Performed an XP system repair due to the Administrator Account having an unknown password
along with Windows Explorer having multiple issues:
Open Containing Folder - not working
Find Target - not working
Explorer columns random view changes.
These all seem to be repaired and working fine.
Now Windows Updates are all returning as failed.
A program named FileAlyzer is also not working properly even after re installation.
I feel/fear the problem is deeper than it first appeared.
Any Help is greatly appreciated. Thank YOU!
==
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3555 (20081025)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=9ef4f4ab36fa664eb867b1462d9d6763
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-10-25 10:36:58
# local_time=2008-10-25 03:36:58 (-0700, US Mountain Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=1278697
# found=6
# scan_time=39104
D:\1downLOADS\corsair\DELL\registryWorkshp.rar Win32/Agent.OBH trojan 9DBC6E4A3042679CA2EC847E008AEF1F
D:\1downLOADS\corsair\DELL\registryWorkshp.rar »RAR »registry.workshop.v3.1.0.patch.exe Win32/Agent.OBH trojan 00000000000000000000000000000000
D:\ADOBE\ADOBEkeys2008.rar probably a variant of Win32/IRCBot trojan 2698C816923FB3F5642CE12B3351BB06
D:\ADOBE\ADOBEkeys2008.rar »RAR »Photoshop Extended CS3 Keygen.exe probably a variant of Win32/IRCBot trojan 00000000000000000000000000000000
D:\CORSAIR\03_2008\registryWorkshp.rar Win32/Agent.OBH trojan 9DBC6E4A3042679CA2EC847E008AEF1F
D:\CORSAIR\03_2008\registryWorkshp.rar »RAR »registry.workshop.v3.1.0.patch.exe Win32/Agent.OBH trojan 00000000000000000000000000000000
==
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:56:00 PM, on 10/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Alwil Software\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [BOC-427] C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\HJT\HijackThis.exe /startupscan
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - [url]http://www.pcpitstop.com/betapit/PCPitStop.CAB[/url]
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - [url]http://www.eset.eu/buxus/docs/OnlineScanner.cab[/url]
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - [url]http://support.f-secure.com/ols/fscax.cab[/url]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [url]http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab[/url]
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BDXGFUPNQQ - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\BDXGFUPNQQ.exe (file missing)
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: BUXODPXTQ - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\BUXODPXTQ.exe (file missing)
O23 - Service: BZJPK - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\BZJPK.exe (file missing)
O23 - Service: CE - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\CE.exe (file missing)
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: ERQ - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\ERQ.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: GRTBECJBMJHD - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\GRTBECJBMJHD.exe (file missing)
O23 - Service: IDQDCN - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\IDQDCN.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IKGV - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\IKGV.exe (file missing)
O23 - Service: MZ - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\MZ.exe (file missing)
O23 - Service: NDHADWU - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\NDHADWU.exe (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: UIZRHZSE - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\UIZRHZSE.exe (file missing)
O23 - Service: UWNBSAORUC - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\UWNBSAORUC.exe (file missing)
O23 - Service: VKCMBC - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\VKCMBC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: XJYQNQLPYGIDLF - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\XJYQNQLPYGIDLF.exe (file missing)
O23 - Service: YMXVTZERQ - Unknown owner - C:\DOCUME~1\mstihkal333\Local Settings\Temp\YMXVTZERQ.exe (file missing)
--
End of file - 6209 bytes