I have a problem that I've determined from reading some previous threads, is a virus. I have thousands of POS Temp Files on my C drive that I cannot delete and my C drive has a red X on it. I downloaded the Hijackthis software and ran a scan. The follwing is the result of that scan. Log file is as follows:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:29 PM, on 3/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\Bianca\Desktop\spider.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Easy SpyRemover\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\tuvvt.exe
O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [Windows Updater Servc] C:\WINDOWS\system32\xpuupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [e8385dc6] rundll32.exe "C:\WINDOWS\system32\xnwuyyeh.dll",b
O4 - HKLM\..\Run: [BMeb0b6e5a] Rundll32.exe "C:\WINDOWS\system32\kptcodbn.dll",s
O4 - HKLM\..\Run: [Easy SpyRemover] D:\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Dominoes -
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
O24 - Desktop Component 0: (no name) -
O24 - Desktop Component 1: (no name) -
O24 - Desktop Component 2: (no name) -
O24 - Desktop Component 3: (no name) - http://www.bulldogevent.homestead.com/files/bullytude1.jpg

--

Can Someone Help? I would appreciate any assistance anyone could provide.

End of file - 4809 bytes

Dani AI

Generated

A few focused, safe steps to try before anyone starts deleting things by hand.

— the symptoms you describe (many undeletable temp files plus a red X overlay on the C: drive) are typical of a persistent infection that recreates files and adds autorun/startup entries. is right about moving this to the Spyware forum for log review; post the full HijackThis log there along with the scans you run. Meanwhile, follow this containment-and-cleaning workflow.

  1. Contain and back up: unplug the PC from the network. From a clean computer, download updated removal tools to removable media (on-demand scanners and a rescue-USB). Copy personal documents/photos only — do not copy or run executables.
  2. Offline or Safe Mode scans: boot into Safe Mode (press F8 on startup) and run full scans with a reputable anti-malware scanner. If files are actively locked or reappear, boot from a rescue CD/USB (offline scanning) and run the scanners there.
  3. Identify and stop persistence: use Autoruns/Process Explorer (Sysinternals) to locate suspicious startup entries and the processes holding files open. Don’t remove registry items unless you know what they do — post findings with your log readers for guidance.
  4. If files are just attribute-protected or locked, try clearing attributes and deleting from Safe Mode or offline environment:
attrib -s -h -r C:\path\to\folder\*.* /S /D
del /F /S /Q C:\path\to\folder\*.*
chkdsk C: /F

Run those only after you have a backup and understand the path you’re deleting.

After removal, disable System Restore before cleaning (to avoid reinfection via restore points), then recreate a clean restore point once you’re confident the system is clean. Run SFC /scannow to repair system files if needed. If the infection resists removal or the system is unstable, back up user files, wipe the disk and do a clean OS install.

When you post to the Spyware forum (per ), include: full HijackThis log, which scans you ran and results, whether you can boot Safe Mode, and what backups you made. Do not run “Fix checked” in HijackThis unless an experienced helper tells you which entries to remove.

if you had read the announcement at the top of the page you would have seen to post hijackthis logs in spyware and other nasties forum .pleas do so ,as that is where most of the log readers help out . follow this link .
http://www.daniweb.com/forums/forum64.html

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.