Logfile of HijackThis v1.99.1
Scan saved at 10:28:41 AM, on 3/31/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\winnt\inetinfomon.exe
C:\WINNT\system32\cmd.exe
C:\Documents and Settings\Administrator\Application Data\mySI\bin\ss.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINNT\System32\SCardSvr.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1EFE292B-6BF7-4FF8-854A-310C1C15EA93} - C:\WINNT\system32\ssqrq.dll (file missing)
O2 - BHO: (no name) - {425D2599-AF6A-4CDD-8E27-0FAD21EA6749} - C:\WINNT\system32\ssqrrrr.dll
O2 - BHO: (no name) - {49293A8E-BCF0-479F-AC9B-0C7D2C362245} - C:\WINNT\system32\xxyab.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINNT\system32\vtboqskp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {86CCA214-6491-4F9A-B91D-94F3F909E85b} - C:\WINNT\system32\vktfdqas.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINNT\system32\wcgaosyg.dll",setvm
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [mySI] "C:\Program Files\mySI\mySI.exe" -tb
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [inetinfomon manager] c:\winnt\inetinfomon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O20 - Winlogon Notify: ssqrq - C:\WINNT\system32\ssqrq.dll (file missing)
O20 - Winlogon Notify: ssqrrrr - C:\WINNT\SYSTEM32\ssqrrrr.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: xxyab - C:\WINNT\system32\xxyab.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Dani AI

Generated

This HijackThis log (Windows 2000 SP4) shows enough red flags to treat the machine as compromised and to proceed carefully. There are multiple unexpected auto-start hooks and Winlogon-style notification DLL entries (a common persistence technique), plus unknown background processes and a user-run helper in Application Data. The system also has more than one real‑time security product installed, which itself can slow or destabilize an older machine and make diagnosis harder. (learn.microsoft.com)

Prioritized, practical next steps (in order):

  • Isolate the PC (unplug network or disable Wi‑Fi) to avoid data leakage.
  • Boot Safe Mode (press F8 during boot) and use an autorun/auto‑start inspector rather than just msconfig — Autoruns from Sysinternals gives a complete view (BHOs, Winlogon Notify, Run keys, services) and can safely disable entries so you can test without deleting. Note the goal is to disable suspicious items, then scan files before removal. (learn.microsoft.com)
  • For any suspicious executable/DLL you find, check its path and hash and upload the file/hash to VirusTotal for a quick multi‑engine second opinion before deleting. If the file is missing but the registry hooks remain, disable the hook first. (virustotal.com)
  • Because modern on‑host scanners often don’t support Windows 2000, use a bootable rescue scanner (boot from USB/CD) such as ESET SysRescue or a current rescue image to run an offline scan and clean persistent components; these run independently of the OS and can remove things running in kernel or Winlogon context. Back up personal files first. (eset.com)

A few extra notes so the plan is safe and effective: prefer disabling entries in Autoruns rather than immediate deletion; uninstall redundant real‑time AVs (keep only one) and use vendor removal tools if available; if removal is uncertain or infections persist, a full image backup followed by a clean OS reinstall is the safest long‑term fix for an out‑of‑support OS like Windows 2000. For quick reference, ’s msconfig tip is a fine first step, but Autoruns + offline rescue scans will give a much more reliable cleanup. (support.microsoft.com)

Try running msconfig

DownLoad here:
http://www.perfectdrivers.com/local/msconfigxp/msconfig.exe


-You can add msconfig to Windows 2000. Put it in the c:\winnt\system32\ (c:\winnt\ works also) folder. * This assumes that c: drive is where Windows 2000 was installed to.


To run msconfig, hit start, run, and type in msconfig

And shut down anything you don't need running.like quick time or word and such.

If not sure about something check here.

Clean out your cookies and history in control panel and internet to my computer and right click on C: drive and do a disc cleanup and then tools then do a defrag.

Go get this download and update and run it.
http://dw.com.com/redir?pid=10639408&merid=69274&mfgid=69274&ltype=dl_dlnow&lop=link&edId=3&siteId=4&oId=3040-8022_4-10639408&ontId=8022_4&dlrs=1&destUrl=http://www.download.com%2F3001-8022_4-10639408.html

Get this and run also.

Have HiJackThis fix these.

O2 - BHO: (no name) - {1EFE292B-6BF7-4FF8-854A-310C1C15EA93} - C:\WINNT\system32\ssqrq.dll (file missing)

O2 - BHO: (no name) - {49293A8E-BCF0-479F-AC9B-0C7D2C362245} - C:\WINNT\system32\xxyab.dll (file missing)

O2 - BHO: (no name) - {86CCA214-6491-4F9A-B91D-94F3F909E85b} - C:\WINNT\system32\vktfdqas.dll (file missing)

O4 - HKCU\..\Run: [inetinfomon manager] c:\winnt\inetinfomon.exe

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker\RunApp.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker\RunApp.exe (file missing)

O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)

O20 - Winlogon Notify: ssqrq - C:\WINNT\system32\ssqrq.dll (file missing)

O20 - Winlogon Notify: xxyab - C:\WINNT\system32\xxyab.dll (file missing)


Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.