This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Taskbar, Desktop, and Windows Explorer Continually reset

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

A few weeks ago, my computer started experiencing issues where upon startup/reboot, windows explorer would reset every 5 to 10 seconds. The taskbar and desktop would disappear (as would windows explorer), but I could still use other programs such as internet explorer. I've worked for a few days on identifying and fixing the issue with no luck. I thought I may have an issue with my Intel Wireless card, so I disabled it. This did not help the situation and actually indicates that the wireless program is not longer available.

I'm pretty sure I have a virus or worm, but do not know how to identify or fix it. I do and did have an up to date virus program (McAffee's). I am running Windows XP. Here are the results of Hijackthis. I would appreciate any help that someone could provide.

Logfile of HijackThis v1.99.1
Scan saved at 2:11:14 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\DWRCS.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Service\pushnow\pushnow.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINNT\system32\SUSS.EXE
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\DWRCST.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\imapi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.corp.sprint.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://iconnect.nextel.com/ic.shtml?TYPE=3…tel.com/portal/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://i-connect.corp.sprint.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sprint Nextel
F3 - REG:win.ini: load=C:\WINNT\system32\ssttq.exe
O4 - HKLM\..\Run: [SocketComm] SCTray.Exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [runner1] C:\WINNT\mrofinu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe"
O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O14 - IERESET.INF: START_PAGE_URL=http://i-connect.corp.sprint.com/
O15 - Trusted Zone: *..nnet
O15 - Trusted Zone: *.mms.sprintpcs.com
O15 - Trusted Zone: *.nws.sprintpcs.com
O15 - Trusted Zone: *.upl.sprintpcs.com
O15 - Trusted Zone: *.xsam.sprintpcs.com
O15 - Trusted Zone: *.nmcc.sprintspectrum.com
O15 - Trusted Zone: *.stic.sprintspectrum.com
O15 - Trusted Zone: *..nnet (HKLM)
O15 - Trusted Zone: *.mms.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.nws.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.upl.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.xsam.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.nmcc.sprintspectrum.com (HKLM)
O15 - Trusted Zone: *.stic.sprintspectrum.com (HKLM)
O15 - Trusted IP range: 10.0-63.*
O15 - Trusted IP range: 10.248-255.*
O15 - Trusted IP range: 172.16-31.*.*
O15 - Trusted IP range: 192.168.*.*
O15 - Trusted IP range: 10.0-63.* (HKLM)
O15 - Trusted IP range: 10.248-255.* (HKLM)
O15 - Trusted IP range: 172.16-31.*.* (HKLM)
O15 - Trusted IP range: 192.168.*.* (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199425720937
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\Software\..\Telephony: DomainName = ad.sprint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O18 - Filter: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\system32\DWRCS.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: OSCM Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
O23 - Service: PictureTaker - LANovation - C:\WINNT\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: Sprint_Push_Now (PushNow) - Sprint FS SD - C:\Service\pushnow\pushnow.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sygate Security Agent (SmcService) - Unknown owner - C:\Program Files\Sygate\SSA\smc.exe (file missing)
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


Thanks for any help you can provide! I would like to at least get temporary access to move my critical files.
I haven't received a response to this post and have been unable to resolve the issue. I do think it is a virus as some weird browsers pop up every now and then. Can someone review my HijackThis log and assist? Thanks, sevi23
[external image: Posted Image]

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
Please post the results log and post a new HijackThis log.
That cleaned alot of issues up. Explore no longer disappears! A virus was found and cleaned in memory modules and in mulitple files on the harddrive. However, I still have a virus somewhere. It has wiped out alot of my programs such as wireless service and has infected SHSTAT.EXE in my virus scanner. My virus scanner cleaned additional viruses, but it will not clean SHSTAT.EXE. It just indicates that is has a virus. Then, I reran the MalWare program and it once again deleted additional virus files.

I would appreciate any additional help you can provide to finish cleaning the machine.

Here are the results of the Malware program:

Malwarebytes' Anti-Malware 1.01
Database version: 297

Scan type: Quick Scan
Objects scanned: 23978
Time elapsed: 14 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 11

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINNT\system32\ssttq.dll (Trojan.Vundo) -> Unloaded module successfully.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1a4571d7-1ba6-4716-9424-fb40a6563c14} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1a4571d7-1ba6-4716-9424-fb40a6563c14} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndblock4.bho (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndblock4.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8f9e2be3-766d-4831-bb0e-766d5b819995} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8f9e2be3-766d-4831-bb0e-766d5b819995} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ism (Adware.AdSponsor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo (Adware.PurityScan) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\QdrPack11 (Adware.ISMonitor) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\winnt\system32\ssttq -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\ISM (Adware.AdSponsor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Start Menu\Programs\Internet Speed Monitor (Adware.AdSponsor) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\QdrPack\QdrPack11.exe (Adware.ISMonitor) -> Quarantined and deleted successfully.
C:\WINNT\system32\ssttq.dll (Trojan.Vundo) -> Failed to delete. (Delete on reboot).
C:\WINNT\system32\qttss.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINNT\system32\qttss.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Local Settings\Temp\D1EC.tmp (Adware.Purityscan) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Local Settings\Temp\TMP209.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Local Settings\Temp\TMP20C.tmp (Adware.ISMonitor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Local Settings\Temp\TMP232.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\ISM\Uninstall.exe (Adware.AdSponsor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk (Adware.AdSponsor) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nextel\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk (Adware.AdSponsor) -> Quarantined and deleted successfully.

New Hijackthis log file:

Logfile of HijackThis v1.99.1
Scan saved at 12:31:53 PM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\DWRCS.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Service\pushnow\pushnow.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINNT\system32\SUSS.EXE
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\DWRCST.exe
C:\WINNT\SCTray.Exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.corp.sprint.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://iconnect.nextel.com/ic.shtml?TYPE=3…tel.com/portal/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://i-connect.corp.sprint.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sprint Nextel
F3 - REG:win.ini: load=C:\WINNT\system32\ssttq.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Actuate\lrxmsie\BIN\IEHelper.dll
O4 - HKLM\..\Run: [SocketComm] SCTray.Exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SSA\smc.exe -startgui
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [runner1] C:\WINNT\mrofinu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O14 - IERESET.INF: START_PAGE_URL=http://i-connect.corp.sprint.com/
O15 - Trusted Zone: *..nnet
O15 - Trusted Zone: *.mms.sprintpcs.com
O15 - Trusted Zone: *.nws.sprintpcs.com
O15 - Trusted Zone: *.upl.sprintpcs.com
O15 - Trusted Zone: *.xsam.sprintpcs.com
O15 - Trusted Zone: *.nmcc.sprintspectrum.com
O15 - Trusted Zone: *.stic.sprintspectrum.com
O15 - Trusted Zone: *..nnet (HKLM)
O15 - Trusted Zone: *.mms.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.nws.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.upl.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.xsam.sprintpcs.com (HKLM)
O15 - Trusted Zone: *.nmcc.sprintspectrum.com (HKLM)
O15 - Trusted Zone: *.stic.sprintspectrum.com (HKLM)
O15 - Trusted IP range: 10.0-63.*
O15 - Trusted IP range: 10.248-255.*
O15 - Trusted IP range: 172.16-31.*.*
O15 - Trusted IP range: 192.168.*.*
O15 - Trusted IP range: 10.0-63.* (HKLM)
O15 - Trusted IP range: 10.248-255.* (HKLM)
O15 - Trusted IP range: 172.16-31.*.* (HKLM)
O15 - Trusted IP range: 192.168.*.* (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199425720937
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\Software\..\Telephony: DomainName = ad.sprint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ad.sprint.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.sprint.com,intranet.sprintspectrum.com,it.sprintspectrum.com,ad.sprint.com,
us.nextel.com,nextel.com
O18 - Filter: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: khffgfd - khffgfd.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\system32\DWRCS.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: OSCM Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
O23 - Service: PictureTaker - LANovation - C:\WINNT\system32\PCTKRNT.SYS
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: Sprint_Push_Now (PushNow) - Sprint FS SD - C:\Service\pushnow\pushnow.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sygate Security Agent (SmcService) - Unknown owner - C:\Program Files\Sygate\SSA\smc.exe (file missing)
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


Thanks for any help you can provide
I suggest you do this:

Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI