Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Aug 14 2008, 12:37 AM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
not to get a bug I could not fix. I find your site well layed out and easy to follow so now I turn to the masters on how to solve this one. I just upgraded from XP Home to XP pro and all these pop-up started I went to MS download site to get the layest and got this error Windows Update Error Code 80070422 and then Error code 1058 showing this path C:\WINDOWS\system32\svchost.exe -k netsvcs I never got pop-ups before and now I keep getting them and cannot stop them no matter how many times i run spybot and antivirus program.. surfing says that the disabled autoupdate are caused by: Vundo-ZLOB-SDBot infection, all of which is protected by a rootkit. which takes an expert to remove..so here i am. Where I am now Windows XP SP2 S&D spybot F-Secure internet security 2008 Full Version when i try to start automatic updates I get the error code 80070422 yes AUD are disabled and cannot start Check if BITS is enabled. using command prompt. yes it is. Check if Windows Module Installer is on Manual (yes it is) Windows Module Installer is running. Windows Update (Using Adminstartive Tools > Services > windows Update (properties). I realised that it is Disabled so i click on Automatic, and it switch back to Disabled again. I have done this repeatedly and when the status is on Automatic (which it should be), Its service status wrote : Stopped. ok. I click on start, a pop up shows up : "Error 1058: The Service cannot be started, either because it is disabled or because it has no enabled devices associated with it." I cleaned all the malware and bots i could find and now at least i can surf and post th this forum. Your help is needed.. ED -----> ARC Hellraiser Here is my Log: ogfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:49:44 PM, on 8/13/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\cisvc.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE C:\Program Files\Logitech\G-series Software\LGDCore.exe C:\Program Files\Logitech\G-series Software\LCDMon.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\tcpsvcs.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\WINDOWS\system32\cidaemon.exe C:\Documents and Settings\Ed Smith\Local Settings\Temporary Internet Files\Content.IE5\DZEROFHV\hijackthis[1].exe R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll R3 - URLSearchHook: (no name) - {02AA16FF-4A3F-025B-B4FE-6C79F45C26CD} - bhoserv.dll (file missing) O1 - Hosts: localhost 127.0.0.1 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll O2 - BHO: (no name) - {2C14F207-731A-4ACD-B5C7-5A6DDB758279} - (no file) O2 - BHO: (no name) - {4C08CB4F-DA7F-4821-B14E-871E04288AF7} - C:\WINDOWS\System32\xxyyvVlj.dll O2 - BHO: (no name) - {4DEABE3F-4A61-47C2-A64D-90453DC01542} - C:\WINDOWS\system32\khfCuSml.dll O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: (no name) - {BD64346B-2B52-44E3-894B-AF687943DADD} - (no file) O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O2 - BHO: {cf8bb1a2-9920-0e7b-f854-5efef3270aed} - {dea0723f-efe5-458f-b7e0-02992a1bb8fc} - C:\WINDOWS\system32\zhpvpq.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing) O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [forces_elite] driver32.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKLM\..\Policies\Explorer\Run: [WHmE0M2XSz] C:\Documents and Settings\All Users\Application Data\ralaxcfg\jszsbehg.exe O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08d9 -f video -m logitech -d 11.1.0.2016 (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x08d9 -f video -m logitech -d 11.1.0.2016 (User 'Default user') O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: &Suspend Webpage Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: &Deny this website - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: &Allow this website - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Ed Smith\Start Menu\Programs\IMVU\Run IMVU.lnk O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU) O12 - Plugin for .ica: C:\Program Files\Internet Explorer\PLUGINS\npican.dll O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll O16 - DPF: Backgammon by pogo - http://gammon.pogo.com/applet/backgammon/b...n-ob-assets.cab O16 - DPF: ChatSpace Full Java Client 4.0.0.320 - http://63.102.226.240:8000/Java/cfs40320.cab O16 - DPF: ConferenceRoom Java Client - http://mail.igl.net:8000/java/cr.cab O16 - DPF: Double Deuce Poker by pogo - http://doublebonus.pogo.com/applet/videopo...e-ob-assets.cab O16 - DPF: High Stakes Poker by pogo - http://drawpoker.pogo.com/applet/drawpoker...r-ob-assets.cab O16 - DPF: Mah Jong Garden by pogo - http://mahjong2.pogo.com/applet/mahjong/ma...g-ob-assets.cab O16 - DPF: Poppit TM by pogo - http://poppit.pogo.com/applet/poppit/poppit-ob-assets.cab O16 - DPF: Spades by pogo - http://spades.pogo.com/applet/spades/spades-ob-assets.cab O16 - DPF: Sweet Tooth TM by pogo - http://sweettooth.pogo.com/applet/sweettoo...h-ob-assets.cab O16 - DPF: Texas Hold'em Poker by pogo - http://holdem2.pogo.com/applet-5.9.4.30/ho...m-ob-assets.cab O16 - DPF: Tri-Peaks by pogo - http://peaks.pogo.com/applet/peaks/peaks-ob-assets.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/22f58673b5f127...ip/RdxIE601.cab O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1216439907765 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1216439365265 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1218595758593 O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://hellraisepics1.spaces.live.com/Phot...ad/MsnPUpld.cab O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl...ArcadeRdxIE.cab O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toontown.com/sv1.0.14.48/ttinst.cab O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/pla...0/Installer.exe O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O20 - Winlogon Notify: khfCuSml - C:\WINDOWS\SYSTEM32\khfCuSml.dll O21 - SSODL: sxfnewqb - {C6DA508E-2F43-45C8-85F5-343ADAA590E2} - (no file) O21 - SSODL: fkdnrwsv - {810D71EC-D1CF-4178-B95A-38FBC2E45610} - (no file) O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe O24 - Desktop Component 0: Privacy Protection - (no file) -- End of file - 15133 bytes |
|
|
|
Aug 20 2008, 05:33 AM
Post
#2
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
ARC Hellraiser,
Welcome, your infected with the SDBot worm amongst others This tool needs to be run from Safemode to be effective, so download it to your desktop, boot to Safemode to run it. QUOTE To Enter Safemode
Tutorial if you need it How to boot into Safemode Download SDFix and save it to your Desktop. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following :
|
|
|
|
Aug 20 2008, 05:29 PM
Post
#3
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
Thanks for the replay...
HR |
|
|
|
Aug 22 2008, 09:37 AM
Post
#4
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
WELL I did what was advised..I am now replaying from work. because my system
has now developed the Blue Screen of death.. Recap Followed the steps Log at the end. Could not run Hijack this..pc would just Hang AND while i was pasting the log I was getting Spamed by the AntiVirus 2009 BS I kept closeing and closeing just enought to get the logs sent to my work PC...as a back up I tried to log on to Here but againg spamed and at login it would just sit there getting more adds and BS so I just shut down and went to bed. BUT when I got up this mornig and was going to post logs I got the Blue screen and a 'Core Dump" and a system32 error.. I tried to restart in Safe Mode BUT it will not boot. I had NO time to do anything else (had to get to work) but did try and restart and each time it Core dumps. If you CAN Please advise what's next.. Hellraiser. SDFix: Version 1.218 Run by Ed Smith on Thu 08/21/2008 at 10:30 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Restoring Default HomePage Value Restoring Default Desktop Components Value Rebooting Checking Files : Trojan Files Found: C:\WINDOWS\system32\khfCuSml.dll - Deleted C:\Documents and Settings\Ed Smith\Application Data\Install.dat - Deleted C:\Documents and Settings\The Kids\Application Data\Install.dat - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-21 23:00:11 Windows 5.1.2600 Service Pack 2 FAT NTAPI scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger" "C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 3.0" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Xfire\\Xfire.exe"="C:\\Program Files\\Xfire\\Xfire.exe:*:Enabled:Xfire" "C:\\ijji\\ENGLISH\\u_gbound.exe"="C:\\ijji\\ENGLISH\\u_gbound.exe:*:Enabled:<ijji Downloader>" "C:\\ijji\\ENGLISH\\Gunbound Revolution\\GunBound.gme"="C:\\ijji\\ENGLISH\\Gunbound Revolution\\GunBound.gme:*:Enabled:GunBound" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Sat 27 Jan 2007 3,350 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys" Sat 27 Jan 2007 8 ..SHR --- "C:\WINDOWS\system32\C4CAA70CCB.sys" Tue 1 Apr 2003 237,636 A..H. --- "C:\Program Files\America Online 8.0\waol.exe" Tue 1 Apr 2003 49,224 A..H. --- "C:\Program Files\America Online 8.0\aolphx.exe" Tue 1 Apr 2003 36,940 A..H. --- "C:\Program Files\America Online 8.0\aoltray.exe" Tue 1 Apr 2003 40,960 A..H. --- "C:\Program Files\America Online 8.0\RBM.exe" Mon 7 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe" Mon 7 Jul 2008 4,891,472 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" Mon 7 Jul 2008 2,156,368 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" Fri 11 Jan 2008 1,959,240 ...H. --- "C:\Program Files\Chocolatier\Chocolatier.exe" Sun 21 Jul 2002 418,816 ...HR --- "C:\WINDOWS\system32\Tools\All.exe" Thu 18 Jul 2002 390,144 ...HR --- "C:\WINDOWS\system32\Tools\Change.exe" Fri 19 Jul 2002 574,464 ...HR --- "C:\WINDOWS\system32\Tools\CheckPath.exe" Mon 19 Aug 2002 430,592 ...HR --- "C:\WINDOWS\system32\Tools\Counter.exe" Mon 22 Jul 2002 390,656 ...HR --- "C:\WINDOWS\system32\Tools\DelFolders.exe" Fri 22 Nov 2002 399,872 ...HR --- "C:\WINDOWS\system32\Tools\DirectSetup.exe" Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RegClean.exe" Fri 19 Jul 2002 388,608 ...HR --- "C:\WINDOWS\system32\Tools\Regexe.exe" Sun 1 Dec 2002 431,616 ...HR --- "C:\WINDOWS\system32\Tools\Restart.exe" Fri 19 Jul 2002 388,096 ...HR --- "C:\WINDOWS\system32\Tools\RunRegexe.exe" Wed 20 Dec 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Tue 1 Apr 2003 49,226 A..H. --- "C:\Program Files\America Online 8.0\COMIT\cswitch.exe" Mon 20 Mar 2006 72 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti8D.tmp" Thu 15 Aug 2002 266,240 A..H. --- "C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 15\Mavis Beacon Teaches Typing.exe" Thu 21 Aug 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4f79e01ce8ee10a7556514a051f797f4\BIT1A.tmp" Thu 21 Aug 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\66b1d8e81a20b4b541ab3e558f2fd638\BIT1B.tmp" Wed 20 Dec 2006 20 A..H. --- "C:\Documents and Settings\Ed Smith\My Documents\My Music\License Backup\drmv1lic.bak" Wed 20 Dec 2006 4,348 ...H. --- "C:\Documents and Settings\Ed Smith\My Documents\My Music\License Backup\drmv1key.bak" Wed 20 Dec 2006 9,654 A.SH. --- "C:\Documents and Settings\Ed Smith\My Documents\My Music\License Backup\drmv2key.bak" Mon 7 Jan 2008 20,992 ...H. --- "C:\Documents and Settings\Ed Smith\Application Data\Microsoft\Word\~WRL1250.tmp" Tue 22 Nov 2005 444 ...HR --- "C:\Documents and Settings\Ed Smith\Application Data\SecuROM\UserData\securom_v7_01.bak" Tue 23 Oct 2007 3,350,528 A..H. --- "C:\Documents and Settings\Ed Smith\Application Data\U3\temp\Launchpad Removal.exe" Tue 1 Apr 2003 106,496 A..H. --- "C:\Program Files\Common Files\aolshare\shell\us\shellext.dll" Finished! |
|
|
|
Aug 22 2008, 09:49 AM
Post
#5
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
The Core Dump error has to do with programs shutting down and not being fully released by memory.
Try running these programs, you can boot to safemode with Network Support to download and run them otherwise you can also transfer them from another computer via CD or Thumb drive Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Download ComboFix from Here or Here to your Desktop. In the event you already have Combofix, this is a new version that I need you to download. It must be saved directly to your desktop. 1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
3. Now double click on combofix.exe & follow the prompts. When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze. |
|
|
|
Aug 22 2008, 01:45 PM
Post
#6
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
Thanks for the Fast Response
I have downloaded both on to a flash and A CD FTI when I run safe mode I see a string od command lines and it just stops and sits there... I will try when i get home from work with network support and see if it starts BTW ---->Error Code = Win32K.sys BF803E1A Base at BF 8000000 0xc00000005 0xBF803E1A 0x00000000 Datestamp 41107f7a |
|
|
|
Aug 22 2008, 02:03 PM
Post
#7
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Safemode will do that, sometimes it takes a few minutes to load
QUOTE BTW ---->Error Code = Win32K.sys BF803E1A Base at BF 8000000 0xc00000005 0xBF803E1A 0x00000000 Datestamp 41107f7a Read this please, you may have other issues on this system besides malware http://forums.techarena.in/windows-xp-support/767831.htm |
|
|
|
Aug 22 2008, 03:56 PM
Post
#8
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
thanks for the heads up
will be later...working late HR |
|
|
|
Aug 24 2008, 10:42 AM
Post
#9
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
Hi all
I am repairing my sysytem from the BSOD Stop:oxoooooo8E error should be back up today Please do not delete thread.. after repair will follow last request from-----> ken545 |
|
|
|
Aug 26 2008, 07:27 AM
Post
#10
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
still trying to repair hard drive
|
|
|
|
Sep 2 2008, 09:19 AM
Post
#11
|
|
|
New Member ![]() Group: New Member Posts: 8 Joined: 13-August 08 From: USA OHIO Member No.: 80,949 Operating System: Windows XP Pro 5.1.2600 SP2 |
UPDATE..fixed BSOD and did a Repair...and it (as you already know made it worse) Following information found here to correct problems,
missing files errors... YOUR forums and database have been most helpful... still not fixed yet... When fixed then we get back to Virus cleanout... HR |
|
|
|
Sep 15 2008, 03:35 PM
Post
#12
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,144 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log |
|
|
|
![]() ![]() |