I am having problems opening up internet explorer I click on the icon and about 5 minutes later I get them to open up, If I click it 10X then 10 of them will open 5 minutes later. I am also having pop-ups etc. I have run Ad-aware 6.1 and spybot search and destroy. S&D finds nothing and ad-aware finds a few things that I erase and then I will run it again later and there are more maybe the same ones? Here is a highjack this log Please Help I have no Idea Thanks Ryun


Logfile of HijackThis v1.99.1
Scan saved at 11:28:34 AM, on 7/28/2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\Program Files\aeic\wcme.exe
C:\WINNT\system32\r?ndll.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\YOP\yop.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) ww1.www.rbsdigital.com
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) www.miwebbusbank.ebanking-services.com
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) www.bvi.bancodevalencia.es
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) ww2.dresdner-privat.de
O1 - Hosts: (null)
O1 - Hosts: (null) ww.hsh-nordbank.de
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: HPOVASMD.BrowserSensor - {04047354-D353-11D2-B3EB-0060B03C5581} - C:\WINNT\Downloaded Program Files\hpBrSn24.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Msxml32DOMDocument Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\System32\dllcache\msxml32.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Crtp] C:\Program Files\aeic\wcme.exe
O4 - HKCU\..\Run: [Kaiw] C:\WINNT\System32\r?ndll.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {04047354-D353-11D2-B3EB-0060B03C5581} (HPOVASMD.BrowserSensor) - https://dealerconnect.chrysler.com/...ugin/hpBrSn.cab
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E46192D8-0F5A-43EE-9223-F58BE7AEE625}: NameServer =
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe

Dani AI

Generated

A short expert summary tied to the posts by , and :

The fresh HijackThis log and ’s follow‑up show the obvious hosts‑file redirects and the odd autorun entries were removed, and the Internet Explorer startup symptoms have cleared up. That pattern — bad hosts entries plus rogue autostart files — matches many banking/redirect infestations and is exactly why multiple scans and a hosts restore were the right first moves.

Why the O1 (hosts) lines mattered, and what to do next

  • The O1 lines in a HijackThis report are hosts‑file redirections; malware often uses them to point bank/login domains at attacker IPs so pages are intercepted or blocked. Treat any credentials entered while those redirects existed as potentially compromised: change critical passwords (email, bank, payment services) from a known‑clean device, enable two‑factor authentication where possible, and monitor accounts for unauthorized activity. Guidance on the O1/hosts behavior and how HijackThis reports it is documented in standard HJT tutorials. (bleepingcomputer.com)
  • Microsoft’s support guidance for restoring/resetting a modified hosts file and the general recommendation to change credentials after a compromise are good reference points. (support.microsoft.com)

About the O16 (DPF/ActiveX) entry

  • O16 entries are Downloaded Program Files / ActiveX controls — many are legitimate browser helper controls used by corporate portals (DealerConnect, etc.). If a control is known and signed by a trusted publisher (and required by business software), leaving that O16 is fine; unrecognized or unsigned controls merit removal and further inspection. The HJT tutorial explains how O16 is reported and why some entries are expected. (bleepingcomputer.com)

DNS entry (O17) note and persistence checks

  • The O17 name‑server addresses 209.244.0.3 / 209.244.0.4 resolve to Level3/CenturyLink public DNS ranges; that is not inherently malicious but any unexpected DNS change should be checked (router/DHCP settings and local TCP/IP config). If uncertainty about persistence remains, run an offline/rescue or rootkit scan and consider saving data and doing a clean OS reinstall for full assurance. (who.is)

Summary: the immediate cleanup looks successful, but follow‑up hardening (credential changes from a clean device, 2FA, verify router/DNS, and one more thorough offline/rootkit scan) will close remaining risk.

Recommended Answers

All 4 Replies

Download and install it. Then run, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.

Download CCleaner and install it.

Download . Extract it to a folder, do not run it now.

Make Windows to show all files:-
Go to Start > My Computer.
Go to Tools menu, click Folder Options (Folder Option will be in View Menu in Win98).
Uncheck Hide protected operating system files.
Then, click to select the option Show hidden files and folders.
Click Apply and then click OK to exit.


Reboot in Safe Mode:-
Restart (or switch ON) the PC.
Then, keep tapping the F8 Key.
From the menu that will be displayed, out of which choose Safe Mode and press Enter.


Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-

O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) ww1.www.rbsdigital.com
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) www.miwebbusbank.ebanking-services.com
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) www.bvi.bancodevalencia.es
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null) ww2.dresdner-privat.de
O1 - Hosts: (null)
O1 - Hosts: (null) ww.hsh-nordbank.de
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O1 - Hosts: (null)
O2 - BHO: HPOVASMD.BrowserSensor - {04047354-D353-11D2-B3EB-0060B03C5581} - C:\WINNT\Downloaded Program Files\hpBrSn24.dll
O2 - BHO: Msxml32DOMDocument Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\System32\dllcache\msxml32.dll
O4 - HKCU\..\Run: [Crtp] C:\Program Files\aeic\wcme.exe
O4 - HKCU\..\Run: [Kaiw] C:\WINNT\System32\r?ndll.exe
O16 - DPF: {04047354-D353-11D2-B3EB-0060B03C5581} (HPOVASMD.BrowserSensor) - https://dealerconnect.chrysler.com/...ugin/hpBrSn.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -

Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.


Exit from HijackThis. Delete these files:-
C:\Program Files\aeic\wcme.exe
C:\WINNT\System32\r?ndll.exe <-- You have to locate this file in System32 folder and delete it. Be careful not to delete the genuine file rundll32.exe.

Delete these folders:-
C:\Program Files\aeic


Next, run CCleaner, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally click "Run Cleaner" and choose "Yes" to continue cleaning.

Run Ewido, click on the "Scanner" button in the left menu, then click on the "Start" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.


Run Hoster, press "Restore Original Hosts" and press "OK". Exit Program.


Reboot to Normal Mode. Run HijackThis again, click Do a System scan and save log, and post the fresh log.

Internet explorer seems to be opening okay again here is a fresh Hijack log Thanks Ryun

one other question the O-16 with dealerconnect in it. you told me to erase it, but dealerconnect is a program we use to interface with Daimlerchrysler should I still erase it?

Logfile of HijackThis v1.99.1
Scan saved at 5:05:29 PM, on 7/28/2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\xtras\mssysmgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {04047354-D353-11D2-B3EB-0060B03C5581} - https://dealerconnect.chrysler.com/wto/plugin/hpBrSn.cab
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) -
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E46192D8-0F5A-43EE-9223-F58BE7AEE625}: NameServer =
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe

Hi,

Log looks clean :D
No need to remove the O16 "Dealerconnect" entry in HijackThis :)

...one other question the O-16 with dealerconnect in it. you told me to erase it, but dealerconnect is a program we use to interface with Daimlerchrysler should I still erase it?

See this thread for some basic information about HijackThis (including O16 entries):
http://www.daniweb.com/techtalkforums/thread28196.html

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.