I have been infected with a trojan which has been cleaned up, but in the process also picked up a lot of adware. Spybot and Macaffee cannot permamently delete this, although they both appear to. With spybot, they are detected and deleted but come right back. WIth Macaffee, they connot be cleaned or deleted, but they can be quaranteened and later deleted with "manage quaranteened files" but they still come fight back.
What can I do?
Here is a "hijack this" log:
Logfile of HijackThis v1.97.7
Scan saved at 1:35:55 PM, on 5/2/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\hkcmd.
exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
C:\Program Files\MusicMatch\MusicMatc
h Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.ex
e
C:\PROGRA~1\mcafee.com\vso
\mcvsshld.
exe
C:\WINDOWS\System32\IEHost
.exe
c:\progra~1\mcafee.com\vso
\mcvsescn.
exe
C:\Program Files\Dell\Support\Alert\b
in\NotifyA
lert.exe
C:\WINDOWS\System32\senrca
ll.exe
C:\WINDOWS\system32\pcs\pc
svc.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\Program Files\Common files\updmgr\updmgr.exe
C:\Program Files\Yahoo!\browser\ybrwi
con.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\PROGRA~1\CLOCKS~1\Sync.
exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\acsd.ex
e
C:\PROGRA~1\Yahoo!\browser
\ycommon.e
xe
c:\PROGRA~1\mcafee.com\vso
\mcvsrte.e
xe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\Program Files\SysAI\SysAI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\WvyQ4U
x.exe
C:\WINDOWS\System32\Qife4.
exe
C:\Documents and Settings\Dell Desktop\Local Settings\Temp\Temporary Directory 1 for cwshredder.zip\CWShredder.
exe
D:\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar = file://C:\WINDOWS\System32
\SearchBar
.htm
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.dell4me.com/mywayR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://yahoo.sbc.com/dslR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.comR3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6
BB168A7031
0} - C:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L (file missing)
R3 - URLSearchHook: IncrediFindBHO Class - {4FC95EDD-4796-4966-9049-2
9649C80111
D} - C:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L (file missing)
O2 - BHO: (no name) - {00000000-0000-0000-0000-0
0000000022
1} - C:\PROGRA~1\Lycos\IEagent\
CSIE.DLL (file missing)
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2
A3C64AE693
9} - (no file)
O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3
D4BF457D4C
8} - C:\Program Files\Lycos\Sidesearch\sid
esearch132
18.dll (file missing)
O2 - BHO: (no name) - {00000EF1-0786-4633-87C6-1
AA7A44296D
A} - (no file)
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-7
86FA05C83A
B} - C:\Program Files\SysAI\AproposPlugin.
dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Common\ycomp5
_1_6_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {4FC95EDD-4796-4966-9049-2
9649C80111
D} - C:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: (no name) - {5D60FF48-95BE-4956-B4C6-6
BB168A7031
0} - C:\PROGRA~1\INCRED~1\BHO\I
NCFIN~1.DL
L (file missing)
O2 - BHO: (no name) - {63B78BC1-A711-4D46-AD2F-C
581AC420D4
1} - C:\PROGRA~1\COMMON~1\WinTo
ols\btiein
.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
05236F6F65
5} - c:\progra~1\mcafee.com\vso
\mcvsshl.d
ll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Common\ycomp5
_1_6_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vs
o\mcmnhdlr
.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
nt\McUpdat
e.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatc
h Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATC
H Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.ex
e
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vs
o\mcvsshld
.exe"
O4 - HKLM\..\Run: [MFMT] C:\WINDOWS\MFMT.exe
O4 - HKLM\..\Run: [z] C:\windows\temp\z.exe
O4 - HKLM\..\Run: [ClrSchLoader] C:\PROGRA~1\Lycos\IEagent\
Loader.exe
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\System32\IEHost
.exe
O4 - HKLM\..\Run: [2HQCYHF3DNW2CN] C:\WINDOWS\System32\NulP8r
9.exe
O4 - HKLM\..\Run: [rs6T3Ei] C:\WINDOWS\System32\senrca
ll.exe
O4 - HKLM\..\Run: [WhenUSearch] C:\PROGRA~1\WHENUS~1\Searc
h.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdat
e.exe"
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pc
svc.exe
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwi
con.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\age
nt\mcregwi
z.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Crru] C:\Documents and Settings\Dell Desktop\Application Data\tecw.exe
O4 - HKCU\..\Run: [WTSS] C:\WINDOWS\System32\wapiit
.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.
exe /q
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\VBouncer\VirtualBoun
cer.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O9 - Extra button: Sidesearch (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://download.yahoo.com/dl/installs/yinst0401.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-0
0104B06BDE
3} (CamImage Class) -
http://www.digitalsurveillancecenter.com/activex/AxisCamControl.cabO16 - DPF: {9CF28A69-7659-4C51-BFD5-9
ADE19E19EC
3} (RegConfig Class) -
http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38109.3273611111O16 - DPF: {A17E30C4-A9BA-11D4-8673-6
0DB54C1000
0} (YahooYMailTo Class) -
http://download.yahoo.com/dl/installs/ymail/ymmapi.dllO16 - DPF: {B9191F79-5613-4C76-AA2A-3
98534BB899
9} (YAddBook Class) -
http://download.yahoo.com/dl/installs/yab_af.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C
18E1ADA438
9} (DwnldGroupMgr Class) -
http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cabO16 - DPF: {D18F962A-3722-4B59-B08D-2
8BB9EB2281
E} (PhotosCtrl Class) -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E855A2D4-987E-4F3B-A51C-6
4D10A7E247
9} (EPSImageControl Class) -
http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab