[Closed] continually prompts for reinstall of McAfee Security
8 min read
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:
- Absence of symptoms does not always mean the computer is clean
- Please do not run any scans or fixes without my direction.
- Finally, stay with this topic until I give you the final 'All clear' post.
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Please post the exeHelper log, and a new DDS log.
Link 1
Link 2
==================================
Disable all antivirus software, then double click on ComboFix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt so we can continue cleaning the system.
I ran ComboFix as you requested. It first created a System Restore point, and then it requested access to the internet to download something from Microsoft to fix "some nastier problems". So I said ok. It asked that I say yes to the EULA, which I did. That window went away, and the whole process just sat at 100% downloaded for basically forever (over 2 hours… I walked off and came back later). It had done nothing, and I saw no activity on the hard disk over the next half hour, so I decided to stop it. I started it again, and this time it went on and gave me a message like "Do not start any other programs while ComboFix is running" and "this typically takes 10 minutes or less but may take a lot longer", so I walked away again for 10 minutes. When I came back, the machine had rebooted. I logged in as the administrator again and lo and behold, ComboFix window is still up. It said "Preparing report" and "Do not run any programs until ComboFix has finished"… so I didn't… however the same crazy stuff was starting up from a normal login to Windows – McAfee messages, Windows Updates wanting to run, etc. Now I am just noticing that the windows updates no longer want to run, so I am wondering if somehow that caused the reboot? Anyway, eventually this DID create a log file, and here it is:
——
ComboFix 09-12-05.06 - Joe 12/06/2009 8:33.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.613 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\virus-DJS\ComboFix.exe
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ATI Technologies\ATI.ACE\atIAcmxx.dll
c:\program files\Shared\lib.dll
c:\program files\Shared\lib.sig
c:\windows\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
c:\windows\syssvc.exe
c:\windows\system32\bszip.dll
c:\windows\system32\Data
c:\windows\system32\iehelper.dll
c:\windows\system32\lsp.dll
c:\windows\system32\regscan.exe
c:\windows\system32\xwreg32.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-01 21:52 . 2009-12-01 21:52 ——– d—–w- c:\program files\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 13:37 . 2009-08-15 03:09 ——– d—–w- c:\program files\Shared
2009-12-05 18:55 . 2009-10-02 00:57 ——– d—–w- c:\program files\txtehn
2009-11-02 00:35 . 2009-11-02 00:35 ——– d—–w- c:\program files\Trend Micro
2009-11-02 00:34 . 2007-04-16 16:50 ——– d—–w- c:\documents and settings\Joe\Application Data\U3
2009-09-25 05:56 . 2004-08-04 10:00 662016 —-a-w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2004-08-04 10:00 133632 —-a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"P17Helper"="P17.dll" [2004-06-10 60928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-15 286720]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-26 811008]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Nic\\My Documents\\My Games\\Warcraft III\\Warcraft III.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"61307:TCP"= 61307:TCP:PORT_61307
"16116:TCP"= 16116:TCP:PORT_16116
"40828:TCP"= 40828:TCP:PORT_40828
"59453:TCP"= 59453:TCP:PORT_59453
"55073:TCP"= 55073:TCP:PORT_55073
"28000:TCP"= 28000:TCP:PORT_28000
"56758:TCP"= 56758:TCP:PORT_56758
"43217:TCP"= 43217:TCP:PORT_43217
"29148:TCP"= 29148:TCP:PORT_29148
"21535:TCP"= 21535:TCP:PORT_21535
"16480:TCP"= 16480:TCP:PORT_16480
"27736:TCP"= 27736:TCP:PORT_27736
"32751:TCP"= 32751:TCP:PORT_32751
"20291:TCP"= 20291:TCP:PORT_20291
"37351:TCP"= 37351:TCP:PORT_37351
"27738:TCP"= 27738:TCP:PORT_27738
"9703:TCP"= 9703:TCP:PORT_9703
"18075:TCP"= 18075:TCP:PORT_18075
"55499:TCP"= 55499:TCP:PORT_55499
"19496:TCP"= 19496:TCP:PORT_19496
"10391:TCP"= 10391:TCP:PORT_10391
"35476:TCP"= 35476:TCP:PORT_35476
"7486:TCP"= 7486:TCP:PORT_7486
"12473:TCP"= 12473:TCP:PORT_12473
"49942:TCP"= 49942:TCP:PORT_49942
"5557:TCP"= 5557:TCP:PORT_5557
"18270:TCP"= 18270:TCP:PORT_18270
"51616:TCP"= 51616:TCP:PORT_51616
"11773:TCP"= 11773:TCP:PORT_11773
"42867:TCP"= 42867:TCP:PORT_42867
"37162:TCP"= 37162:TCP:PORT_37162
"47530:TCP"= 47530:TCP:PORT_47530
"26821:TCP"= 26821:TCP:PORT_26821
"38609:TCP"= 38609:TCP:PORT_38609
"44156:TCP"= 44156:TCP:PORT_44156
"25070:TCP"= 25070:TCP:PORT_25070
"7423:TCP"= 7423:TCP:PORT_7423
"43805:TCP"= 43805:TCP:PORT_43805
"23021:TCP"= 23021:TCP:PORT_23021
"59408:TCP"= 59408:TCP:PORT_59408
"13423:TCP"= 13423:TCP:PORT_13423
"27270:TCP"= 27270:TCP:PORT_27270
"24110:TCP"= 24110:TCP:PORT_24110
"9827:TCP"= 9827:TCP:PORT_9827
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"9375:TCP"= 9375:TCP:PORT_9375
"28434:TCP"= 28434:TCP:PORT_28434
"41517:TCP"= 41517:TCP:PORT_41517
"26751:TCP"= 26751:TCP:PORT_26751
"43672:TCP"= 43672:TCP:PORT_43672
"21595:TCP"= 21595:TCP:PORT_21595
"30435:TCP"= 30435:TCP:PORT_30435
"63043:TCP"= 63043:TCP:PORT_63043
"26543:TCP"= 26543:TCP:PORT_26543
"20123:TCP"= 20123:TCP:PORT_20123
"62973:TCP"= 62973:TCP:PORT_62973
"19487:TCP"= 19487:TCP:PORT_19487
"17360:TCP"= 17360:TCP:PORT_17360
"50343:TCP"= 50343:TCP:PORT_50343
"39220:TCP"= 39220:TCP:PORT_39220
"42793:TCP"= 42793:TCP:PORT_42793
"52318:TCP"= 52318:TCP:PORT_52318
"10776:TCP"= 10776:TCP:PORT_10776
"23410:TCP"= 23410:TCP:PORT_23410
"17405:TCP"= 17405:TCP:PORT_17405
"43620:TCP"= 43620:TCP:PORT_43620
"23330:TCP"= 23330:TCP:PORT_23330
"52890:TCP"= 52890:TCP:PORT_52890
"44539:TCP"= 44539:TCP:PORT_44539
"51231:TCP"= 51231:TCP:PORT_51231
"63785:TCP"= 63785:TCP:PORT_63785
"11449:TCP"= 11449:TCP:PORT_11449
"49436:TCP"= 49436:TCP:PORT_49436
"47215:TCP"= 47215:TCP:PORT_47215
"64036:TCP"= 64036:TCP:PORT_64036
"34800:TCP"= 34800:TCP:PORT_34800
"62641:TCP"= 62641:TCP:PORT_62641
"7043:TCP"= 7043:TCP:PORT_7043
"7446:TCP"= 7446:TCP:PORT_7446
"33934:TCP"= 33934:TCP:PORT_33934
"44870:TCP"= 44870:TCP:PORT_44870
"34415:TCP"= 34415:TCP:PORT_34415
"20246:TCP"= 20246:TCP:PORT_20246
"10131:TCP"= 10131:TCP:PORT_10131
"38626:TCP"= 38626:TCP:PORT_38626
"50500:TCP"= 50500:TCP:PORT_50500
"5820:TCP"= 5820:TCP:PORT_5820
"63220:TCP"= 63220:TCP:PORT_63220
"13836:TCP"= 13836:TCP:PORT_13836
"54646:TCP"= 54646:TCP:PORT_54646
"49461:TCP"= 49461:TCP:PORT_49461
"26079:TCP"= 26079:TCP:PORT_26079
"21542:TCP"= 21542:TCP:PORT_21542
"33782:TCP"= 33782:TCP:PORT_33782
"64258:TCP"= 64258:TCP:PORT_64258
"35016:TCP"= 35016:TCP:PORT_35016
"40867:TCP"= 40867:TCP:PORT_40867
"5960:TCP"= 5960:TCP:PORT_5960
"7705:TCP"= 7705:TCP:PORT_7705
"56940:TCP"= 56940:TCP:PORT_56940
"51244:TCP"= 51244:TCP:PORT_51244
"55191:TCP"= 55191:TCP:PORT_55191
"55728:TCP"= 55728:TCP:PORT_55728
"46526:TCP"= 46526:TCP:PORT_46526
"50656:TCP"= 50656:TCP:PORT_50656
"38698:TCP"= 38698:TCP:PORT_38698
"6893:TCP"= 6893:TCP:PORT_6893
"50011:TCP"= 50011:TCP:PORT_50011
"52461:TCP"= 52461:TCP:PORT_52461
"58310:TCP"= 58310:TCP:PORT_58310
"9914:TCP"= 9914:TCP:PORT_9914
"49414:TCP"= 49414:TCP:PORT_49414
"33680:TCP"= 33680:TCP:PORT_33680
"25566:TCP"= 25566:TCP:PORT_25566
"11890:TCP"= 11890:TCP:PORT_11890
"65455:TCP"= 65455:TCP:PORT_65455
"19724:TCP"= 19724:TCP:PORT_19724
"18508:TCP"= 18508:TCP:PORT_18508
"30518:TCP"= 30518:TCP:PORT_30518
"13141:TCP"= 13141:TCP:PORT_13141
"5259:TCP"= 5259:TCP:PORT_5259
"33305:TCP"= 33305:TCP:PORT_33305
"43873:TCP"= 43873:TCP:PORT_43873
"7640:TCP"= 7640:TCP:PORT_7640
"12272:TCP"= 12272:TCP:PORT_12272
"49845:TCP"= 49845:TCP:PORT_49845
"30796:TCP"= 30796:TCP:PORT_30796
"26410:TCP"= 26410:TCP:PORT_26410
"42263:TCP"= 42263:TCP:PORT_42263
"34592:TCP"= 34592:TCP:PORT_34592
"46493:TCP"= 46493:TCP:PORT_46493
"29204:TCP"= 29204:TCP:PORT_29204
"13712:TCP"= 13712:TCP:PORT_13712
"54866:TCP"= 54866:TCP:PORT_54866
"8123:TCP"= 8123:TCP:PORT_8123
"25446:TCP"= 25446:TCP:PORT_25446
"45556:TCP"= 45556:TCP:PORT_45556
"52036:TCP"= 52036:TCP:PORT_52036
"50650:TCP"= 50650:TCP:PORT_50650
"26160:TCP"= 26160:TCP:PORT_26160
"24964:TCP"= 24964:TCP:PORT_24964
"41379:TCP"= 41379:TCP:PORT_41379
"64774:TCP"= 64774:TCP:PORT_64774
"41013:TCP"= 41013:TCP:PORT_41013
R3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [6/17/2005 12:50 AM 23296]
.
——- Supplementary Scan ——-
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-AIM - c:\program files\AIM\aim.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-06 08:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3108)
c:\progra~1\mcafee.com\vso\McVSSkt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\progra~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\Rundll32.exe
c:\program files\Real\RealPlayer\RealPlay.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
c:\progra~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Completion time: 2009-12-06 08:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-06 13:50
Pre-Run: 5,154,013,184 bytes free
Post-Run: 5,942,210,560 bytes free
- - End Of File - - 57AC15AB5C9C4134CE724BE506AFA98C
I hope I haven't done anything to mess you up….
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
DirLook::
c:\program files\txtehn
Registry::
[-HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Anyway, here's C:\ComboFix.txt as you requested:
ComboFix 09-12-05.06 - Joe 12/06/2009 16:34.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.647 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\virus-DJS\ComboFix.exe
Command switches used :: c:\documents and settings\Joe\My Documents\virus-DJS\CFScript.txt
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Shared
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-01 21:52 . 2009-12-01 21:52 ——– d—–w- c:\program files\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-05 18:55 . 2009-10-02 00:57 ——– d—–w- c:\program files\txtehn
2009-11-02 00:35 . 2009-11-02 00:35 ——– d—–w- c:\program files\Trend Micro
2009-11-02 00:34 . 2007-04-16 16:50 ——– d—–w- c:\documents and settings\Joe\Application Data\U3
2009-09-25 05:56 . 2004-08-04 10:00 662016 ——w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2004-08-04 10:00 133632 —-a-w- c:\windows\system32\msv1_0.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\program files\txtehn —-
((((((((((((((((((((((((((((( SnapShot@2009-12-06_13.43.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-06 13:59 . 2009-12-06 13:59 37888 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Windows.Pres#\8acb476a0d4ee17a12881e17ae74a6af\System.Windows.Presentation.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 36864 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.DynamicD#\4b87ca3482a3c0ee733e028ecee7de65\System.Web.DynamicData.Design.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 94208 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ComponentMod#\a0c71055364bd356971791284c3fb910\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 82944 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.AddIn.Contra#\f9a75bbdc2ce7db578b5977766a09b99\System.AddIn.Contract.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 55296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Vsa\f2673aec397c52796aef05bb9d2668df\Microsoft.Vsa.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 65024 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\d513fe1a81c441e7656a9b062cff4e9f\Microsoft.Build.Framework.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 74752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\c5d504724d7f351b1d034615dbb72a2a\Microsoft.Build.Framework.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 14336 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\dfsvc\a664ccab020f93f1d533919f57131190\dfsvc.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 321536 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\WsatConfig\e2098e43d115155d6ba91ba3a7e577cf\WsatConfig.ni.exe
+ 2009-12-06 13:59 . 2009-12-06 13:59 400896 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Xml.Linq\eb23b78564687badff1bd1f1d0a0ec97\System.Xml.Linq.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 129536 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Routing\e7666364bf9f3ba5f4833c9efedd8218\System.Web.Routing.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 202240 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.RegularE#\b5f1b8791e6c47e5bd5e7018c346c586\System.Web.RegularExpressions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 859648 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Extensio#\884eacddf339b8b342f66aedff5f8ef9\System.Web.Extensions.Design.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 328704 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Entity\9e199645bd26f1afe58ebe185d1e7f0f\System.Web.Entity.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 301056 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Entity.D#\652017ebe962ab2eb271c2524f31cd61\System.Web.Entity.Design.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 547328 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.DynamicD#\d0070c1c1a642ae30394e00bc0d82336\System.Web.DynamicData.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 141312 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Abstract#\1896753d02d146be1988d32241300f51\System.Web.Abstractions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 627200 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Transactions\408e637346ef628a3f54fb1b9b83ac9f\System.Transactions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 212992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceProce#\1f61bccb700d687775cf778dd77752e9\System.ServiceProcess.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 676352 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Security\a9e9b885a6601469c4058375cc74d856\System.Security.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 311296 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Runtime.Seri#\9bc34a79af9c3ed2cf17a0226c769b4c\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 621056 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Net\5f74a84e9d28c2332c51f6e30da0e125\System.Net.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 998400 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Management\2c208e4c5521f31057ea7d6e93c6a567\System.Management.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 330752 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Management.I#\818b20a7c6f3b2fe97bf008ca24080c1\System.Management.Instrumentation.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 280064 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.Wrapper.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 627712 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.EnterpriseSe#\8a7d0bd0057a8ed38291d5662248f7a1\System.EnterpriseServices.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 881152 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\c92fc19800e701c90f90ab7a2ab44c47\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 455680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\a601f47a98ee67df424685c9a66ea449\System.DirectoryServices.Protocols.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 939008 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Service#\b91b44015859163646f210d284f7166a\System.Data.Services.Client.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 354816 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Service#\1b35297e07b85071daecdb06f96750a1\System.Data.Services.Design.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 756736 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Entity.#\cf906bf9146d1f0013451ec63b58e064\System.Data.Entity.Design.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 135680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.DataSet#\4ff4134b0d490c090e03d74e104517c4\System.Data.DataSetExtensions.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 971264 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Configuration\7c743462baccf29b3567b0e3ec9ac134\System.Configuration.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 141312 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Configuratio#\443e3a85c491b2de4a2ac654cb957484\System.Configuration.Install.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 633856 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.AddIn\cba35f47925431a54d0e6ae147a292f1\System.AddIn.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 366080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\SMSvcHost\6af32fe5cbec0aa54e2efa6910c73651\SMSvcHost.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 256000 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\SMDiagnostics\7602d7687fb9bd21cd9ae60d2b187c99\SMDiagnostics.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 320512 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ServiceModelReg\a23dc25782df04533a13e348203e4dc5\ServiceModelReg.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 133632 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\MSBuild\eade8c1c9c1e8e5ffb50e6c9b9af0f6a\MSBuild.ni.exe
+ 2009-12-06 13:56 . 2009-12-06 13:56 386560 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Transacti#\fc4d66e0a92b3767006a84f2519d2457\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 144384 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\58ca3ecc52b7246b448c109817198a0b\Microsoft.Build.Utilities.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 175104 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4dd43724dd92026577c6f588270137a0\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 839680 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8c651f75bb741330370986dcad8e9e5b\Microsoft.Build.Engine.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 222720 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\a6dcbae619ccd938bfe808c54d6d3ae0\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 220672 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\CustomMarshalers\77688ce14f221ed94a9f442ae4736123\CustomMarshalers.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 410112 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\ComSvcConfig\a17c65f0cffaa4f792dd38d50df9d526\ComSvcConfig.ni.exe
+ 2009-12-06 13:59 . 2009-12-06 13:59 1356288 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.WorkflowServ#\fa48917b13629d8effa80dd4a2f2973d\System.WorkflowServices.ni.dll
+ 2009-12-06 13:59 . 2009-12-06 13:59 1908224 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Run#\6fe66ee6f3c81996bc148f1ebe7ec030\System.Workflow.Runtime.ni.dll
+ 2009-12-06 13:59 . 2009-12-06 13:59 4514304 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Com#\9d0b61f2f1ebdc300bd970f594c422ef\System.Workflow.ComponentModel.ni.dll
+ 2009-12-06 13:59 . 2009-12-06 13:59 2992640 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Workflow.Act#\65328898148a720d394f802f192fc2a0\System.Workflow.Activities.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1840640 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Services\ea07ac791bb5cb9f83679e3dd1a0c0cc\System.Web.Services.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 2209280 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Mobile\29e2f8b1fb691ced973acf49fcee6ec1\System.Web.Mobile.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 2403328 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web.Extensio#\981dea02bc63c0c083e335adf9018788\System.Web.Extensions.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1706496 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceModel#\e182695d05ea57257568bc5f3208aca7\System.ServiceModel.Web.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1116672 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.DirectorySer#\f47ebb9db460874b1bcbfc391dc970b1\System.DirectoryServices.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1801216 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Deployment\c94a427baa7683f4221b91f90c18461b\System.Deployment.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 2510336 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.SqlXml\272152f0cc139490729e215611a4b244\System.Data.SqlXml.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 1328128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Services\112a48e34620a0210eb850040da8a31b\System.Data.Services.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 9924096 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Data.Entity\9012cac7819660f61f1c69cf8e4f2ccf\System.Data.Entity.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 1712128 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6eee9b772b6d12d3dbd82f118c2ab2e5\Microsoft.VisualBasic.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 1093120 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Transacti#\f19e9b439636d0744597fff1331cad04\Microsoft.Transactions.Bridge.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 2332160 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.JScript\5b1af7b5be24c7ace065fe1c81c2b650\Microsoft.JScript.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 1620992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\9eec1cc7ac37e0c7f3205e8156149c5a\Microsoft.Build.Tasks.ni.dll
+ 2009-12-06 13:57 . 2009-12-06 13:57 1966080 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\28c0730288453d57d5dcd62903c4d31b\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 1888768 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\5dd4f58999eed37c12aee7ea9f9863ac\Microsoft.Build.Engine.ni.dll
+ 2009-12-06 13:58 . 2009-12-06 13:58 11796992 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.Web\5cea03cfb008f2eac1439a9905467f37\System.Web.ni.dll
+ 2009-12-06 13:56 . 2009-12-06 13:56 17317888 c:\windows\ASSEMBLY\NativeImages_v2.0.50727_32\System.ServiceModel\06d6eab93282d2b136a377bd50b7c5a9\System.ServiceModel.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"P17Helper"="P17.dll" [2004-06-10 60928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-15 286720]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-26 811008]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Nic\\My Documents\\My Games\\Warcraft III\\Warcraft III.exe"=
R3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [6/17/2005 12:50 AM 23296]
.
——- Supplementary Scan ——-
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: turbotax.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-06 16:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1996)
c:\progra~1\mcafee.com\vso\McVSSkt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-06 16:43
ComboFix-quarantined-files.txt 2009-12-06 21:43
ComboFix2.txt 2009-12-06 13:50
Pre-Run: 5,865,046,016 bytes free
Post-Run: 5,835,161,600 bytes free
- - End Of File - - E8CBCDDC75D1892FB57C112B3E7A446D
Thanks as usual…
c:\program files\txtehn
1) Update Adobe Reader
Your current version of Adobe Reader is out of date, and may contain security issues. Please uninstall the version you have now from Add/Remove programs, and then download and install the latest Adobe Reader.
2) Update Java
Your version of Java is outdated.
Please download JavaRa to your desktop and unzip it to its own folder
Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
3) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected .
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
4) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.
- Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox. - Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
- When prompted allow the Add-On/Active X to install.
- Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
- Now click on Advanced Settings and select the following:
- Scan for potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth Technology
- Now click on: [external image: Posted Image]
- The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
- When completed the Online Scan will begin automatically.
- Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
- When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
- Now click on: [external image: Posted Image]
- Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
- Copy and paste that log as a reply to this topic.
5) What You Will Need To Post:
- MBAM log
- ESET log
- How the PC is performing now
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
File::
C:\Documents and Settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class
C:\Downloads\AgeOfCastles_Setup-dm[1].exe
C:\I386\GTDownDE_87.ocx
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix log:
ComboFix 09-12-05.06 - Joe 12/07/2009 7:34.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.649 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\virus-DJS\ComboFix.exe
Command switches used :: c:\documents and settings\Joe\My Documents\virus-DJS\CFScript2.txt
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FILE ::
"c:\documents and settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class"
"c:\downloads\AgeOfCastles_Setup-dm[1].exe"
"c:\i386\GTDownDE_87.ocx"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Guest1\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\animan.class-4379e08d-7f49fc95.class
c:\downloads\AgeOfCastles_Setup-dm[1].exe
c:\i386\GTDownDE_87.ocx
.
((((((((((((((((((((((((( Files Created from 2009-11-07 to 2009-12-07 )))))))))))))))))))))))))))))))
.
2009-12-07 05:31 . 2009-12-07 05:31 ——– d—–w- c:\program files\ESET
2009-12-07 05:23 . 2009-12-07 05:23 ——– d—–w- c:\documents and settings\Joe\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-12-07 03:30 . 2009-12-07 03:30 ——– d—–w- c:\documents and settings\Joe\Application Data\Malwarebytes
2009-12-07 03:30 . 2009-12-03 21:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-07 03:30 . 2009-12-07 03:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-07 03:30 . 2009-12-07 03:30 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-07 03:30 . 2009-12-03 21:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-07 03:27 . 2009-12-07 03:27 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-07 03:19 . 2009-12-07 03:19 ——– d—–w- c:\program files\JavaRa
2009-12-07 01:00 . 2009-10-10 07:07 38208 —-a-w- c:\documents and settings\Joe\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-07 00:59 . 2009-12-07 00:59 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-07 00:57 . 2009-12-07 00:57 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-12-07 00:57 . 2009-12-07 05:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-01 21:52 . 2009-12-01 21:52 ——– d—–w- c:\program files\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 03:27 . 2005-06-17 05:35 ——– d—–w- c:\program files\Java
2009-12-07 01:03 . 2006-01-23 06:07 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-02 00:35 . 2009-11-02 00:35 ——– d—–w- c:\program files\Trend Micro
2009-11-02 00:34 . 2007-04-16 16:50 ——– d—–w- c:\documents and settings\Joe\Application Data\U3
2009-09-25 05:56 . 2004-08-04 10:00 662016 ——w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2004-08-04 10:00 133632 —-a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-12-06_21.41.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-07 12:25 . 2009-12-07 12:25 16384 c:\windows\temp\Perflib_Perfdata_6f0.dat
+ 2009-12-07 01:00 . 2009-12-07 01:00 21504 c:\windows\Installer\128bb7.msi
+ 2009-12-07 00:59 . 2009-12-07 00:59 27648 c:\windows\Installer\128bb2.msi
+ 2009-12-07 03:27 . 2009-12-07 03:27 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-12-07 03:27 . 2009-12-07 03:27 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-12-07 03:27 . 2009-12-07 03:27 145184 c:\windows\SYSTEM32\java.exe
+ 2009-12-07 03:27 . 2009-12-07 03:27 1757696 c:\windows\Installer\9a015f.msi
+ 2009-12-07 01:05 . 2009-12-07 01:05 3940352 c:\windows\Installer\128bbc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"P17Helper"="P17.dll" [2004-06-10 60928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-15 286720]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-07 149280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-26 811008]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2005\\QBDBMgrN.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Nic\\My Documents\\My Games\\Warcraft III\\Warcraft III.exe"=
R3 NaiFiltr;NaiFiltr;c:\windows\SYSTEM32\DRIVERS\NaiFiltr.sys [6/17/2005 12:50 AM 23296]
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.dell4me.com/myway
mSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: turbotax.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-07 07:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-07 07:44
ComboFix-quarantined-files.txt 2009-12-07 12:43
ComboFix2.txt 2009-12-06 21:43
ComboFix3.txt 2009-12-06 13:50
Pre-Run: 5,972,361,216 bytes free
Post-Run: 5,956,153,344 bytes free
- - End Of File - - 0547D9BBE48CB9CB16D7FED869E80EF5
MBAM log:
Malwarebytes' Anti-Malware 1.42
Database version: 3307
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
12/7/2009 8:54:27 AM
mbam-log-2
Scan type: Full Scan (C:\|)
Objects scanned: 203479
Time elapsed: 43 minute(s), 2 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\I386\GTDownDE_87.ocx.vir (Adware.Gdown) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\syssvc.exe.vir (Trojan.Downloader) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe.vir (Rogue.Installer) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\iehelper.dll.vir (Trojan.BHO) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\lsp.dll.vir (Trojan.Proxy) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098106.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098122.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098126.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1206\A0098182.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099793.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099878.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099880.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1211\A0099881.dll (Trojan.Proxy) -> No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1214\A0101354.ocx (Adware.Gdown) -> No action taken.
Now we'll follow the McAfee reinstallation instructions, located here.
Read through them first to make sure everything will be possible for you (make sure you have your licence key and access to a download, or something along those lines). Essentially, you will remove it from Add/Remove Programs, then run their product removal tool, then reinstall.
Let me know if you have any questions, otherwise proceed with that.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI