1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

error message:C:\WINDOWS\system32\drivers\conime.exe

Discussion in 'Virus & Other Malware Removal' started by aguysoinneed, Jul 1, 2007.

Thread Status:
Not open for further replies.
  1. aguysoinneed

    aguysoinneed Thread Starter

    Jul 1, 2007
    hi guys, i must commend this life-saving service u r rendering.
    i followed the instruction given someone on this topic up to a point where one is to copy and paste a log. My log is thus:

    Logfile of HijackThis v1.99.1
    Scan saved at 10:57:20 AM, on 7/1/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://zinblog.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://zinblog.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://zinblog.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://leadwayportal
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://zinblog.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Leadway Assurance Company
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\drivers\conime.exe
    F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system\lsass.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
    O4 - HKLM\..\Run: [SVCHOST] C:\WINDOWS\svchost.exe
    O4 - HKLM\..\Run: [Task Manager] C:\WINDOWS\svhost32.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://leadwayportal
    O16 - DPF: Casa 3rdPty - Misc - file://C:\CitiDirect MS\citidirect\ie\casathrdpty.cab
    O16 - DPF: Casa 3rdPty - Swing 1 - file://C:\CitiDirect MS\citidirect\ie\casaswing1.cab
    O16 - DPF: Casa 3rdPty - Swing 2 - file://C:\CitiDirect MS\citidirect\ie\casaswing2.cab
    O16 - DPF: Casa Access Profile - file://C:\CitiDirect MS\citidirect\ie\casaaccprofmaint.cab
    O16 - DPF: Casa AML User Approval - file://C:\CitiDirect MS\citidirect\ie\casaamluserapproval.cab
    O16 - DPF: Casa Audit - file://C:\CitiDirect MS\citidirect\ie\casaaudit.cab
    O16 - DPF: Casa AWT - file://C:\CitiDirect MS\citidirect\ie\casaawt.cab
    O16 - DPF: Casa Broadcast - file://C:\CitiDirect MS\citidirect\ie\casabrdcast.cab
    O16 - DPF: Casa BTR - file://C:\CitiDirect MS\citidirect\ie\casabtr.cab
    O16 - DPF: Casa Cab Verifier - file://C:\CitiDirect MS\citidirect\ie\casacabverifier.cab
    O16 - DPF: Casa CBServiceOps - file://C:\CitiDirect MS\citidirect\ie\casacbserviceops.cab
    O16 - DPF: Casa Citi-Netting - file://C:\CitiDirect MS\citidirect\ie\casanetting.cab
    O16 - DPF: Casa Client Association - file://C:\CitiDirect MS\citidirect\ie\casaclntassoc.cab
    O16 - DPF: Casa Client Def - file://C:\CitiDirect MS\citidirect\ie\casaclntdef.cab
    O16 - DPF: Casa Code Pages - file://C:\CitiDirect MS\citidirect\ie\casacodepage.cab
    O16 - DPF: Casa CollItems - file://C:\CitiDirect MS\citidirect\ie\casacollitems.cab
    O16 - DPF: Casa CustomReport - file://C:\CitiDirect MS\citidirect\ie\casacustomreport.cab
    O16 - DPF: Casa Default - file://C:\CitiDirect MS\citidirect\ie\casadefault.cab
    O16 - DPF: Casa DtvmrmInvestments - file://C:\CitiDirect MS\citidirect\ie\casadtvmrm.cab
    O16 - DPF: Casa Fidelity - file://C:\CitiDirect MS\citidirect\ie\casafidelity.cab
    O16 - DPF: Casa File Delivery - file://C:\CitiDirect MS\citidirect\ie\casafiledelivery.cab
    O16 - DPF: Casa File Import - file://C:\CitiDirect MS\citidirect\ie\casafileimport.cab
    O16 - DPF: Casa Flow Maint - file://C:\CitiDirect MS\citidirect\ie\casaflowmaint.cab
    O16 - DPF: Casa Framework - file://C:\CitiDirect MS\citidirect\ie\casaframework.cab
    O16 - DPF: Casa Framework Validators - file://C:\CitiDirect MS\citidirect\ie\casaframeworkvalidators.cab
    O16 - DPF: Casa Global Trade Common - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradecommon.cab
    O16 - DPF: Casa Global Trade Detail - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradedetail.cab
    O16 - DPF: Casa Global Trade Lib - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradelib.cab
    O16 - DPF: Casa Global Trade PI - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradepi.cab
    O16 - DPF: Casa Global Trade Summary - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradesummary.cab
    O16 - DPF: Casa GlobalTrade - Barb44 - file://C:\CitiDirect MS\citidirect\ie\casaglobaltrade_barb44.cab
    O16 - DPF: Casa GlobalTrade ApprovalSummary - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradeapprovalsummary.cab
    O16 - DPF: Casa GlobalTrade PO - file://C:\CitiDirect MS\citidirect\ie\casaglobaltradepo.cab
    O16 - DPF: Casa IBM XML Parser - file://C:\CitiDirect MS\citidirect\ie\casaxml.cab
    O16 - DPF: Casa ILC - file://C:\CitiDirect MS\citidirect\ie\casailc.cab
    O16 - DPF: Casa Images - file://C:\CitiDirect MS\citidirect\ie\casaimages.cab
    O16 - DPF: Casa Infrastructure - file://C:\CitiDirect MS\citidirect\ie\casainfr.cab
    O16 - DPF: Casa JPIPreLoader - file://C:\CitiDirect MS\citidirect\ie\casajpipreloader.cab
    O16 - DPF: Casa Language ar_EG - file://C:\CitiDirect MS\citidirect\ie\casa_ar_eg.cab
    O16 - DPF: Casa Language bg_BG - file://C:\CitiDirect MS\citidirect\ie\casa_bg_bg.cab
    O16 - DPF: Casa Language cs_CZ - file://C:\CitiDirect MS\citidirect\ie\casa_cs_cz.cab
    O16 - DPF: Casa Language de_DE - file://C:\CitiDirect MS\citidirect\ie\casa_de_de.cab
    O16 - DPF: Casa Language el_GR - file://C:\CitiDirect MS\citidirect\ie\casa_el_gr.cab
    O16 - DPF: Casa Language es_AR - file://C:\CitiDirect MS\citidirect\ie\casa_es_ar.cab
    O16 - DPF: Casa Language es_ES - file://C:\CitiDirect MS\citidirect\ie\casa_es_es.cab
    O16 - DPF: Casa Language fr_FR - file://C:\CitiDirect MS\citidirect\ie\casa_fr_fr.cab
    O16 - DPF: Casa Language he_IL - file://C:\CitiDirect MS\citidirect\ie\casa_he_il.cab
    O16 - DPF: Casa Language hu_HU - file://C:\CitiDirect MS\citidirect\ie\casa_hu_hu.cab
    O16 - DPF: Casa Language it_IT - file://C:\CitiDirect MS\citidirect\ie\casa_it_it.cab
    O16 - DPF: Casa Language ja_JP - file://C:\CitiDirect MS\citidirect\ie\casa_ja_jp.cab
    O16 - DPF: Casa Language kk_KZ - file://C:\CitiDirect MS\citidirect\ie\casa_kk_kz.cab
    O16 - DPF: Casa Language ko_KP - file://C:\CitiDirect MS\citidirect\ie\casa_ko_kp.cab
    O16 - DPF: Casa Language nl_NL - file://C:\CitiDirect MS\citidirect\ie\casa_nl_nl.cab
    O16 - DPF: Casa Language pl_PL - file://C:\CitiDirect MS\citidirect\ie\casa_pl_pl.cab
    O16 - DPF: Casa Language pt_BR - file://C:\CitiDirect MS\citidirect\ie\casa_pt_br.cab
    O16 - DPF: Casa Language ro_RO - file://C:\CitiDirect MS\citidirect\ie\casa_ro_ro.cab
    O16 - DPF: Casa Language ru_RU - file://C:\CitiDirect MS\citidirect\ie\casa_ru_ru.cab
    O16 - DPF: Casa Language sk_SK - file://C:\CitiDirect MS\citidirect\ie\casa_sk_sk.cab
    O16 - DPF: Casa Language th_TH - file://C:\CitiDirect MS\citidirect\ie\casa_th_th.cab
    O16 - DPF: Casa Language tr_TR - file://C:\CitiDirect MS\citidirect\ie\casa_tr_tr.cab
    O16 - DPF: Casa Language uk_UA - file://C:\CitiDirect MS\citidirect\ie\casa_uk_ua.cab
    O16 - DPF: Casa Language zh_CN - file://C:\CitiDirect MS\citidirect\ie\casa_zh_cn.cab
    O16 - DPF: Casa Language zh_TW - file://C:\CitiDirect MS\citidirect\ie\casa_zh_tw.cab
    O16 - DPF: Casa Libraries - file://C:\CitiDirect MS\citidirect\ie\casalibs.cab
    O16 - DPF: Casa Liquidity - file://C:\CitiDirect MS\citidirect\ie\casaliquidity.cab
    O16 - DPF: Casa List Manager - file://C:\CitiDirect MS\citidirect\ie\casalistmgr.cab
    O16 - DPF: Casa Lockbox - file://C:\CitiDirect MS\citidirect\ie\casalockbox.cab
    O16 - DPF: Casa Misc - file://C:\CitiDirect MS\citidirect\ie\casamisc.cab
    O16 - DPF: Casa Payments Banamex - file://C:\CitiDirect MS\citidirect\ie\casapmtsbanamex.cab
    O16 - DPF: Casa Payments Common - file://C:\CitiDirect MS\citidirect\ie\casapmtscomm.cab
    O16 - DPF: Casa Payments Detail - file://C:\CitiDirect MS\citidirect\ie\casapmtsdtl.cab
    O16 - DPF: Casa Payments Disbursements - file://C:\CitiDirect MS\citidirect\ie\casadisbursements.cab
    O16 - DPF: Casa Payments Libraries - file://C:\CitiDirect MS\citidirect\ie\casapmtslibs.cab
    O16 - DPF: Casa Payments Misc - file://C:\CitiDirect MS\citidirect\ie\casapmtsmisc.cab
    O16 - DPF: Casa Pref Mgr - file://C:\CitiDirect MS\citidirect\ie\casaprefmgr.cab
    O16 - DPF: Casa Receivables Mandates - file://C:\CitiDirect MS\citidirect\ie\casareceivablesmandates.cab
    O16 - DPF: Casa ReceivablesDirectDebit - file://C:\CitiDirect MS\citidirect\ie\casareceivablesdirectdebit.cab
    O16 - DPF: Casa ReceivablesInquiries - file://C:\CitiDirect MS\citidirect\ie\casareceivablesinquiries.cab
    O16 - DPF: Casa Report - file://C:\CitiDirect MS\citidirect\ie\casareport.cab
    O16 - DPF: Casa Safeword - file://C:\CitiDirect MS\citidirect\ie\casasafeword.cab
    O16 - DPF: Casa SDR - file://C:\CitiDirect MS\citidirect\ie\casasdr.cab
    O16 - DPF: Casa Security Admin - file://C:\CitiDirect MS\citidirect\ie\casasecurityadmin.cab
    O16 - DPF: Casa ServForCollItems - file://C:\CitiDirect MS\citidirect\ie\casaservforcollitems.cab
    O16 - DPF: Casa Taiwan CBR - file://C:\CitiDirect MS\citidirect\ie\casatwcbr.cab
    O16 - DPF: Casa Trade FI Common - file://C:\CitiDirect MS\citidirect\ie\casaficommon.cab
    O16 - DPF: Casa Trade FI Detail - file://C:\CitiDirect MS\citidirect\ie\casafidetail.cab
    O16 - DPF: Casa Trade FI Lib - file://C:\CitiDirect MS\citidirect\ie\casafilib.cab
    O16 - DPF: Casa Trade FI Summary - file://C:\CitiDirect MS\citidirect\ie\casafisummary.cab
    O16 - DPF: Casa User Maint - file://C:\CitiDirect MS\citidirect\ie\casausrmaint.cab
    O16 - DPF: casahelper - file://C:\CitiDirect MS\citidirect\ie\casahelper.cab
    O16 - DPF: CasaReceivablesServices - file://C:\CitiDirect MS\citidirect\ie\casareceivablesservices.cab
    O16 - DPF: CasaServForProducts - file://C:\CitiDirect MS\citidirect\ie\casaservforproducts.cab
    O16 - DPF: CasaSSPymt - file://C:\CitiDirect MS\citidirect\ie\casasspymt.cab
    O16 - DPF: CasaSSRpts - file://C:\CitiDirect MS\citidirect\ie\casassrpts.cab
    O16 - DPF: CasaWHPymt - file://C:\CitiDirect MS\citidirect\ie\casawhpymt.cab
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = leadway.com.ng
    O17 - HKLM\Software\..\Telephony: DomainName = leadway.com.ng
    O17 - HKLM\System\CCS\Services\Tcpip\..\{23A64143-29D5-4458-BE1D-AFECBBC0C013}: NameServer =
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = leadway.com.ng
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = leadway.com.ng
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = leadway.com.ng
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    please what shd i do next. thank you
  2. Cookiegal

    Cookiegal Administrator Malware Specialist Coordinator

    Aug 27, 2003
    Hi and welcome to TSG,

    Download AVG Anti-Spyware from HERE and save that file to your desktop. Note for AVG Free anti-virus users only: this is not the same program that you already have, this is an anti-spyware program.

    When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.

    1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.
    2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.
    4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.

    Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.

    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:

    1. Launch AVG Anti-Spyware by double clicking the icon on your desktop.
    2. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    3. AVG will now begin the scanning process. Please be patient as this may take a little time.
      Once the scan is complete, do the following:
    4. If you have any infections you will be prompted. Then select "Apply all actions."
    5. Next select the "Reports" icon at the top.
    6. Select the "Save report as" button in the lower left-hand of the screen and save it to a text file on your system (make sure to remember where you saved that file. This is important).
    7. Close AVG Anti-Spyware and reboot your system back into Normal Mode.

    Please go HERE to run Panda's ActiveScan
    • You need to use IE to run this scan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

    Come back here and post a new HijackThis log along with the logs from the AVG and Panda scans.
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/590618

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice