Hi Jholland,

I have the same problem what Asurocks had. My Windows start is fully disabled I am not able to use any of the options provided by Windows start i.e, All Programs, Control Panel, Setting etc. I think this is caused by a virus. Can you please help me?

I have run the Hijack on my computer and pasted below its result

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:52:34 PM, on 12/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\System.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: 127.1 localhost
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 www.b3sk.cn
O1 - Hosts: 127.1
O1 - Hosts: 127.1 www.ms2a.cn
O1 - Hosts: 127.1 www.wo9188.cn
O1 - Hosts: 127.1 www.fgetchr.cn
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 www.s1na1.com.cn
O1 - Hosts: 127.1 www.dianyinjzd.cn
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 a.
O1 - Hosts: 127.1 b.
O1 - Hosts: 127.1 c.
O1 - Hosts: 127.1 x.
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 www.133mm.cn
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 biqulu.cn
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 www.giaitrituoitre.net
O1 - Hosts: 127.1 mekiep.com
O1 - Hosts: 127.1
O1 - Hosts: 127.1 a.
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 www.jb88.net
O1 - Hosts: 127.1 6.a88a.com
O1 - Hosts: 127.1 w.
O1 - Hosts: 127.1 m.c5x8.com
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 u.
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 downloads.zango.com
O1 - Hosts: 127.1 ftp.surfnet.nl
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1
O1 - Hosts: 127.1 sao6666.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [3PMmUpdate] rundll32 "C:\WINDOWS\Update.dll",Main
O4 - HKLM\..\Run: [HBService32] System.exe
O4 - HKLM\..\Run: [MPKrnl] rundll32 "C:\WINDOWS\MPKrnl.dll",KrnlMsgProc
O4 - HKLM\..\Run: [RRT-Auto] C:\DOCUME~1\SSAD\LOCALS~1\Temp\Rar$EX00.985\RRT.exe auto
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\kamsoft.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKLM\..\Policies\Explorer\Run: [MPMKrnl] rundll32 "C:\WINDOWS\MKMKrnl.dll",KMainProc
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
O20 - AppInit_DLLs: 01AFE3DC.dll,HBmhly.dll,HBZHUXIAN.dll,HBQQFFO.dll,HBWOW.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll
O21 - SSODL: Upnp - {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll
O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Unknown owner - C:\Program Files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


Please reply and tell me what should I do next


Thanks,
Shankar Sangoli

Dani AI

Generated

Quick expert summary for : the HijackThis output shows three urgent red flags — a very large block of HOSTS entries redirecting many domains to a loopback address, several unfamiliar startup/run entries (oddly named .exe keys), and a populated AppInit_DLLs string with many nonstandard DLL names. Those items provide persistence and can block normal Explorer/Start-menu behavior. ’s question about account privileges is important: some fixes require an administrative session, and ’s advice to get an on-system scan done is the right first direction.

Triage steps (safe order):

  • Back up personal data first (documents, photos, email files) to external media before making changes.
  • If the Start menu won’t work, open Task Manager (Ctrl+Shift+Esc) → File → New Task (Run...) and launch Notepad or Explorer. Use Notepad to open C:\WINDOWS\system32\drivers\etc\hosts, save a copy (hosts.backup) and remove unknown lines (leave only the default localhost entry). If the file is locked, boot to Safe Mode or use a clean USB/live environment to edit it offline.
  • From Task Manager you can also run regedit and export HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows (to capture the AppInit_DLLs value) and export the Run keys under HKLM\...\Run and HKCU\...\Run for posting.

Deeper cleanup and what to post:

  • On a clean PC download Sysinternals Autoruns and Process Explorer, copy to USB, then run Autoruns on the infected machine (Safe Mode if possible) and save the full report. Uncheck (don’t delete) clearly malicious entries for testing, and post the saved Autoruns log plus your hosts file contents and the exported registry values so helpers can confirm removals.
  • If rootkit behavior is suspected, use a reputable vendor’s rescue/bootable scanner (offline scan) before attempting registry surgery.

If unsure or if the machine holds critical data, make a full disk image and consider a clean reinstall — Windows XP is long out of support, so plan an upgrade after recovery.

Recommended Answers

All 2 Replies

if u could describe your problem little bit more , then it ll lot more easier for ppl like me who dont know the problem that other guy had ,

2 q's as of now .

1. r u in admin account ? if so then try to go in safe mood ot try loging in as admin), and execute malwarebytes there , run a scan and post log .
2. i could not understand that if u could not execute any programs then how did u do hijack this ?

Manau

Pls do the following:

1. - Download Malwarebytes' Anti-Malware (http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

2. - Pls run HJT again and post the log.

In your reply, post the logs (in this order):
1. - Malware Bytes Log
2. - Hijackthis Log

Thanks,

Cohen

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.