Infected by Figaro.sys virus. Unfortunately, system rebooted and virus became intrenched. Details:
Have run Norton Corporate AV, Malware, Spybot
Quad-core processor - 3g RAM
XP Pro - SP3
Network machine - HIJACK this file to follow -
System keeps rebooting and every file seems program takes longer to start. HELP!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:13 PM, on 12/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\PrevxCSI\prevxcsi.ex
e
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
C:\WINDOWS\System32\svchos
t.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\System32\TSIRCS
RV.EXE
C:\WINDOWS\system32\Search
Indexer.ex
e
C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
32\nSvcApp
Flt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
32\nSvcIp.
exe
C:\WINDOWS\TSI32\tsircusr.
exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraid
service.ex
e
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL
32.EXE
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\Program Files\PrevxCSI\prevxcsi.ex
e
C:\Program Files\Microsoft Hardware\Keyboard\type32.e
xe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\AcroDist.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
C:\Program Files\PopMessenger\PopMess
enger.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapim
gr.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\Search
ProtocolHo
st.exe
C:\WINDOWS\system32\wbem\u
nsecapp.ex
e
C:\WINDOWS\system32\wuaucl
t.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.google.ieR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://www.google.ieR1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005F2 - REG:system.ini: UserInit=C:\WINDOWS\system
32\userini
t.exe,C:\W
INDOWS\TSI
32\tsircus
r.exe,
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\5
.0.926.345
0\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-7
6C02E2E7C4
E} - C:\Program Files\Google\Google Toolbar\Component\fastsear
ch_219B3E1
547538286.
dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraid
service.ex
e
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.e
xe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKCU\..\Run: [PopMessenger] C:\Program Files\PopMessenger\PopMess
enger.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECapture.
html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppend.h
tml
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECaptureS
elLinks.ht
ml
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppendSe
lLinks.htm
l
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECapture.
html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppend.h
tml
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IECapture.
html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClien
t.dll/Acro
IEAppend.h
tml
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-0
0C04FAE2D4
F} - C:\PROGRA~1\MI3AA1~1\INetR
epl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\PROGRA~1\MI3AA1~1\INetR
epl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-0
0C04FAE2D4
F} - C:\PROGRA~1\MI3AA1~1\INetR
epl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.
dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.
dll
O15 - Trusted Zone:
http://loandocs.ss3.swiftsend.comO15 - Trusted Zone:
http://docs.swiftsend.comO15 - Trusted Zone:
http://loandocs.swiftsend.comO15 - Trusted Zone:
http://docs.swiftsend2.comO15 - Trusted Zone:
http://loandocs.swiftsend2.comO15 - Trusted Zone:
http://www.swiftview.comO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1223397853218O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-0
0104B64F12
6} (Sview Control) -
http://products.swiftview.com/install.html?id=sv8/3_IN_1_CAB&ctx=&ref=O16 - DPF: {A796D216-2DE1-4EA8-BABB-F
E6E7C95909
8} (HPSDDX Class) -
http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = mcp.local
O17 - HKLM\Software\..\Telephony
: DomainName = mcp.local
O17 - HKLM\System\CCS\Services\T
cpip\..\{E
813AC4D-A2
B9-4B03-B1
C4-188A753
7825C}: NameServer = 192.168.1.101
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = mcp.local
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.ex
e
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
32\nSvcApp
Flt.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessM
anager\bin
32\nSvcIp.
exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: TSI Remote Control Service (TSIRCSRV) - Laplink Software, Inc. - C:\WINDOWS\System32\TSIRCS
RV.EXE
--
End of file - 9563 bytes
Start Free Trial