This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Generic Host failure, Svchost.exe, and that Defender loo

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thank god something like this exists. I was about to pull my hair out with this problem, but I will start from the top.

About a week ago, I Searching for some music on The Pirate Bay, and one of their banner adds starts up that application that looks like defender and starts causing problems. I have seen this thing before and quickly killed the browser and end tasked the thing. I have been hit before by this bit of malware, but I thought I had beefed up my defenses. I run an up to date Norton, Cyber armor, and Defender.

Well, I ran Norton, virus found and quarenteened, then I ran Adware and go the rest of it. After a reboot, I started to get a Generic Host Process failure at startup caused by Svchost.exe. The data behind the failure had about 36 DLLs in it. The web seems to have been affected on my PC, with some simple sights coming up quickly and others not at all. My web is hit and miss, so I apologize in advance if I missed someone elses thread related to this. In my attempt to solve it myself, I have uploaded all the recent Microsoft Hot Fixes on the subject and installed SP3. No Goodie. So, here is my Hijack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:16:39 PM, on 6/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Belkin\F1U201.401\usbshare.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\Hummbird\inetd32.exe
C:\Program Files\netDeploy\Launcher\ndserv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\CyberArmor\casvc.exe
C:\PROGRA~1\CYBERA~1\pcs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\CYBERA~1\pcshelp.exe
C:\Program Files\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thepiratebay.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=wwwgate.ti.com:80;gopher=wwwgate.ti.com:80;http=wwwgate.ti.com:80;https=wwwg
ate.ti.com:81;socks=wwwgate.ti.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [CyberArmorHelper] C:\PROGRA~1\CYBERA~1\pcshelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: F1U201.401.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…oad/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1245974797718
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - http://www.alleghenyludlum.com/viewer/acti…tivexviewer.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://f2.pg.photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab?
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ent.ti.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ent.ti.com
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: cahooknt.dll
O20 - Winlogon Notify: iiffFxwv - iiffFxwv.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: CyberArmor Run Service (CyberArmorRunService) - InfoExpress - C:\Program Files\CyberArmor\casvc.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Communications Ltd. - C:\WINDOWS\System32\Hummbird\inetd32.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ndserv - Open Software Associates Ltd. - C:\Program Files\netDeploy\Launcher\ndserv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

–
End of file - 11416 bytes

Thanks,

Russ Barrow
Hi there I will need to look deeper as HJT does not show enough data for me

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Thanks for the help, I have attached the OTS and Hijack this log files. I ran the scan as you requested, and it did have the following error: "MaxScriptStatements" -> Reg Error: Invalid Data Type

Attachments:

Hi you have multiple infections there and some are rootkits so I will need to use a bigger hammer

Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YN -> iiffFxwv -> 
[Files/Folders - Created Within 30 Days]
NY -> sys -> C:\Program Files\sys
NY -> 010112010146118114.dat -> C:\WINDOWS\010112010146118114.dat
NY -> ld10.exe -> C:\WINDOWS\ld10.exe
NY -> _psisdecd.dll -> C:\WINDOWS\System32\_psisdecd.dll
NY -> efccyyAS.dll -> C:\WINDOWS\System32\efccyyAS.dll
NY -> phqghume.sys -> C:\WINDOWS\System32\drivers\phqghume.sys
NY -> hRsYyyay.ini2 -> C:\WINDOWS\System32\hRsYyyay.ini2
NY -> hRsYyyay.ini -> C:\WINDOWS\System32\hRsYyyay.ini
NY -> senekavubuwmde.dll -> C:\WINDOWS\System32\senekavubuwmde.dll
NY -> senekaleynxixr.dll -> C:\WINDOWS\System32\senekaleynxixr.dll
NY -> senekafilrntjn.dll -> C:\WINDOWS\System32\senekafilrntjn.dll
NY -> senekaudyynayh.sys -> C:\WINDOWS\System32\drivers\senekaudyynayh.sys
NY -> yJTDdfii.ini2 -> C:\WINDOWS\System32\yJTDdfii.ini2
NY -> jnzkk.dll -> C:\WINDOWS\jnzkk.dll
NY -> JGJJJJKO.ini -> C:\WINDOWS\JGJJJJKO.ini
NY -> qwimp.ini -> C:\WINDOWS\qwimp.ini
[Files/Folders - Modified Within 30 Days]
NY ->  (BARROW-Russ Barrow).job -> C:\WINDOWS\tasks\ (BARROW-Russ Barrow).job
NY -> rznsvuzi.job -> C:\WINDOWS\tasks\rznsvuzi.job
NY -> 010112010146118114.dat -> C:\WINDOWS\010112010146118114.dat
NY -> ld10.exe -> C:\WINDOWS\ld10.exe
NY -> utt7AA.tmp.exe -> C:\Documents and Settings\Russ Barrow\Local Settings\Temp\utt7AA.tmp.exe
NY -> tmpC8A.exe -> C:\WINDOWS\Temp\tmpC8A.exe
NY -> System.dll -> C:\Documents and Settings\Russ Barrow\Local Settings\Temp\nst37D.tmp\System.dll
NY -> mun7.exe -> C:\Documents and Settings\Russ Barrow\Local Settings\Temp\mun7.exe
[File - Lop Check]
NY -> rznsvuzi.job -> C:\WINDOWS\Tasks\rznsvuzi.job
[Alternate Data Streams]
NY -> @Alternate Data Stream - 356 bytes -> C:\WINDOWS\System32\drivers\pqdxqplr.sys:changelist
[Empty Temp Folders]
[Start Explorer]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

I will review the information when it comes back in.

THEN

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
I ran the script you provided and attempted the Run Fix in OTS, but it had an error during the deletion of the temp files. The error was "Range Check Error". It then appeared hung up. I gave it plenty of time, no good. So, I eventually killed it and started explorer and ran it again. Same thing, but it was very quick to get to the error this time. I think it finished everything but deletion of the temp files and starting Explorer. The log simply says: Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Russ Barrow\Local Settings\Temp\Temporary Internet Files\Content.IE5\POPTMR6O\;aid=187973647;ko=0;cid=24770921;rid=24788774;rv=1;×tamp=1203196687328;eid1=2;ecn1=1;etm1=10;eid2=1052;ecn2=1;etm2=0;eid3=1 045;ecn3=1;etm3=7;eid4=12;ecn4=1;etm4=7;[1].gif not found! File\Folder C:\Documents and Settings\Russ Barrow\Local Settings\Temp\Temporary Internet Files\Content.IE5\FYPO65M4\418,4445,37353,47182,47458,48104,49516,49554,49935,52263,52508,52738,52901, 54438,54682,54733,54766&RawValues=ZIP%2C75201%2CTLD%2Cnet&Redirect=;ord=cdtxNjt,bdIouidnsxKgi[1].htm not found! Registry entries deleted on Reboot… Then, I downloaded and ran the Combo-Fix tool and it completed without any issues. I have attached the log. Now, when it rebooted, I did not get any Generic Services errors, or anything else, but the web is still extremely slow. Now, as an observation, the router is flashing as if I were downloading a large file (similiar to a bit torrent session). I think we are getting there, just something simple remains. Thanks, Russ

Attachments:

I ran the script you provided and attempted the Run Fix in OTS, but it had an error during the deletion of the temp files. The error was "Range Check Error". It then appeared hung up. I gave it plenty of time, no good. So, I eventually killed it and started explorer and ran it again. Same thing, but it was very quick to get to the error this time. I think it finished everything but deletion of the temp files and starting Explorer. The log simply says:


Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\Russ Barrow\Local Settings\Temp\Temporary Internet Files\Content.IE5\POPTMR6O\;aid=187973647;ko=0;cid=24770921;rid=24788774;rv=1;×tamp=1203196687328;eid1=2;ecn1=1;etm1=10;eid2=1052;ecn2=1;etm2=0;eid3=1
045;ecn3=1;etm3=7;eid4=12;ecn4=1;etm4=7;[1].gif not found!
File\Folder C:\Documents and Settings\Russ Barrow\Local Settings\Temp\Temporary Internet Files\Content.IE5\FYPO65M4\418,4445,37353,47182,47458,48104,49516,49554,49935,52263,52508,52738,52901,
54438,54682,54733,54766&RawValues=ZIP%2C75201%2CTLD%2Cnet&Redirect=;ord=cdtxNjt,bdIouidnsxKgi[1].htm not found!

Registry entries deleted on Reboot…


Then, I downloaded and ran the Combo-Fix tool and it completed without any issues. I have attached the log.

Now, when it rebooted, I did not get any Generic Services errors, or anything else, but the web is still extremely slow. Now, as an observation, the router is flashing as if I were downloading a large file (similiar to a bit torrent session). I think we are getting there, just something simple remains.

Thanks,

Russ

ComboFix 09-06-26.02 - Russ Barrow 06/28/2009 18:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.732 [GMT -6:00]
Running from: c:\program files\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Darnella Barrow\Desktop\Privacy Protector.url
c:\documents and settings\Russ Barrow\Application Data\Adobe\Player.exe
c:\documents and settings\Russ Barrow\Application Data\inst.exe
c:\documents and settings\Russ Barrow\Local Settings\Temporary Internet Files\Tvm.log
c:\program files\INSTALL.LOG
c:\program files\PCHealthCenter
c:\program files\PCHealthCenter\0.gif
c:\program files\PCHealthCenter\1.gif
c:\program files\PCHealthCenter\2.gif
c:\program files\PCHealthCenter\3.gif
c:\program files\PCHealthCenter\foo.txt
c:\program files\PCHealthCenter\sc.html
c:\program files\TS-2009
c:\program files\TS-2009\totalsecure.s2
c:\program files\TS-2009\totalsecure.s3
c:\program files\TS-2009\totalsecure.s6
c:\windows\k.txt
c:\windows\system32\42KJE738.ocx
c:\windows\system32\Cache
c:\windows\system32\senekafwfluenb.dat
c:\windows\system32\senekamtuacbuk.dat
c:\windows\system32\svchost2.exe
c:\windows\system32\svchost3.exe
c:\windows\system32\wbem\proquota.exe
c:\windows\TEMP\{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}\_ISRES.DLL
c:\windows\TEMP\{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}\ISRT.DLL
c:\windows\TEMP\NLU11.tmp\CCERASER.DLL
c:\windows\TEMP\NLU11.tmp\ECMSVR32.DLL
c:\windows\TEMP\NLU11.tmp\EECTRL.SYS
c:\windows\TEMP\NLU11.tmp\ERASER.SYS
c:\windows\TEMP\NLU11.tmp\naveng.sys
c:\windows\TEMP\NLU11.tmp\naveng32.dll
c:\windows\TEMP\NLU11.tmp\navex15.sys
c:\windows\TEMP\NLU11.tmp\navex32a.dll
c:\windows\TEMP\NLU15.tmp\CCERASER.DLL
c:\windows\TEMP\NLU15.tmp\ECMSVR32.DLL
c:\windows\TEMP\NLU15.tmp\EECTRL.SYS
c:\windows\TEMP\NLU15.tmp\ERASER.SYS
c:\windows\TEMP\NLU1A.tmp\CCERASER.DLL
c:\windows\TEMP\NLU1A.tmp\ECMSVR32.DLL
c:\windows\TEMP\NLU1A.tmp\EECTRL.SYS
c:\windows\TEMP\NLU1A.tmp\ERASER.SYS
c:\windows\TEMP\NLU1A.tmp\naveng.sys
c:\windows\TEMP\NLU1A.tmp\naveng32.dll
c:\windows\TEMP\NLU1A.tmp\navex15.sys
c:\windows\TEMP\NLU1A.tmp\navex32a.dll
c:\windows\TEMP\NLU2D.tmp\CCERASER.DLL
c:\windows\TEMP\NLU2D.tmp\ECMSVR32.DLL
c:\windows\TEMP\NLU2D.tmp\EECTRL.SYS
c:\windows\TEMP\NLU2D.tmp\ERASER.SYS
c:\windows\TEMP\NLU2D.tmp\naveng.sys
c:\windows\TEMP\NLU2D.tmp\naveng32.dll
c:\windows\TEMP\NLU2D.tmp\navex15.sys
c:\windows\TEMP\NLU2D.tmp\navex32a.dll
C:\x
F:\Autorun.inf

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP
——-\Legacy_SYS
——-\Legacy_SYSDRV
——-\Service_Iprip
——-\Service_sys


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.

2009-06-29 00:43 . 2008-04-14 11:42 50176 —-a-w- c:\windows\system32\proquota.exe
2009-06-29 00:43 . 2008-04-14 11:42 50176 —-a-w- c:\windows\system32\dllcache\proquota.exe
2009-06-29 00:34 . 2009-06-29 00:34 3042087 —-a-r- c:\program files\Combo-Fix.exe
2009-06-29 00:12 . 2009-06-29 00:12 ——– d—–w- C:\_OTS
2009-06-28 03:44 . 2009-06-28 03:44 82080 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-06-28 03:44 . 2009-06-28 03:44 24096 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-06-28 03:44 . 2009-06-28 03:44 168208 —-a-w- c:\windows\system32\guard32.dll
2009-06-28 03:44 . 2009-06-28 03:44 132640 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-06-28 03:44 . 2009-06-28 03:44 ——– d—–w- c:\program files\COMODO
2009-06-28 03:36 . 2009-06-28 03:36 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-28 03:36 . 2009-06-28 03:36 ——– d—–w- c:\program files\SpywareBlaster
2009-06-28 03:16 . 2009-06-28 03:16 ——– d—–w- c:\program files\Trend Micro
2009-06-28 02:56 . 2009-06-28 02:56 ——– d—–w- c:\program files\ERUNT
2009-06-28 01:41 . 2009-06-28 01:41 ——– d—–w- c:\program files\backups
2009-06-28 01:13 . 2009-06-28 01:10 218112 —-a-w- c:\program files\HijackThis.exe
2009-06-27 21:54 . 2009-06-27 21:54 ——– d—–w- c:\documents and settings\Russ Barrow\Application Data\uniblue
2009-06-27 21:54 . 2009-06-27 21:54 ——– d—–w- c:\program files\Uniblue
2009-06-27 21:44 . 2009-06-27 22:14 692168 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-27 21:44 . 2009-06-27 21:44 ——– d—–w- c:\windows\system32\XPSViewer
2009-06-27 21:43 . 2009-06-27 21:43 ——– d—–w- c:\program files\MSBuild
2009-06-27 21:43 . 2009-06-27 21:43 ——– d—–w- c:\program files\Reference Assemblies
2009-06-27 21:42 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-27 21:42 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-06-27 21:42 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-27 21:42 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-06-27 21:42 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-27 21:42 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-06-27 21:42 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-27 21:32 . 2009-06-27 21:32 ——– d–h–r- C:\AHCache
2009-06-27 21:31 . 2009-06-27 21:26 2327856 —-a-w- c:\program files\speedupmypc3plc.exe
2009-06-27 20:48 . 2006-02-28 12:00 61440 —-a-w- c:\windows\system32\msvcrt40.dll
2009-06-27 20:48 . 2006-02-28 12:00 61440 —-a-w- c:\windows\system32\dllcache\msvcrt40.dll
2009-06-26 19:56 . 2002-08-29 11:00 18944 —-a-w- c:\windows\system32\simptcp.dll
2009-06-26 19:56 . 2002-08-29 11:00 18944 —-a-w- c:\windows\system32\dllcache\simptcp.dll
2009-06-26 19:46 . 2009-06-26 19:46 ——– d—–w- c:\windows\system32\en
2009-06-26 16:31 . 2008-04-14 11:41 35328 —-a-w- c:\windows\system32\iprip.dll
2009-06-26 16:31 . 2008-04-14 11:41 35328 —-a-w- c:\windows\system32\dllcache\iprip.dll
2009-06-26 16:31 . 2009-06-26 16:34 ——– d—–w- c:\windows\ServicePackFiles
2009-06-26 16:27 . 2008-04-14 04:06 144384 ——w- c:\windows\system32\drivers\hdaudbus.sys
2009-06-26 16:27 . 2008-04-14 06:10 10240 ——w- c:\windows\system32\drivers\sffp_mmc.sys
2009-06-26 00:32 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\dllcache\bthport.sys
2009-06-26 00:30 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-06-26 00:30 . 2008-04-21 12:08 215552 ——w- c:\windows\system32\dllcache\wordpad.exe
2009-06-26 00:29 . 2008-05-08 14:02 203136 ——w- c:\windows\system32\dllcache\rmcast.sys
2009-06-26 00:29 . 2008-10-24 11:21 455296 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-26 00:29 . 2008-12-11 10:57 333952 ——w- c:\windows\system32\dllcache\srv.sys
2009-06-26 00:29 . 2008-05-01 14:33 331776 ——w- c:\windows\system32\dllcache\msadce.dll
2009-06-26 00:29 . 2008-04-11 19:04 691712 ——w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-26 00:29 . 2008-10-15 16:34 337408 ——w- c:\windows\system32\dllcache\netapi32.dll
2009-05-31 01:21 . 2009-05-31 01:21 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 00:46 . 2004-09-14 01:11 ——– d—–w- c:\program files\CyberArmor
2009-06-29 00:46 . 2009-05-16 14:47 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-06-29 00:46 . 2008-03-19 01:55 ——– d—–w- c:\documents and settings\Russ Barrow\Application Data\DNA
2009-06-29 00:46 . 2008-03-19 01:55 ——– d—–w- c:\program files\DNA
2009-06-28 17:10 . 2003-03-27 16:31 ——– d—–w- c:\program files\Britannica
2009-06-28 02:58 . 2009-06-28 01:13 11314 —-a-w- c:\program files\hijackthis.log
2009-06-28 02:21 . 2002-09-03 14:58 78843 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-06-27 23:50 . 2007-11-14 02:56 ——– d—–w- c:\documents and settings\Russ Barrow\Application Data\BitTorrent
2009-06-27 21:56 . 2009-06-27 21:56 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-06-27 21:53 . 2003-03-31 23:36 96848 —-a-w- c:\documents and settings\Russ Barrow\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-27 21:31 . 2008-01-18 03:01 ——– d—–w- c:\program files\Ashampoo
2009-06-27 20:43 . 2003-12-01 02:46 ——– d—–w- c:\program files\Google
2009-05-15 01:12 . 2007-11-14 02:55 ——– d—–w- c:\program files\BitTorrent
2009-05-07 15:32 . 2002-08-29 11:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-04 08:46 . 2009-06-27 21:56 2835656 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\speedupmypc2009.exe
2009-05-03 20:44 . 2003-12-26 03:32 ——– d—–w- c:\documents and settings\Russ Barrow\Application Data\Cyberlink
2009-05-03 20:19 . 2003-12-25 20:03 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2009-05-03 20:08 . 2003-03-27 16:28 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-03 20:04 . 2003-12-25 20:03 ——– d—–w- c:\program files\CyberLink
2009-05-03 19:55 . 2009-05-03 19:55 ——– d—–w- c:\program files\Digital Photo Navigator 1.5
2009-05-01 18:30 . 2009-05-01 18:30 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-04-29 09:45 . 2009-06-27 21:56 845128 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\58D97068\B74607BA\System.Data.SQLite.dll
2009-04-29 09:45 . 2009-06-27 21:56 771368 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\9966075F\B74607BA\UBSysMan.dll
2009-04-29 09:45 . 2009-06-27 21:56 614696 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\7AEFAE8C\B74607BA\Launcher.exe
2009-04-29 09:45 . 2009-06-27 21:56 54608 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\D720648F\B74607BA\Interop.IWshRuntimeLibrary.dll
2009-04-29 09:45 . 2009-06-27 21:56 519168 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\78B94F67\B74607BA\IsLicense40.dll
2009-04-29 09:45 . 2009-06-27 21:56 474408 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\62A3297F\B74607BA\AvalonCommon.dll
2009-04-29 09:45 . 2009-06-27 21:56 395048 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\C77843B\B74607BA\SUMPBackend.dll
2009-04-29 09:45 . 2009-06-27 21:56 345008 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\4BF757A\B74607BA\IsLicense30.dll
2009-04-29 09:45 . 2009-06-27 21:56 236840 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\683B013A\B74607BA\PowerSuiteBackendUtils.dll
2009-04-29 09:45 . 2009-06-27 21:56 197968 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\6A0591D6\B74607BA\ICSharpCode.SharpZipLib.dll
2009-04-29 09:45 . 2009-06-27 21:56 1250600 -c–a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\B430549D\B74607BA\SUMP.exe
2009-04-29 04:56 . 2005-10-21 18:51 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2006-08-22 00:50 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2002-08-29 11:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-05-12 21:24 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2004-06-23 18:55 . 2004-09-11 01:47 20480 —-a-w- c:\program files\ProcManager.exe
2002-07-26 23:02 . 2008-01-05 01:58 153088 —-a-w- c:\program files\UNWISE.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-03 68856]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-06-11 318272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2004-02-12 90224]
"USB2Check"="c:\windows\system32\PCLECoInst.dll" [2005-12-21 73728]
"USBToolTip"="c:\program files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2006-01-23 196608]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2008-05-22 151552]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-27 68592]
"CyberArmorHelper"="c:\progra~1\CYBERA~1\pcshelp.exe" [2005-05-19 69632]
"CgaViewer"="c:\progra~1\CYBERG~1\cgav.exe" [2005-04-14 81976]
"CgaHelper"="c:\progra~1\CYBERG~1\cgahelp.exe" [2005-04-14 90174]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\Russ Barrow\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
F1U201.401.lnk - c:\program files\Belkin\F1U201.401\usbshare.exe [2008-5-5 135168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SYSTEM32\cahooknt.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 CGAgent;CyberGatekeeper Agent;c:\progra~1\CYBERG~1\cgasvc.exe [9/13/2004 7:11 PM 73788]
R2 CyberArmorRunService;CyberArmor Run Service;c:\program files\CyberArmor\casvc.exe [6/8/2006 4:01 PM 65536]
R2 ndserv;ndserv;c:\program files\netDeploy\Launcher\ndserv.exe [4/4/2003 12:52 PM 859648]
R2 Viexca2k;CyberArmor Registry Driver;c:\windows\SYSTEM32\DRIVERS\viexca2k.sys [6/8/2006 4:01 PM 21504]
R2 Viexpf2k;CyberArmor W2KDriver;c:\windows\SYSTEM32\DRIVERS\viexpf2k.sys [9/13/2004 7:11 PM 424479]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S4 DistRestart;DistRestart;c:\windows\srvany.exe –> c:\windows\srvany.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\cc1b534f-740e-4174-b6a4-b786dd211fb9]
c:\windows\System32\bamoorn.exe
.
Contents of the 'Scheduled Tasks' folder

2009-06-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-06-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://thepiratebay.org/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
uInternet Settings,ProxyServer = ftp=wwwgate.ti.com:80;gopher=wwwgate.ti.com:80;http=wwwgate.ti.com:80;https=wwwg
ate.ti.com:81;socks=wwwgate.ti.com:80
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-28 18:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\TMP000000302C7CFD6EE7D99CBB 524288 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-541624744-611074163-757372905-1006\Software\Microsoft\Driver Signing]
@Denied: (2) (Administrators)
@Allowed: (2) (Administrators)
"Policy"=dword:00000000

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,05,e2,68,f8,d9,
b5,59,16,c8,28,51,af,b0,29,a3,98,34,39,f5,6b,75,33,37,0c,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,87,8c,40,05,cf,
3a,36,e2,71,3b,04,66,8b,46,0d,96,93,08,f8,51,66,4b,dc,27,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,d9,cf,ac,7e,8e,
ca,81,80,25,da,ec,7e,55,20,c9,26,e7,37,4c,cc,df,1a,cf,90,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,6d,29,d3,30,f7,
8b,a7,98,3e,1e,9e,e0,57,5a,93,61,9a,1e,6a,2a,47,4e,d0,ca,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,24,e2,e0,be,69,
76,fc,94,cd,44,cd,b9,a6,33,6c,cd,4e,54,a6,30,20,8d,5f,8d,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,32,cc,1a,58,c2,
d6,a7,55,b0,18,ed,a7,3f,8d,37,a4,51,31,e7,0c,26,2f,06,42,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,fe,f4,d0,10,e1,
46,c3,46,31,77,e1,ba,b1,f8,68,02,40,e3,a3,18,52,13,e1,22,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,a7,f1,18,f4,61,
80,84,c4,83,6c,56,8b,a0,85,96,ab,55,88,ed,27,79,3b,af,55,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,da,d3,92,fe,ad,
d5,81,8d,51,fa,6e,91,28,9e,14,cc,10,10,aa,87,b4,76,33,82,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,82,54,1e,ca,3f,
3e,29,9f,b1,cd,45,5a,a8,c4,f8,b9,51,66,7c,85,19,68,11,1d,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,80,3c,cf,31,21,
ac,36,10,e3,0e,66,d5,eb,bc,2f,6b,ee,f5,c7,f5,5a,21,7e,50,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,01,bd,df,a9,08,
80,ec,f4,fa,ea,66,7f,d4,3b,6b,70,55,93,81,f5,e0,f7,07,03,6c,43,2d,1e,aa,22,\

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\

[HKEY_LOCAL_MACHINE\software\Microsoft\Driver Signing]
@Denied: (2) (Administrators)
@Allowed: (2) (Administrators)
"Policy"=hex:00,00,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4084)
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Exceed.nt\HESHELL.DLL
c:\program files\Microsoft Office\Office10\msohev.dll
c:\program files\Exceed.nt\hclftpoa.dll
c:\program files\Exceed.nt\hclFTPx.dll
c:\program files\Exceed.nt\hclFTPx.nls
c:\program files\Exceed.nt\HESHELL.NLS
c:\program files\Exceed.nt\ftpseui.dll
c:\program files\Exceed.nt\ftpseui.nls
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\CYBERG~1\cgagent.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\progra~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\windows\SYSTEM32\Hummbird\inetd32.exe
c:\progra~1\SYMANT~1\SYMANT~1\Rtvscan.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\SYSTEM32\TCPSVCS.EXE
c:\windows\SYSTEM32\MsPMSPSv.exe
c:\progra~1\CYBERA~1\pcs.exe
.
**************************************************************************
.
Completion time: 2009-06-29 18:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-29 00:54

Pre-Run: 21,720,203,264 bytes free
Post-Run: 22,422,167,552 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

368 — E O F — 2009-06-26 21:01

Attachments:

OK progress so on to the next stage :thumbup: Let me know of any problems on completion

A quick tidy up and then a MBAM run to see if any orphans remain

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean

THEN

Download and run Auslogics Disc Defragmenter

FINALLY FOR NOW

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
I am downloading the files on a working computer since the web is so slow on the PC we are trying to fix, but the last program "Malwarebytes" does not have a good link. I looked at several other websites for this program, and they all go back to CNet, that is not operating (broken Link). I will run the other programs and follow-up with you. Thanks Russ
Ok, ran the TFC, and man did it run fast. The PC rebooted and once again, everything comes up error free, but Internet barely works. I am now running the Defrag which may take a while. Now, just an obervation. Once again, I notice how the ethernet light to the Router is just blinking at least 2 times a second. I watched it during the TFC and reboot. It never stopped but for about 1.5 seconds when the computer actually was shutdown and starting back up. Do you think this indicates a hardware task (ethernet like pinging) that is operating outside of the OS. I don't have a clue what I am talking about here, but I do notice obvious changes in the PC behavior. Thanks, Russ
Lets try a copy from major geeks although the Cnet works OK for me http://majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Just had a quick look at my router and I also get a flickering whilst I am typing this

Lets also refresh your net

Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

ipconfig /flushdns (The space between g and / is needed)
regsvr32 netshell.dll
regsvr32 netcfgx.dll
regsvr32 netman.dll

Exit

Restart the computer.

Let me know if you have problems getting MBAM if not post the log :thumbup:
Alright, I just could not get over how the router is just a pinging away, so I did a couple of tests. First thing I did was turn off the PC, and the router socket light that has the PC in it was still pinging away. I had to unplug the computer to stop it. So, this made me think that perhaps a hardware issue is present, perhaps caused by the hijack/virus (firmware damage). So, I connected up my Aircard and tried it out. I was able to get on the web and download the Malwarebytes program without any problem, granted the 3G card is not as fast as the FIOS. I have a scan in progress and will provide the log when complete. So far, it does list 4 items infected. Thanks, Russ
Sounds like a coincidental router problem, have you tried resetting it ? The elements found by MBAM were just orphan registry entries Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI