I have an XP pro workstation, and seems to be infected with some adware or spyware that i cannot shift with the usual spyware removers "ada aware" etc but keep getting various ad pop ups and trojan detections, our virus software will deal with those but not the underlying problem. Another thing i have to load explorer as a new task when my user logs in. My HJ log file as follows.
Many Thanks
Paul
Logfile of HijackThis v1.99.1
Scan saved at 17:08, on 07/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Lavasoft\Ad-Aware\aa
wservice.e
xe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileA
gent.exe
C:\Program Files\Bonjour\mDNSResponde
r.exe
C:\Program Files\McAfee\Common Framework\FrameworkService
.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\RealVNC\VNC4\WinVNC4
.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
E
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\WINDOWS\system32\rundll
32.exe
C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.1128.54
62\GoogleT
oolbarNoti
fier.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
E
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\pmcguire\Desktop\
HijackThis
.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.google.co.ukR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.google.co.ukO2 - BHO: (no name) - {36AEF43F-7EC7-40E5-9D82-7
0FC86CDB91
9} - C:\WINDOWS\system32\xxyvSK
aW.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
309F01C523
1} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5
164760863C
6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: (no name) - {B6E95516-27C0-443D-9BA9-A
BD8C12BAE1
6} - C:\WINDOWS\system32\nNEtqR
iJ.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: {0c21efbb-e444-0f9a-9f74-a
73325feb2c
f} - {fc2bef52-337a-47f9-a9f0-4
44ebbfe12c
0} - C:\WINDOWS\system32\vofksn
.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
ync.exe /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EX
E
O4 - HKLM\..\Run: [ac3f3e32] rundll32.exe "C:\WINDOWS\system32\hphye
ovy.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\1
.2.1128.54
62\GoogleT
oolbarNoti
fier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
" /background
O4 - HKCU\..\Run: [WISE-FTP Task Planner] "C:\Program Files\AceBIT\WISE-FTP 5\wf_tp.exe" /bg
O4 - Startup: AdsGone.lnk = Program Files\AdsGone\AdsGone.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.h
tm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\pmcguire\Applicat
ion Data\Dealio\kb124\res\Deal
ioSearch.h
tml
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O14 - IERESET.INF: START_PAGE_URL=
http://www.google.co.ukO16 - DPF: {485D813E-EE26-4DF8-9FAF-D
EDF2885306
E} (NSHelp Class) -
http://192.168.77.2/ConnectComputer/nshelp.dllO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D
4730F4EE49
9} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-0
4C2F616BCA
7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cabO16 - DPF: {D8089245-3211-40F6-819B-9
E5E92CD61A
2} (FlashXControl Object) -
https://flashcasino.ladbrokes.com/instant-play-en/FlashAX.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = RallsBuilders.local
O17 - HKLM\Software\..\Telephony
: DomainName = RallsBuilders.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = RallsBuilders.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\WINDOW~4\MESSE
N~1\MSGRAP
~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8
E305202313
F} - C:\PROGRA~1\WINDOW~4\MESSE
N~1\MSGRAP
~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxde
v.dll
O20 - Winlogon Notify: nNEtqRiJ - C:\WINDOWS\SYSTEM32\nNEtqR
iJ.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aa
wservice.e
xe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0
) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileA
gent.exe
O23 - Service: ##Id_String1.6844F930_1628
_4223_B5CC
_5BB94B879
762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
ice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService
.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\XEClient\BIN\omtsreco.e
xe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksL
icensing.e
xe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4
.exe" -service (file missing)