This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] continually prompts for reinstall of McAfee Security

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This computer has an issue where it continually puts up prompts to reinstall the McAfee Security Suite. We cannot uninstall the version we find in Add/Remove Programs, nor can we reinstall the software from scratch. It becomes so annoying we cannot perform any tasks with this machine; it took several attempts to save the requisite programs and log files for this post. Any assistance you can give would be a tremendous help. I had great luck with HijackThis in the past, so I decided to try this route first – NOTHING has been attempted to correct the problem at the current time. RootRepeal.txt : ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/01 17:00 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xAA504000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF79F9000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA7961000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 000 Function Name: NtAcceptConnectPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057f38e #: 001 Function Name: NtAccessCheck Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80578c0c #: 002 Function Name: NtAccessCheckAndAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058a83a #: 003 Function Name: NtAccessCheckByType Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058f870 #: 004 Function Name: NtAccessCheckByTypeAndAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058f68a #: 005 Function Name: NtAccessCheckByTypeResultList Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80636850 #: 006 Function Name: NtAccessCheckByTypeResultListAndAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806389e1 #: 007 Function Name: NtAccessCheckByTypeResultListAndAuditAlarmByHandle Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80638a2a #: 008 Function Name: NtAddAtom Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057468b #: 009 Function Name: NtAddBootEntry Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472bf #: 010 Function Name: NtAdjustGroupsToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8063600f #: 011 Function Name: NtAdjustPrivilegesToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058ec11 #: 012 Function Name: NtAlertResumeThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062e154 #: 013 Function Name: NtAlertThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057aeb1 #: 014 Function Name: NtAllocateLocallyUniqueId Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058bcb2 #: 015 Function Name: NtAllocateUserPhysicalPages Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80625269 #: 016 Function Name: NtAllocateUuids Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805dbfb0 #: 017 Function Name: NtAllocateVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056801d #: 018 Function Name: NtAreMappedFilesTheSame Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d8b51 #: 019 Function Name: NtAssignProcessToJobObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a1c40 #: 021 Function Name: NtCancelDeviceWakeupRequest Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472ab #: 022 Function Name: NtCancelIoFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805c92bc #: 024 Function Name: NtClearEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805686c9 #: 025 Function Name: NtClose Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80566dc9 #: 026 Function Name: NtCloseObjectAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058f07f #: 027 Function Name: NtCompactKeys Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064d2cf #: 028 Function Name: NtCompareTokens Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058e981 #: 029 Function Name: NtCompleteConnectPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805802b1 #: 030 Function Name: NtCompressKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064d53d #: 031 Function Name: NtConnectPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058a88c #: 033 Function Name: NtCreateDebugObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80658280 #: 034 Function Name: NtCreateDirectoryObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a1fe8 #: 035 Function Name: NtCreateEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056ad30 #: 036 Function Name: NtCreateEventPair Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647910 #: 037 Function Name: NtCreateFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056fc78 #: 038 Function Name: NtCreateIoCompletion Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058fc7b #: 039 Function Name: NtCreateJobObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805aa986 #: 040 Function Name: NtCreateJobSet Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062e5fd #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056e829 #: 042 Function Name: NtCreateMailslotFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d8a42 #: 043 Function Name: NtCreateMutant Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057b281 #: 044 Function Name: NtCreateNamedPipeFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80580135 #: 045 Function Name: NtCreatePagingFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805bafd8 #: 046 Function Name: NtCreatePort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80597571 #: 047 Function Name: NtCreateProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805b0b34 #: 048 Function Name: NtCreateProcessEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80581f0e #: 049 Function Name: NtCreateProfile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647f47 #: 051 Function Name: NtCreateSemaphore Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805738bf #: 052 Function Name: NtCreateSymbolicLinkObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a0cf9 #: 053 Function Name: NtCreateThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057c52b #: 054 Function Name: NtCreateTimer Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059c2fa #: 055 Function Name: NtCreateToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a82ed #: 056 Function Name: NtCreateWaitablePort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a257a #: 057 Function Name: NtDebugActiveProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806593fd #: 058 Function Name: NtDebugContinue Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80659557 #: 060 Function Name: NtDeleteAtom Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80589e6a #: 061 Function Name: NtDeleteBootEntry Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472ab #: 062 Function Name: NtDeleteFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d7427 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805951c2 #: 064 Function Name: NtDeleteObjectAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80638a81 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80593b38 #: 066 Function Name: NtDeviceIoControlFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057d2e1 #: 067 Function Name: NtDisplayString Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805be6e9 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80572ba6 #: 069 Function Name: NtDuplicateToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057e69a #: 070 Function Name: NtEnumerateBootEntries Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472bf #: 071 Function Name: NtEnumerateKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056ef30 #: 072 Function Name: NtEnumerateSystemEnvironmentValuesEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647297 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057fc04 #: 074 Function Name: NtExtendSection Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80624090 #: 075 Function Name: NtFilterToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805b0317 #: 076 Function Name: NtFindAtom Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058f9d4 #: 077 Function Name: NtFlushBuffersFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80589fe7 #: 078 Function Name: NtFlushInstructionCache Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80576a6a #: 079 Function Name: NtFlushKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059a988 #: 080 Function Name: NtFlushVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805dcf1e #: 081 Function Name: NtFlushWriteBuffer Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80625acb #: 082 Function Name: NtFreeUserPhysicalPages Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062561e #: 083 Function Name: NtFreeVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80568948 #: 084 Function Name: NtFsControlFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057ad99 #: 085 Function Name: NtGetContextThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805dfa3d #: 086 Function Name: NtGetDevicePowerState Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062a93f #: 087 Function Name: NtGetPlugPlayEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059f89c #: 089 Function Name: NtImpersonateAnonymousToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80597595 #: 090 Function Name: NtImpersonateClientOfPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058e3ed #: 091 Function Name: NtImpersonateThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057a92e #: 092 Function Name: NtInitializeRegistry Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a3031 #: 093 Function Name: NtInitiatePowerAction Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062a70b #: 094 Function Name: NtIsProcessInJob Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062e4b3 #: 095 Function Name: NtIsSystemResumeAutomatic Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062a926 #: 096 Function Name: NtListenPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805aa416 #: 097 Function Name: NtLoadDriver Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a410a #: 098 Function Name: NtLoadKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805ae510 #: 099 Function Name: NtLoadKey2 Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805ae35e #: 100 Function Name: NtLockFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058c4f2 #: 101 Function Name: NtLockProductActivationKeys Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805b04e7 #: 102 Function Name: NtLockRegistryKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d4063 #: 103 Function Name: NtLockVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805af954 #: 104 Function Name: NtMakePermanentObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a0fca #: 105 Function Name: NtMakeTemporaryObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a11b7 #: 106 Function Name: NtMapUserPhysicalPages Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80624755 #: 107 Function Name: NtMapUserPhysicalPagesScatter Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80624c29 #: 108 Function Name: NtMapViewOfSection Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805723ec #: 109 Function Name: NtModifyBootEntry Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472ab #: 110 Function Name: NtNotifyChangeDirectoryFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80591159 #: 111 Function Name: NtNotifyChangeKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80590ea2 #: 112 Function Name: NtNotifyChangeMultipleKeys Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80590f6b #: 113 Function Name: NtOpenDirectoryObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057ffcf #: 114 Function Name: NtOpenEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058051e #: 115 Function Name: NtOpenEventPair Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647a03 #: 116 Function Name: NtOpenFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056fc13 #: 117 Function Name: NtOpenIoCompletion Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80615157 #: 118 Function Name: NtOpenJobObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062e855 #: 119 Function Name: NtOpenKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80567d7b #: 120 Function Name: NtOpenMutant Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057b32f #: 121 Function Name: NtOpenObjectAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059e516 #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80572d86 #: 123 Function Name: NtOpenProcessToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056c0c1 #: 124 Function Name: NtOpenProcessTokenEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056c2ba #: 125 Function Name: NtOpenSection Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057678b #: 126 Function Name: NtOpenSemaphore Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805db0f2 #: 127 Function Name: NtOpenSymbolicLinkObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057fe9b #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058c892 #: 129 Function Name: NtOpenThreadToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056bb5e #: 130 Function Name: NtOpenThreadTokenEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056bacc #: 131 Function Name: NtOpenTimer Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647839 #: 132 Function Name: NtPlugPlayControl Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805996de #: 133 Function Name: NtPowerInformation Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059d2bc #: 134 Function Name: NtPrivilegeCheck Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059b208 #: 135 Function Name: NtPrivilegeObjectAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805dbe1f #: 136 Function Name: NtPrivilegedServiceAuditAlarm Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805aa72a #: 137 Function Name: NtProtectVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80573135 #: 138 Function Name: NtPulseEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a24d2 #: 139 Function Name: NtQueryAttributesFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805704f3 #: 140 Function Name: NtQueryBootEntryOrder Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472bf #: 141 Function Name: NtQueryBootOptions Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472bf #: 143 Function Name: NtQueryDefaultLocale Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80565faa #: 144 Function Name: NtQueryDefaultUILanguage Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80580e19 #: 145 Function Name: NtQueryDirectoryFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80573595 #: 146 Function Name: NtQueryDirectoryObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80586a3b #: 147 Function Name: NtQueryEaFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806155e0 #: 148 Function Name: NtQueryEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058004c #: 149 Function Name: NtQueryFullAttributesFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80579a01 #: 150 Function Name: NtQueryInformationAtom Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d6e50 #: 151 Function Name: NtQueryInformationFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805714fe #: 152 Function Name: NtQueryInformationJobObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80582ff7 #: 153 Function Name: NtQueryInformationPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80621b63 #: 154 Function Name: NtQueryInformationProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056bcfc #: 155 Function Name: NtQueryInformationThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805664f7 #: 156 Function Name: NtQueryInformationToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056c82b #: 157 Function Name: NtQueryInstallUILanguage Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058072e #: 158 Function Name: NtQueryIntervalProfile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806483f7 #: 159 Function Name: NtQueryIoCompletion Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80615218 #: 160 Function Name: NtQueryKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056ec39 #: 161 Function Name: NtQueryMultipleValueKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064ccf0 #: 162 Function Name: NtQueryMutant Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647d7c #: 163 Function Name: NtQueryObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80581750 #: 164 Function Name: NtQueryOpenSubKeys Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064cef6 #: 165 Function Name: NtQueryPerformanceCounter Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80566831 #: 166 Function Name: NtQueryQuotaInformationFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80615eab #: 167 Function Name: NtQuerySection Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80579e19 #: 168 Function Name: NtQuerySecurityObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059b0a3 #: 169 Function Name: NtQuerySemaphore Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80646b5f #: 170 Function Name: NtQuerySymbolicLinkObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057fd0c #: 171 Function Name: NtQuerySystemEnvironmentValue Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472e7 #: 172 Function Name: NtQuerySystemEnvironmentValueEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647284 #: 173 Function Name: NtQuerySystemInformation Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057d812 #: 174 Function Name: NtQuerySystemTime Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058fb5c #: 175 Function Name: NtQueryTimer Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805908e3 #: 176 Function Name: NtQueryTimerResolution Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058627f #: 177 Function Name: NtQueryValueKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056b183 #: 178 Function Name: NtQueryVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056c3b8 #: 179 Function Name: NtQueryVolumeInformationFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056febb #: 180 Function Name: NtQueueApcThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058f71b #: 182 Function Name: NtRaiseHardError Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064689b #: 183 Function Name: NtReadFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80570158 #: 184 Function Name: NtReadFileScatter Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d9efc #: 185 Function Name: NtReadRequestData Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058e732 #: 186 Function Name: NtReadVirtualMemory Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057a5c5 #: 187 Function Name: NtRegisterThreadTerminatePort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057cc78 #: 189 Function Name: NtReleaseSemaphore Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8058a51e #: 190 Function Name: NtRemoveIoCompletion Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805662f2 #: 191 Function Name: NtRemoveProcessDebug Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806594d2 #: 192 Function Name: NtRenameKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064d137 #: 193 Function Name: NtReplaceKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064d62a #: 194 Function Name: NtReplyPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057e393 #: 195 Function Name: NtReplyWaitReceivePort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80569f16 #: 196 Function Name: NtReplyWaitReceivePortEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80569a2e #: 197 Function Name: NtReplyWaitReplyPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80621c42 #: 198 Function Name: NtRequestDeviceWakeup Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062a8b3 #: 199 Function Name: NtRequestPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80589ab8 #: 200 Function Name: NtRequestWaitReplyPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80575faa #: 201 Function Name: NtRequestWakeupLatency Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062a6ac #: 202 Function Name: NtResetEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059c7e3 #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064c148 #: 205 Function Name: NtResumeProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062e0f4 #: 206 Function Name: NtResumeThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057cb9e #: 207 Function Name: NtSaveKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064c1ef #: 208 Function Name: NtSaveKeyEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064c287 #: 209 Function Name: NtSaveMergedKeys Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064c35b #: 210 Function Name: NtSecureConnectPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8057ea7a #: 211 Function Name: NtSetBootEntryOrder Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472bf #: 212 Function Name: NtSetBootOptions Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806472bf #: 213 Function Name: NtSetContextThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062c4b3 #: 214 Function Name: NtSetDebugFilterState Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8065b01c #: 215 Function Name: NtSetDefaultHardErrorPort Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805d4dbf #: 216 Function Name: NtSetDefaultLocale Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805ae01d #: 217 Function Name: NtSetDefaultUILanguage Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805adfc4 #: 218 Function Name: NtSetEaFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80615b2f #: 219 Function Name: NtSetEvent Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80568718 #: 220 Function Name: NtSetEventBoostPriority Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80574c3e #: 221 Function Name: NtSetHighEventPair Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647d03 #: 222 Function Name: NtSetHighWaitLowEventPair Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647c23 #: 223 Function Name: NtSetInformationDebugObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80658e71 #: 224 Function Name: NtSetInformationFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80576f1c #: 225 Function Name: NtSetInformationJobObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805aaada #: 226 Function Name: NtSetInformationKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064c853 #: 227 Function Name: NtSetInformationObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80580653 #: 228 Function Name: NtSetInformationProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8056bdcd #: 229 Function Name: NtSetInformationThread Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80574826 #: 230 Function Name: NtSetInformationToken Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a7e85 #: 231 Function Name: NtSetIntervalProfile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647f23 #: 232 Function Name: NtSetIoCompletion Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80576dd1 #: 233 Function Name: NtSetLdtEntries Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062d1d7 #: 234 Function Name: NtSetLowEventPair Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647c97 #: 235 Function Name: NtSetLowWaitHighEventPair Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647baf #: 236 Function Name: NtSetQuotaInformationFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80615e83 #: 237 Function Name: NtSetSecurityObject Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8059b8c1 #: 238 Function Name: NtSetSystemEnvironmentValue Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647584 #: 239 Function Name: NtSetSystemEnvironmentValueEx Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80647284 #: 240 Function Name: NtSetSystemInformation Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805a26f4 #: 241 Function Name: NtSetSystemPowerState Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80665927 #: 242 Function Name: NtSetSystemTime Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806461e5 #: 243 Function Name: NtSetThreadExecutionState Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805df7ac #: 245 Function Name: NtSetTimerResolution Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805dfe32 #: 246 Function Name: NtSetUuidSeed Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x805aa8d6 #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80573d0d #: 248 Function Name: NtSetVolumeInformationFile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x806163c5 #: 249 Function Name: NtShutdownSystem Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064592f #: 251 Function Name: NtStartProfile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8064818e #: 252 Function Name: NtStopProfile Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x80648347 #: 253 Function Name: NtSuspendProcess Status: Hooked by "C:\WINDOWS\system32\ntoskrnl.exe" at address 0x8062e099 #: 254 Function Na==EOF== ========================================================================= DDS log : DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 16:56:50.17 on Tue 12/01/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.545 [GMT -5:00] FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch SVCHOST.EXE C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\Ati2evxx.exe SVCHOST.EXE SVCHOST.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe SVCHOST.EXE C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\fxssvc.exe C:\Program Files\iPod\bin\iPodService.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe c:\program files\common files\installshield\updateservice\isuspm.exe C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Joe\My Documents\virus-DJS\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uDefault_Page_URL = hxxp://www.dell4me.com/myway uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.dell4me.com/myway mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.dell4me.com/myway mSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: N/A: {4d25f926-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\1.bin\deSrcAs.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: BHO: {22e1eff7-d8dd-4bbc-9ce8-87edbe8c1a40} - c:\windows\system32\iehelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll TB: McAfee VirusScan: {ba52b914-b692-46c4-b683-905236f6f655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [system tool] c:\program files\txtehn\xcrxsysguard.exe mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r mRun: [P17Helper] Rundll32 P17.dll,P17Helper mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [VSOCheckTask] "c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" /checktask mRun: [MCAgentExe] c:\progra~1\mcafee.com\agent\mcagent.exe mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\McUpdate.exe mRun: [VirusScan Online] c:\progra~1\mcafee.com\vso\mcvsshld.exe mRun: [MPFExe] c:\progra~1\mcafee.com\person~1\MpfTray.exe mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe" mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [system tool] c:\program files\txtehn\xcrxsysguard.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll LSP: c:\windows\system32\lsp.dll Trusted Zone: turbotax.com DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} - hxxp://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://hgtv2.view22.com/view22/app/view22rte.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088] R2 MCVSRte;McAfee.com VirusScan Online Realtime Engine;c:\progra~1\mcafee.com\vso\mcvsrte.exe [2005-6-17 122880] R3 McShield;McAfee.com McShield;c:\progra~1\mcafee.com\vso\mcshield.exe [2005-6-17 225375] R3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [2005-6-17 23296] S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe [2005-6-17 249856] =============== Created Last 30 ================ 2009-11-01 19:35 –d—– c:\program files\Trend Micro 2009-11-01 19:35 –d—– C:\HJT-save ==================== Find3M ==================== 2009-10-03 13:33 222,208 a——- c:\windows\syssvc.exe 2009-10-03 13:33 12,032 a——- c:\windows\system32\iehelper.dll 2009-10-01 20:08 180,224 a——- c:\windows\system32\lsp.dll 2009-09-11 09:33 133,632 a——- c:\windows\system32\SET1B.tmp 2009-09-11 09:33 133,632 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-09-04 15:45 58,880 a——- c:\windows\system32\SETB6.tmp 2009-09-04 15:45 58,880 ——– c:\windows\system32\dllcache\msasn1.dll 2009-05-25 12:23 34 a——- c:\documents and settings\joe\jagex_runescape_preferences.dat ============= FINISH: 16:57:27.06 ===============

Attachments:

[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)

Please post the exeHelper log, and a new DDS log.
Thanks for your help, Raktor! I really appreciate it. Sorry it took me so long to get back to you this time; I'll do better from now on. :) here is the exehelper.exe log: exeHelper by Raktor Build 20091204 Run at 13:55:23 on 12/05/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Removing HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system tool Deleting file C:\Program Files\txtehn\xcrxsysguard.exe Removing HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system tool Checking for bad processes… Checking for bad files… Deleting file C:\WINDOWS\system32\~.exe Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– And here is a new DDS log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 13:56:54.89 on Sat 12/05/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.562 [GMT -5:00] FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch SVCHOST.EXE C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\Ati2evxx.exe SVCHOST.EXE SVCHOST.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe SVCHOST.EXE C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\system32\CTsvcCDA.EXE c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\system32\wuauclt.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Joe\My Documents\virus-DJS\exeHelper.com C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Joe\My Documents\virus-DJS\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uDefault_Page_URL = hxxp://www.dell4me.com/myway uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.dell4me.com/myway mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.dell4me.com/myway mSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: N/A: {4d25f926-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\1.bin\deSrcAs.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: BHO: {22e1eff7-d8dd-4bbc-9ce8-87edbe8c1a40} - c:\windows\system32\iehelper.dll BHO: : {4d25f921-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\1.bin\deSrcAs.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll TB: McAfee VirusScan: {ba52b914-b692-46c4-b683-905236f6f655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r mRun: [P17Helper] Rundll32 P17.dll,P17Helper mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [VSOCheckTask] "c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" /checktask mRun: [MCAgentExe] c:\progra~1\mcafee.com\agent\mcagent.exe mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\McUpdate.exe mRun: [VirusScan Online] c:\progra~1\mcafee.com\vso\mcvsshld.exe mRun: [MPFExe] c:\progra~1\mcafee.com\person~1\MpfTray.exe mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe" mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe" mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll LSP: c:\windows\system32\lsp.dll Trusted Zone: turbotax.com DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} - hxxp://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} - hxxp://hgtv2.view22.com/view22/app/view22rte.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: AtiExtEvent - Ati2evxx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088] R2 MCVSRte;McAfee.com VirusScan Online Realtime Engine;c:\progra~1\mcafee.com\vso\mcvsrte.exe [2005-6-17 122880] R3 McShield;McAfee.com McShield;c:\progra~1\mcafee.com\vso\mcshield.exe [2005-6-17 225375] R3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [2005-6-17 23296] S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe [2005-6-17 249856] =============== Created Last 30 ================ ==================== Find3M ==================== 2009-10-03 13:33 222,208 a——- c:\windows\syssvc.exe 2009-10-03 13:33 12,032 a——- c:\windows\system32\iehelper.dll 2009-10-01 20:08 180,224 a——- c:\windows\system32\lsp.dll 2009-09-18 04:56 18,432 ——– c:\windows\system32\dllcache\iedw.exe 2009-09-11 09:33 133,632 a——- c:\windows\system32\msv1_0.dll 2009-09-11 09:33 133,632 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-05-25 12:23 34 a——- c:\documents and settings\joe\jagex_runescape_preferences.dat ============= FINISH: 13:57:38.37 =============== I attached another Attach zip file even though you didn't mention it directly, since it was created by the DDS process. Thanks again!

Attachments:

Download Combofix from any of the links below, directly to your desktop.

Link 1
Link 2


==================================

Disable all antivirus software, then double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Raktor,

I ran ComboFix as you requested. It first created a System Restore point, and then it requested access to the internet to download something from Microsoft to fix "some nastier problems". So I said ok. It asked that I say yes to the EULA, which I did. That window went away, and the whole process just sat at 100% downloaded for basically forever (over 2 hours… I walked off and came back later). It had done nothing, and I saw no activity on the hard disk over the next half hour, so I decided to stop it. I started it again, and this time it went on and gave me a message like "Do not start any other programs while ComboFix is running" and "this typically takes 10 minutes or less but may take a lot longer", so I walked away again for 10 minutes. When I came back, the machine had rebooted. I logged in as the administrator again and lo and behold, ComboFix window is still up. It said "Preparing report" and "Do not run any programs until ComboFix has finished"… so I didn't… however the same crazy stuff was starting up from a normal login to Windows – McAfee messages, Windows Updates wanting to run, etc. Now I am just noticing that the windows updates no longer want to run, so I am wondering if somehow that caused the reboot? Anyway, eventually this DID create a log file, and here it is:

——

ComboFix 09-12-05.06 - Joe 12/06/2009 8:33.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.613 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\virus-DJS\ComboFix.exe
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ATI Technologies\ATI.ACE\atIAcmxx.dll
c:\program files\Shared\lib.dll
c:\program files\Shared\lib.sig
c:\windows\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
c:\windows\syssvc.exe
c:\windows\system32\bszip.dll
c:\windows\system32\Data
c:\windows\system32\iehelper.dll
c:\windows\system32\lsp.dll
c:\windows\system32\regscan.exe
c:\windows\system32\xwreg32.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.

2009-12-01 21:52 . 2009-12-01 21:52 ——– d—–w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 13:37 . 2009-08-15 03:09 ——– d—–w- c:\program files\Shared
2009-12-05 18:55 . 2009-10-02 00:57 ——– d—–w- c:\program files\txtehn
2009-11-02 00:35 . 2009-11-02 00:35 ——– d—–w- c:\program files\Trend Micro
2009-11-02 00:34 . 2007-04-16 16:50 ——– d—–w- c:\documents and settings\Joe\Application Data\U3
2009-09-25 05:56 . 2004-08-04 10:00 662016 —-a-w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2004-08-04 10:00 133632 —-a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"P17Helper"="P17.dll" [2004-06-10 60928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-15 286720]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-26 811008]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Nic\\My Documents\\My Games\\Warcraft III\\Warcraft III.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"61307:TCP"= 61307:TCP:PORT_61307
"16116:TCP"= 16116:TCP:PORT_16116
"40828:TCP"= 40828:TCP:PORT_40828
"59453:TCP"= 59453:TCP:PORT_59453
"55073:TCP"= 55073:TCP:PORT_55073
"28000:TCP"= 28000:TCP:PORT_28000
"56758:TCP"= 56758:TCP:PORT_56758
"43217:TCP"= 43217:TCP:PORT_43217
"29148:TCP"= 29148:TCP:PORT_29148
"21535:TCP"= 21535:TCP:PORT_21535
"16480:TCP"= 16480:TCP:PORT_16480
"27736:TCP"= 27736:TCP:PORT_27736
"32751:TCP"= 32751:TCP:PORT_32751
"20291:TCP"= 20291:TCP:PORT_20291
"37351:TCP"= 37351:TCP:PORT_37351
"27738:TCP"= 27738:TCP:PORT_27738
"9703:TCP"= 9703:TCP:PORT_9703
"18075:TCP"= 18075:TCP:PORT_18075
"55499:TCP"= 55499:TCP:PORT_55499
"19496:TCP"= 19496:TCP:PORT_19496
"10391:TCP"= 10391:TCP:PORT_10391
"35476:TCP"= 35476:TCP:PORT_35476
"7486:TCP"= 7486:TCP:PORT_7486
"12473:TCP"= 12473:TCP:PORT_12473
"49942:TCP"= 49942:TCP:PORT_49942
"5557:TCP"= 5557:TCP:PORT_5557
"18270:TCP"= 18270:TCP:PORT_18270
"51616:TCP"= 51616:TCP:PORT_51616
"11773:TCP"= 11773:TCP:PORT_11773
"42867:TCP"= 42867:TCP:PORT_42867
"37162:TCP"= 37162:TCP:PORT_37162
"47530:TCP"= 47530:TCP:PORT_47530
"26821:TCP"= 26821:TCP:PORT_26821
"38609:TCP"= 38609:TCP:PORT_38609
"44156:TCP"= 44156:TCP:PORT_44156
"25070:TCP"= 25070:TCP:PORT_25070
"7423:TCP"= 7423:TCP:PORT_7423
"43805:TCP"= 43805:TCP:PORT_43805
"23021:TCP"= 23021:TCP:PORT_23021
"59408:TCP"= 59408:TCP:PORT_59408
"13423:TCP"= 13423:TCP:PORT_13423
"27270:TCP"= 27270:TCP:PORT_27270
"24110:TCP"= 24110:TCP:PORT_24110
"9827:TCP"= 9827:TCP:PORT_9827
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"9375:TCP"= 9375:TCP:PORT_9375
"28434:TCP"= 28434:TCP:PORT_28434
"41517:TCP"= 41517:TCP:PORT_41517
"26751:TCP"= 26751:TCP:PORT_26751
"43672:TCP"= 43672:TCP:PORT_43672
"21595:TCP"= 21595:TCP:PORT_21595
"30435:TCP"= 30435:TCP:PORT_30435
"63043:TCP"= 63043:TCP:PORT_63043
"26543:TCP"= 26543:TCP:PORT_26543
"20123:TCP"= 20123:TCP:PORT_20123
"62973:TCP"= 62973:TCP:PORT_62973
"19487:TCP"= 19487:TCP:PORT_19487
"17360:TCP"= 17360:TCP:PORT_17360
"50343:TCP"= 50343:TCP:PORT_50343
"39220:TCP"= 39220:TCP:PORT_39220
"42793:TCP"= 42793:TCP:PORT_42793
"52318:TCP"= 52318:TCP:PORT_52318
"10776:TCP"= 10776:TCP:PORT_10776
"23410:TCP"= 23410:TCP:PORT_23410
"17405:TCP"= 17405:TCP:PORT_17405
"43620:TCP"= 43620:TCP:PORT_43620
"23330:TCP"= 23330:TCP:PORT_23330
"52890:TCP"= 52890:TCP:PORT_52890
"44539:TCP"= 44539:TCP:PORT_44539
"51231:TCP"= 51231:TCP:PORT_51231
"63785:TCP"= 63785:TCP:PORT_63785
"11449:TCP"= 11449:TCP:PORT_11449
"49436:TCP"= 49436:TCP:PORT_49436
"47215:TCP"= 47215:TCP:PORT_47215
"64036:TCP"= 64036:TCP:PORT_64036
"34800:TCP"= 34800:TCP:PORT_34800
"62641:TCP"= 62641:TCP:PORT_62641
"7043:TCP"= 7043:TCP:PORT_7043
"7446:TCP"= 7446:TCP:PORT_7446
"33934:TCP"= 33934:TCP:PORT_33934
"44870:TCP"= 44870:TCP:PORT_44870
"34415:TCP"= 34415:TCP:PORT_34415
"20246:TCP"= 20246:TCP:PORT_20246
"10131:TCP"= 10131:TCP:PORT_10131
"38626:TCP"= 38626:TCP:PORT_38626
"50500:TCP"= 50500:TCP:PORT_50500
"5820:TCP"= 5820:TCP:PORT_5820
"63220:TCP"= 63220:TCP:PORT_63220
"13836:TCP"= 13836:TCP:PORT_13836
"54646:TCP"= 54646:TCP:PORT_54646
"49461:TCP"= 49461:TCP:PORT_49461
"26079:TCP"= 26079:TCP:PORT_26079
"21542:TCP"= 21542:TCP:PORT_21542
"33782:TCP"= 33782:TCP:PORT_33782
"64258:TCP"= 64258:TCP:PORT_64258
"35016:TCP"= 35016:TCP:PORT_35016
"40867:TCP"= 40867:TCP:PORT_40867
"5960:TCP"= 5960:TCP:PORT_5960
"7705:TCP"= 7705:TCP:PORT_7705
"56940:TCP"= 56940:TCP:PORT_56940
"51244:TCP"= 51244:TCP:PORT_51244
"55191:TCP"= 55191:TCP:PORT_55191
"55728:TCP"= 55728:TCP:PORT_55728
"46526:TCP"= 46526:TCP:PORT_46526
"50656:TCP"= 50656:TCP:PORT_50656
"38698:TCP"= 38698:TCP:PORT_38698
"6893:TCP"= 6893:TCP:PORT_6893
"50011:TCP"= 50011:TCP:PORT_50011
"52461:TCP"= 52461:TCP:PORT_52461
"58310:TCP"= 58310:TCP:PORT_58310
"9914:TCP"= 9914:TCP:PORT_9914
"49414:TCP"= 49414:TCP:PORT_49414
"33680:TCP"= 33680:TCP:PORT_33680
"25566:TCP"= 25566:TCP:PORT_25566
"11890:TCP"= 11890:TCP:PORT_11890
"65455:TCP"= 65455:TCP:PORT_65455
"19724:TCP"= 19724:TCP:PORT_19724
"18508:TCP"= 18508:TCP:PORT_18508
"30518:TCP"= 30518:TCP:PORT_30518
"13141:TCP"= 13141:TCP:PORT_13141
"5259:TCP"= 5259:TCP:PORT_5259
"33305:TCP"= 33305:TCP:PORT_33305
"43873:TCP"= 43873:TCP:PORT_43873
"7640:TCP"= 7640:TCP:PORT_7640
"12272:TCP"= 12272:TCP:PORT_12272
"49845:TCP"= 49845:TCP:PORT_49845
"30796:TCP"= 30796:TCP:PORT_30796
"26410:TCP"= 26410:TCP:PORT_26410
"42263:TCP"= 42263:TCP:PORT_42263
"34592:TCP"= 34592:TCP:PORT_34592
"46493:TCP"= 46493:TCP:PORT_46493
"29204:TCP"= 29204:TCP:PORT_29204
"13712:TCP"= 13712:TCP:PORT_13712
"54866:TCP"= 54866:TCP:PORT_54866
"8123:TCP"= 8123:TCP:PORT_8123
"25446:TCP"= 25446:TCP:PORT_25446
"45556:TCP"= 45556:TCP:PORT_45556
"52036:TCP"= 52036:TCP:PORT_52036
"50650:TCP"= 50650:TCP:PORT_50650
"26160:TCP"= 26160:TCP:PORT_26160
"24964:TCP"= 24964:TCP:PORT_24964
"41379:TCP"= 41379:TCP:PORT_41379
"64774:TCP"= 64774:TCP:PORT_64774
"41013:TCP"= 41013:TCP:PORT_41013

R3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [6/17/2005 12:50 AM 23296]
.
——- Supplementary Scan ——-
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-AIM - c:\program files\AIM\aim.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-06 08:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3108)
c:\progra~1\mcafee.com\vso\McVSSkt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\progra~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\Rundll32.exe
c:\program files\Real\RealPlayer\RealPlay.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
c:\progra~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Completion time: 2009-12-06 08:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-06 13:50

Pre-Run: 5,154,013,184 bytes free
Post-Run: 5,942,210,560 bytes free

- - End Of File - - 57AC15AB5C9C4134CE724BE506AFA98C


I hope I haven't done anything to mess you up….
That was all perfect, just make sure McAfee is/stays disabled until the end - it really does not like Combofix.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DirLook::
c:\program files\txtehn

Registry::
[-HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Performed the necessary drag/drop operation as requested. ComboFix appeared to run to completion this time (I saw it go through stage_50, delete Shared Files, etc.) During the process, Window's Security Center popped up a balloon stating that "McAfee VirusScan was turned off", so I figured that was good. Also, the Google Toolbar popped a balloon that said it blocked the changing of the search settings…

Anyway, here's C:\ComboFix.txt as you requested:

ComboFix 09-12-05.06 - Joe 12/06/2009 16:34.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.647 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\virus-DJS\ComboFix.exe
Command switches used :: c:\documents and settings\Joe\My Documents\virus-DJS\CFScript.txt
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Shared

.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.

2009-12-01 21:52 . 2009-12-01 21:52 ——– d—–w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-05 18:55 . 2009-10-02 00:57 ——– d—–w- c:\program files\txtehn
2009-11-02 00:35 . 2009-11-02 00:35 ——– d—–w- c:\program files\Trend Micro
2009-11-02 00:34 . 2007-04-16 16:50 ——– d—–w- c:\documents and settings\Joe\Application Data\U3
2009-09-25 05:56 . 2004-08-04 10:00 662016 ——w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2004-08-04 10:00 133632 —-a-w- c:\windows\system32\msv1_0.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\program files\txtehn —-



((((((((((((((((((((((((((((( SnapShot@2009-12-06_13.43.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-06 13:59 . 2009-12-06 13:59 37888 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Windows.Pres#\8acb476a0d4ee17a12881e17ae74a6af\System.Windows.Presentation.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 36864 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.DynamicD#\4b87ca3482a3c0ee733e028ecee7de65\System.Web.DynamicData.Design.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 94208 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ComponentMod#\a0c71055364bd356971791284c3fb910\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 82944 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f9a75bbdc2ce7db578b5977766a09b99\System.AddIn.Contract.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 55296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2673aec397c52796aef05bb9d2668df\Microsoft.Vsa.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 65024 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d513fe1a81c441e7656a9b062cff4e9f\Microsoft.Build.Framework.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 74752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\c5d504724d7f351b1d034615dbb72a2a\Microsoft.Build.Framework.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 14336 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\dfsvc\a664ccab020f93f1d533919f57131190\dfsvc.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 321536 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\WsatConfig\e2098e43d115155d6ba91ba3a7e577cf\WsatConfig.ni.exe
+ 2009-12-06 13:59 . 2009-12-06 13:59 400896 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Xml.Linq\eb23b78564687badff1bd1f1d0a0ec97\System.Xml.Linq.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 129536 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Routing\e7666364bf9f3ba5f4833c9efedd8218\System.Web.Routing.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 202240 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5f1b8791e6c47e5bd5e7018c346c586\System.Web.RegularExpressions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 859648 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Extensio#\884eacddf339b8b342f66aedff5f8ef9\System.Web.Extensions.Design.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 328704 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Entity\9e199645bd26f1afe58ebe185d1e7f0f\System.Web.Entity.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 301056 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Entity.D#\652017ebe962ab2eb271c2524f31cd61\System.Web.Entity.Design.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 547328 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.DynamicD#\d0070c1c1a642ae30394e00bc0d82336\System.Web.DynamicData.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 141312 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Abstract#\1896753d02d146be1988d32241300f51\System.Web.Abstractions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 627200 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Transactions\408e637346ef628a3f54fb1b9b83ac9f\System.Transactions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 212992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceProce#\1f61bccb700d687775cf778dd77752e9\System.ServiceProcess.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 676352 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Security\a9e9b885a6601469c4058375cc74d856\System.Security.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 311296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9bc34a79af9c3ed2cf17a0226c769b4c\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 621056 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Net\5f74a84e9d28c2332c51f6e30da0e125\System.Net.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 998400 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Management\2c208e4c5521f31057ea7d6e93c6a567\System.Management.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 330752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Management.I#\818b20a7c6f3b2fe97bf008ca24080c1\System.Management.Instrumentation.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 280064 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.Wrapper.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 627712 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 881152 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\c92fc19800e701c90f90ab7a2ab44c47\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 455680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\a601f47a98ee67df424685c9a66ea449\System.DirectoryServices.Protocols.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 939008 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Service#\b91b44015859163646f210d284f7166a\System.Data.Services.Client.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 354816 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Service#\1b35297e07b85071daecdb06f96750a1\System.Data.Services.Design.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 756736 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Entity.#\cf906bf9146d1f0013451ec63b58e064\System.Data.Entity.Design.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 135680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.DataSet#\4ff4134b0d490c090e03d74e104517c4\System.Data.DataSetExtensions.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 971264 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Configuration\7c743462baccf29b3567b0e3ec9ac134\System.Configuration.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 141312 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Configuratio#\443e3a85c491b2de4a2ac654cb957484\System.Configuration.Install.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 633856 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.AddIn\cba35f47925431a54d0e6ae147a292f1\System.AddIn.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 366080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\SMSvcHost\6af32fe5cbec0aa54e2efa6910c73651\SMSvcHost.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 256000 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\SMDiagnostics\7602d7687fb9bd21cd9ae60d2b187c99\SMDiagnostics.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 320512 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ServiceModelReg\a23dc25782df04533a13e348203e4dc5\ServiceModelReg.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 133632 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\MSBuild\eade8c1c9c1e8e5ffb50e6c9b9af0f6a\MSBuild.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 386560 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fc4d66e0a92b3767006a84f2519d2457\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 144384 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\58ca3ecc52b7246b448c109817198a0b\Microsoft.Build.Utilities.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 175104 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4dd43724dd92026577c6f588270137a0\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 839680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8c651f75bb741330370986dcad8e9e5b\Microsoft.Build.Engine.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 222720 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a6dcbae619ccd938bfe808c54d6d3ae0\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 220672 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\CustomMarshalers\77688ce14f221ed94a9f442ae4736123\CustomMarshalers.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 410112 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ComSvcConfig\a17c65f0cffaa4f792dd38d50df9d526\ComSvcConfig.ni.exe
+ 2009-12-06 13:59 . 2009-12-06 13:59 1356288 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.WorkflowServ#\fa48917b13629d8effa80dd4a2f2973d\System.WorkflowServices.ni.dll
+ 2009-12-06 13:59 . 2009-12-06 13:59 1908224 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Run#\6fe66ee6f3c81996bc148f1ebe7ec030\System.Workflow.Runtime.ni.dll
+ 2009-12-06 13:59 . 2009-12-06 13:59 4514304 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Com#\9d0b61f2f1ebdc300bd970f594c422ef\System.Workflow.ComponentModel.ni.dll
+ 2009-12-06 13:59 . 2009-12-06 13:59 2992640 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Act#\65328898148a720d394f802f192fc2a0\System.Workflow.Activities.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1840640 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Services\ea07ac791bb5cb9f83679e3dd1a0c0cc\System.Web.Services.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 2209280 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Mobile\29e2f8b1fb691ced973acf49fcee6ec1\System.Web.Mobile.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 2403328 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Extensio#\981dea02bc63c0c083e335adf9018788\System.Web.Extensions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1706496 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceModel#\e182695d05ea57257568bc5f3208aca7\System.ServiceModel.Web.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1116672 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\f47ebb9db460874b1bcbfc391dc970b1\System.DirectoryServices.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1801216 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Deployment\c94a427baa7683f4221b91f90c18461b\System.Deployment.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 2510336 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.SqlXml\272152f0cc139490729e215611a4b244\System.Data.SqlXml.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1328128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Services\112a48e34620a0210eb850040da8a31b\System.Data.Services.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 9924096 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Entity\9012cac7819660f61f1c69cf8e4f2ccf\System.Data.Entity.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 1712128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6eee9b772b6d12d3dbd82f118c2ab2e5\Microsoft.VisualBasic.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 1093120 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f19e9b439636d0744597fff1331cad04\Microsoft.Transactions.Bridge.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 2332160 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.JScript\5b1af7b5be24c7ace065fe1c81c2b650\Microsoft.JScript.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 1620992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\9eec1cc7ac37e0c7f3205e8156149c5a\Microsoft.Build.Tasks.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 1966080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\28c0730288453d57d5dcd62903c4d31b\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 1888768 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5dd4f58999eed37c12aee7ea9f9863ac\Microsoft.Build.Engine.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 11796992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web\5cea03cfb008f2eac1439a9905467f37\System.Web.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 17317888 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceModel\06d6eab93282d2b136a377bd50b7c5a9\System.ServiceModel.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"P17Helper"="P17.dll" [2004-06-10 60928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-15 286720]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-26 811008]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Nic\\My Documents\\My Games\\Warcraft III\\Warcraft III.exe"=

R3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [6/17/2005 12:50 AM 23296]
.
——- Supplementary Scan ——-
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: turbotax.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-06 16:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1996)
c:\progra~1\mcafee.com\vso\McVSSkt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-06 16:43
ComboFix-quarantined-files.txt 2009-12-06 21:43
ComboFix2.txt 2009-12-06 13:50

Pre-Run: 5,865,046,016 bytes free
Post-Run: 5,835,161,600 bytes free

- - End Of File - - E8CBCDDC75D1892FB57C112B3E7A446D

Thanks as usual… :)
Please navigate to and delete this folder
c:\program files\txtehn

1) Update Adobe Reader
Your current version of Adobe Reader is out of date, and may contain security issues. Please uninstall the version you have now from Add/Remove programs, and then download and install the latest Adobe Reader.

2) Update Java
Your version of Java is outdated.

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

3) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

4) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

5) What You Will Need To Post:
  • MBAM log
  • ESET log
  • How the PC is performing now
Removed directory, uninstalled / reinstalled Adobe Acrobat Reader, used JavaRa to uninstall / reinstall Java. On MBAM it worked the *first time* ; I remember it cleaned 23 problems, all related to "Adware.MyWebSearch". I saved the log, ran ESET, saved that log, but then my machine wouldn't reboot. I clicked Restart: nothing. Shutdown: nothing. I couldn't run any programs though because if I clicked them, it would say "system is shutting down". And at that point I couldn't get a task manager window. So I waited for 30 minutes … still no shutdown. So I hard booted the system with the power button. When it came back up, I re-ran MBAM to see if anything took, realizing it saved logs with a date / time stamp, figuring it would just add another log to the directory. I had no idea it would REMOVE THE OLD LOG. Grrrr… I am posting the only mbam log I have, along with the ESET log: MBAM log: Malwarebytes' Anti-Malware 1.42 Database version: 3307 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 12/7/2009 12:05:59 AM mbam-log-2009-12-07 (00-05-59).txt Scan type: Quick Scan Objects scanned: 129773 Time elapsed: 5 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 7 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 3 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\TypeLib\{4d25f920-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4d25f923-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4d25f921-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f924-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Delete on reboot. C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Delete on reboot. Files Infected: C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (Adware.MyWebSearch) -> Delete on reboot. ESET log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=613e570f1f969a498467ff5581a58f41 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-07 07:03:44 # local_time=2009-12-07 02:03:44 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 2959186 2959186 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=80004 # found=23 # cleaned=0 # scan_time=5283 C:\Documents and Settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class Java/TrojanDownloader.OpenStream.NAC trojan 00000000000000000000000000000000 I C:\Downloads\AgeOfCastles_Setup-dm[1].exe Win32/Adware.Trymedia application 00000000000000000000000000000000 I C:\I386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent application 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Shared\lib.dll.vir Win32/BHO.NMM trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\syssvc.exe.vir Win32/Agent.PTT trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe.vir Win32/Adware.WinFixer application 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\iehelper.dll.vir Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\lsp.dll.vir Win32/Agent.PTT trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\regscan.exe.vir a variant of Win32/TrojanDownloader.Agent.HLP trojan 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\xwreg32.dll.vir probably a variant of Win32/TrojanDownloader.Monkif.AA trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098106.dll Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098122.dll Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098126.exe Win32/Agent.PTT trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098182.dll Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1210\A0099750.exe Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1210\A0099751.exe probably a variant of Win32/TrojanDropper.Agent trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099793.exe Win32/Agent.PTT trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099877.dll Win32/BHO.NMM trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099878.exe Win32/Agent.PTT trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099880.dll Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099881.dll Win32/Agent.PTT trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099882.exe a variant of Win32/TrojanDownloader.Agent.HLP trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099883.dll probably a variant of Win32/TrojanDownloader.Monkif.AA trojan 00000000000000000000000000000000 I Sorry if I notgood something up…
You also asked how the system was performing… things all still appear to be the same.. I haven't tried to uninstall / reinstall McAfee Security Suite yet, but I still get several messages at startup about it needing to be installed correctly or reinstalled. I also notice that, somewhere during the startup process, the screen blanks for a moment as if the power settings had the monitor go off after 1 minute, but right now I have it on an Always On mode so I could keep from having to use the mouse or keyboard to wake the monitor during the ESET scan. I think it only lasts a moment, but I must confess I generally have moved the mouse at that point trying to close the McAfee windows as they pop up.
That's fine, I get the general idea. :) Please run MBAM again, as 'Full Scan', after running Combofix as per these instructions. Post both logs. After we've got all the bugs off, we'll fix McAfee.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class
C:\Downloads\AgeOfCastles_Setup-dm[1].exe
C:\I386\GTDownDE_87.ocx


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Okay… ran ComboFix and MBAM as instructed. You didn't mention whether I should remove the problems found with MBAM or not… I decided to err on the side of caution and NOT remove these things, which is evident in the log. I can always run the scan again, right?

ComboFix log:

ComboFix 09-12-05.06 - Joe 12/07/2009 7:34.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.649 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\virus-DJS\ComboFix.exe
Command switches used :: c:\documents and settings\Joe\My Documents\virus-DJS\CFScript2.txt
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"c:\documents and settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class"
"c:\downloads\AgeOfCastles_Setup-dm[1].exe"
"c:\i386\GTDownDE_87.ocx"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class
c:\downloads\AgeOfCastles_Setup-dm[1].exe
c:\i386\GTDownDE_87.ocx

.
((((((((((((((((((((((((( Files Created from 2009-11-07 to 2009-12-07 )))))))))))))))))))))))))))))))
.

2009-12-07 05:31 . 2009-12-07 05:31 ——– d—–w- c:\program files\ESET
2009-12-07 05:23 . 2009-12-07 05:23 ——– d—–w- c:\documents and settings\Joe\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-12-07 03:30 . 2009-12-07 03:30 ——– d—–w- c:\documents and settings\Joe\Application Data\Malwarebytes
2009-12-07 03:30 . 2009-12-03 21:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-07 03:30 . 2009-12-07 03:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-07 03:30 . 2009-12-07 03:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-07 03:30 . 2009-12-03 21:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-07 03:27 . 2009-12-07 03:27 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-07 03:19 . 2009-12-07 03:19 ——– d—–w- c:\program files\JavaRa
2009-12-07 01:00 . 2009-10-10 07:07 38208 —-a-w- c:\documents and settings\Joe\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-07 00:59 . 2009-12-07 00:59 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-07 00:57 . 2009-12-07 00:57 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-12-07 00:57 . 2009-12-07 05:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-01 21:52 . 2009-12-01 21:52 ——– d—–w- c:\program files\ERUNT

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 03:27 . 2005-06-17 05:35 ——– d—–w- c:\program files\Java
2009-12-07 01:03 . 2006-01-23 06:07 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-02 00:35 . 2009-11-02 00:35 ——– d—–w- c:\program files\Trend Micro
2009-11-02 00:34 . 2007-04-16 16:50 ——– d—–w- c:\documents and settings\Joe\Application Data\U3
2009-09-25 05:56 . 2004-08-04 10:00 662016 ——w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2004-08-04 10:00 133632 —-a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((( SnapShot_2009-12-06_21.41.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-07 12:25 . 2009-12-07 12:25 16384 c:\windows\temp\Perflib_Perfdata_6f0.dat
+ 2009-12-07 01:00 . 2009-12-07 01:00 21504 c:\windows\Installer\128bb7.msi
+ 2009-12-07 00:59 . 2009-12-07 00:59 27648 c:\windows\Installer\128bb2.msi
+ 2009-12-07 03:27 . 2009-12-07 03:27 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-12-07 03:27 . 2009-12-07 03:27 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-12-07 03:27 . 2009-12-07 03:27 145184 c:\windows\SYSTEM32\java.exe
+ 2009-12-07 03:27 . 2009-12-07 03:27 1757696 c:\windows\Installer\9a015f.msi
+ 2009-12-07 01:05 . 2009-12-07 01:05 3940352 c:\windows\Installer\128bbc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"P17Helper"="P17.dll" [2004-06-10 60928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-15 286720]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-07 149280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-26 811008]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Nic\\My Documents\\My Games\\Warcraft III\\Warcraft III.exe"=

R3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [6/17/2005 12:50 AM 23296]
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: turbotax.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-07 07:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-07 07:44
ComboFix-quarantined-files.txt 2009-12-07 12:43
ComboFix2.txt 2009-12-06 21:43
ComboFix3.txt 2009-12-06 13:50

Pre-Run: 5,972,361,216 bytes free
Post-Run: 5,956,153,344 bytes free

- - End Of File - - 0547D9BBE48CB9CB16D7FED869E80EF5

MBAM log:

Malwarebytes' Anti-Malware 1.42
Database version: 3307
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

12/7/2009 8:54:27 AM
mbam-log-2

Scan type: Full Scan (C:\|)
Objects scanned: 203479
Time elapsed: 43 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Qoobox\Quarantine\C\I386\GTDownDE_87.ocx.vir (Adware.Gdown) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\syssvc.exe.vir (Trojan.Downloader) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe.vir (Rogue.Installer) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\iehelper.dll.vir (Trojan.BHO) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\lsp.dll.vir (Trojan.Proxy) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098106.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098122.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098126.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098182.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099793.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099878.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099880.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099881.dll (Trojan.Proxy) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1214\A0101354.ocx (Adware.Gdown) -> No action taken.
You could have removed them, but we'll get them later - they're all just in quarantine at the moment anyway. :)

Now we'll follow the McAfee reinstallation instructions, located here.
Read through them first to make sure everything will be possible for you (make sure you have your licence key and access to a download, or something along those lines). Essentially, you will remove it from Add/Remove Programs, then run their product removal tool, then reinstall.

Let me know if you have any questions, otherwise proceed with that.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI