I was trying to open up internet explorer, and it crashed my system for a good half hour. I finally was able to boot it without any trouble and do a system restore. This is the hijackthis file after I was able to do a system restore. It slowed down everything, I was't able to end programs, open up internet explorer, control panel, hardly anything. the only program it let me open up with no problem was mirc.

Thanks,
RJ

Logfile of HijackThis v1.99.1
Scan saved at 2:11:32 AM, on 8/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\regscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Owner\My Documents\My Received Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - Startup: PowerReg Scheduler V3.exe
O16 - DPF: YExplorer1_8US.CAB -
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

Dani AI

Generated

Good catch by and good follow-up from — the first HijackThis showed a suspicious autorun (a regscan.exe process in System32 plus an HKCU Run entry) while the later log looks much cleaner. Infections rarely damage hardware directly, but they can corrupt drivers or system files and make the machine behave like it has a failing video card, so treat both possibilities (malware + hardware) seriously.

Practical verification steps (do these before making permanent changes): examine live network connections and map them to processes, inspect startup locations with built-in tools and a reputable startup viewer, and check for orphaned BHOs or missing-file entries that HijackThis reported. Useful commands and checks:

netstat -ano            (list active connections and PIDs)
tasklist /FI "PID eq <pid>"   (map a PID to an executable)
msconfig                 (quick startup/services check)

Also run Autoruns/Process Explorer (Sysinternals) to reveal hidden Run keys, services, scheduled tasks and BHOs; right-click suspicious EXEs -> Properties -> Digital Signatures / timestamps to spot fakes.

Safe removal workflow: boot Safe Mode (or use a clean rescue environment), update signatures and run full scans with at least two different up-to-date anti-malware engines, and use Autoruns to disable suspicious startup entries before deleting files. Back up the registry and create an image or full data backup before manual registry edits or file removals. If a rootkit is suspected, use an offline scanner or bootable rescue media. If the infection persists or core system files are altered, a repair install or clean reinstall is the most reliable recovery.

After cleanup: reinstall or update device drivers (video drivers if display issues remain), change important passwords, monitor outbound connections for several days, and keep regular image backups plus updated anti-malware tools. Save both the original and follow-up HijackThis logs for forensic comparison.

Recommended Answers

All 10 Replies

Was just wondering if anyone see's anything in the HiJack this Log that needs to be removed? Or will the system restore keep whatever happened in check. I'm sorry, not trying to bug, just trying to make sure the computer is okay.

thanks again,
RJ

Hi RJ,

I'm not one of the virus experts here, but your log says your system captured a trojan backdoor, probably W32.RBot.HA or an old one that uses the filename "regscan.exe":
Process:
C:\WINDOWS\system32\regscan.exe
Registry key:
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe

It's described here:

You can follow the removal instructions there.

This entry is also considered nasty, but rather harmless: (Spyware)
O4 - Startup: PowerReg Scheduler V3.exe

It's described here:

But I wonder why your antivirus software doesn't find anything? Did you update it before running it? Did you run it in safe mode? Maybe you try this one:

and run an updated Spybot S+D in safe mode, let it remove everything it finds.

Disable system restore to remove all restore points, since the trojan is most likely buried there, too.
I'm not one of the malware removal experts here and just wanted to help out, so I can't give you real instructions on that, sorry.

Xpenetrator,

Thanks for responding. The system restore only help for a bit anyways, cuz now today, my roomate went to turn the computer on and now something wrong with the "video" card we think, it's in the shop. I run a virus scan on both computers every other day. It's hard to maintain both, but the more I keep doing this the more I get better at it. I'm just uncertain of certain things so I post here for help.

I dont know if this backdoor thing can affect any hardware, but we'll see what my tech says monday. But if anyone else can find anything else in the hijack this log, please let me know, when I get the computer back. I'll run it again, see if it's still there, and start working on removing it.

Thanks again,
RJ

Technically, infections can't infect/affect hardware per se, but they can corrupt software associated with a given piece of hardware (driver software and the like).

Aside from the infection Xpenetrator mentioned, your log is clean.

NEW HiJackThis Log. It looks clean to me, just asking to make sure though.

Logfile of HijackThis v1.99.1
Scan saved at 2:36:21 PM, on 8/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Owner\My Documents\My Received Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O16 - DPF: YExplorer1_8US.CAB -
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

Looks clean to me, too. :mrgreen:

<>

Yarrr, Matey- 'tis a clean log ye be havin' there!

</>

You can buy clean log for 1.5 pie! Or me tell police! :cheesy:

You can buy clean log for 1.5 pie!

or cash equivalent. :D

Gotta love Weebl 'n Bob; it's all about the PIE!

Love them! And naaargh! Try to eat or throw cash! Much funnier with pie! :) (But I guess you wish you had a nickel for every virus file you killed. I wouldn't have earned a quarter yet..:))

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.