I'm working on a laptop with some serious Trojan/Spyware issues. I have tried to install and run all the major removers. No luck. For example when trying to install Spy Sweeper, the program starts to install, gets to the "Accept the Terms and Conditions" and then disappears from the screen. Something is stopping the install of all these programs. Also the Control Panel is NOT in the Start Menu. I've tried installing in Safe Mode too. I can get on the web and IE7 will go to the page I choose.... then other pages will start Popping up. I was able to get HJT to install and run...Here is the log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:38 PM, on 12/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\trprhh
as.exe
c:\program files\mcafee.com\agent\mcd
etect.exe
c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
c:\PROGRA~1\mcafee.com\age
nt\mctsksh
d.exe
C:\PROGRA~1\McAfee.com\PER
SON~1\MpfS
ervice.exe
C:\Program Files\Dell\NICCONFIGSVC\NI
CCONFIGSVC
.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\PROGRA~1\mcafee.com\age
nt\McAgent
.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee\SPAMKI~
1\mskagent
.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Documents and Settings\Steph\Application
Data\iwcgsss.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\auto
run.exe
C:\DOCUME~1\Steph\LOCALS~1
\Temp\mons
erver.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exe
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
05236F6F65
5} - c:\progra~1\mcafee.com\vso
\mcvsshl.d
ll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-4
5AF8282558
3} - (no file)
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printe
r.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\age
nt\mcupdat
e.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
nt\McAgent
.exe
O4 - HKLM\..\Run: [a80a6aa6] rundll32.exe "C:\WINDOWS\system32\ibrij
nos.dll",b
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~
1\mskagent
.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolv
s.exe
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\Steph\Application
Data\erppmkirxqwn.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User 'Default user')
O4 - Startup: findfast.exe
O4 - Global Startup: autorun.exe
O7 - HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Policies\
System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_03\bi
n\npjpi142
_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\j2re1.4.2_03\bi
n\npjpi142
_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3
582CCF489E
1} - c:\PROGRA~1\mcafee\SPAMKI~
1\mcapfbho
.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3
582CCF489E
1} - c:\PROGRA~1\mcafee\SPAMKI~
1\mcapfbho
.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9
BD8C29F7F7
5} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8
226143CFC0
A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-6
2B522420EC
C} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {95D88B35-A521-472B-A182-B
B1A9835642
1} (Pearson Installation Assistant 2) -
http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cabO16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C
6DAD9515D5
A} (Pearson MyEconLab Player Control) -
http://asp.mathxl.com/books/_Players/EconPlayer.cabO20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.
dll
O23 - Service: DomainService - - C:\WINDOWS\system32\trprhh
as.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcd
etect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age
nt\mctsksh
d.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
nt\mcupdmg
r.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PER
SON~1\MpfS
ervice.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~
1\MSKSrvr.
exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NI
CCONFIGSVC
.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYS
VC.EXE (file missing)
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows Media Player\profsyxyviq.html
--
End of file - 6601 bytes
Any Ideas to get this crap off the machine?
Thanks ...Don