I have Xp antivirus 2008 that a customer installed on there PC. I have a hijack log and I attemped to run e Remover It did find somethings but I could not get updates so it still exists. I can get to task manager but all of the system restore dates have been wiped out or it. Running Xp media center with Ca antivirus and spyware
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:17 AM, on 7/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Bonjour\mDNSResponde
r.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\eHome\ehRecvr.e
xe
C:\WINDOWS\eHome\ehSched.e
xe
C:\Program Files\CA\SharedComponents\
PPRT\bin\I
TMRTSVC.ex
e
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\WINDOWS\system32\IoctlS
vc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\ehome\ehtray.ex
e
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe
C:\Program Files\Canon\CAL\CALMAIN.ex
e
C:\Program Files\Dell AIO Printer 946\dlcimon.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\WINDOWS\system32\wscntf
y.exe
C:\PROGRA~1\MYWEBS~1\bar\1
.bin\m3Src
hMn.exe
C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwsoe
mon.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActivePro
tection.ex
e
C:\WINDOWS\eHome\ehmsas.ex
e
C:\WINDOWS\system32\lphcj9
9j0ep8v.ex
e
C:\Program Files\rhcn99j0ep8v\rhcn99j
0ep8v.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStor
eSvr.exe
C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dlcico
ms.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\3M\PSN2Lite\Psn2Lite
.exe
C:\WINDOWS\system32\dlcjco
ms.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\PROGRA~1\3M\PSN2Lite\PS
NGive.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingS
ervice.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\dllhos
t.exe
C:\WINDOWS\system32\taskmg
r.exe
E:\HiJackThis.exe
C:\WINDOWS\system32\rundll
32.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer,SearchURL =
http://internetsearchservice.comR1 - HKLM\Software\Microsoft\In
ternet Explorer,SearchURL =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://internetsearchservice.com/ie6.htmlR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://internetsearchservice.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.toggle.com/en/index.php?rvs=hompag&d=79919372R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://internetsearchservice.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://internetsearchservice.com/ie6.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://internetsearchservice.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://internetsearchservice.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://internetsearchservice.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Search,Default_Pa
ge_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6061207R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5
838F569A31
D} - C:\Program Files\MyWebSearch\SrchAstt
\1.bin\MWS
SRCAS.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-1
70DE4475CC
A} - C:\Program Files\MyWebSearch\bar\1.bi
n\MWSBAR.D
LL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.ex
e
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTA
L~1\UPDATE
~1\ISUSPM.
exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\DLC
Itime.dll,
_RunDLLEnt
ry@16
O4 - HKLM\..\Run: [dlcimon.exe] "C:\Program Files\Dell AIO Printer 946\dlcimon.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1
.bin\M3PLU
GIN.DLL,UP
F
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\
1.bin\m3Sr
chMn.exe" /m=0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwsoe
mon.exe
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\DLC
Jtime.dll,
_RunDLLEnt
ry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.e
xe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Jigsaw] C:\DOCUME~1\Kelsey\LOCALS~
1\Temp\391
3574.exe
O4 - HKLM\..\Run: [lphcj99j0ep8v] C:\WINDOWS\system32\lphcj9
9j0ep8v.ex
e
O4 - HKLM\..\Run: [SMrhcn99j0ep8v] C:\Program Files\rhcn99j0ep8v\rhcn99j
0ep8v.exe
O4 - HKLM\..\Run: [DelayLoad] C:\DOCUME~1\Kelsey\LOCALS~
1\Temp\atm
adm2.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwsoe
mon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C
6C-4d9f-84
C7-88D8A56
B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStor
eSvr.exe" ASO-616B5711-6DAE-4795-A05
F-39A1E510
4020
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKCU\..\Policies\Explorer\
Run: [EPRmS6RUlW] C:\Documents and Settings\All Users\Application Data\lavorebg\hifwjmzq.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSN2Lite\Psn2Lite
.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm458NYUSO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_06\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_06\bin
\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MI1933~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprov
au.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-3
14DEE697D8
3} (Facebook Photo Uploader 5) -
http://upload.facebook.com/controls/FacebookPhotoUploader5.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cabO16 - DPF: {406B5949-7190-4245-91A9-3
0A17DE16AD
0} (Snapfish Activia) -
http://www2.snapfish.com/SnapfishActivia.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-6
2B522420EC
C} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0
001023E6D5
A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterfly.com/downloads/Uploader.cabO20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
1\GOEC62~1
.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.ex
e
O23 - Service: dlci_device - - C:\WINDOWS\system32\dlcico
ms.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco
ms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
ice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\
PPRT\bin\I
TMRTSVC.ex
e
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwssv
c.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingS
ervice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlS
vc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
--
End of file - 12970 bytes
Start Free Trial