![]() ![]() |
Nov 4 2009, 07:51 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 82 Joined: 17-November 04 From: Canada Member No.: 18,591 |
Hello WTT Team...
I have had this very annoying small problem for a couple months now, i have tried to resolve it on my own, but im at my witts end now so here i am, on my laptop i have the Sympatico Security Manager, when i start up my laptop i get the daily regular updates, then not long after i get this popup (to me its a popup) eventhough they are set up to "not allow", this popup always says the same thing...Update to Sympatico Security Manager is ready to be installed...To Install this update, Sympatico Security Manager will exit. it also has a "about this update" to click on and it wont let me, it just opens up the windows security centre..now i know ive already had the update because Security Manager never asks it just automatically updates and then it tells me at the bottom right of the screen that the Manager has been sucessfully updated.! now if i click on the red X to close it and even click update it opens up a window, pretends to download (the green bar never makes it to 100%) opens Windows Security Center and cancels out the Malware and warns me my machine is not protected that i need to turn on the malware protection option, when i do activate the malware protection the Sympatico Security Manager turns back on and sometimes its ok for a while then i get this dumb popup again...over and over many times a day...ive tried googling on it, havent found anything on it. This is what ive done so far..Malwarebytes, came out clean, did CCleaner and ATF , ran Sympatico Security anti-spyware , I always have a Sympatico.CA spyware that amazingly reappears everyday, and the anti-virus always comes out clean, ran Spybot it found double-click got rid of that, i ran Panda that came out clean...dont know what else to do and its driving me mad! If someone can look at my HJT log id really appreciate it! thank you in advance... Snow Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:54:23 PM, on 03/11/2009 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18828) Boot mode: Safe mode Running processes: C:\Windows\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Security Manager\pkR.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0" O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [Sympatico Security Manager] "C:\Program Files\Bell\Security Manager\Rps.exe" O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\Onetouch.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Internet Service Advisor\SSA.exe" /AUTORUN O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun O4 - HKCU\..\Run: [Google Update] "C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Security Manager\IdxClnR.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user') O4 - Startup: OneNote Table Of Contents.onetoc2 O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resou...NPUplden-ca.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/...can8/oscan8.cab O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe O23 - Service: Sympatico Security Manager (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\RpsSecurityAware.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Sympatico Security Manager Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Security Manager\rpsupdaterR.exe O23 - Service: Sympatico Security Manager Firewall (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Security Manager\Fws.exe O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 9605 bytes |
|
|
|
Nov 7 2009, 05:21 AM
Post
#2
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,918 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Please do the following:
Please download DDS from either of these links LINK 1 LINK 2 and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. NEXT ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries |
|
|
|
Nov 8 2009, 01:11 PM
Post
#3
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 82 Joined: 17-November 04 From: Canada Member No.: 18,591 |
Hello Catbyte...
i cant post the scans it wont let me due to them being to big...what do i do? Snow |
|
|
|
Nov 8 2009, 01:26 PM
Post
#4
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,918 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
zip them up and attach them or upload to media fire and post the sharing link.
http://www.mediafire.com Please check that you checked / unchecked the appropriate boxes in GMER - the log shouldn't be that large |
|
|
|
Nov 8 2009, 03:02 PM
Post
#5
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 82 Joined: 17-November 04 From: Canada Member No.: 18,591 |
I hope i did this right...here they are...
http://www.mediafire.com/?mydnnaa0zqj http://www.mediafire.com/?k2wllwlkdum http://www.mediafire.com/?knrdwam1d0x |
|
|
|
Nov 8 2009, 03:20 PM
Post
#6
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,918 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: Download Combofix from either of the links below, and save it to your desktop. Link 1 Link 2 **Note: It is important that it is saved directly to your desktop** -------------------------------------------------------------------- IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here -------------------------------------------------------------------- Double click on ComboFix.exe & follow the prompts.
|
|
|
|
Nov 10 2009, 07:55 AM
Post
#7
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 82 Joined: 17-November 04 From: Canada Member No.: 18,591 |
goodmorning...
here is the combofix log... ComboFix 09-11-08.03 - user 10/11/2009 8:13.1.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.1982.1294 [GMT -5:00] Running from: c:\users\user\Desktop\ComboFix.exe AV: Bell Internet Security Services Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755} FW: Bell Internet Security Services Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22} SP: Bell Internet Security Services Anti-Spyware *enabled* (Updated) {307352C6-1CBD-11DB-8AF6-B622A1EF5492} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\INSTALL.LOG c:\windows\system32\KBL.LOG c:\windows\system32\oem19.inf c:\windows\system32\oem4.inf . ((((((((((((((((((((((((( Files Created from 2009-10-10 to 2009-11-10 ))))))))))))))))))))))))))))))) . 2009-11-10 13:34 . 2009-11-10 13:34 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-11-06 00:45 . 2009-11-10 11:41 -------- d-----w- c:\users\user\Tracing 2009-11-06 00:38 . 2006-11-29 18:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll 2009-11-06 00:36 . 2009-11-06 00:36 -------- d-----w- c:\program files\Microsoft 2009-11-06 00:35 . 2009-11-06 00:35 -------- d-----w- c:\program files\Windows Live SkyDrive 2009-11-06 00:30 . 2009-11-06 00:30 -------- d-----w- c:\program files\Common Files\Windows Live 2009-11-06 00:12 . 2009-11-10 13:35 3360032 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-11-06 00:09 . 2009-11-06 00:12 12288 d-----w- c:\program files\Personal Vault Backup Manager 2009-11-06 00:07 . 2008-11-26 20:19 53192 ----a-w- c:\windows\system32\drivers\rp_skt32.sys 2009-11-06 00:07 . 2008-08-07 02:20 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys 2009-11-06 00:05 . 2008-08-28 18:16 71184 ----a-w- c:\windows\system32\drivers\DefragFS.sys 2009-11-06 00:05 . 2009-11-06 00:05 -------- d-----w- c:\programdata\Raxco 2009-11-06 00:05 . 2009-11-06 00:05 -------- d-----w- c:\program files\Raxco 2009-11-06 00:01 . 2009-11-06 00:04 90125872 ----a-w- c:\users\user\AppData\Roaming\Bell\Internet Service Advisor\downloads\Bell_Internet_Security_Services.41.exe.dir\Bell_Internet_Security_Services.exe 2009-11-04 23:31 . 2009-11-04 23:31 -------- d-----w- c:\users\user\AppData\Local\Apple Computer 2009-11-04 19:43 . 2009-11-04 19:43 -------- d-----w- c:\users\user\AppData\Local\Apple 2009-11-04 12:33 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll 2009-11-04 12:33 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe 2009-11-04 12:33 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-11-04 12:33 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll 2009-11-04 12:33 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll 2009-11-04 12:33 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-11-04 12:33 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll 2009-11-04 12:32 . 2009-08-07 00:23 171608 ----a-w- c:\windows\system32\wuwebv.dll 2009-11-04 12:32 . 2009-08-06 23:44 33792 ----a-w- c:\windows\system32\wuapp.exe 2009-11-03 19:00 . 2009-11-03 19:36 4096 d-----w- c:\programdata\Spybot - Search & Destroy 2009-11-03 19:00 . 2009-11-03 19:00 8192 d-----w- c:\program files\Spybot - Search & Destroy 2009-10-31 19:18 . 2009-11-10 11:44 -------- d-----w- c:\users\user\AppData\Local\Adobe 2009-10-30 23:50 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe 2009-10-30 23:50 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2009-10-16 10:23 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll 2009-10-16 10:23 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-10-16 10:23 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-10-16 10:20 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll 2009-10-16 10:20 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys 2009-10-16 10:20 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL 2009-10-11 17:29 . 2009-10-11 17:29 -------- d-----w- c:\users\user\AppData\Roaming\GARMIN 2009-10-11 17:21 . 2009-10-11 17:21 -------- d-----w- c:\program files\Garmin GPS Plugin 2009-10-11 17:20 . 2009-10-11 17:20 -------- d-----w- c:\program files\DIFX 2009-10-11 17:20 . 2009-10-11 17:20 -------- d-----w- c:\program files\Garmin . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-10 11:00 . 2008-03-10 15:44 672380 ----a-w- c:\windows\system32\perfh00C.dat 2009-11-10 11:00 . 2008-03-10 15:44 127578 ----a-w- c:\windows\system32\perfc00C.dat 2009-11-10 10:58 . 2008-09-30 00:24 4096 d-----w- c:\programdata\Google Updater 2009-11-10 02:59 . 2009-11-06 00:12 43256 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-11-09 23:21 . 2009-02-17 11:19 56160 ----a-w- c:\programdata\nvModes.dat 2009-11-06 11:00 . 2008-07-15 00:17 8192 d-----w- c:\programdata\Microsoft Help 2009-11-06 00:39 . 2008-07-16 01:02 4096 d-----w- c:\program files\Windows Live 2009-11-06 00:25 . 2008-07-16 12:42 4096 d-----w- c:\users\user\AppData\Roaming\Bell 2009-11-06 00:05 . 2008-07-16 12:42 4096 d-----w- c:\program files\Bell 2009-11-06 00:05 . 2008-07-16 12:42 4096 d-----w- c:\programdata\Bell 2009-11-06 00:04 . 2008-03-10 17:02 8192 d--h--w- c:\program files\InstallShield Installation Information 2009-11-03 01:42 . 2009-10-03 18:41 195456 ------w- c:\windows\system32\MpSigStub.exe 2009-10-31 00:24 . 2009-10-04 19:40 -------- d-----w- c:\program files\CCleaner 2009-10-17 13:21 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail 2009-10-07 00:50 . 2009-08-11 18:37 -------- d-----w- c:\programdata\Motive 2009-10-04 19:37 . 2009-10-04 19:06 4096 d-----w- c:\programdata\STOPzilla! 2009-10-04 19:34 . 2009-10-04 19:08 -------- d-----w- c:\programdata\SITEguard 2009-10-04 19:13 . 2009-10-04 19:13 888 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg 2009-10-04 19:06 . 2009-10-04 19:06 -------- d-----w- c:\program files\Common Files\iS3 2009-10-02 13:35 . 2008-08-13 23:04 -------- d-----w- c:\programdata\Skype 2009-10-01 10:25 . 2008-03-10 18:10 4096 d-----w- c:\program files\Java 2009-09-30 17:55 . 2009-09-30 17:55 -------- d-----w- c:\users\user\AppData\Roaming\Malwarebytes 2009-09-30 17:55 . 2009-09-30 17:54 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-30 17:54 . 2009-09-30 17:54 -------- d-----w- c:\programdata\Malwarebytes 2009-09-30 01:30 . 2009-02-09 22:56 -------- d-----w- c:\program files\Common Files\AOL 2009-09-29 15:04 . 2009-09-29 15:04 -------- d-----w- c:\program files\Trend Micro 2009-09-21 22:00 . 2008-07-16 00:22 6944 ----a-w- c:\users\user\AppData\Local\d3d9caps.dat 2009-09-18 10:13 . 2009-09-17 10:23 -------- d-----w- c:\programdata\NOS 2009-09-10 18:54 . 2009-09-30 17:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 18:53 . 2009-09-30 17:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-08-29 00:27 . 2009-09-19 03:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-29 00:14 . 2009-09-19 03:15 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-08-27 05:22 . 2009-10-16 10:21 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-27 05:17 . 2009-10-16 10:21 109056 ----a-w- c:\windows\system32\iesysprep.dll 2009-08-27 05:17 . 2009-10-16 10:21 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-08-27 03:42 . 2009-10-16 10:21 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL 2009-08-14 16:27 . 2009-09-16 23:55 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-08-14 15:53 . 2009-09-16 23:55 17920 ----a-w- c:\windows\system32\netevent.dll 2009-08-14 13:49 . 2009-09-16 23:55 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-08-14 13:49 . 2009-09-16 23:55 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-08-14 13:49 . 2009-09-16 23:55 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-08-14 13:49 . 2009-09-16 23:55 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-08-14 13:49 . 2009-09-16 23:55 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-08-14 13:49 . 2009-09-16 23:55 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-08-14 13:49 . 2009-09-16 23:55 10240 ----a-w- c:\windows\system32\finger.exe 2009-08-14 13:48 . 2009-09-16 23:55 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys 2009-08-14 13:48 . 2009-09-16 23:55 105984 ----a-w- c:\windows\system32\netiohlp.dll 2008-09-28 19:16 . 2008-09-28 19:16 951 ----a-w- c:\program files\Get OpenOffice.org.lnk 2008-07-15 15:41 . 2008-07-15 15:41 22 --sha-w- c:\windows\SMINST\HPCD.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VaultIcon1] @="{B976888E-DC7B-456C-A62F-44EA07ED231F}" [HKEY_CLASSES_ROOT\CLSID\{B976888E-DC7B-456C-A62F-44EA07ED231F}] 2009-07-02 19:32 503808 ----a-w- c:\program files\Personal Vault Backup Manager\VaultClientMenu.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968] "Google Update"="c:\users\user\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-10-16 133104] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-20 468264] "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560] "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "SSA.exe"="c:\program files\Bell\Internet Service Advisor\SSA.exe" [2009-06-29 3245296] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote Table Of Contents.onetoc2 [2008-11-16 3656] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2009-1-18 303104] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk * [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup backupExtension=.Startup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex( R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [22/09/2008 4:58 PM 693512] R2 RadialpointSafeConnectAgent;Bell Internet Security Services SafeConnectAgent;c:\program files\Bell\Bell Internet Security Services\SafeConnect\bin\SanaAgent.exe [14/11/2008 6:28 PM 4937752] R2 VaultClientSRV;Personal Vault Backup Manager Service;c:\program files\Personal Vault Backup Manager\VaultClientSRV.exe [02/07/2009 2:32 PM 1047632] R2 VaultClientUpgrade;Personal Vault Backup Manager Upgrade Service;c:\program files\Personal Vault Backup Manager\VaultClientUpgrade.exe [02/07/2009 2:32 PM 56400] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [09/02/2009 5:57 PM 24652] R3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [22/09/2008 4:58 PM 910600] R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\Bell\Bell Internet Security Services\SafeConnect\Driver\platform_VISTA\SafeConnectDriver.sys [14/11/2008 6:28 PM 161304] R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\Bell\Bell Internet Security Services\SafeConnect\Driver\platform_VISTA\SafeConnectFilter.sys [14/11/2008 6:28 PM 29720] R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\Bell\Bell Internet Security Services\SafeConnect\Driver\platform_VISTA\SafeConnectShim.sys [14/11/2008 6:28 PM 29248] S3 Radialpoint Security Services;Bell Internet Security Services;c:\program files\Bell\Bell Internet Security Services\RpsSecurityAwareR.exe [07/07/2009 1:24 PM 175184] --- Other Services/Drivers In Memory --- *NewlyCreated* - MBR *Deregistered* - mbr *Deregistered* - PROCEXP113 [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-11-10 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-30 11:08] 2009-11-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2421398992-4195468196-789225359-1000Core.job - c:\users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-16 17:08] 2009-11-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2421398992-4195468196-789225359-1000UA.job - c:\users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-16 17:08] 2009-10-14 c:\windows\Tasks\Rescue Reminder for 2HAPWC4A.job - c:\program files\Maxtor\ManagerApp\MaxUtilities.exe [2008-07-21 21:52] . . ------- Supplementary Scan ------- . uStart Page = hxxp://sympatico.msn.ca/ mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\q6jh5uey.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.sympatico.ca/ FF - plugin: c:\program files\Bell\Internet Service Advisor\nprpspa.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: c:\users\user\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . - - - - ORPHANS REMOVED - - - - HKCU-Run-HPAdvisor - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe HKLM-Run-MaxtorOneTouch - c:\program files\Maxtor\ManagerApp\Onetouch.exe AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\user\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-10 08:35 Windows 6.0.6002 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2009-11-10 8:42 ComboFix-quarantined-files.txt 2009-11-10 13:42 Pre-Run: 239,623,958,528 bytes free Post-Run: 238,799,007,744 bytes free - - End Of File - - A727F10EBDABE052EDA5281FF0A9755A |
|
|
|
Nov 10 2009, 08:08 AM
Post
#8
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,918 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following:
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT **Vista users - right click on the IE icon and run as administrator Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
Nov 10 2009, 02:58 PM
Post
#9
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 82 Joined: 17-November 04 From: Canada Member No.: 18,591 |
Hello Catbyte here are the reports...
seems to work fine after rebooting, that window popup with my security manager didnt come up at all... Malwarebytes' Anti-Malware 1.41 Database version: 3140 Windows 6.0.6002 Service Pack 2 10/11/2009 11:31:43 AM mbam-log-2009-11-10 (11-31-43).txt Scan type: Quick Scan Objects scanned: 93233 Time elapsed: 7 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Tuesday, November 10, 2009 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, November 10, 2009 14:27:17 Records in database: 3188069 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ D:\ E:\ Scan statistics Objects scanned 241105 Threats found 0 Infected objects found 0 Suspicious objects found 0 Scan duration 03:40:25 No threats found. Scanned area is clean. Selected area has been scanned. |
|
|
|
Nov 10 2009, 08:47 PM
Post
#10
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,918 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
You are clean, just some housekeeping to do now, please do the following: Visit ADOBEand download the latest version of Acrobat Reader (version 9.2) Having the latest updates ensures there are no security vulnerabilities in your system. NEXT Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
NEXT Follow these steps to uninstall Combofix
![]() NEXT Now to remove the rest of the tools that we have used in fixing your machine:
Note: If there are any remaining logs/tools > right click and delete them NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Nov 11 2009, 06:49 AM
Post
#11
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 82 Joined: 17-November 04 From: Canada Member No.: 18,591 |
Hello Catbyte..
thats great news! thank you once again for all your help! Snow |
|
|
|
Nov 11 2009, 06:52 AM
Post
#12
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,918 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
20 | Wakenaam | 349 | Today, 09:54 AM Last post by: Tomk |
|||
![]() |
16 | mesa215 | 270 | Today, 12:05 AM Last post by: Raktor |
|||
![]() |
23 | cherfxst | 378 | Yesterday, 09:36 PM Last post by: oldman960 |
|||
![]() |
17 | stjohn | 350 | Yesterday, 06:17 PM Last post by: CatByte |
|||
|
Time is now: 20th November 2009 - 07:02 PM |