Plagued
Topic Starter
GF's comp got plagued with trojans. Probably from downloading too much porn… Anyway, her comp was a nightmare. Had nearly a dozen anti-virus/spyware programs all running. God only knows what was going on. The malware got in the system restore, so I disabled that. I removed all the questionable programs through the add/remove programs in the control panel. I disabled/deleted every instance of all the different anti-virus/spyware/adware programs so that I can install the professional software we use at my office. So as of now, there is zero protection. Anyway, here's the HJT log. I notice right off that winself is known malware…
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:49:20 PM, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:..WINDOWS..System32..smss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..spoolsv.exe
C:..WINDOWS..winself.exe
C:..WINDOWS..system32..nvsvc32.exe
C:..Program Files..Common Files..New Boundary..PrismXL..PRISMXL.SYS
C:..WINDOWS..System32..snmp.exe
C:..Program Files..Common Files..Symantec Shared..CCPD-LC..symlcsvc.exe
C:..Program Files..Webroot..Spy Sweeper..SpySweeper.exe
C:..WINDOWS..system32..vbpdtvdp.exe
C:..WINDOWS..Explorer.EXE
C:..Program Files..Compact Wireless-G USB Adapter Wireless Network Monitor..WLService.exe
C:..Program Files..Compact Wireless-G USB Adapter Wireless Network Monitor..WUSB54GC.exe
C:..Program Files..Digital Media Reader..shwiconem.exe
C:..WINDOWS..zHotkey.exe
C:..Program Files..Common Files..Real..Update_OB..realsched.exe
C:..WINDOWS..system32..PRISMSVR.EXE
C:..Program Files..Yahoo!..Search Protection..SearchProtection.exe
C:..WINDOWS..RTHDCPL.EXE
C:..Program Files..CyberLink..PowerDVD..PDVDServ.exe
C:..Program Files..QuickTime..qttask.exe
C:..WINDOWS..system32..RUNDLL32.EXE
C:..WINDOWS..system32..accwizz.exe
C:..Program Files..Messenger..msmsgs.exe
C:..WINDOWS..system32..ctfmon.exe
C:..Program Files..2Wire 802.11g Wireless..PRISMCFG.EXE
C:..PROGRA~1..Webshots..webshots.scr
C:..WINDOWS..system32..wuauclt.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Search Bar = http://us. rd. yahoo. com/customize/ycomp/defaults/sb. r{}*http://www. yahoo. com
R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = C:..WINDOWS..system32..spywarewarning.mht
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = http://go. microsoft. com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Page = http://go. microsoft. com/fwlink/?LinkId=54896
R0 - HKLM..Software..Microsoft..Internet Explorer..Main,Start Page = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKCU..Software..Microsoft..Internet Explorer..SearchURL,(Default) = http://us. rd. yahoo. com/customize/ycomp/defaults/su. r{}
EDIT: sorry about all the explorer stuff at the bottom. I had a bunch of windows open…
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:49:20 PM, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:..WINDOWS..System32..smss.exe
C:..WINDOWS..system32..winlogon.exe
C:..WINDOWS..system32..services.exe
C:..WINDOWS..system32..lsass.exe
C:..WINDOWS..system32..svchost.exe
C:..WINDOWS..System32..svchost.exe
C:..WINDOWS..system32..spoolsv.exe
C:..WINDOWS..winself.exe
C:..WINDOWS..system32..nvsvc32.exe
C:..Program Files..Common Files..New Boundary..PrismXL..PRISMXL.SYS
C:..WINDOWS..System32..snmp.exe
C:..Program Files..Common Files..Symantec Shared..CCPD-LC..symlcsvc.exe
C:..Program Files..Webroot..Spy Sweeper..SpySweeper.exe
C:..WINDOWS..system32..vbpdtvdp.exe
C:..WINDOWS..Explorer.EXE
C:..Program Files..Compact Wireless-G USB Adapter Wireless Network Monitor..WLService.exe
C:..Program Files..Compact Wireless-G USB Adapter Wireless Network Monitor..WUSB54GC.exe
C:..Program Files..Digital Media Reader..shwiconem.exe
C:..WINDOWS..zHotkey.exe
C:..Program Files..Common Files..Real..Update_OB..realsched.exe
C:..WINDOWS..system32..PRISMSVR.EXE
C:..Program Files..Yahoo!..Search Protection..SearchProtection.exe
C:..WINDOWS..RTHDCPL.EXE
C:..Program Files..CyberLink..PowerDVD..PDVDServ.exe
C:..Program Files..QuickTime..qttask.exe
C:..WINDOWS..system32..RUNDLL32.EXE
C:..WINDOWS..system32..accwizz.exe
C:..Program Files..Messenger..msmsgs.exe
C:..WINDOWS..system32..ctfmon.exe
C:..Program Files..2Wire 802.11g Wireless..PRISMCFG.EXE
C:..PROGRA~1..Webshots..webshots.scr
C:..WINDOWS..system32..wuauclt.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Search Bar = http://us. rd. yahoo. com/customize/ycomp/defaults/sb. r{}*http://www. yahoo. com
R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = C:..WINDOWS..system32..spywarewarning.mht
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = http://go. microsoft. com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Page = http://go. microsoft. com/fwlink/?LinkId=54896
R0 - HKLM..Software..Microsoft..Internet Explorer..Main,Start Page = http://go. microsoft. com/fwlink/?LinkId=69157
R1 - HKCU..Software..Microsoft..Internet Explorer..SearchURL,(Default) = http://us. rd. yahoo. com/customize/ycomp/defaults/su. r{}
EDIT: sorry about all the explorer stuff at the bottom. I had a bunch of windows open…