I can't get my icons and explorer.exe to run. I 've read a bunch of different forums but I may be in the wrong order so far I've
- ran ad-aware, spybot, McAfee and AVG anti-virus and anti-spyware they are finding trojans but they keep coming back
- tried a second profile
- tried turning off active desktop
- tried deleting suspicious .exe out of the registry's run file
here are the logs for AVG and hijackthis ran in safemode...it won't run in normal mode
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:20:18 PM 5/25/2007
+ Scan result:
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP267\A0032129.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP267\A0032130.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP267\A0032132.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINNT\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINNT\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0032042.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP267\A0032078.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP267\A0032079.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP271\A0034381.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP271\A0034382.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0031991.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0031999.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP267\A0032131.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\WINNT\SYSTEM32\T2\dlb66.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\WINNT\SYSTEM32\T2\dlb66.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\WINNT\SYSTEM32\T2\dlb66.exe/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0032044.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0032053.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP271\A0034397.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP271\A0034398.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINNT\SYSTEM32\twinsndv.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Application Data\tmp2A.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Application Data\tmp2B.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\A18ZMDE5\rellatsnitneilc22_05[1] -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0031919.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Local Settings\Temp\tni23.tmp -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@cupolaventures.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@techrepublic.com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@adopt.specificclick[3].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@m.webtrends[3].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@m.webtrends[4].txt -> TrackingCookie.Webtrends : Cleaned.
C:\WINNT\sammy3.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0032052.exe -> Trojan.BHO.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0031992.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP266\A0032055.exe -> Trojan.Tibs.aa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0A7AC40F-8F52-416B-97DA-5B4322463791}\RP271\A0034379.exe -> Trojan.Tibs.aa : Cleaned with backup (quarantined).
C:\WINNT\SYSTEM32\dlh9jkd1q7.exe -> Trojan.Tibs.aa : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 3:18:55 PM, on 5/26/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\HJT\analyzehis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} -
C:\WINNT\System32\fcccbba.dll (file missing)
O2 - BHO: (no name) - {3FA12F5F-0431-495C-A26A-54335796C5B2} -
C:\WINNT\System32\qopmj.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {691caa4d-7edb-4243-9a40-c683c6131456} -
C:\WINNT\system32\mprsvc.dll
O2 - BHO: (no name) - {6FE1E89A-0D0C-4701-B2F3-5B682B263E70} -
C:\WINNT\System32\jdaqowwc.dll (file missing)
O2 - BHO: (no name) - {A24B57F8-505D-4fc5-9960-740E304D1ABA} -
C:\WINNT\System32\tmp29.tmp.dll
O2 - BHO: 0 - {C29735EF-12F3-4F5D-C586-966CBCFD6984} - C:\Program
Files\ComPlus Applications\quda.dll (file missing)
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -
C:\WINNT\System32\dnsersnd.dll (file missing)
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} -
C:\WINNT\System32\nzdd.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [setup] rundll32.exe
"C:\WINNT\System32\wreqpihw.dll",realset
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network
Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network
Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program
Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie
Washer\washidx.exe "Administrator"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate]
C:\WINNT\System32\Macromed\Flash\GetFlash.exe
O4 - Startup: TA_Start.lnk = C:\WINNT\SYSTEM32\dwdsregt.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program
Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Encarta Encyclopedia -
{2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia -
{2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common
Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} -
C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37}
- C:\Program Files\Common Files\Microsoft Shared\Reference
2001\A\ERS_DEF.HTM
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINNT\System32\Shdocvw.dll
O20 - Winlogon Notify: fcccbba - fcccbba.dll (file missing)
O20 - Winlogon Notify: mprsvc - C:\WINNT\SYSTEM32\mprsvc.dll
O20 - Winlogon Notify: qopmj - C:\WINNT\System32\qopmj.dll
O20 - Winlogon Notify: winzxe32 - winzxe32.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner -
C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network
Associates, Inc. - C:\Program Files\Network Associates\Common
Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates,
Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network
Associates, Inc. - C:\Program Files\Network
Associates\VirusScan\vstskmgr.exe
O23 - Service: Net Agent - Unknown owner - C:\WINNT\dls0523pmw.exe (file
missing)
please help