 - Hosts: http://www.asdfaiisdfd.com
O1 - Hosts: http://www.asdfaoosdfd.com
O1 - Hosts: http://www.asdfappsdfd.com
O1 - Hosts: http://www.asdfasssdfd.com
O1 - Hosts: http://www.aswwdfasdfd.com
O1 - Hosts: http://www.asdeefasdfd.com
O1 - Hosts: http://www.asdfffasdfd.com
O1 - Hosts: http://www.asdfavvvsdfd.com
O1 - Hosts: http://www.asnnndfasdfd.com
O1 - Hosts: http://www.asdmmmfasdfd.com
O1 - Hosts: http://www.asdfaffsdfd.com
O1 - Hosts: http://www.asdhhfasdfd.com
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: KODAK Software Updater.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredi ... xdm088KFGB
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_12\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocach ... 0.15-3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/tes ... eGames.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - http://a.download.toontown.com/sv1.0.28.9/ttinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://webgames.d.tmsrv.com/c=3ac503b49 ... der_v6.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

End of file - 11771 bytes
Wiccan Witch
Active Member
Posts: 1
Joined: January 5th, 2009, 1:47 pm
Register to Remove

Re: HJT log file

Unread postby silver » January 14th, 2009, 2:29 am

Hi Wiccan Witch,

I'm sorry it's taken so long for you to get a response, if you still need help please do as follows:

Download RSIT by random/random to your Desktop (right-click the link, select Save Target As..., select your Desktop and press Save)

  • Double click RSIT.exe to start the program, and click Continue at the disclaimer screen.
  • When the scan is complete, two text files will open - log.txt <- this one will be maximized and info.txt <-this one will be minimized
  • Make sure Format->Word Wrap is unchecked
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt and info.txt in your reply

Once complete, please post both RSIT logs, you won't need to produce a new HijackThis log as RSIT produces one for you.
User avatar
Regular Member
Posts: 9219
Joined: August 7th, 2006, 9:40 pm
Location: GMT+7

Re: HJT log file

Unread postby silver » January 17th, 2009, 8:08 am

Do you still need help with your machine?

If the instructions are unclear or something isn't working, please let me know before proceeding.
User avatar
Regular Member
Posts: 9219
Joined: August 7th, 2006, 9:40 pm
Location: GMT+7

Re: HJT log file

Unread postby silver » January 19th, 2009, 7:33 pm

Due to a Lack of Response this topic is now closed.

If you still require help, please open a new thread in the Malware Removal forum.

If you have been helped and wish to donate to help with the costs of this volunteer site,
please read Donations For Malware Removal
User avatar
Regular Member
Posts: 9219
Joined: August 7th, 2006, 9:40 pm
Location: GMT+7
Register to Remove

  • Similar Topics
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!

Who is online

Users browsing this forum: No registered users and 9 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware