This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Seemingly unable to completely clean my system...

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have used Adaware, Spybot, Trend Micro's Housecall, and I still seem to have a buncha carp** on my machine.

Logfile of HijackThis v1.99.1
Scan saved at 1:37:24 PM, on 10/30/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\UGlQ\command.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\ctfmon.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - (no file)
O2 - BHO: (no name) - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - (no file)
O4 - HKLM\..\Run: [cinhrmo] C:\WINDOWS\cinhrmo.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ythgwdd] C:\WINDOWS\ythgwdd.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\kdkgss.exe reg_run
O4 - HKLM\..\Run: [WindowsUpdateNT] C:\WINDOWS\System\svwhost.exe /s
O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mpsegment] C:\WINDOWS\System32\mpsegment.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Explorer32] C:\WINDOWS\System32\efsdfgxg.exe
O4 - HKLM\..\Run: [APD123] C:\WINDOWS\System32\APD123.exe
O4 - HKLM\..\RunServices: [Explorer64] C:\WINDOWS\System32\efsdfgxg.exe
O4 - HKLM\..\RunServices: [mpsegment] C:\WINDOWS\System32\mpsegment.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [irassync] C:\WINDOWS\System32\irasyncd.exe
O4 - HKCU\..\Run: [CMSystem] "C:\Program Files\CMSystem\CMSystem.exe"
O4 - HKCU\..\Run: [aupd] C:\WINDOWS\System32\sysvcs.exe
O4 - HKCU\..\Run: [mpsegment] C:\WINDOWS\System32\mpsegment.exe
O4 - HKCU\..\Run: [WindowsUpdateNT] C:\WINDOWS\System\svwhost.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\UGlQ\command.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

I also have a problem with IE having green links on seemingly random words, and a popup of 1-4 new pages on sites I know for a fact have no popups.

Also, a few relatively new problems…

1. I keep getting Windows Explorer has an encountered a problem and needs to shut down.

2. I also cannot run IE with the desktop shortcut, I have to explore My Computer then type in a web address to be able to surf the net. With the IE shortcut, all I get is a message saying that IE has encountered a problem and needs to shutdown.

3. My desktop has been hijacked and I can't get rid of the 'Spyware Infection' box int he middle of this blue desktop. It's ugly too.

4. The running processes above is not what my machine shows when I first boot up… it's a cleaned version, where I went in and shut down everything I didn't recognize or want.
Some changes have happened since my last post… I no longer get explorer.exe errors, but I do notice that explorer.exe constantly increases in memory size, like it has a memory leak. I got rid of command.exe following instructions from another one of your posts, however, the like still shows up in HJT except with (file missing) at the end. I can start IExplorer from the desktop shortcut again. I got my desktop back.
Hello Sir Geryon, welcome to the forum.

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.


Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Ok, ran the scan(nearly an hour tom complete).

Also, as soon as I returned to normal mode, TeaTimer, the SpyBot resident blocker, started spamming me with attempts from winsync to add itself to global system startup.

Logfile of HijackThis v1.99.1
Scan saved at 7:40:49 PM, on 11/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\CTFMON.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - (no file)
O2 - BHO: (no name) - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O20 - Winlogon Notify: st3 - C:\WINDOWS\system32\st3.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 7:37:42 PM, 11/4/2005
+ Report-Checksum: 7FED5989

+ Scan result:

C:\command.exe -> TrojanDropper.Delf.ev : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\pip@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\PiP\Cookies\[removed][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\99_app99.exe -> TrojanDropper.Agent.xw : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\iA.tmp -> Spyware.SurfSide : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\ICD1.tmp\UWFX5_0001_LP1014NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\k_5BE7.tmp -> Trojan.EliteBar.a : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\maxdd.game -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\pcs_0021.exe -> Spyware.Pacer : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\qvxt3.game -> TrojanProxy.Small.bo : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temp\sntaudio.tmp -> Spyware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\20RMBG35\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\573JP90E\WinFixer2005ScannerInstall[1].cab/UWFX5_0001_LP1014NetInstaller.exe -> Not-A-Virus.Downloader.Agent.d : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\KRTRY2J9\ysb_prompt[1].htm -> TrojanDownloader.IstBar.j : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\PTRV6296\latest[1].exe -> Trojan.Crypt.l : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\PTRV6296\loadppc[1].exe -> Spyware.Zbar : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\PTRV6296\win32[1].exe -> TrojanDownloader.Tibs.q : Cleaned with backup
C:\Documents and Settings\PiP\Local Settings\Temporary Internet Files\Content.IE5\VPH0DAWS\ztoolbar[1].bmp -> Spyware.TNS-Search : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][1].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@affiliates.x10[1].txt -> Spyware.Cookie.X10 : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Gamingpromo : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@cnn.122.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@edge.ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@gamingpromo[1].txt -> Spyware.Cookie.Gamingpromo : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir [removed][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Sir PiP\Cookies\sir pip@yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Sir PiP\Local Settings\Temporary Internet Files\Content.IE5\7RXPP9HY\ibar[1].js -> TrojanDownloader.IstBar.ad : Cleaned with backup
C:\Documents and Settings\Sir PiP\Local Settings\Temporary Internet Files\Content.IE5\7RXPP9HY\prompt[1].htm -> TrojanDownloader.IstBar.j : Cleaned with backup
C:\Documents and Settings\Sir PiP\Local Settings\Temporary Internet Files\Content.IE5\AR8ZP67Y\prompt[1].htm -> TrojanDownloader.IstBar.j : Cleaned with backup
C:\Documents and Settings\Sir PiP\Local Settings\Temporary Internet Files\Content.IE5\AR8ZP67Y\ysb_prompt[1].htm -> TrojanDownloader.IstBar.j : Cleaned with backup
C:\Documents and Settings\Sir PiP\Local Settings\Temporary Internet Files\Content.IE5\YQ61H5GA\ysb_prompt[1].htm -> TrojanDownloader.IstBar.j : Cleaned with backup
C:\hijackthis\backups\backup-20051030-132449-173.dll -> TrojanDownloader.Delf.lh : Cleaned with backup
C:\hijackthis\backups\backup-20051030-132449-555.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\hijackthis\backups\backup-20051030-132449-884.dll -> TrojanDownloader.Delf.h : Cleaned with backup
C:\hijackthis\backups\backup-20051030-214803-124.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\hijackthis\backups\backup-20051102-132144-359-dtdk.exe -> TrojanDownloader.Qoologic.ac : Cleaned with backup
C:\Program Files\Cas\Client\casmf.dll -> Spyware.CASClient : Cleaned with backup
C:\Program Files\CasStub\casstub.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\WINDOWS\adsldpbc.dll -> TrojanDownloader.Delf.lh : Cleaned with backup
C:\WINDOWS\cinhrmo.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\win32.exe -> TrojanDownloader.Tibs.q : Cleaned with backup
C:\WINDOWS\hxruqif.exe -> TrojanDownloader.VB.hj : Cleaned with backup
C:\WINDOWS\q2738468.dll -> TrojanDownloader.Delf.pa : Cleaned with backup
C:\WINDOWS\system\svwhost.exe -> Backdoor.Agent.px : Cleaned with backup
C:\WINDOWS\system32\APD123.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\system32\birdihuy32.dll -> TrojanProxy.Small.ct : Cleaned with backup
C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\WINDOWS\system32\kernels32.exe -> TrojanDownloader.Tibs.q : Cleaned with backup
C:\WINDOWS\system32\mpsegment.exe -> TrojanProxy.Small.bo : Cleaned with backup
C:\WINDOWS\system32\MTE2ODM6ODoxNg.exe -> Spyware.ISearch : Cleaned with backup
C:\WINDOWS\system32\netlanm.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\pshwr.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\rastmon.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\repairs302972949.dll -> Spyware.SurfSide : Cleaned with backup
C:\WINDOWS\system32\vgactl.cpl -> TrojanDownloader.Qoologic.ad : Cleaned with backup
C:\WINDOWS\system32\wuauclt.dll -> TrojanDownloader.Small : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__st3.dll -> TrojanDownloader.Delf.h : Cleaned with backup
C:\WINDOWS\wnrookl.exe -> Spyware.Hijacker.Generic : Cleaned with backup


::Report End
You need To disable TeaTimer until clean.

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts

If TeaTimer still warns about changes, allow the changes.




I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - (no file)
O2 - BHO: (no name) - {95C60327-8E17-44D6-98EB-7EB70CC606DD} - (no file)
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run


Close ALL windows and browsers except HijackThis and click "Fix checked"



Open C:\WINDOWS\System32\ykyipc.exe <–Delete this file
Open C:\WINDOWS\system32\st3.dll <–Delete this file



Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL




Download Registrar Lite from here:
http://www.resplendence.com/download/reglite.exe

Put it in its own folder. You may want to keep this program. It is an excellent free, registry editor.

Copy and paste the follow text into the address bar, then hit 'Go':
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

In the pane on the right are the values associated with that key.
We want to remove this one -> st3

Right click on it, and select delete.
If you get a confirmation question, respond OK then close out the program.


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Done all that was requested that I could.

However, the two files you asked me to go delete are not present in the c:\windows\system32 folder.

As for the way my machine acts afterwards, explorer.exe still increases in memory about every second, and games still have that pause and jump that makes them unplayable, unless I shutdown explorer.exe before I run them. Windows with no desktop icons, taskbar, or start menu sucks. <_<

Here's the new log.

Logfile of HijackThis v1.99.1
Scan saved at 9:44:16 PM, on 11/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\hijackthis\HijackThis.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\wuauclt.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
I suggest you do this:


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run

Close ALL windows and browsers except HijackThis and click "Fix checked"





Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


delete these files if listed:

C:\WINDOWS\System32\ykyipc.exe


Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I always run my machine to show hidden files and known file extensions.

I fixed the requested HJT entry, and rebooted into Safe Mode. I navigated to the system32 folder, and found the file. I right clicked it, selected delete, and was told it was in use. It then disappeared from the list.

I emptied the mentioned Temp and Prefetch folders, but was told a file in \Local Settings\Temp was in use and could not be deleted. It was the only file that could not be. I entered Normal Mode, and I could delete it. It's name is CmdLineExt02.dll. I also told IE to empty its temporary files.

I have noticed my machine seems to boot slow, like it's loading some CPU intensive program on login to Windows.

Explorer.exe is still increasing it's memory usage. Is this related to winsync?

Logfile of HijackThis v1.99.1
Scan saved at 10:10:06 PM, on 11/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Close all windows and browsers.
Open HijackThis

Click on Open Misc Tools
Click on Delete a File On Reboot
Click once on the file below to select it:
C:\WINDOWS\System32\ykyipc.exe



Click on the Back button to exit Process Manager

Now, back at the main screen of HijackThis, proceed to Scan.
and put a check by these.

O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run

Close ALL windows and browsers except HijackThis and click "Fix checked"

Reboot and lets see if it's gone. :thumbup:
Did as asked, but since the file was not actually there and/or visible, I had to enter the command line into the file name box. It said it'd delete it on bootup, and I heard an error sound on bootup, once I logged in, the kind of sound you hear when you try to delete a file and get the 'in use' error.

Logfile of HijackThis v1.99.1
Scan saved at 10:26:37 PM, on 11/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\devldr32.exe
C:\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
click Start>Run and type regedit tap enter key.


Regedit will open. Make sure My Computer is highlighted. At the top of the window click edit> Find> then copy and paste the following into the window.

ykyipc.exe

Then click find now.
When you find the entry right click on it and select delete, answer ok at the prompt.
Next, press "F3" to continue searching, if another instance is found, repeat the above steps, until you see the "completed searching" message.

Reboot and post a new HJT log
Searched the registry, found 2 instances of the file name. I deleted both keys, rebooted, and searched the registry again. Nothing was found.

Logfile of HijackThis v1.99.1
Scan saved at 10:45:25 PM, on 11/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Start Killbox, Use standard file kill.(default settings).
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINDOWS\System32\ykyipc.exe


Back in Killbox go > file > paste from clipboard, now click the red X
that looks like a stop sign, wait until a success message appears.
Repeat those same step's until each file has been deleted.


Note: if a file cannot be deleted [x] check delete on reboot, then go back to
standard file kill for the next file in the list.

When finished exit Killbox and restart your PC.
File was found and deleted. I rebooted, had Killbox check for the file again, it was found again. Tried deleting the file, then fixing the entry in HJT, and rebooted again. File was still present.

Logfile of HijackThis v1.99.1
Scan saved at 11:01:31 PM, on 11/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\imapi.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ykyipc.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695043905
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130695034265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102…all/xscan53.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Copy these instructions into a new text document and leave it open.
Close all unnecessary program's including the Internet connection and all browsers.
Start Killbox, Lower down near the yellow triangle use the drop-down to end each rundll32.exe process.
There can be several end each of them.. use the drop-down again to end the Explorer.exe process.
Your desktop will disappear, thats OK.
Next:
Using standard file kill.(default settings).
Copy this whole list into the windows clipboard, all the Bolded below.


C:\WINDOWS\System32\ykyipc.exe


Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt., wait until a success message appears.
Continue hitting the red button until all files in the list have been deleted.

Now go tools "start explorer shell".

When finished exit Killbox.

You will need to reset your quick-launch toolbar, to do that first right click on the windows taskbar,
in the context menu > toolbars > and uncheck quick-launch, repeat until all are unchecked, now you can again place a check next to it and re-arrange the windows taskbar to your preferences.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI