Hi, i think i have the same nasty problem...
I am not very good in pc, but i have dowloaded hijack and this is my log.
My pc has becomed incredibilly slow...Please help me!


Logfile of HijackThis v1.99.0
Scan saved at 12.26.07, on 20/12/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Grisoft\AVG6\avgw.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Documents and Settings\Daniele\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F2 - REG:system.ini: Shell=Explorer.exe winsock.scr
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [dxset.exe] C:\WINDOWS\dxsetu.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O23 - Service: AVG6 Service - GRISOFT s.r.o - C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Dani AI

Generated

This is a typical persistence/infection pattern: a rogue program was added to the shell/startup so it runs at logon, produces the error seen at boot and drags the machine down. was on the right track — running HijackThis from a clean folder and removing the offending startup keys is the correct first move — but a few safer, follow‑up steps make the cleanup reliable and reduce the chance of reinfection.

Recommended sequence (safe order):

  1. Boot to Safe Mode.
  2. Back up the registry (Regedit -> File -> Export) and create a System Restore point before changing anything.
  3. Run an up‑to‑date HijackThis from a new folder and remove the suspicious shell/startup entries that point to a screensaver/executable. After fixing the keys, delete the corresponding file from the Windows folder while still in Safe Mode. Use Autoruns (Sysinternals) to double‑check for other persistence points (services, scheduled tasks, run/RunOnce, browser helper objects).
  4. Repair the Winsock/IP stack and reboot (see commands below).
  5. Run a full scan with an updated antivirus plus a dedicated anti‑malware scanner (on clean boot or from Safe Mode). If a suspicious file remains, submit it to VirusTotal for multiple AV checks before trusting its removal.

Useful commands to run from an elevated command prompt:

netsh winsock reset
netsh int ip reset resetlog.txt
sfc /scannow

Cautions: always delete unknown files only from Safe Mode and after confirming their path and hash. Export any registry keys before editing. If the machine still exhibits signs of compromise (hidden processes, repeated startup entries, or intercepted credentials), the safest route is to back up personal data and perform a clean OS reinstall. ’s winsock repair suggestion is valid; the built‑in netsh winsock reset (XP SP2 and later) is a dependable, zero‑cost alternative.

Recommended Answers

All 4 Replies

Right-click on your desktop, select New, Folder; name it something like HJT or hijackthis; then, drag the hijackthis.exe icon that is on your desktop into that new folder.

Scan with hijackthis and have it fix the following entries:

F2 - REG:system.ini: Shell=Explorer.exe winsock.scr
O4 - HKLM\..\Run: [dxset.exe] C:\WINDOWS\dxsetu.exe

Be sure all windows are closed other than hijackthis before hitting the Fix button.

Go to C:\WINDOWS and delete dxsetu.exe

You can also try winsockfix and see if it helps resolve the problem:

http://www.digitalminds.net/index.pl/downloads

Get the latest version of hijackthis (1.99.1) from here:

Close all browser windows, scan with the new hijackthis, and post a new log please.

wow! one from the lost and found

wow! one from the lost and found

Been trying to get the unanswered threads caught up :)

Bit of a late Christmas present eh? :D

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.