O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O23 - Service: AntipyPro_12 (AntipPro2009_12) - Unknown owner - C:\WINDOWS\svchast.exe
Delete those.
Main Topics
Browse All TopicsHere is the log file from Hijack This, I can't get this infestation of Windows Antivirus off my XP machine, anyone see the problem here?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:06:27 PM, on 8/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\svchast.exe
C:\Program Files\Broadcom\ASFIPMon\As
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\system32\nvsvc3
C:\WINDOWS\system32\svchos
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\blp\API\Office Tools\Bloomberg.UIServer.e
C:\blp\API\Office Tools\Bloomberg.RtdServer.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmg
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\wuaucl
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CLRHost] C:\blp\API\Office Tools\bbxlcmd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKUS\S-1-5-21-3486897370-2
O4 - HKUS\S-1-5-21-73586283-879
O4 - HKUS\S-1-5-18\..\Run: [minix32] C:\WINDOWS\system32\minix3
O4 - HKUS\.DEFAULT\..\Run: [minix32] C:\WINDOWS\system32\minix3
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CS1\Services\T
O23 - Service: AntipyPro_12 (AntipPro2009_12) - Unknown owner - C:\WINDOWS\svchast.exe
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\As
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
--
End of file - 4582 bytes
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Run Combofix using this tutorial and it should clean up the rest of the problem. Malwarebytes or spybot S&D should also be run just in case.
http://www.bleepingcompute
CAM.com is an adult webcame site that usually is a result of a spyware infection redirecting you to it. It has no business being in the tcpip or domain parameters.
AntipyPro is a spyware/malware program and is names svchAst.exe to make it look like a normal running program svchost.exe. It needs to be deleted.'
Combofix and malwarebytes are both known to remove these infections.
CAM.com is the "Cambridge Computer Corporation". It's no spyware at all.
You are right with Antipypro. Removal process is described at http://www.bleepingcompute
Go to http://www.techmixer.com/k
I ran them both in safe mode. It can't seem to delete some sort of rootkit (as it is called when I scan in anti-malware). The name of the file is: c:\windows\system32\driver
Also, now I am getting bluescreens with error STOP:0x0000008e after I type my login and can only get into the computer with safe mode or with the last known working configuration option.
On the plus side the pop-up screens are gone.
Combofix script function should take care of it.
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------
File::
c
c:
c:\
c:\w
c:
c:\window
c:\documents and settings\rsmithline\Applic
c:\wind
c:\docu
c:\docu
c:\wind
c:\wind
Folder:
c:\progra
Driver::
AntipPro2009_12
zqpohgnly
R
c:
c:\windows\system32\driver
-
3. Save the above as CFScript.txt in the --> C:\ in the same location as Combofix.exe
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
Business Accounts
Answer for Membership
by: gtworekPosted on 2009-08-03 at 09:11:32ID: 25005765
Looks pretty well.