I am having problems with malware/virus removal on a Dell Dimension 4600. At first I could not access System Restore or hidden files and folders. I was able to gain control after running Symantec and Spybot. I then ran Symantec, Spybot, and Trendmicro's Houscall on it with System Restore turned off and view hidden files and folders enabled. However on reboot, the Adsense popup program and a foreign language program that had been uninstalled through Add/Remove programs will reappear. Deleted shorcuts to MSDOS also reappear with a new file name. I would just reformat/reinstall XP, but there are documents that need to be recovered if possible. I am currently working on another computer with similar problems. A flashdrive became infected when she copied the documents to it, consequently it is now on two computers. The following is a Hijackthis log. Any help would be greatly appreciated.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:27:41 AM, on 10/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\wuauclt.exe
c:\fgc\fgcrepl.exe
c:\fgc\f101\fgcupd.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntf
y.exe
C:\WINDOWS\system\rundll32
.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system\rundll32
.exe
C:\WINDOWS\Driver.\daemon.
exe
C:\WINDOWS\system32\dla\tf
swctrl.exe
C:\WINDOWS\system32\hkcmd.
exe
C:\WINDOWS\system32\igfxpe
rs.exe
C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\hjt\hjt.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
www.3929.cn?tn=102737R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com/R3 - URLSearchHook: (no name) - - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system\run
dll32.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
32\userini
t.exe,C:\W
INDOWS\sys
tem\rundll
32.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O2 - BHO: Info cache - {285AB8C6-FB22-4D17-8834-0
64E2BA0A6F
0} - C:\WINDOWS\Kler\pbhealth.d
ll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_01\bin
\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\3
.0.1225.98
68\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
swctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpe
rs.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
Service\is
uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [360] C:\WINDOWS\360safe.exe
O4 - HKLM\..\Run: [RavMonS] C:\WINDOWS\soni.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
ger.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\
Run: [explorer] C:\WINDOWS\system32\wuaucl
t.exe
O4 - HKLM\..\Policies\Explorer\
Run: [internetnet] C:\WINDOWS\system32\wuaucl
t.exe
O4 - HKLM\..\Policies\Explorer\
Run: [user] C:\WINDOWS\Driver..\daemon
.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_01\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_01\bin
\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprov
au.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0
E3A5CAA8CD
8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813O16 - DPF: {149E45D8-163E-4189-86FC-4
5022AB2B6C
9} (SpinTop DRM Control) - file://C:\Program Files\SCRABBLE\Images\stg_
drm.ocx
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {215B8138-A3CF-44C5-803F-8
226143CFC0
A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {2D72C39D-53F6-4AEA-A9DB-1
298429DA97
4} (3DVista Viewer Control) -
http://www.3dvista.com/downloads/viewer3dv.cabO16 - DPF: {2DEF4530-8CE6-41C9-84B6-A
54536C9021
3} (Crystal Report Viewer Control 9) -
https://www.etoreports.com/viewer9/activeXViewer/activexviewer.cabO16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsth
elper.dll
O16 - DPF: {55027008-315F-4F45-BBC3-8
BE11976474
1} (Slide Image Uploader Control) -
http://www.slide.com/uploader/SlideImageUploader.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-6
2B522420EC
C} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {77E32299-629F-43C6-AB77-6
A1E6D7663F
6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX27.cabO16 - DPF: {CC450D71-CC90-424C-8638-1
F2DBAC87A5
4} (ArmHelper Control) - file://C:\Program Files\SCRABBLE\Images\armh
elper.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-1
90EE4A9C7F
7} (SproutLauncherCtrl Class) -
http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-7
3DB16A1543
A} (PopCapLoader Object) -
http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cabO16 - DPF: {EA6246B4-F380-443F-8727-9
AEA3371146
C} (CPlayFirstWeddingDashCont
rol Object) -
http://www.playfirst.com/play/game/weddingdash/WeddingDash.1.0.0.44.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{6
ED9273C-2A
83-460A-92
88-82F0B06
C382B}: NameServer = 65.32.1.65
O23 - Service: CtjcKem - Unknown owner - C:\WINDOWS\wuauclt.exe
O23 - Service: FGC Replication (fgcrepl) - Fortres Grand Corporation - c:\fgc\fgcrepl.exe
O23 - Service: Fortres 101 Update (fgcupdate) - Unknown owner - c:\fgc\f101\fgcupd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: Viewpoint Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
--
End of file - 8619 bytes