This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] New HJT log

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello
I've been referred here from Windows forum. Basically, my desktop is ONLY my wallpaper, no icons, no Start button.
One person, at least, thinks the various symptoms could be from malware. Meanwhile, I am working the machine pretty much through the Task Manager. Can open some programs from New Task in that. Can't browse in Windows Explorer, or go to Control Panel, for instance. I will come right back here and edit in the location of that thread, where all the details have been detailed, and various suggestions made and tried. http://forums.whatthetech.com/All_desktop_…er_t103241.html




Here is HJT log, for openers.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:46:24 PM, on 5/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080226
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080226
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=YD…f_uJIidTMkfE3mA
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ForceField Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\Components\TrustCheckerIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ForceField Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\Components\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [AppMgrGui] C:\Program Files\AppStream\WindowsClient\bin\exeForService.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /start_mode="auto"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-1735693432-2183833273-2223226336-1006\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup (User '?')
O4 - HKUS\S-1-5-21-1735693432-2183833273-2223226336-1006\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (User '?')
O4 - HKUS\S-1-5-21-1735693432-2183833273-2223226336-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-1735693432-2183833273-2223226336-1006\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 (User '?')
O4 - HKUS\S-1-5-21-1735693432-2183833273-2223226336-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1735693432-2183833273-2223226336-1006\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Timer Wizard.lnk = C:\Program Files\Timer Wizard\Timer Wizard.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\scieplugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1209314190312
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: ASWLNDLL - C:\WINDOWS\SYSTEM32\ASWLNDLL.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AWE 5.1.0 Application Manager (AppMgrService) - AppStream Inc. - C:\Program Files\AppStream\WindowsClient\bin\AppMgrService.exe
O23 - Service: The Shield Deluxe 2008 (AVP) - PCSecurityShield - C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: ForceField IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10094 bytes
DO NOT use any TOOLS such as Combofix, MBAM, SmitfraudFix, Vundofix, or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

Also please describe how your computer behaves at the moment.
Thanks for your help in this. I'm going to need instructions in how to shut off Shield Deluxe. I think that is my only realtime AV A-Malware. Also have Windows firewall, if that counts. I can't get to anything except through the Task Manager — not an availale icon anywhere to open and thence shut down anything. I'm doing somewhat well opening simple things like Firefox out of the New Task box. Also, per saving Combofix to desktop — so far I cannot open anything through New Task that is on the desktop. I can start stuff that I save to the C drive. Adjunct question — should we wait for my initial Carbonite backup to complete? I think we shut it off last night. I can look up to see how far it has progressed — might be most of the way there. Denno
physically disconnect from the internet

Open taskmanager and copy/paste this line
"%userprofile%\desktop\combofix.exe" /killall
Click OK.

this will start ComboFix in a special way.
When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Wow! Wrinkles everywhere.

Lemme see if I can recall the sequence.

I pulled the internet connection and started Combofix the way you said.
During the startup process it pointed out I did not have System Restore and did I want to download and install it?
Wasn't quite sure how to handle this, but put the internet plug back. Combofix decided I still wasn't connected and proceeded with scan. I went away and when I got back there had been a bluescreen shutdown of windows.

Restarted, Combofix continued and made a log and here it is.


(forgot and attached it too, but here is the paste-in):




ComboFix 09-05-22.07 - Miekro S. Dallalio 05/23/2009 13:28.1 - NTFSx86
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\klogon.dll
c:\windows\system32\x64

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_IAS


((((((((((((((((((((((((( Files Created from 2009-04-23 to 2009-05-23 )))))))))))))))))))))))))))))))
.

2009-05-23 16:12 . 2009-05-23 16:12 2977615 —-a-w C:\ComboFix.exe
2009-05-23 14:40 . 2009-05-23 14:40 50688 —-a-w C:\ATF_Cleaner.exe
2009-05-23 04:45 . 2009-05-23 04:45 ——– d—–w c:\program files\CodeStuff
2009-05-23 04:06 . 2006-09-25 18:50 707869 —-a-w C:\StarterSetup.exe
2009-05-23 04:04 . 2006-09-25 18:50 707869 —-a-w c:\program files\StarterSetup.exe
2009-05-23 03:46 . 2009-05-23 03:46 ——– d—–w c:\program files\Trend Micro
2009-05-23 03:45 . 2009-05-23 03:45 812344 —-a-w C:\HJTInstall.exe
2009-05-22 03:01 . 2001-08-17 16:10 35871 —-a-w c:\windows\system32\dllcache\wbfirdma.sys
2009-05-22 03:00 . 2001-08-17 17:28 793598 —-a-w c:\windows\system32\dllcache\usr1806.sys
2009-05-22 02:59 . 2001-08-17 16:51 222336 —-a-w c:\windows\system32\dllcache\trid3dm.sys
2009-05-22 02:58 . 2001-08-17 17:50 103936 —-a-w c:\windows\system32\dllcache\sx.sys
2009-05-22 02:57 . 2001-08-17 17:53 9600 —-a-w c:\windows\system32\dllcache\sonymc.sys
2009-05-22 02:56 . 2001-08-17 18:56 150144 —-a-w c:\windows\system32\dllcache\sis6306v.dll
2009-05-22 02:55 . 2001-08-17 18:56 245632 —-a-w c:\windows\system32\dllcache\s3savmx.dll
2009-05-22 02:54 . 2001-08-17 17:51 19584 —-a-w c:\windows\system32\dllcache\rasirda.sys
2009-05-22 02:53 . 2001-08-18 02:36 16384 —-a-w c:\windows\system32\dllcache\philcam1.dll
2009-05-22 02:52 . 2001-08-17 16:12 27209 —-a-w c:\windows\system32\dllcache\otc06x5.sys
2009-05-22 02:51 . 2001-08-17 18:56 35392 —-a-w c:\windows\system32\dllcache\n9i128.dll
2009-05-22 02:50 . 2001-08-18 02:36 47616 —-a-w c:\windows\system32\dllcache\memgrp.dll
2009-05-22 02:49 . 2001-08-18 02:36 8704 —-a-w c:\windows\system32\dllcache\kbdjpn.dll
2009-05-22 02:48 . 2001-08-17 18:05 141056 —-a-w c:\windows\system32\dllcache\icam3.sys
2009-05-22 02:47 . 2001-08-18 02:36 68608 —-a-w c:\windows\system32\dllcache\hpgt53tk.dll
2009-05-22 02:46 . 2001-08-17 16:13 27165 —-a-w c:\windows\system32\dllcache\fetnd5.sys
2009-05-22 02:45 . 2001-08-17 16:11 153631 —-a-w c:\windows\system32\dllcache\el90xnd5.sys
2009-05-22 02:44 . 2001-08-18 02:36 80896 —-a-w c:\windows\system32\dllcache\dc210usd.dll
2009-05-22 02:43 . 2001-08-17 17:51 13824 —-a-w c:\windows\system32\dllcache\bulltlp3.sys
2009-05-22 02:42 . 2001-08-17 18:56 66048 —-a-w c:\windows\system32\dllcache\s3legacy.dll
2009-05-19 18:59 . 2009-05-19 18:59 ——– d—–w c:\documents and settings\All Users\Application Data\Carbonite
2009-05-19 18:59 . 2009-05-19 18:59 ——– d—–w c:\program files\Carbonite
2009-05-15 02:27 . 2009-05-15 02:27 152576 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-13 03:33 . 2009-05-13 03:33 ——– d—–w C:\Denno
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w c:\windows\system32\GPhotos.scr

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-19 01:06 . 2008-09-07 22:40 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-18 19:38 . 2008-04-21 15:12 908 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\wklnhst.dat
2009-05-15 02:41 . 2008-07-17 00:48 ——– d—–w c:\documents and settings\Miekro S. Dallalio\Application Data\OpenOffice.org2
2009-05-15 02:28 . 2008-02-26 17:39 ——– d—–w c:\program files\Java
2009-05-14 22:56 . 2008-05-14 04:18 224 —-a-w c:\windows\system32\lkfl.dat
2009-05-14 22:56 . 2008-02-26 17:51 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-09 12:52 . 2008-04-14 06:24 ——– d—–w c:\program files\XoftSpySE
2009-04-26 01:07 . 2008-04-13 04:17 ——– d—–w c:\program files\AZZ Cardfile
2009-04-15 02:07 . 2008-02-26 17:44 ——– d—–w c:\program files\Google
2009-04-07 16:08 . 2009-04-07 16:08 1915520 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-04-07 16:07 . 2009-04-07 16:07 ——– d—–w c:\documents and settings\Miekro S. Dallalio\Application Data\Move Networks
2009-04-07 16:07 . 2009-04-07 16:07 34062 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Move Networks\ie_bin\Uninst.exe
2009-03-28 22:45 . 2009-03-28 22:45 57344 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-4a49cce5-n\Decora-SSE.dll
2009-03-28 22:45 . 2009-03-28 22:45 24064 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-23dc31c1-n\Decora-D3D.dll
2009-03-28 22:45 . 2009-03-28 22:45 499712 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-74547280-n\msvcp71.dll
2009-03-28 22:45 . 2009-03-28 22:45 499712 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-74547280-n\jmc.dll
2009-03-28 22:45 . 2009-03-28 22:45 348160 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-74547280-n\msvcr71.dll
2009-03-13 01:40 . 2009-03-13 01:40 57344 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\37\3976f065-33fd5033-n\Decora-SSE.dll
2009-03-13 01:40 . 2009-03-13 01:40 24064 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\37\2c4a0065-13cf07ec-n\Decora-D3D.dll
2009-03-13 01:40 . 2009-03-13 01:40 315392 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-15dba563-n\jogl.dll
2009-03-13 01:40 . 2009-03-13 01:40 20480 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-15dba563-n\jogl_awt.dll
2009-03-13 01:40 . 2009-03-13 01:40 114688 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-15dba563-n\jogl_cg.dll
2009-03-13 01:40 . 2009-03-13 01:40 503808 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-6dd3534c-n\msvcp71.dll
2009-03-13 01:40 . 2009-03-13 01:40 499712 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-6dd3534c-n\jmc.dll
2009-03-13 01:40 . 2009-03-13 01:40 348160 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\38\39ba6e6-6dd3534c-n\msvcr71.dll
2009-03-13 01:40 . 2009-03-13 01:40 20480 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-5d876822-n\gluegen-rt.dll
2009-03-13 01:38 . 2009-03-13 01:38 152576 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-09 17:29 . 2009-03-09 17:29 97144 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-03-09 17:29 . 2009-03-09 17:29 1010552 —-a-w c:\documents and settings\Miekro S. Dallalio\Application Data\Move Networks\ie_bin\qsp2ie071303000006.dll
2009-03-09 09:19 . 2008-12-10 15:56 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2004-08-10 18:51 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-10 18:51 826368 —-a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-01-09 20:13 583312 —-a-r c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-01-09 20:13 583312 —-a-r c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-01-09 20:13 583312 —-a-r c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-22 167368]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-14 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-14 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-14 138008]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"AppMgrGui"="c:\program files\AppStream\WindowsClient\bin\exeForService.exe" [2006-09-27 24064]
"EPSON Stylus Photo RX620 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-19 98304]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2008-05-03 441592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-01-09 669840]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-06-14 16132608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ASWLNDLL]
2007-05-14 01:45 6656 —-a-w c:\windows\system32\ASWLNDLL.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\WS_FTP Pro\\ftp95pro.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC

R2 AppMgrService;AWE 5.1.0 Application Manager;c:\program files\AppStream\WindowsClient\bin\AppMgrService.exe [2006-09-27 1990656]
R3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [2008-05-03 35064]
S1 APPSTREAM;APPSTREAM;c:\windows\System32\Drivers\APPSTREAM.SYS [2007-05-14 115284]
S2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\DRIVERS\datunidr.sys [2007-08-24 5376]
S2 IswSvc;ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2008-05-03 191736]
S2 REGHOOK;REGHOOK;c:\windows\System32\Drivers\REGHOOK.SYS [2006-09-27 54879]
S2 VSPD;VSPD;c:\windows\System32\Drivers\VSPD.SYS [2006-09-27 31321]


— Other Services/Drivers In Memory —

*Deregistered* - aawservice
*Deregistered* - AFD
*Deregistered* - AppMgrService
*Deregistered* - APPSTREAM
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - AVP
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - datunidr
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - DLABMFSM
*Deregistered* - DLABOIOM
*Deregistered* - DLADResM
*Deregistered* - DLAIFS_M
*Deregistered* - DLAOPIOM
*Deregistered* - DLAPoolM
*Deregistered* - DLARTL_M
*Deregistered* - DLAUDF_M
*Deregistered* - DLAUDFAM
*Deregistered* - Dnscache
*Deregistered* - DRVNDDM
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - Fax
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gusvc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - hnmsvc
*Deregistered* - i2omgmt
*Deregistered* - iaStor
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - IswSvc
*Deregistered* - JavaQuickStarterService
*Deregistered* - Kbdclass
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - Packet
*Deregistered* - PartMgr
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - REGHOOK
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sprtsvc_dellsupportcenter
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - VSPD
*Deregistered* - w32time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-05-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-02-26 00:12]

2009-05-23 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-10-24 18:59]

2009-05-12 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-10-24 18:59]
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=YD_ZMgbfxFGVf_uJIidTMkfE3mA
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Miekro S. Dallalio\Application Data\Mozilla\Firefox\Profiles\zrz382q3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-23 14:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\ASWLNDLL.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-23 14:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-23 18:04

Pre-Run: 209,027,710,976 bytes free
Post-Run: 210,075,570,176 bytes free

Current=4 Default=4 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
320 — E O F — 2009-05-13 17:24

Attachments:

No desktop. Pardon my compulsivity (have I mentioned being compulsive?)….did you get the bit about lacking the recovery console? Something said Combofix will not attempt certain serious fixes w/o that function installed.

No desktop.
Pardon my compulsivity (have I mentioned being compulsive?)….did you get the bit about lacking the recovery console? Something said Combofix will not attempt certain serious fixes w/o that function installed.

Yes I did. CF will run and work without it.


In Task Manager, do you have Explorer.exe running?

If it's running, End process on it.

Open your Task Manager.(alt / ctrl /del) Click File and select New Task (Run…)

Then type explorer.exe to start it.


If not listed Then type explorer.exe to start it.
Not there and doesn't show up upon command. No, wait a minute — it shows up and then disappears, all in one second. Doesn't do this every time, either. It has my user name in the second column when it does that. (Far as I know, I'm the only user on this machine as far as it knows). BTW, what I'm doing today is ducking into the office between yardwork, so checking the thread once in awhile.
Open taskmanager, type in Regedit tap Enter Key

Make sure "My Computer" is highlighted

Click "Edit"> "Find"
Type in ASWLNDLL.dll tap Enter Key.
Right Click on the file if found and select "Delete"

Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.

Close Regedit.

Reboot

Next:

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Did the first half.

When I go thru New Task, navigate to C:\Program files\Internet Explorer\iexplore.exe" I get a message that Windows cannot locate http://google.com. Is there another way to open IE?

Meanwhile, went to eset thru FF, the site seems to say that FF is now supported. Installed eset installer in C:\, started it thru New Task. It started downloading and then a window came up saying an unsupported operation had been attempted.
Same result twice.
ie.inf does not appear to be on the computer. It is on the reinstall CD. I managed to copy/paste it into Windows and start an install. It called for MSWRD632.WPC This was on the CD the first time I looked for it, but got some message about an invalid file path. Now I am not finding the doggone file. Believe me, this is "high-level computing" for me. My brain is spinning and my wife is chivvying for me to mow the lawn. I'll try it again tonight and see if I can get the install done. This is to bring up IE, yes? And then do the CF run.

ie.inf does not appear to be on the computer. It is on the reinstall CD. I managed to copy/paste it into Windows and start an install. It called for MSWRD632.WPC This was on the CD the first time I looked for it, but got some message about an invalid file path. Now I am not finding the doggone file.

Believe me, this is "high-level computing" for me. My brain is spinning and my wife is chivvying for me to mow the lawn. I'll try it again tonight and see if I can get the install done. This is to bring up IE, yes? And then do the CF run.

Yes. it's to install IE.
This is looking more and more like you'r going to need to reinstall Windows.
I still may be able to do the above install when I can keep all the false trail clear in my mind and backtrack as needed.
(Of course, who knows if all these procedures will eventualy fix the mystery problem).

But there is the total-sidestep approach, is there not (?), of slaving this HD to another with a clean Windows. Then use the current HD as file storage, or copy over files and programs and then reformat it.

Would still like to have an idea of what went wrong and especially how to prevent a recurrence.
.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI