This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows explorer has encountered a problem

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi LDTate, continuation of a cold thread here
http://forums.whatthetech.com/index.php?sh…st&p=426759
sorry about the lack of activity, I was in a Cornish Vale with no internet access (barely analog TV!)
Problem still remains - a couple of crashes of explorer per day, when switching application that may or may not include explorer. I have run many cleaners, spyware & virus checkers now: Symmantec AV, AVG, Kaspersky, Windows live, Ccleaner, Lavasoft, Spybot S&D, none reporting malicious stuff. Fairly sure it's not an infection, but may be the legacy of one because my main AV (Symmantec Corporate) has contained the exact file but not cleaned up on a previous occasion. AVG did not have real time enabled because SAV did. SAV is paid/licensed so I'll take AVG off now it's expired.
As per your last advice, I now include ATF and Combofix, logs as below. Combofix went straight for instsrv.exe, which I imagine is installed for use by my company's IT dept since I understand this to be a windows file.

ComboFix 08-01-10.2 - r49961 2008-01-10 12:38:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.415 [GMT 0:00]
Running from: E:\Applications\ComboFix\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\instsrv.exe

.
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.

2008-01-10 12:34 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 23:48 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-01-06 23:48 . 2007-07-30 19:18 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2008-01-06 23:48 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-01-06 23:48 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-01-06 23:48 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-01-06 23:48 . 2007-07-30 19:18 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-28 19:46 . 2007-12-28 19:46 d——– C:\Program Files\GetDataBack
2007-12-21 15:08 . 2007-12-21 15:08 d——– C:\Program Files\Canon
2007-12-21 15:07 . 2000-03-24 16:10 271,872 –a—— C:\WINDOWS\system32\UCS32P.DLL
2007-12-21 15:07 . 2000-03-24 16:08 155,648 –a—— C:\WINDOWS\system32\MG600.DLL
2007-12-21 15:07 . 2000-03-24 16:08 98,816 –a—— C:\WINDOWS\system32\FB63UUSD.dll
2007-12-21 15:07 . 2000-03-24 16:18 13,824 –a—— C:\WINDOWS\system32\FB63UCPL.DLL
2007-12-12 09:00 . 2004-08-03 23:08 31,744 –a—— C:\WINDOWS\system32\drivers\wceusbsh.sys
2007-12-12 09:00 . 2004-08-03 23:08 31,744 –a–c— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-12-11 10:12 . 2007-12-11 10:12 d——– D:\Profiles\r49961\Application Data\Grisoft
2007-12-11 10:09 . 2007-12-11 10:09 d——– D:\Profiles\All Users\Application Data\Grisoft
2007-12-11 10:09 . 2007-05-30 12:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 09:03 . 2008-01-09 21:54 d——– D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2007-12-10 15:48 . 2004-08-04 00:56 116,224 –a–c— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-12-10 15:48 . 2001-08-17 22:37 99,865 –a–c— C:\WINDOWS\system32\dllcache\xlog.exe
2007-12-10 15:48 . 2001-08-17 22:37 27,648 –a–c— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-12-10 15:48 . 2001-08-17 22:36 23,040 –a–c— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-12-10 15:48 . 2001-08-17 22:36 17,408 –a–c— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-12-10 15:48 . 2001-08-17 12:11 16,970 –a–c— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-12-10 15:48 . 2001-08-17 22:37 4,608 –a–c— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-12-10 15:46 . 2004-08-03 21:32 571,392 –a–c— C:\WINDOWS\system32\dllcache\tintlgnt.ime
2007-12-10 15:45 . 2001-08-17 22:36 495,616 –a–c— C:\WINDOWS\system32\dllcache\sblfx.dll
2007-12-10 15:44 . 2001-08-17 13:28 899,146 –a–c— C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2007-12-10 15:43 . 2001-08-17 14:05 351,616 –a–c— C:\WINDOWS\system32\dllcache\ovcodek2.sys
2007-12-10 15:42 . 2001-08-23 13:00 1,875,968 –a–c— C:\WINDOWS\system32\dllcache\msir3jp.lex
2007-12-10 15:41 . 2001-08-17 13:28 802,683 –a–c— C:\WINDOWS\system32\dllcache\ltsm.sys
2007-12-10 15:40 . 2001-08-23 13:00 1,158,818 –a–c— C:\WINDOWS\system32\dllcache\korwbrkr.lex
2007-12-10 15:40 . 2001-08-17 22:36 242,176 –a–c— C:\WINDOWS\system32\dllcache\kdsusd.dll
2007-12-10 15:40 . 2004-08-03 23:00 87,424 –a–c— C:\WINDOWS\system32\dllcache\irda.sys
2007-12-10 15:40 . 2001-08-23 13:00 70,656 –a–c— C:\WINDOWS\system32\dllcache\korwbrkr.dll
2007-12-10 15:40 . 2001-08-17 22:36 45,568 –a–c— C:\WINDOWS\system32\dllcache\kdsui.dll
2007-12-10 15:40 . 2001-08-17 22:36 37,376 –a–c— C:\WINDOWS\system32\dllcache\kousd.dll
2007-12-10 15:40 . 2001-08-17 13:49 26,624 –a–c— C:\WINDOWS\system32\dllcache\irstusb.sys
2007-12-10 15:40 . 2001-08-17 13:49 23,552 –a–c— C:\WINDOWS\system32\dllcache\irmk7.sys
2007-12-10 15:40 . 2001-08-17 13:51 18,688 –a–c— C:\WINDOWS\system32\dllcache\irsir.sys
2007-12-10 15:38 . 2001-08-23 13:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2007-12-10 15:37 . 2001-08-17 14:56 1,733,120 –a–c— C:\WINDOWS\system32\dllcache\g400d.dll
2007-12-10 15:36 . 2001-08-17 12:14 952,007 –a–c— C:\WINDOWS\system32\dllcache\diwan.sys
2007-12-10 15:35 . 2001-08-23 13:00 1,677,824 –a–c— C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-10 15:34 . 2001-08-17 13:28 762,780 –a–c— C:\WINDOWS\system32\dllcache\3cwmcru.sys
2007-12-10 15:33 . 2001-08-17 14:56 66,048 –a–c— C:\WINDOWS\system32\dllcache\s3legacy.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 12:42 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-01-07 23:12 ——— d—–w C:\Program Files\CCleaner
2008-01-06 17:12 ——— d—–w C:\Program Files\lx_cats
2007-12-27 16:16 ——— d—–w C:\Program Files\Paint Shop Pro 5
2007-12-17 21:29 ——— d—–w D:\Profiles\r49961\Application Data\Skype
2007-12-01 10:23 ——— d—–w C:\Program Files\DC++
2007-11-28 12:21 ——— d—–w C:\Program Files\Lexmark
2007-11-28 11:33 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-28 11:28 ——— d—–w C:\Program Files\patches
2007-11-27 14:05 ——— d—–w D:\Profiles\All Users\Application Data\Kaspersky Lab
2007-11-18 16:57 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-11-18 16:57 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-11-18 16:31 ——— d—–w C:\Program Files\Motorola Phone Tools
2007-11-18 16:30 ——— d—–w C:\Program Files\Common Files\Motorola Shared
2007-11-18 16:29 92,064 —-a-w D:\Profiles\r49961\mqdmmdm.sys
2007-11-18 16:29 9,232 —-a-w D:\Profiles\r49961\mqdmmdfl.sys
2007-11-18 16:29 79,328 —-a-w D:\Profiles\r49961\mqdmserd.sys
2007-11-18 16:29 66,656 —-a-w D:\Profiles\r49961\mqdmbus.sys
2007-11-18 16:29 6,208 —-a-w D:\Profiles\r49961\mqdmcmnt.sys
2007-11-18 16:29 5,936 —-a-w D:\Profiles\r49961\mqdmwhnt.sys
2007-11-18 16:29 4,048 —-a-w D:\Profiles\r49961\mqdmcr.sys
2007-11-18 16:29 25,600 —-a-w D:\Profiles\r49961\usbsermptxp.sys
2007-11-18 16:29 22,768 —-a-w D:\Profiles\r49961\usbsermpt.sys
2007-11-18 10:41 ——— d—–w D:\Profiles\All Users\Application Data\BVRP Software
2007-11-18 10:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-18 10:39 22,768 —-a-w C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-11-18 10:12 ——— d—–w C:\Program Files\LiveUpdate
2007-11-17 16:20 ——— d—–w D:\Profiles\r49961\Application Data\Acronis
2007-11-12 20:34 ——— d—–w D:\Profiles\All Users\Application Data\DVD Shrink
2007-11-12 00:16 ——— d—–w C:\Program Files\illiminable
2007-10-23 04:12 121,038 —-a-w C:\WINDOWS\Clean_Messenger.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-10-24 18:05 4687352]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 17:35 3900776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Blocker"="C:\Program Files\Internet Explorer\Iereg.exe" [2005-06-14 13:29 111218]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-26 20:30 282624]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 17:33 48800]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2006-05-27 03:51 85744]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 22:44 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 22:41 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 22:45 118784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 14:58 1032192]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 11:56 569413]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 19:13 176128]
"HRHCM"="C:\Program Files\Internet Explorer\PLUGINS\iemod.exe" [2005-12-20 15:31 111107]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-16 21:12 1164912]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 21:17 1941784]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 21:13 87584]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2005-12-01 18:38 65536]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:56 15360]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 17:35 3900776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Media"= 0 (0x0)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"Btn_PrintPreview"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSetActiveDesktop"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

R2 AMBroker;Access Manager Configuration Service;"C:\Program Files\AccessManager\Client\AMBroker.exe" [2004-11-03 08:45]
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2006-02-09 02:50]
R2 Sygman;SSA Integration Manager;"C:\Program Files\AccessManager\Client\sygman.exe" [2004-11-03 08:48]
R3 lxcy_device;lxcy_device;C:\WINDOWS\system32\lxcycoms.exe [2006-02-20 19:23]
R3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2006-02-09 02:50]
S0 black;black;C:\WINDOWS\system32\drivers\BlackDrv.sys []
S3 DAPlugin;Visual Insight DA Plugin;C:\Program Files\AccessManager\Client\DAPlugin.exe [2004-11-03 08:56]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-02-27 14:31]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]
S3 sp_spi_da;Visual Insight Dial Analysis;C:\Program Files\AccessManager\SMOC\spi_da.exe [2004-10-15 16:40]
S4 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-05-07 21:11]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##msiadmin.freescale.net#MSIADMIN#SMSPKG#Office2003#source]
\Shell\AutoRun\command - Y:\setuppro.EXE /AUTORUN
\Shell\configure\command - Y:\setuppro.EXE
\Shell\install\command - Y:\setuppro.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999-999-99-FSL-OfficeCommunicator-ENG-manual}]
"C:\Program Files\Microsoft Office Communicator\CurrentKeys.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-2K3}]
C:\WINDOWS\SAFE_Sender_FSL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-IMRemoval}]
"C:\WINDOWS\Clean_Messenger.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-NETMEETING}]
C:\WINDOWS\FSLnetmeeting.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-EZCD52}]
C:\WINNT\System32\REGEZCD5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-IE6SP1}]
C:\WINDOWS\MotIESet6_SP1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0-0-0-0-MOT-IE6FreeScale}]
C:\WINDOWS\ieproxy.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0-0-0-0-MOT-IE6PRE}]
C:\WINDOWS\MotIESet6_pre.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9D467580-AF3D-4e3c-8893-4F29CB100EB2}]
"C:\WINDOWS\SAVasetup.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-10 12:42:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-10 12:46:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 12:46:04
.
2008-01-09 08:22:31 — E O F —





Logfile of HijackThis v1.99.1
Scan saved at 13:09:50, on 10/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.freescale.net:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.freescale.net;freescale.net;*.mot.com;
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Blocker] "C:\Program Files\Internet Explorer\Iereg.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [HRHCM] "C:\Program Files\Internet Explorer\PLUGINS\iemod.exe" /s
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126394220883
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163431684203
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-emea.freescale.net/ConferencingBin/xcliacc.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = emea.freescale.net,sps.mot.com,am.freescale.net,ap.freescale.net,fsl.freescale.n
et,freescale.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = emea.freescale.net,sps.mot.com,am.freescale.net,ap.freescale.net,fsl.freescale.n
et,freescale.net
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Thanks for looking,
Mike
You need to get the latest combofix.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    Only after the above:


    Download ComboFix from Here to your Desktop.

    **Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
    ——————————————————————–
    • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
    • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
    • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
    ——————————————————————–

    Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
    Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

    ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

    *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI