1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Control Panel MIA?

Discussion in 'Virus & Other Malware Removal' started by Gailwind, Feb 10, 2008.

Thread Status:
Not open for further replies.
  1. Gailwind

    Gailwind Thread Starter

    Joined:
    Feb 10, 2008
    Messages:
    1
    Trying to bring back my daughters laptop without doing a complete restage as her boyfriend is certainly causing her (and now I!) some grief.

    I've added her to my Zone Alarm Security Suite (get 3 PC's ) and ran both spyware/virus which cleaned up a lot. Had to run SmitFraudFix which I found on a helpful forum and it ran to completion to bring back the control panel in safe mode. Still can't get the control panel back in regular mode though. Also still have other unexpected restrictions. Does this hijack log give any indication of why or whether there are any other problems?

    Once I get this all cleaned up (if possible) I'll bring her current with Windows updates and SP's.

    Thank you for your review!

    Presario 2500, Win XP Home SP1

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:13:25 AM, on 2/10/2008
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\Program Files\Words\Words.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\BitComet\BitComet.exe
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R3 - URLSearchHook: (no name) - {3B901CD6-F01A-A99F-1973-A8581271F5B9} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1DEAD194-BF23-4157-8299-77074160DA6C} - (no file)
    O2 - BHO: {e4c516ae-2dd3-140b-f2b4-caa1800d0363} - {3630d008-1aac-4b2f-b041-3dd2ea615c4e} - C:\WINDOWS\System32\nqaocigv.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
    O2 - BHO: (no name) - {3B901CD6-F01A-A99F-1973-A8581271F5B9} - (no file)
    O2 - BHO: CoolBHO - {5C2A9795-B130-4622-B036-BDCAD28602DC} - C:\Program Files\Cool\Cool.dll
    O2 - BHO: (no name) - {76F262CF-0308-0FB4-F7A3-043266F3A47C} - C:\Program Files\Xvzjuvop\fvptfiqp.dll
    O2 - BHO: Sertificate Infj - {C888CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\Media\mmdrv.dll
    O2 - BHO: (no name) - {E9BD0828-1FD9-410C-A50F-43EBE65D310F} - C:\WINDOWS\system32\awtqrpo.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [{DB-BD-DB-BF-ZN}] C:\WINDOWS\system32\kkdsrngq.exe CHD003
    O4 - HKLM\..\Run: [SearchIndexer] "rundll32.exe" "C:\WINDOWS\System32\kkluivld.dll",sitypnow
    O4 - HKLM\..\Run: [anwnuvov] "rundll32.exe" "C:\Program Files\anwnuvov\apwbelmz.dll",Init
    O4 - HKLM\..\Run: [f94mggfhfghodftdf] C:\DOCUME~1\TRACYW~1\LOCALS~1\Temp\winlogan.exe
    O4 - HKLM\..\Run: [GenProtect] C:\WINDOWS\GenProtect.exe
    O4 - HKLM\..\Run: [bedmdoju] regsvr32 /u "C:\Documents and Settings\All Users.WINDOWS\Application Data\bedmdoju.dll"
    O4 - HKLM\..\Run: [707dbd10] "rundll32.exe" "C:\WINDOWS\System32\vxoeypmb.dll",b
    O4 - HKCU\..\Run: [Insider] "C:\Program Files\Insider\Insider.exe"
    O4 - HKCU\..\Run: [Words] "C:\Program Files\Words\Words.exe"
    O4 - HKCU\..\Run: [WinTouch] "C:\Documents and Settings\Tracy" Warren\Application Data\WinTouch\WinTouch.exe
    O4 - HKCU\..\Run: [SfKg6w] "C:\Documents and Settings\Tracy" Warren\Application Data\Microsoft\Windows\oykkde.exe
    O4 - HKCU\..\Run: [main] C:\WINDOWS\System32\drivers\system.exe
    O4 - HKCU\..\Run: [default] "C:\Documents and Settings\Tracy" Warren\winmain.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe
    O4 - HKCU\..\Run: [f94mggfhfghodftdf] C:\DOCUME~1\TRACYW~1\LOCALS~1\Temp\winlogan.exe
    O4 - HKCU\..\Run: [Windows Rescue System] C:\DOCUME~1\TRACYW~1\LOCALS~1\Temp\winsto.exe
    O4 - HKCU\..\Run: [Access Control App] C:\DOCUME~1\TRACYW~1\LOCALS~1\Temp\winsto.exe
    O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] "C:\Documents and Settings\Tracy" Warren\Application Data\ryzog.exe
    O4 - HKCU\..\RunOnce: [sysinit] C:\WINDOWS\System32\drivers\system.exe
    O4 - HKUS\S-1-5-18\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe (User 'Default user')
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\kkdsrngq.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.9.24.dll
    O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189469032895
    O16 - DPF: {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} - ms-its:mhtml:file://c:\\nores.mht!http://adxtnet.net/code/chm/xpre.chm::/xpreload.ocx
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/insaniquarium/popcaploader_v6.cab
    O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://remotevpn.meijer.com/dana-cached/setup/JuniperSetupSP1.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{585BA2EE-4FD3-4B93-92B9-6CEAA0616E76}: NameServer = 85.255.116.155,85.255.112.26
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E07D1BEA-C4E6-4151-A244-992927096080}: NameServer = 85.255.116.155,85.255.112.26
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.155 85.255.112.26
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.155 85.255.112.26
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.155 85.255.112.26
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.155 85.255.112.26
    O20 - AppInit_DLLs: swrcdzc.dll
    O20 - Winlogon Notify: awtqrpo - awtqrpo.dll (file missing)
    O20 - Winlogon Notify: winnxl32 - winnxl32.dll (file missing)
    O21 - SSODL: DrvInfo - {C888CF11-124F-3562-44AC-E685D962C63C} - C:\WINDOWS\Media\mmdrv.dll
    O22 - SharedTaskScheduler: sdf4dr4gfdgeetj - {B5AC49A2-94F3-42BD-F434-2604812C897D} - (no file)
    O22 - SharedTaskScheduler: JGhjddf9dtj - {B5AF0562-94F3-42BD-F434-2604812C297D} - (no file)
    O23 - Service: Browser - Unknown owner - C:\DOCUME~1\TRACYW~1\LOCALS~1\Temp\883149.exe (file missing)
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Microsoft Inet Service - Unknown owner - C:\WINDOWS\System32\_svchost.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\rteseripro.html

    --
    End of file - 8116 bytes
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/681552

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice