My XP Pro SP2 machine was infected with W32/alemod.f and Alfacleaner. By following instructions on this and other sites (greyknight17 and others) I managed to clean things up - McAfee virus scans, AdAware, HJT, manual replacement of wininet.dll and removal of other files, Ewido, etc.. HJT removed the program entry for Alfacleaner in my registry, but there are several other Alfacleaner entries still present. They do not look serious and I think I should be able to delete them by hand, but I want to be sure before I do this (I will backup the registry first). A list of these registry entries follows:
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AlfaCleaner]
"Order"=hex:08,00,00,00,02,00,00,00,b2,01,00,00,01,00,00,00,03,00,00,00,80,00,\
00,00,00,00,00,00,72,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,60,00,32,\
00,da,02,00,00,5c,34,11,bc,20,00,41,4c,46,41,43,4c,7e,31,2e,4c,4e,4b,00,00,\
36,00,03,00,04,00,ef,be,5c,34,11,bc,5c,34,11,bc,14,00,00,00,41,00,6c,00,66,\
00,61,00,43,00,6c,00,65,00,61,00,6e,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,\
00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,\
00,92,00,00,00,01,00,00,00,84,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,\
72,00,32,00,4c,06,00,00,5c,34,11,bc,20,00,52,45,47,49,53,54,7e,31,2e,4c,4e,\
4b,00,00,48,00,03,00,04,00,ef,be,5c,34,11,bc,5c,34,11,bc,14,00,00,00,52,00,\
65,00,67,00,69,00,73,00,74,00,65,00,72,00,20,00,41,00,6c,00,66,00,61,00,43,\
00,6c,00,65,00,61,00,6e,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,\
0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,94,00,00,\
00,02,00,00,00,86,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,74,00,32,00,\
a3,02,00,00,5c,34,11,bc,20,00,55,4e,49,4e,53,54,7e,31,2e,4c,4e,4b,00,00,4a,\
00,03,00,04,00,ef,be,5c,34,11,bc,5c,34,11,bc,14,00,00,00,55,00,6e,00,69,00,\
6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,41,00,6c,00,66,00,61,00,43,00,6c,\
00,65,00,61,00,6e,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,\
00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00
[HKEY_USERS\S-1-5-21-1445258045-2690133624-1694720459-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\AlfaCleaner]
"Order"=hex:08,00,00,00,02,00,00,00,b2,01,00,00,01,00,00,00,03,00,00,00,80,00,\
00,00,00,00,00,00,72,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,60,00,32,\
00,da,02,00,00,5c,34,11,bc,20,00,41,4c,46,41,43,4c,7e,31,2e,4c,4e,4b,00,00,\
36,00,03,00,04,00,ef,be,5c,34,11,bc,5c,34,11,bc,14,00,00,00,41,00,6c,00,66,\
00,61,00,43,00,6c,00,65,00,61,00,6e,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,\
00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,\
00,92,00,00,00,01,00,00,00,84,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,\
72,00,32,00,4c,06,00,00,5c,34,11,bc,20,00,52,45,47,49,53,54,7e,31,2e,4c,4e,\
4b,00,00,48,00,03,00,04,00,ef,be,5c,34,11,bc,5c,34,11,bc,14,00,00,00,52,00,\
65,00,67,00,69,00,73,00,74,00,65,00,72,00,20,00,41,00,6c,00,66,00,61,00,43,\
00,6c,00,65,00,61,00,6e,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,\
0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,94,00,00,\
00,02,00,00,00,86,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,74,00,32,00,\
a3,02,00,00,5c,34,11,bc,20,00,55,4e,49,4e,53,54,7e,31,2e,4c,4e,4b,00,00,4a,\
00,03,00,04,00,ef,be,5c,34,11,bc,5c,34,11,bc,14,00,00,00,55,00,6e,00,69,00,\
6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,41,00,6c,00,66,00,61,00,43,00,6c,\
00,65,00,61,00,6e,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,\
00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANER]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANER\0000]
"Service"="alfacleaner"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="alfacleaner"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANER\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANER\0000]
"Service"="alfacleaner"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="alfacleaner"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANER\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANERSERVICE]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANERSERVICE\0000]
"Service"="AlfaCleanerService"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="AlfaCleanerService"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALFACLEANERSERVICE\0000]
"Service"="AlfaCleanerService"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="AlfaCleanerService"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANER]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANER\0000]
"Service"="alfacleaner"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="alfacleaner"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANER\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANER\0000]
"Service"="alfacleaner"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="alfacleaner"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANER\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANERSERVICE]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANERSERVICE\0000]
"Service"="AlfaCleanerService"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="AlfaCleanerService"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALFACLEANERSERVICE\0000]
"Service"="AlfaCleanerService"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="AlfaCleanerService"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANER]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANER\0000]
"Service"="alfacleaner"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="alfacleaner"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANER\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANER\0000]
"Service"="alfacleaner"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="alfacleaner"
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANER\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANERSERVICE]
"NextInstance"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANERSERVICE\0000]
"Service"="AlfaCleanerService"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="AlfaCleanerService"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALFACLEANERSERVICE\0000]
"Service"="AlfaCleanerService"
"Legacy"=dword:00000001
"ConfigFlags"=dword:00000000
"Class"="LegacyDriver"
"ClassGUID"="{8ECC055D-047F-11D1-A537-0000F8753ED1}"
"DeviceDesc"="AlfaCleanerService"
Can someone knowledgeable about these things confirm that it is OK for me to go ahead and delete these?
Thanks for your help.
Barry