Ok where do I start. I have cleaned all of the temp files off the computer all the cookies etc. I noticed I couldnt get AVG to install or Adaware because there was a virus or something running killing the process of the install file. So I totally pulled the Hard drive from the machine hooked it up to another machine that was clean and had AVG and Adaware etc. on it. I booted up with the clean machine and put the infected hard drive as the slave. I ran a AVG scan it found about 200 viruses got them removed I have rescanned the hard drive it found nothing. Then I ran adaware while I had the Hard drive hooked up as slave. and it found somethings it removed those. Next I decided to Rehook up the Hard drive to the computer it came out of and boot it up. So I did. Still cant install AVG or adaware or Spybot. I got a program called Counterspy to install and ran a scan found a few more malware things. I removed those. I was able to install a program called winpatrol on the machine that shows running processes startup programs etc... Zonealarm installed but the process is killed. Spybot,adaware,Avg,Avast will not install at all! You click the install file and it will not run. I have noticed this virus likes to rename itself. At one point it was named EXPLORE.exe trying to make it look like EXPLORER.exe in the task manager. I have ran Killbox to try to delete these files and everytime I restart to delete the file it just comes back and is renamed something else. And you cannot kill the process in the task manager. I have also ran mcafee stinger on the machine. If someone can help me figure this one out Big kudos to you! Because I remove spyware and viruses from machines all the time but I cant figure this out!
This is a log showing what the machine looks like when I do a Diagnostic startup from msconfig. The virus or whatever it is is still there I can not install any anti-virus or anti-spyware tools.
Logfile of HijackThis v1.99.1
Scan saved at 11:03:17 AM, on 05/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\userin
it.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\BILLPS~1\WINPA
T~1\winpat
rol.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Documents and Settings\Nicki\Desktop\New
Folder\HijackThis.exe
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
N3 - Netscape 7: user_pref("browser.search.
defaulteng
ine", "
http://www.google.com/");
(C:\Documents and Settings\Nicki\Application
Data\Mozilla\Profiles\defa
ult\d04kir
t2.slt\pre
fs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
ycomp5_3_1
6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-0
5D28BCF79F
5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
ycomp5_3_1
6_0.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9
EE0F344C38
5} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmg
.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCt
r\Binaries
\MSConfig.
exe /auto
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPA
T~1\winpat
rol.exe
O4 - HKLM\..\Run: [sunasDtServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
ch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\shdocv
w.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\shdocv
w.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\PROGRA~1\AWS\WEATHE~1\W
eather.exe
(file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=
http://www.insightbb.comO16 - DPF: {1C203F13-95AD-11D0-A84B-0
0A0247B735
B} (Sheridan ActiveTreeView Control) -
https://www.ext.ch2m.com/cgi-bin/controls/sstree.cabO16 - DPF: {2F5B39C5-C6F5-447A-A946-4
8B382C5398
5} -
http://www.pacimedia.com/install/pcs_0025.exeO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cabO16 - DPF: {35020238-5912-11D1-9A00-0
0C04FD8DC2
E} (DameWare DTP Control Class) -
https://www.ext.ch2m.com/cgi-bin/controls/ddtp.dllO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {4855C21B-E452-4661-A702-E
D3493CE74D
F} -
http://sp.ask.com/docs/toolbar/download/askbar-inst.cabO16 - DPF: {9522B3FB-7A2B-4646-8AF6-3
6E7F593073
C} (cpbrkpie Control) -
http://a19.g.akamai.net/7/19/7125/4047/ftp...23/cpbrkpie.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
F47A330807
8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dllO16 - DPF: {E77C0D62-882A-456F-AD8F-7
C6C9569B8C
7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/ac.../ActiveData.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0
010B556D97
8} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
vc.dll
==========================
==========
==========
=======
Here is what the machine looks like after I do a normal startup
Logfile of HijackThis v1.99.1
Scan saved at 11:34:35 AM, on 05/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\brsvc0
1a.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\brss01
a.exe
C:\WINDOWS\system32\driver
s\KodakCCS
.exe
C:\WINDOWS\System32\ScsiAc
cess.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\BILLPS~1\WINPA
T~1\winpat
rol.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDTServ.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\WINDOWS\system32\ps2.ex
e
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\System32\igfxtr
ay.exe
C:\windows\system\hpsysdrv
.exe
C:\WINDOWS\System32\hphmon
05.exe
C:\WINDOWS\System32\hkcmd.
exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\interMute\PopSubtrac
t\PopSub.e
xe
C:\Program Files\Common Files\Real\Update_OB\rnath
chk.exe
C:\Documents and Settings\Nicki\Desktop\New
Folder\HijackThis.exe
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
N3 - Netscape 7: user_pref("browser.search.
defaulteng
ine", "
http://www.google.com/");
(C:\Documents and Settings\Nicki\Application
Data\Mozilla\Profiles\defa
ult\d04kir
t2.slt\pre
fs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
ycomp5_3_1
6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: FlashEnhancer Extnder - {A749B4BC-7621-4a80-9220-D
0A283367DD
5} - c:\Program Files\Fln\fln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-0
5D28BCF79F
5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
ycomp5_3_1
6_0.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9
EE0F344C38
5} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPA
T~1\winpat
rol.exe
O4 - HKLM\..\Run: [sunasDtServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDTServ.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Insight\BBClient\Pro
grams\RegC
on.exe" /admincheck
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD
.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
e
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon
05.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [FlnCPY] "C:\Program Files\Common Files\Java\flncpy.exe"
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.e
xe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PopSubtract.lnk = C:\Program Files\interMute\PopSubtrac
t\PopSub.e
xe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
ch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\shdocv
w.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\System32\shdocv
w.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
0B0D0A1DE4
5} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\PROGRA~1\AWS\WEATHE~1\W
eather.exe
(file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=
http://www.insightbb.comO16 - DPF: {1C203F13-95AD-11D0-A84B-0
0A0247B735
B} (Sheridan ActiveTreeView Control) -
https://www.ext.ch2m.com/cgi-bin/controls/sstree.cabO16 - DPF: {2F5B39C5-C6F5-447A-A946-4
8B382C5398
5} -
http://www.pacimedia.com/install/pcs_0025.exeO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cabO16 - DPF: {35020238-5912-11D1-9A00-0
0C04FD8DC2
E} (DameWare DTP Control Class) -
https://www.ext.ch2m.com/cgi-bin/controls/ddtp.dllO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {4855C21B-E452-4661-A702-E
D3493CE74D
F} -
http://sp.ask.com/docs/toolbar/download/askbar-inst.cabO16 - DPF: {9522B3FB-7A2B-4646-8AF6-3
6E7F593073
C} (cpbrkpie Control) -
http://a19.g.akamai.net/7/19/7125/4047/ftp...23/cpbrkpie.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
F47A330807
8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dllO16 - DPF: {E77C0D62-882A-456F-AD8F-7
C6C9569B8C
7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/ac.../ActiveData.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0
010B556D97
8} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
vc.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc0
1a.exe
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\system32\cmdtel
.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\driver
s\KodakCCS
.exe
O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\system32\ahtun.
exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAc
cess.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe (file missing)