How do I remove the infection and keep the good DLL code?
The VISTA PC is shutdown and the power plug has been removed from the P/S while awaiting my getting to work on it.
All HW meets/exceeds VISTA requirements.
04.29.2008 at 06:07PM PDT, ID: 21467450
Following is the HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 6:02:24 PM, on 4/29/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1) VISTA with SP1
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Running processes:
C:\Windows\system32\tasken
g.exe
C:\Windows\system32\userin
it.exe
C:\Windows\system32\Dwm.ex
e
C:\Windows\Explorer.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Microsoft Office\Office12\GrooveMoni
tor.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonito
r.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Windows\System32\mobsyn
c.exe
C:\Program Files\SpywareRemover\Spywa
reRemover.
exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexSto
reSvr.exe
C:\Users\Richard Jackson\AppData\Local\Temp
\Temp1_hij
ackthis_19
9.zip\Hija
ckThis.exe
C:\Program Files\ThreatFire\TFTray.ex
e
C:\PROGRA~1\MI1933~1\Offic
e12\OUTLOO
K.EXE
C:\Windows\system32\Search
ProtocolHo
st.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.comcast.net/toolbar2.0/search/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.comcast.net/toolbar2.0/search/R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-B
E2DF4D9AE2
9} - C:\PROGRA~1\COMCAS~1\COMCA
S~1.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0
BBC1D38A37
E} - C:\Program Files\Microsoft Office\Office12\GrooveShel
lExtension
s.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.5.0_11\bin
\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-B
E2DF4D9AE2
9} - C:\PROGRA~1\COMCAS~1\COMCA
S~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DesktopMaestro] C:\Program Files\Desktop Maestro\deskmech.exe /QS
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\hpz
tsb10.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.
exe
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
\nTrayFw.e
xe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\P
CPOptimize
.exe -boot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMoni
tor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.ex
e
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\RunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerF
ault.exe -k -rq
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCe
nter
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-
4d9f-84C7-
88D8A56B10
AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonito
r.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [Network World iDemand] "C:\Program Files\Network World iDemand\Network World iDemand.exe" -r
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpywareRemover] C:\Program Files\SpywareRemover\Spywa
reRemover.
exe -boot
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.e
xe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\Office12\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_11\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_11\bin
\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MI1933~1\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MI1933~1\Offic
e12\ONBttn
IE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MI1933~1\OFFIC
E11\REFIEB
AR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi
.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napins
p.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O15 - Trusted Zone: *.akmai.net
O15 - Trusted Zone: *.skillport.com
O15 - Trusted Zone: *.skillsoft.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-B
E107C0EC16
6} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase2895.cabO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160873352358O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-0
4C2F616BCA
7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3
CB6248B04C
D} - C:\Program Files\Microsoft Office\Office12\GrooveSyst
emServices
.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-0
0C04F8EC29
4} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SAS
WINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\Windows\SYSTEM32\WgaLog
on.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
4D524869DB
5} - C:\Windows\system32\wpdshs
erviceobj.
dll
O23 - Service: @%windir%\system32\inetsrv
\iisres.dl
l,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypse
rv.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
\nSvcAppFl
t.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\Apa
che Group\Apache2\bin\apache.e
xe" -k runservice (file missing)
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: @%windir%\system32\inetsrv
\iisres.dl
l,-30007 (IISADMIN) - Unknown owner - %windir%\system32\inetsrv\
inetinfo.e
xe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLB
IZ\Binn\sq
lservr.exe
" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\
sqlservr.e
xe" -sMSSMLBIZ (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexing
Service.ex
e
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
\nSvcIp.ex
e
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
\nSvcLog.e
xe
O23 - Service: @%SystemRoot%\system32\qwa
ve.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: @%SystemRoot%\system32\sec
logon.dll,
-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: SpywareRemover Scanning Engine (SpywareRemoverSrv) - Unknown owner - C:\Program Files\SpywareRemover\Spywa
reRemover.
srv.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLB
IZ\Binn\sq
lagent.EXE
" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService
.exe
O23 - Service: @%windir%\system32\inetsrv
\iisres.dl
l,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.
exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv
\iisres.dl
l,-20001 (WMSvc) - Unknown owner - %windir%\system32\inetsrv\
wmsvc.exe (file missing)
Start Free Trial