Cannot remove virus. The same registry entry (seen as the 04 entry in the HijackThis log below) I remove in safe mode comes back in normal mode. I´ve ran SmitFraud, SDFix, ComboFix, Spybot, Kapersky online, VundoFix, FixVundo, VundoBeGone (or something like that), WebRoot SpySweeper, and more. I´ve ran HijackThis and removed all the 016s, but I see some there now-don´t think they are the problem. I´ve manually removed the 04 item show in the log below, as well as other suspect items in the registry, but it keeps coming back after I reboot in normal mode. In fact, in normal mode, if I delete from regedit, close regedit and re-open it, it´s already back in there and in msconfig as a startup item. WHAT RUNS THAT WILL AUTOMATICALLY RE-ENTER IS IN MSCONFIG? I cannot find it in C:Windows or in the System32 folder. Should I try superantispyware or malwarebytes? Something is running automatically and it seems like I should be able to find it. Any suggestions? I get rid of viruses all the time for clients, so I´m fairly savy, but cannot get rid of this one. Here is the HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:13, on 9/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Intel\Wireless\Bin\E
vtEng.exe
C:\Program Files\Intel\Wireless\Bin\S
24EvMon.ex
e
C:\Program Files\Intel\Wireless\Bin\W
LKeeper.ex
e
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Bonjour\mDNSResponde
r.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLic
ensing.exe
C:\WINDOWS\eHome\ehRecvr.e
xe
C:\WINDOWS\eHome\ehSched.e
xe
c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
c:\PROGRA~1\mcafee.com\vso
\mcvsrte.e
xe
C:\WINDOWS\system32\HPZipm
12.exe
C:\Program Files\Intel\Wireless\Bin\R
egSrvc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\Search
Indexer.ex
e
C:\WINDOWS\system32\dllhos
t.exe
C:\WINDOWS\system32\wscntf
y.exe
C:\Program Files\Intel\Wireless\bin\Z
CfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\i
frmewrk.ex
e
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\PROGRA~1\Intel\Wireless
\Bin\Dot1X
Cfg.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\explorer.exe
C:\Documents and Settings\reyes viguerias\Desktop\HiJackTh
is.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://home.netscape.com/home/winsearch200.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://keyword.netscape.com/keyword/%sR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\Program Files\Yahoo!\Common\yiesrv
c.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
05236F6F65
5} - c:\progra~1\mcafee.com\vso
\mcvsshl.d
ll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-6
4B5B4FF55D
0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MCUpdateExe] "C:\PROGRA~1\mcafee.com\ag
ent\McUpda
te.exe"
O4 - HKLM\..\Run: [MCAgentExe] "c:\PROGRA~1\mcafee.com\ag
ent\mcagen
t.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\Z
CfgSvc.exe
"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\i
frmewrk.ex
e" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [3c536e43] rundll32.exe "C:\WINDOWS\system32\qsbqj
uml.dll",b
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpct
r\Binaries
\MSCONFIG.
EXE /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmo
n.exe"
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\Program Files\Yahoo!\Common\yiesrv
c.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - D:\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D
4730F4EE49
9} -
O16 - DPF: {5ED80217-570B-4DA9-BF44-B
E107C0EC16
6} -
O16 - DPF: {8731163E-77B9-4F91-9122-F
112521C28A
F} -
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C
5B2B409087
6} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLic
ensing.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\E
vtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso
\mcshield.
exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
nt\mcupdmg
r.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso
\mcvsrte.e
xe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\R
egSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S
24EvMon.ex
e
O23 - Service: Motor de Spy Sweeper de Webroot (WebrootSpySweeperService)
- Webroot Software, Inc. (
www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\W
LKeeper.ex
e
--
End of file - 7260 bytes
Start Free Trial