Good work- you've cleaned out a fair number of "unwanted guests".
There are still infections present though, so:
First: C:\DOCUME~1\OWNER~1.UPP\LOCALS~1\Temp\Rar$EX00.438\HijackThis.ex
The log entry above indicates that you are running HijackThis from within a Temp/Temporary folder. Please do the following:
Create a folder for HJT outside of any Temp/Temporary folders and move the HijackThis.exe file to that folder now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.
One of the normal steps in eliminating malicious programs is to entirely delete the contents of all Temp folders. Given that, if HijackThis (and other data that you care about) is living in those Temp folders, it will be erased along with everything else!
Temp/Temporary folders are just that- Temporary. They are not meant for permanent storage, as their contents are often delete in the course of troubleshooting, by running disk clean-up utilities, etc.
-------------------------------------------------------------------------------------
You will need to close/quit all web browser programs and disconnect from the Internet for much of the following, so you should print out these instructions or save them into a text file with Notepad.
1. Open the Services utility in your Administrative Tools control panel.
* In the list of services, locate the service named "NTBOOTMGR" and double-click on it.
* In the General tab of the Properties window that opens, click the Stop button if the service is not already stopped.
* Once the service is stopped, choose Disabled in the "Startup Type" drop-down menu and then click OK.
* Repeat the above for the NTLOAD and NTSVCMGR services.
* Close the Services utility after that.
2. Download and install the following utilities:
CCleaner - www.ccleaner.com
Webroot Spy Sweeper (14 day free trial) - http://www.webroot.com/shoppingcart...4011&vcode=DT02
Microsoft Anti-Spyware beta - http://www.microsoft.com/downloads/...&displaylang=en
- Open Spy Sweeper, click on "Options", and then click on "Update Definitions" under the Program Options tab. Do not run a scan yet; just close the program once the update completes.
- Open ewido. In the main screen, click "Update" and click "Start Update". After the update process completes, exit from Ewido.
- Open MS Antispyware beta. Make sure the "AntiSpyware Autoupdater" feature is enabled, and that it has downloaded the most current antispyware updates. Close the program after you've verified this.
- Open McAfee and make sure that it has the most current virus definitions installed. Again- don't scan yet, just close the program once it's updated.
3. Run HijackTHis again, put a check mark next to the following entries, and then click the "Fix checked" button:
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hp8865.tmp
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [WindowsUpdateNT] C:\RECYCLER\svwhost.exe /s
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [WindowsUpdateNT] C:\RECYCLER\svwhost.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0AA5CA8F-77DA-403C-B2AA-C0B672E1324D}: NameServer = 85.255.113.205,85.255.112.231
O17 - HKLM\System\CCS\Services\Tcpip\..\{D9FB9304-42F9-4B81-BB21-2F46B77B572C}: NameServer = 85.255.113.205,85.255.112.231
O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
O23 - Service: NTBOOTMGR (NTBOOT) - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntuser.exe (file missing)
O23 - Service: NTLOAD - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe (file missing)
O23 - Service: NTSVCMGR - Unknown owner - C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe (file missing)
- Once HJT finishes the fix, click on the "Config" button in the lower right corner of HijackThis' main window. In the next window click on the "Misc Tools" button at the top then click the "Delete an NT service" button. Type the following in the box and click OK:
NTBOOTMGR
Repeat the above deletion for NTLOAD and NTSVCMGR. Close HJT after that.
4. Reboot into Safe Mode and:
Open CCleaner.
- Go to Options-> Advanced: Uncheck "Only delete files in Windows Temp folders older than 48 hours"
- Go to Options>CustomFolders>Add Folder>Navigate to these folders (click on bold file once and hit OK) :
* C:\Windows\Temp
* C:\Windows\Prefetch
* C:\Documents and Settings\\Local Settings\Temporary Internet Files\ (This will delete all your cached internet content including cookies.)
* C:\Documents and Settings\\Local Settings\Temp
* C:\Documents and Settings\\Local Settings\Temporary Internet Files
* C:\Documents and Settings\\Local Settings\Temp
* C:\Documents and Settings\\Cookies
* C:\Documents and Settings\\Cookies
Hit OK
- In left pane, scroll down to "Advanced, Custom Folders", put a check in Custom Folders
- Click on Run Cleaner
It may take a while for the program to perform its cleaning, so be patient. Close the program when it has finished.
- Run McAfee, MS Antispyware, and ewido; have the programs fix all malicious items they find.
When ewido finds the first malicious object on your system, it will ask you if it should clean it. When it asks this, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
Save the log file that ewido will create after it finishes scanning; you'll be including that log in your next post here.
- Run Spy Sweeper.
* Under the Sweep Options tab, select ALL options under 'What to Sweep'.
* Click the "Sweep" icon and then "Start" to begin scanning.
*When the scan completes, click Next to automatically quarantine all detected items.
*Click the Results icon, select Session Log, and then click Save to File. Save the scan results to your desktop and close Spy Sweeper.
5. Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types".
- Look for the following files and delete them if found:
C:\WINDOWS\system32\hp8865.tmp
C:\WINDOWS\system32\browsela.dll
msupdate32.dll
C:\winstall.exe
C:\RECYCLER\svwhost.exe
C:\WINDOWS\SYSTEM\DRIVER\ntuser.exe C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe C:\WINDOWS\SYSTEM\DRIVER\ntsrv.exe
- Delete the C:\Program Files\winupdatesfolder entirely.
6. Empty your Recycle Bin, reboot normally, run HijackThis again, and post the new log. Also post the logs that ewido and Spy Sweeper generated.