The results.
I did what all you asked:
Disabled Resident Protection, then in tools, in Resident, unchecked "Resident Tea-Timer" (earlier both were checked and active). Exited, restarted the compu.
Did a system scan only with HijackThis, and looked for the following entries:
* R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
* R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page
* O2 - BHO: (no name) - {826A5ED9-1316-4EFD-87F8-AA400C5D551A} - C:\WINDOWS.1\system32\mlJYPJCR.dll
* O20 - Winlogon Notify: Antiwpa - antiwpa.dll (file missing
* O20 - Winlogon Notify: mlJYPJCR - C:\WINDOWS.1\SYSTEM32\mlJYPJCR.dll
Found all of them, and fixed them all, then restarted the computer.
After restart, went to HijackThis > Config > Misc Tools > Delete an NT service (actually I was not sure if I had to do it, but I still did it), and then typed WIQ for deletion, but got the message that the service is running, so disable it and then delete it. I could have done that (I think you go to services and do it), but wasn't sure, so didn't do anything.
Enabled viewing of hidden and protected system files, and allowed file extensions to be viewed.
Went to C:\WINDOWS.1\system32\, and found the file "mlJYPJCR.dll"; tried to delete it, but got the access denied type message, so went to BitDefender, and in AntiVirus, tried to use the quarantine feature, but that also failed (said it was not able to complete the action), so finally closed everything, opened HijackThis, and used the Tool of deleting a file, and selected "mlJYPJCR.dll". Restarted the compu.
On restart, went to C:\WINDOWS.1\system32\, and found that "mlJYPJCR.dll" was still there.
Restarted the Spybot SD services.
The problem is still there; let me tell you what all the problems are: first, whenever the computer starts, it gives a message of New Hardware Found, which I cancel, though once I allowed it to run, but it just searched and then said that the hardware could not be installed; second, the little window keeps opening, asking whether I want to connect or work offline, I always cancel this, (and I have already uninstalled Internet Explorer from the Control Panel > Add Remove Software thing); third, Zone Alarm gives a warning every few minutes of having blocked the site 89.188.16.50.
I am posting the logs now.
And yes, I tried to run ComboFix.exe, it changed the date time settings, and then in a command prompt window, it began a scan, saying it would typically take about ten minutes, and then all of a sudden the compu restarted on its own, and CheckDisk automatically started. I thought there might have been some other prob, so I ran ComboFix again, and again the same thing happened.
What exactly has got into my compu?
And hey, thanks for all the help that you are giving me.
uninstall_list OLD.txt:
3D Galaxy Journey Screensaver
3D World Atlas
3Planesoft Screensaver Manager 1.1
7 Wonders
7-Zip 4.57
A1Click Ultra PC Cleaner 1.01 (Registered Version)
Ad-Aware SE Professional
Adobe Flash Player Plugin
Adobe PageMaker 6.5
Adobe Reader 6.0
Age of Castles
Age Of Japan
Alchemy 1.2
Ancient Seal (remove only)
ATI Catalyst Control Center
ATI Display Driver
Atomica Deluxe 2.5
Aveyond
Beetle Bug 2 (remove only)
Bejeweled Deluxe 1.6z
Big Money Deluxe 1.11
BitDefender Internet Security v10
Bookworm Adventures Deluxe
Cablenut 4.08
Catan (remove only)
CDisplayEx 1.4
Chrysanth NETime Author [Trial]
Ciao Bella (remove only)
Codec Pack - All In 1 6.0.3.0
Combined Community Codec Pack 2008-01-24
Cradle of Rome (remove only)
DAEMON Tools
Dataone Usage Finder 2.0
Diamond Detective
Download Direct
Dynasty (remove only)
Dynomite 1.20
Ease MP3 WAV Converter 1.50
eMule
Escape From Paradise
Fairy Godmother Tycoon (remove only)
Fairy Jewels (remove only)
Fairy Treasure (remove only)
Fizzball
FLV Player 1.3.3
FTP Navigator
Google Talk (remove only)
Happy Hour
Hide IP Platinum 3.5
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Huawei MT882 USB ADSL Modem
Ice Cream Tycoon
Incrediball The Seven Sapphires (remove only)
InFlac 1.1.1
Java(TM) 6 Update 3
Jewel Quest 2
Jewels of Cleopatra
K-Lite Mega Codec Pack 1.17
Koi Fish 3D Screensaver 1.0
LaserJet 1020 series
LimeWire 4.16.6
LingvoSoft Talking Dictionary 2006 (English<->Hindi) for Windows
Luxor 2 (remove only)
Magic Ball 2 Magic Hearts (remove only)
Magic Ball 3 (remove only)
Magic ISO Maker v5.3 (build 0216)
Master of Defense (remove only)
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Microsoft Reader
Microsoft Visual C++ 2005 Redistributable
Mirror Magic Deluxe (remove only)
Mozilla Firefox (2.0)
MSXML 4.0 SP2 Parser and SDK
Mummy Maze Deluxe 1.1
Nero 7 Essentials
NingPo MahJong Deluxe 1.04
Noah's Ark Deluxe 1.1
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia PC Suite
Passware Kit Enterprise 8.0
PC Connectivity Solution
PeerGuardian 2.0
Peggle (remove only)
Pirate Poppers (remove only)
Plantasia (remove only)
Power Voice II
QuickTime for Windows (32-bit)
Rainbow Mystery
REALTEK Gigabit and Fast Ethernet NIC Driver
Realtek High Definition Audio Driver
Reaxxion (remove only)
Registry Clean Expert
RegVac Registry Cleaner 5.01 (Registered Version)
Sandlot Games Client Services
Sandlot Games Client Services 1.2.2
SpongeBob SquarePants Bubble Rush! (remove only)
SpongeBob SquarePants Diner Dash (remove only)
SpongeBob SquarePants Obstacle Odyssey (remove only)
Spybot - Search & Destroy
Spyware Doctor 5.0
Super Granny 3 (remove only)
Sweet Home 3D version 1.2
Syberia
Tetris Game Gold
TipTop Deluxe 1.1
Tropic Ball (remove only)
Turtle Odyssey 2 (remove only)
TypingMaster Typing Test
Venice Deluxe
VideoLAN VLC media player 0.8.6c
ViDown FLV Downloader V0.8.3
Virtual Villagers - The Lost Children (remove only)
VobSub v2.23 (Remove Only)
War Chess
WAV MP3 Converter 2.3 build 733
Westward (remove only)
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
WinHTTrack Website Copier 3.42
WinMHT
WinPcap 4.0
WinRAR archiver
Yahoo! Messenger
Zodiac Tower
ZoneAlarm Pro
Zune Desktop Theme
---
uninstall_list NEW.txt:
3D Galaxy Journey Screensaver
3D World Atlas
3Planesoft Screensaver Manager 1.1
7 Wonders
7-Zip 4.57
A1Click Ultra PC Cleaner 1.01 (Registered Version)
Ad-Aware SE Professional
Adobe Flash Player Plugin
Adobe PageMaker 6.5
Adobe Reader 6.0
Age of Castles
Age Of Japan
Alchemy 1.2
Ancient Seal (remove only)
ATI Catalyst Control Center
ATI Display Driver
Atomica Deluxe 2.5
Aveyond
Beetle Bug 2 (remove only)
Bejeweled Deluxe 1.6z
Big Money Deluxe 1.11
BitDefender Internet Security v10
Bookworm Adventures Deluxe
Cablenut 4.08
Catan (remove only)
CDisplayEx 1.4
Chrysanth NETime Author [Trial]
Ciao Bella (remove only)
Codec Pack - All In 1 6.0.3.0
Combined Community Codec Pack 2008-01-24
Cradle of Rome (remove only)
DAEMON Tools
Dataone Usage Finder 2.0
Diamond Detective
Download Direct
Dynasty (remove only)
Dynomite 1.20
Ease MP3 WAV Converter 1.50
eMule
Escape From Paradise
Fairy Godmother Tycoon (remove only)
Fairy Jewels (remove only)
Fairy Treasure (remove only)
Fizzball
FLV Player 1.3.3
FTP Navigator
Google Talk (remove only)
Happy Hour
Hide IP Platinum 3.5
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Huawei MT882 USB ADSL Modem
Ice Cream Tycoon
Incrediball The Seven Sapphires (remove only)
InFlac 1.1.1
Java(TM) 6 Update 3
Jewel Quest 2
Jewels of Cleopatra
K-Lite Mega Codec Pack 1.17
Koi Fish 3D Screensaver 1.0
LaserJet 1020 series
LimeWire 4.16.6
LingvoSoft Talking Dictionary 2006 (English<->Hindi) for Windows
Luxor 2 (remove only)
Magic Ball 2 Magic Hearts (remove only)
Magic Ball 3 (remove only)
Magic ISO Maker v5.3 (build 0216)
Master of Defense (remove only)
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Microsoft Reader
Microsoft Visual C++ 2005 Redistributable
Mirror Magic Deluxe (remove only)
Mozilla Firefox (2.0)
MSXML 4.0 SP2 Parser and SDK
Mummy Maze Deluxe 1.1
Nero 7 Essentials
NingPo MahJong Deluxe 1.04
Noah's Ark Deluxe 1.1
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia PC Suite
Passware Kit Enterprise 8.0
PC Connectivity Solution
PeerGuardian 2.0
Peggle (remove only)
Pirate Poppers (remove only)
Plantasia (remove only)
Power Voice II
QuickTime for Windows (32-bit)
Rainbow Mystery
REALTEK Gigabit and Fast Ethernet NIC Driver
Realtek High Definition Audio Driver
Reaxxion (remove only)
Registry Clean Expert
RegVac Registry Cleaner 5.01 (Registered Version)
Sandlot Games Client Services
Sandlot Games Client Services 1.2.2
SpongeBob SquarePants Bubble Rush! (remove only)
SpongeBob SquarePants Diner Dash (remove only)
SpongeBob SquarePants Obstacle Odyssey (remove only)
Spybot - Search & Destroy
Spyware Doctor 5.0
Super Granny 3 (remove only)
Sweet Home 3D version 1.2
Syberia
Tetris Game Gold
TipTop Deluxe 1.1
Tropic Ball (remove only)
Turtle Odyssey 2 (remove only)
TypingMaster Typing Test
Venice Deluxe
VideoLAN VLC media player 0.8.6c
ViDown FLV Downloader V0.8.3
Virtual Villagers - The Lost Children (remove only)
VobSub v2.23 (Remove Only)
War Chess
WAV MP3 Converter 2.3 build 733
Westward (remove only)
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
WinHTTrack Website Copier 3.42
WinMHT
WinPcap 4.0
WinRAR archiver
Yahoo! Messenger
Zodiac Tower
ZoneAlarm Pro
Zune Desktop Theme
---
hijackthis 10.04.08.log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49, on 2008-04-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS.1\System32\smss.exe
C:\WINDOWS.1\system32\csrss.exe
C:\WINDOWS.1\system32\winlogon.exe
C:\WINDOWS.1\system32\services.exe
C:\WINDOWS.1\system32\lsass.exe
C:\WINDOWS.1\system32\Ati2evxx.exe
C:\WINDOWS.1\system32\svchost.exe
C:\WINDOWS.1\system32\svchost.exe
C:\WINDOWS.1\System32\svchost.exe
C:\WINDOWS.1\system32\svchost.exe
C:\WINDOWS.1\system32\svchost.exe
C:\WINDOWS.1\system32\ZONELABS\vsmon.exe
C:\WINDOWS.1\system32\Ati2evxx.exe
C:\WINDOWS.1\Explorer.EXE
C:\WINDOWS.1\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\Spyware Doctor\svcntaux.exe
D:\Program Files\Spyware Doctor\swdsvc.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
D:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS.1\system32\wdfmgr.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\WINDOWS.1\System32\alg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS.1\RTHDCPL.EXE
C:\Program Files\Huawei\MT882\dslagent.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS.1\system32\ctfmon.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Hijack This\HiJackThis.exe
C:\WINDOWS.1\system32\wbem\wmiprvse.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {826A5ED9-1316-4EFD-87F8-AA400C5D551A} - C:\WINDOWS.1\system32\mlJYPJCR.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Huawei\MT882\dslagent.exe
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [SDTray] "D:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.1\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] F:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] F:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O8 - Extra context menu item: Download all by Rapidown... - C:\Program Files\Rapidown\RapidownGetAll.htm
O8 - Extra context menu item: Download by Rapidown... - C:\Program Files\Rapidown\RapidownGet.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save page with WinMHT... - C:\Program Files\WinMHT\iewmht0.htm
O8 - Extra context menu item: Save selection with WinMHT... - C:\Program Files\WinMHT\iewmht2.htm
O8 - Extra context menu item: Use ViDown to download - C:\Program Files\ViDown\vd_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (file missing)
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - E:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - E:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E1E73B44-2D20-47A9-9CA2-B534CEBBF856} (F-Secure Health Check 1.0) -
http://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABC9AD18-99AB-4F25-8F72-629FCF281A4E}: NameServer = 218.248.240.208,61.1.96.71
O20 - Winlogon Notify: mlJYPJCR - C:\WINDOWS.1\SYSTEM32\mlJYPJCR.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS.1\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS.1\system32\ZONELABS\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: WIQ - Unknown owner - C:\DOCUME~1\Skynet\LOCALS~1\Temp\WIQ.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
--
End of file - 7684 bytes
---