I have a very very bad virus problem on a machine. I have ran bit defender online scanner. I have ran spybot search and destroy. Everytime I clean the machine as soon as I reboot it there are tons of viruses back on it. The viruses are so bad that I cannot even do anything when I boot normally. I basically need to load safemode to do anything (ie cleaning). I need a little bit more assistance in identifying what neds to be removed. I have included a copy of my HiJack this log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54, on 2008-03-01
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuaucl
t.exe
C:\Program Files\Java\jre1.5.0_10\bin
\jusched.e
xe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\System32\wuaucl
t.exe
C:\WINDOWS\System32\rundll
32.exe
C:\WINDOWS\System32\Rundll
32.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\WINDOWS\System32\ICROSO
~1\wuauclt
.exe
C:\Program Files\Common Files\?ssembly\?srss.exe
C:\Program Files\xInsIDE\xInsIDE.exe
C:\Program Files\NoDNS\NoDNS.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn1
\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn1
\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [acbec763] rundll32.exe "C:\WINDOWS\System32\hfvcm
jjq.dll",b
O4 - HKLM\..\Run: [BMaf8df4ff] Rundll32.exe "C:\WINDOWS\System32\chnvm
ddi.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [Dots] "C:\WINDOWS\System32\ICROS
O~1\wuaucl
t.exe" -vt yazb
O4 - HKCU\..\Run: [Ghy] "C:\Program Files\Common Files\?ssembly\?srss.exe"
O4 - HKCU\..\Run: [xInsIDE] C:\Program Files\xInsIDE\xInsIDE.exe
O4 - HKCU\..\Run: [NoDNS] C:\Program Files\\NoDNS\\NoDNS.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_10\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_10\bin
\ssv.dll
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-0
0105A1B41B
8} - C:\WINDOWS\Downloaded Program Files\SbCIe02d.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-0
0aa003c157
a} - C:\WINDOWS\web\related.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprov
au.dll
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsth
elper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2
D05CB95953
7} (MSN Photo Upload Tool) -
http://by125fd.bay125.hotmail.msn.com/resources/MsnPUpld.cabO16 - DPF: {50BD5CDA-4BA8-4048-8FAA-7
63F222E41D
8} - ms-its:mhtml:file://c:\\no
res.mht!
http://adxanet.net/code/chm/xpre.chm::/xpreload.ocxO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D
4730F4EE49
9} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {640B39C1-D713-464F-92C3-7
5BD972B95E
E} -
http://www.sidestep.com/get/k42037/sb02d.cabO16 - DPF: {7D30109B-DD2B-4339-BE80-1
CD48723C2B
C} (LiveX(v6.0.1.0)) -
http://bowwow22.serveftp.com/cab/Live.cab--
End of file - 4336 bytes