I got hit with a drive-by download via Firefox 3.5 last night and in my panic ran all the anti- software I have installed: Spybot, AVG, Spysweeper. They found quite a lot of infections and I tried cleaning them all. Now when I boot into Windows I get the dialog asking me what program to use to open command.com. I then tried Safe Mode which is still working, and that's what I'm using right now.
I then came on this website, went through the instructions, and ran Hijack This. Here's the log. Thanks so much for your help!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:36 AM, on 7/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpySweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla\Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://beginnersoccer.com/WebSiteManager/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\msxitso.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\msffbvqf.exe
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\OrbitDL\orbitcth.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\OrbitDL\GrabPro.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O4 - HKLM\..\Run: [Logitech Utility] "C:\WINDOWS\Logi_MwX.Exe"
O4 - HKLM\..\Run: [Alcmtr] "C:\WINDOWS\ALCMTR.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Samsung PanelMgr] "C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\AcroRead\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3186] "cmd.exe" /c del "C:\WINDOWS\system32\UACxjgfjwyktlemplkin.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3702] "command.com" /c del "C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9702] "cmd.exe" /c del "C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1848] "command.com" /c del "C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3147] "cmd.exe" /c del "C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft\ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\RunOnce: [Shockwave Updater] "C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE" -Update -1100465 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5" -"http://www.iwon.com/home/modules/launchGame/games/includes/blockDotGameIFrame.jhtml?categoryId=3&gameId=551&browser=FF"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8042] "command.com" /c del "C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5756] "cmd.exe" /c del "C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3335] "command.com" /c del "C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7388] "cmd.exe" /c del "C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7400] "command.com" /c del "C:\WINDOWS\system32\drivers\UACarscpxrlxbqjoepfb.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1707] "cmd.exe" /c del "C:\WINDOWS\system32\drivers\UACarscpxrlxbqjoepfb.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7486] "command.com" /c del "C:\WINDOWS\system32\drivers\UACarscpxrlxbqjoepfb.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6783] "cmd.exe" /c del "C:\WINDOWS\system32\drivers\UACarscpxrlxbqjoepfb.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1581] "command.com" /c del "C:\WINDOWS\system32\UACbbmqhrifwuvrbdwyw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6710] "cmd.exe" /c del "C:\WINDOWS\system32\UACbbmqhrifwuvrbdwyw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7578] "command.com" /c del "C:\WINDOWS\system32\uacinit.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6757] "cmd.exe" /c del "C:\WINDOWS\system32\uacinit.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9123] "command.com" /c del "C:\WINDOWS\system32\uacinit.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8837] "cmd.exe" /c del "C:\WINDOWS\system32\uacinit.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7019] "command.com" /c del "C:\WINDOWS\system32\UACovybhmtvpjwcpxmqs.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2701] "cmd.exe" /c del "C:\WINDOWS\system32\UACovybhmtvpjwcpxmqs.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3871] "command.com" /c del "C:\WINDOWS\system32\UACrsklvmphwekxidvbu.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6720] "cmd.exe" /c del "C:\WINDOWS\system32\UACrsklvmphwekxidvbu.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4589] "command.com" /c del "C:\WINDOWS\system32\UACtjettiqxhklvmhatm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5498] "cmd.exe" /c del "C:\WINDOWS\system32\UACtjettiqxhklvmhatm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4862] "command.com" /c del "C:\WINDOWS\system32\UACxjgfjwyktlemplkin.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8530] "cmd.exe" /c del "C:\WINDOWS\system32\UACxjgfjwyktlemplkin.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5711] "command.com" /c del "C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3917] "cmd.exe" /c del "C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9116] "command.com" /c del "C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8433] "cmd.exe" /c del "C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job"
O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\system32\mslnimh.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0992 -f video -m logitech -d 11.5.0.1145 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0992 -f video -m logitech -d 11.5.0.1145 (User 'Default user')
O4 - Startup: Explorer.lnk = C:\WINDOWS\explorer.exe
O4 - Startup: KeyText.lnk = C:\Program Files\KeyText\KeyText.exe
O4 - Startup: NotePro.lnk = C:\Program Files\NoteTab\NoteTab.exe
O4 - Global Startup: Mozy.lnk = C:\Program Files\Mozy\mozystat.exe
O4 - Global Startup: RSIGuard.lnk = ?
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/204
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\OrbitDL\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\ACTIVE~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\ACTIVE~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\ACTIVE~1\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1214611352327
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/A...oadcontrol.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\avgwdsvc.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\SpySweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\SpySweeper\WRConsumerService.exe
--
End of file - 11882 bytes