Hi there,
I got a nasty spyware that installed a number of different malwares and other nasties on my computer. I unplugged the network and ran AVG and MalwareBytes immediately, full scans. I then ran spybot search & destroy after multiple scans of the aforementioned continued to pull up the same problems that it repeatedly repaired.
Unfortunately, now my computer will boot to the windows Xp login screen. However, after selecting a user account --administrator or not-- the computer immediately flashes to that dreaded blue screen, and only for a second or maybe two, before forcing a restart. Rinse and repeat. Thank goodness it still works in safe mode!
I did verify that I do not have two firewalls running at the same time. MalwareBytes and AVG are not turning up any new nasties either. So unplugging the network did that. It's just that now...
Here's my hijack this log. Anyone have any good words of advice?
I'm using an Acer Laptop Aspire 5670, windows XP SP3
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:38:37 PM, on 2/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode with network supportRunning processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\services.exe
C:\WINDOWS\System32\reader_s.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\services.exe
C:\WINDOWS\services.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\services.exe
C:\WINDOWS\services.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\WCSMON.EXE
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\TEMP\init.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: Ask.com Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\Supertoolbar\GenericAskToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA2048] command.com /c del "C:\Program Files\Microsoft Common\svchost.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3602] cmd.exe /c del "C:\Program Files\Microsoft Common\svchost.exe"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [winhpdrv] "C:\Documents and Settings\Brian\Application Data\Google\xtgoj6119471.exe"
O4 - HKCU\..\Run: [a4f7k1ms2wd9jn1fq0czjvf96ys] C:\WINDOWS\TEMP\f43bgsi.exe
O4 - HKCU\..\Run: [oou52bec0uab1bd1d] C:\DOCUME~1\Brian\LOCALS~1\Temp\bdcvdrye.exe
O4 - HKCU\..\Run: [euff70ce9m2iswgruhwyyfhrt] C:\WINDOWS\TEMP\js7mfa6uf0d96.exe
O4 - HKCU\..\Run: [df2j8qd4ta4g2my98vynajl] C:\DOCUME~1\Brian\LOCALS~1\Temp\adv1hb.exe
O4 - HKCU\..\Run: [q4eqr7370maodhgm7clg1qesb7st1bxeqqcd0r] C:\WINDOWS\TEMP\ar1yiursao1dw.exe
O4 - HKCU\..\Run: [mpu1m1i1p0swg4ef8sea35l] C:\WINDOWS\TEMP\ilyau89pmx3cu.exe
O4 - HKCU\..\Run: [o3dbxyay5p8fjs3i16lpne9iy604ducpxw3ag7z5kuzg4rxt8] C:\DOCUME~1\Brian\LOCALS~1\Temp\ws1sw0w1ofe6.exe
O4 - HKCU\..\Run: [btcnfo09evs46e3yvunnahq3q38gxj4h6] C:\DOCUME~1\Brian\LOCALS~1\Temp\bqa1mzlevcl.exe
O4 - HKCU\..\Run: [mfxg6ecuj7jrcr451vqqxof] C:\WINDOWS\TEMP\m6mylpc0q.exe
O4 - HKCU\..\Run: [ogd0kpd52cw4qr7mf859iz6nbr9f3zjym] C:\WINDOWS\TEMP\yyfiqu5.exe
O4 - HKCU\..\Run: [jym4iigub59qlz9h8y82ip0j0z095n48te3f] C:\WINDOWS\TEMP\flpa0pa4dd.exe
O4 - HKCU\..\Run: [pgfquqd8634s07b1j2lpwv6l96ckmt8] C:\WINDOWS\TEMP\o8a133vc7za.exe
O4 - HKCU\..\Run: [drslmieq3l] C:\DOCUME~1\Brian\LOCALS~1\Temp\i7zuolkp.exe
O4 - HKCU\..\Run: [ua7mndy75d0fmey0fiuxm1hn58qd7fiajzcxkpmvnirr19] C:\DOCUME~1\Brian\LOCALS~1\Temp\qztafw7hgt6.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Brian\reader_s.exe
O4 - HKCU\..\Run: [j6cdm587z60u7qyvsbs7efdyr4ml1b4c83] C:\DOCUME~1\Brian\LOCALS~1\Temp\jjbkff.exe
O4 - HKCU\..\Run: [xynlj56721k0fvrvpk6t710aqeybk10] C:\DOCUME~1\Brian\LOCALS~1\Temp\kagi6wf.exe
O4 - HKCU\..\Run: [j0bxwdywgg6topx417lltndyhk8kp7pakdhghbac] C:\DOCUME~1\Brian\LOCALS~1\Temp\rjinzeng6.exe
O4 - HKCU\..\Run: [ay03sj94lvvyylju3a2ev04i0ihu2b] C:\DOCUME~1\Brian\LOCALS~1\Temp\qsdpn7px.exe
O4 - HKCU\..\Run: [ah4lmcflwk3yn0m11fijvcyn4lzykugc7p01ruq82cgkk] C:\DOCUME~1\Brian\LOCALS~1\Temp\fvwqqe.exe
O4 - HKCU\..\Run: [fins5t5jt8qs85895uflamlnpshkbl2rzgzx5w4dqy1zl] C:\DOCUME~1\Brian\LOCALS~1\Temp\xnohvyhfjhu.exe
O4 - HKCU\..\Run: [jveir5u0ko72s66h2dkoyou0nzfwdqa5iik18whu3] C:\DOCUME~1\Brian\LOCALS~1\Temp\qxl9n5waf89cl.exe
O4 - HKCU\..\Run: [xjnlc3b47tc6o] C:\DOCUME~1\Brian\LOCALS~1\Temp\t7gttlwr8.exe
O4 - HKCU\..\Run: [unr1nmmcbrmvm8v94pmyaoqck0y6gzwv] C:\DOCUME~1\Brian\LOCALS~1\Temp\uylrk2xnzm.exe
O4 - HKCU\..\Run: [ey6vw8tzy] C:\DOCUME~1\Brian\LOCALS~1\Temp\lp6xi7sw.exe
O4 - HKCU\..\Run: [jf9nz449tkw7osntj88chqj1khc5kgd6dn9i97] C:\DOCUME~1\Brian\LOCALS~1\Temp\xnuy5fjee.exe
O4 - HKCU\..\Run: [zffb2ap2opau24m75uiwhmk45] C:\DOCUME~1\Brian\LOCALS~1\Temp\emkjord.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB9537] command.com /c del "C:\Program Files\Microsoft Common\svchost.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1170] cmd.exe /c del "C:\Program Files\Microsoft Common\svchost.exe"
O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Chris\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0992 -f video -m logitech -d 11.80.1048.0 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\Chris\reader_s.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0992 -f video -m logitech -d 11.80.1048.0 (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll ozgoui.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: hgGxVOfc - hgGxVOfc.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - c:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IP SEC PROTOCOL POLLER (IPSecPooler) - Unknown owner - C:\WINDOWS\system32\ipsecpooler.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Unknown owner - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: QoS RSVP (RSVP) - Unknown owner - C:\WINDOWS\system32\rsvp.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Performance Logs and Alerts (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe--
End of file - 13693 bytes