This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] not acting right

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ran malwarebytes and it found quite a few problems today. About a month ago mcafee stoped working so I installed norton and I have not been able to remove mcafee. I just need to make sure everything is ok.
I have a log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:32:21 PM, on 8/26/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16890)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Sony\Network Utility\LANUtil.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnyinsit.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\iolo\System Mechanic Professional\SysMech.exe
C:\Windows\system32\taskmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files\iolo\Common\Lib\ioloLManager.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MoneyInsights] "C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnyinsit.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\Ralea\AppData\Local\Temp\~DF49A9.tmp C:\Users\Ralea\AppData\Local\Temp\~DF4994.tmp C:\Users\Ralea\AppData\Local\Temp\~DF4865.tmp C:\Users\Ralea\AppData\Local\Temp\~DF4855.tmp C:\Users\Ralea\AppData\Local\Temp\~DF484F.tmp C:\Users\Ralea\AppData\Local\Temp\~DF479D.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF8D8F.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF8D00.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF7798.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF7785.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF73AE.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF739B.tmp C:\Users\Ralea\AppData\Local\Temp\Low\HSPERF~1.SH! (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [DelayShred] c:\PROGRA~1\mcafee\mshr\ShrCL.EXE /P7 /q C:\Users\Ralea\AppData\Local\Temp\~DF49A9.tmp C:\Users\Ralea\AppData\Local\Temp\~DF4994.tmp C:\Users\Ralea\AppData\Local\Temp\~DF4865.tmp C:\Users\Ralea\AppData\Local\Temp\~DF4855.tmp C:\Users\Ralea\AppData\Local\Temp\~DF484F.tmp C:\Users\Ralea\AppData\Local\Temp\~DF479D.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF8D8F.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF8D00.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF7798.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF7785.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF73AE.tmp C:\Users\Ralea\AppData\Local\Temp\Low\~DF739B.tmp C:\Users\Ralea\AppData\Local\Temp\Low\HSPERF~1.SH! (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Users\Ralea\Desktop\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Users\Ralea\Desktop\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Users\Ralea\Desktop\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/…s/wlscctrl2.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://chill.comcast.net/Gameshell/GameHos…ronGameHost.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\coIEPlg.dll
O23 - Service: McAfee Application Installer Cleanup (0247911251322469) (0247911251322469mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\024791~1.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe
O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 10647 bytes
Hi raymon823,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Use the link below to see how to run the McAfee Consumer Products Removal tool
http://service.mcafee.com/FAQDocument.aspx?id=TS100507

  • Download DDS and save it to your desktop from
  • Here
  • here or
  • here.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click DDS icon to run the tool (may take up to 3 minutes to run)
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
  • We Need to check for Rootkits with RootRepeal
    • Download RootRepeal from one of the following locations and save it to your desktop.
    • Open [external image: Posted Image] on your desktop.
    • Click the [external image: Posted Image] tab.
    • Click the [external image: Posted Image] button.
    • In the Select Scan dialog, check
      [external image: Posted Image]
    • Push Ok
    • Check the box for your main system drive (Usually C:), and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
  • Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.

  • Copy/paste the DDS.txt log (that you've previously saved to your desktop) onto your post.

  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/01 19:07 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP0 ================================================== SSDT ——————- SYSENTER/INT2E Hooked [0x8188c9c0]! ==EOF== DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 18:57:14.96 on Tue 09/01/2009 Internet Explorer: 7.0.6000.16890 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1014.218 [GMT -4:00] AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} SP: Norton Internet Security *disabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A} FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\iolo\common\lib\ioloServiceManager.exe C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Program Files\Sony\Network Utility\NSUService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Program Files\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Sony\Network Utility\LANUtil.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnyinsit.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe C:\Windows\system32\wuauclt.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Ralea\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://comcast.net/ uDefault_Page_URL = hxxp://www.sony.com/vaiopeople mDefault_Page_URL = hxxp://www.sony.com/vaiopeople uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.5.0.135\IPSBHO.DLL BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.5.0.135\coIEPlg.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [NSUFloatingUI] "c:\program files\sony\network utility\LANUtil.exe" uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [MoneyInsights] "c:\program files\microsoft money plus\mnycorefiles\mnyinsit.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [iolo Startup] "c:\program files\iolo\common\lib\ioloLManager.exe" dRunOnce: [DelayShred] c:\progra~1\mcafee\mshr\shrcl.exe /p7 /q c:\users\ralea\appdata\local\temp\~df49a9.tmp c:\users\ralea\appdata\local\temp\~df4994.tmp c:\users\ralea\appdata\local\temp\~df4865.tmp c:\users\ralea\appdata\local\temp\~df4855.tmp c:\users\ralea\appdata\local\temp\~df484f.tmp c:\users\ralea\appdata\local\temp\~df479d.tmp c:\users\ralea\appdata\local\temp\low\~df8d8f.tmp c:\users\ralea\appdata\local\temp\low\~df8d00.tmp c:\users\ralea\appdata\local\temp\low\~df7798.tmp c:\users\ralea\appdata\local\temp\low\~df7785.tmp c:\users\ralea\appdata\local\temp\low\~df73ae.tmp c:\users\ralea\appdata\local\temp\low\~df739b.tmp c:\users\ralea\appdata\local\temp\low\HSPERF~1.SH! StartupFolder: c:\users\ralea\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-us\local\search.html IE: &D&ownload &with BitComet - c:\users\ralea\desktop\bitcomet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\users\ralea\desktop\bitcomet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\users\ralea\desktop\bitcomet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: internet Trusted Zone: mcafee.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://chill.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.5.0.135\CoIEPlg.dll Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1005000.087\SymEFA.sys [2009-4-29 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1005000.087\BHDrvx86.sys [2009-4-29 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1005000.087\cchpx86.sys [2009-4-29 482352] R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2009-2-7 20392] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090810.001\IDSvix86.sys [2009-8-12 293424] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-8-26 615280] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-8-26 615280] R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.5.0.135\ccSvcHst.exe [2009-4-29 115560] R2 NSUService;NSUService;c:\program files\sony\network utility\NSUService.exe [2007-8-25 200704] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nis\1005000.087\symndisv.sys [2009-4-29 39984] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-8-26 812544] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 regfile=NOTEPAD.EXE %1 scrfile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-08-26 18:31 –d—– c:\program files\Trend Micro 2009-08-26 18:21 –d—– c:\users\ralea\appdata\roaming\McAfee 2009-08-26 17:20 93,024 a——- c:\windows\system32\IncContxMenu.dll 2009-08-26 16:50 –d—– c:\users\ralea\appdata\roaming\Malwarebytes 2009-08-26 16:50 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-26 16:50 –d—– c:\programdata\Malwarebytes 2009-08-26 16:50 –d—– c:\progra~2\Malwarebytes 2009-08-26 16:50 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-26 16:50 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-26 03:05 2,048 a——- c:\windows\system32\tzres.dll 2009-08-26 01:09 1,686,016 a——- c:\windows\system32\gameux.dll 2009-08-26 01:09 28,672 a——- c:\windows\system32\Apphlpdm.dll 2009-08-26 01:09 4,247,552 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-17 21:09 494,592 a——- c:\windows\system32\kerberos.dll 2009-08-17 21:09 216,576 a——- c:\windows\system32\msv1_0.dll 2009-08-17 21:09 175,104 a——- c:\windows\system32\wdigest.dll 2009-08-17 21:09 1,233,920 a——- c:\windows\system32\lsasrv.dll 2009-08-17 21:09 408,136 a——- c:\windows\system32\drivers\ksecdd.sys 2009-08-17 21:09 272,384 a——- c:\windows\system32\schannel.dll 2009-08-17 21:09 72,704 a——- c:\windows\system32\secur32.dll 2009-08-17 21:09 7,680 a——- c:\windows\system32\lsass.exe 2009-08-12 03:36 4,096 a——- c:\windows\system32\msdxm.ocx 2009-08-12 03:36 4,096 a——- c:\windows\system32\dxmasf.dll 2009-08-12 03:36 8,147,968 a——- c:\windows\system32\wmploc.DLL 2009-08-12 03:36 43,520 a——- c:\windows\system32\msdxm.tlb 2009-08-12 03:36 18,432 a——- c:\windows\system32\amcompat.tlb 2009-08-06 03:20 97,800 a——- c:\windows\system32\infocardapi.dll 2009-08-06 03:20 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-08-06 03:20 37,384 a——- c:\windows\system32\infocardcpl.cpl 2009-08-06 03:20 622,080 a——- c:\windows\system32\icardagt.exe 2009-08-06 03:20 11,264 a——- c:\windows\system32\icardres.dll 2009-08-06 03:20 43,544 a——- c:\windows\system32\PresentationHostProxy.dll 2009-08-06 03:20 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll 2009-08-06 03:20 326,160 a——- c:\windows\system32\PresentationHost.exe 2009-08-06 03:15 49,152 a——- c:\windows\ocsetup_cbs_install_NetFx3.perf 2009-08-06 03:15 16,384 a——- c:\windows\ocsetup_cbs_install_NetFx3.dpx 2009-08-06 03:15 48,562,176 a——- c:\windows\ocsetup_install_NetFx3.etl 2009-08-06 03:03 96,760 a——- c:\windows\system32\dfshim.dll 2009-08-06 03:03 282,112 a——- c:\windows\system32\mscoree.dll 2009-08-06 03:03 41,984 a——- c:\windows\system32\netfxperf.dll 2009-08-06 03:02 158,720 a——- c:\windows\system32\mscorier.dll 2009-08-06 03:02 83,968 a——- c:\windows\system32\mscories.dll ==================== Find3M ==================== 2009-08-14 11:21 2,102,112 a——- c:\windows\system32\Incinerator.dll 2009-08-10 22:32 86,016 a——- c:\windows\inf\infstrng.dat 2009-08-10 22:32 51,200 a——- c:\windows\inf\infpub.dat 2009-07-18 08:17 827,392 a——- c:\windows\system32\wininet.dll 2009-07-18 08:10 56,320 a——- c:\windows\system32\iesetup.dll 2009-07-18 08:10 78,336 a——- c:\windows\system32\ieencode.dll 2009-07-18 08:10 52,736 a——- c:\windows\apppatch\iebrshim.dll 2009-07-18 08:07 72,704 a——- c:\windows\system32\admparse.dll 2009-07-18 06:00 26,624 a——- c:\windows\system32\ieUnatt.exe 2009-07-18 04:34 48,128 a——- c:\windows\system32\mshtmler.dll 2009-07-17 10:52 71,680 a——- c:\windows\system32\atl.dll 2009-07-14 12:05 30,208 a——- c:\windows\system32\iolobtdfg.exe 2009-07-14 09:02 313,344 a——- c:\windows\system32\wmpdxm.dll 2009-07-14 09:00 7,680 a——- c:\windows\system32\spwmp.dll 2009-07-07 21:36 11,776 a——- c:\windows\system32\smrgdf.exe 2009-06-15 11:29 156,160 a——- c:\windows\system32\t2embed.dll 2009-06-15 11:23 24,064 a——- c:\windows\system32\lpk.dll 2009-06-15 11:22 72,704 a——- c:\windows\system32\fontsub.dll 2009-06-15 11:21 10,240 a——- c:\windows\system32\dciman32.dll 2009-06-15 11:20 34,304 a——- c:\windows\system32\atmlib.dll 2009-06-15 09:03 289,792 a——- c:\windows\system32\atmfd.dll 2009-06-10 08:16 156,160 a——- c:\windows\system32\wkssvc.dll 2009-06-10 08:10 123,904 a——- c:\windows\system32\msvfw32.dll 2009-06-10 08:10 31,232 a——- c:\windows\system32\msvidc32.dll 2009-06-10 08:09 12,800 a——- c:\windows\system32\msrle32.dll 2009-06-10 08:07 82,944 a——- c:\windows\system32\mciavi32.dll 2009-06-10 08:04 88,576 a——- c:\windows\system32\avifil32.dll 2009-06-10 08:04 65,024 a——- c:\windows\system32\avicap32.dll 2009-06-05 08:27 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2009-06-05 08:27 449,024 a——- c:\windows\apppatch\AcSpecfc.dll 2009-06-05 08:27 537,600 a——- c:\windows\apppatch\AcLayers.dll 2009-06-05 08:27 2,143,744 a——- c:\windows\apppatch\AcGenral.dll 2009-06-05 04:29 2,560 a——- c:\windows\apppatch\AcRes.dll 2009-06-04 08:47 36,352 a——- c:\windows\system32\tsgqec.dll 2009-06-04 08:43 1,871,872 a——- c:\windows\system32\mstscax.dll 2009-06-04 08:36 116,736 a——- c:\windows\system32\aaclient.dll 2009-04-29 21:15 86,016 a——- c:\windows\inf\infstor.dat 2009-04-09 14:30 502 a——- c:\users\ralea\appdata\roaming\wklnhst.dat 2008-12-10 04:29 174 a–sh— c:\program files\desktop.ini 2008-06-11 03:11 665,600 a——- c:\windows\inf\drvindex.dat 2007-08-25 10:02 1,132,112 a——- c:\programdata\pswi_preloaded.exe 2007-08-25 10:02 1,132,112 a——- c:\progra~2\pswi_preloaded.exe 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2007-08-26 17:25 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 18:59:31.39 ===============

Attachments:

raymon823,

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 16".
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u16-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI