This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]ย at least 1 trojan

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

[attachment removed]๐Ÿ“ŽAttach.txt[attachment removed][attachment removed][attachment removed]I ran all my regular scans today and actually suspected they would turn something up since when i did google searches I started getting a second search called lucky results that was similar to the original - redirects always a big red flag. Spybot said Win32.KillAV-KQ and I had spybot fix it. Had several things come up on Malwarebytes and will post that log. I did have them fix everything that came up as well. I followed all instructions and did what I was supposed to prior to posting this. I was unable to do the GMER scan. It caused my computer torestart twice, freeze completely once, and the last time it again restarted. The last time it scanned for a long time but I couldn't find any saved log - and I didn't save anything (because when I came in the computer had restarted itself again) No problem with DDS, will post that log here too. I did a mcafee scan which turned up nothing and it scans automatically - I'm not sure that program is worth what I pay for it - I keep getting infected with things - this is the 3rd since march. Thanks in advance for help. It would be nice if spybot and malwarebytes fixed everything, but I know it can't be that easy. Malwarebytes' Anti-Malware 1.42 Database version: 3297 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/1/2010 4:19:44 PM mbam-log-2010-01-01 (16-19-35).txt Scan type: Quick Scan Objects scanned: 142847 Time elapsed: 12 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 2 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Program Files\Shared\lib.dll (Adware.Deepdive) -> No action taken. C:\WINDOWS\default32.dll (Trojan.Downloader) -> No action taken. Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{c568967b-cc3f-438d-9dba-0c4f20cff5c9} (Trojan.Downloader) -> No action taken. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\Shared\lib.dll (Adware.Deepdive) -> No action taken. C:\Program Files\Shared\lib.sig (Adware.Deepdive) -> No action taken. C:\WINDOWS\default32.dll (Trojan.Downloader) -> No action taken. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:27:15.67 on Fri 01/01/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1437 [GMT -6:00] AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Messenger\msmsgs.exe C:\Garmin\gStart.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\system32\HPZipm12.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Intel\IntelDH\Intelยฎ Quick Resume Technology Drivers\Elservice.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\HP\KBD\KBD.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\DISC\DISCover.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\DISC\DiscUpdMgr.exe C:\Program Files\DISC\DiscStreamHub.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [gStart] c:\garmin\gStart.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode mRun: [RTHDCPL] RTHDCPL.EXE mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe mRun: [DMAScheduler] "c:\program files\hp digitalmedia archive\DMAScheduler.exe" mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [] mRun: [PCDrProfiler] mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [Reminder] "c:\windows\creator\Remind_XP.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: Google Sidewikiโ€ฆ - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: trymedia.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-8 214664] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-8-28 93320] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-6-29 359952] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-6-29 144704] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-6-29 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-6-29 35272] S2 0076031261622494mcinstcleanup;McAfee Application Installer Cleanup (0076031261622494);c:\windows\temp\007603~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service โ€“> c:\windows\temp\007603~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-8-15 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-6-29 40552] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-6-29 606736] =============== Created Last 30 ================ 2009-12-28 13:53 โ€“dโ€”โ€“ c:\program files\Shared 2009-12-26 16:07 43,664 aโ€”hโ€” c:\windows\system32\mlfcache.dat 2009-12-26 09:12 107,368 aโ€”โ€”- c:\windows\system32\GEARAspi.dll 2009-12-26 09:12 26,600 aโ€”โ€”- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-12-26 09:12 โ€“dโ€”โ€“ c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-12-26 09:09 2,065,696 aโ€”โ€”- c:\windows\system32\usbaaplrc.dll 2009-12-26 09:09 40,448 aโ€”โ€”- c:\windows\system32\drivers\usbaapl.sys ==================== Find3M ==================== 2009-12-30 14:55 38,224 aโ€”โ€”- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-30 14:54 19,160 aโ€”โ€”- c:\windows\system32\drivers\mbam.sys 2009-10-28 08:40 173,056 โ€”โ€”โ€“ c:\windows\system32\dllcache\ie4uinit.exe 2009-10-20 23:38 75,776 aโ€”โ€”- c:\windows\system32\strmfilt.dll 2009-10-20 23:38 25,088 aโ€”โ€”- c:\windows\system32\httpapi.dll 2009-10-20 23:38 75,776 โ€”โ€”โ€“ c:\windows\system32\dllcache\strmfilt.dll 2009-10-20 23:38 25,088 โ€”โ€”โ€“ c:\windows\system32\dllcache\httpapi.dll 2009-10-20 10:20 265,728 โ€”โ€”โ€“ c:\windows\system32\dllcache\http.sys 2009-10-13 04:30 270,336 aโ€”โ€”- c:\windows\system32\oakley.dll 2009-10-13 04:30 270,336 โ€”โ€”โ€“ c:\windows\system32\dllcache\oakley.dll 2009-10-12 07:38 149,504 aโ€”โ€”- c:\windows\system32\rastls.dll 2009-10-12 07:38 149,504 โ€”โ€”โ€“ c:\windows\system32\dllcache\rastls.dll 2009-10-12 07:38 79,872 aโ€”โ€”- c:\windows\system32\raschap.dll 2009-10-12 07:38 79,872 โ€”โ€”โ€“ c:\windows\system32\dllcache\raschap.dll 2009-09-05 13:57 53,976 aโ€”โ€”- c:\docume~1\hp_adm~1.you\applic~1\GDIPFONTCACHEV1.DAT 2009-08-20 19:20 0 aโ€”โ€”- c:\documents and settings\hp_administrator.your-4dacd0ea75\settings.dat 2008-01-30 21:51 61,480 aโ€”โ€”- c:\documents and settings\hp_administrator.your-4dacd0ea75\GoToAssistDownloadHelper.exe 2009-08-20 21:07 32,768 aโ€“shโ€” c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009081020090817\index.dat 2009-08-20 21:07 32,768 aโ€“shโ€” c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082020090821\index.dat ============= FINISH: 20:28:00.51 ===============[attachment removed][attachment removed][attachme nt=6611:Attach.txt]
Hi Wilma1313, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



Your version of MBAM is quite a bit out of date. Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • MBAM log
  • new DDS.txt taken after the MBAM scan.
Thanks
I thought I was keeping up better with updates but looks like not so much. Here is the new scan with updated program. Happily clean. Malwarebytes' Anti-Malware 1.43 Database version: 3504 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/6/2010 8:05:52 PM mbam-log-2010-01-06 (20-05-52).txt Scan type: Quick Scan Objects scanned: 146714 Time elapsed: 14 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Sorry, tired from work and following directions poorly tonight. Here is the DDS txt scan. Thanks much for your help. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:20:57.87 on Wed 01/06/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1298 [GMT -6:00] AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Garmin\gStart.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\McAfee\MPF\MPFSrv.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Intel\IntelDH\Intelยฎ Quick Resume Technology Drivers\Elservice.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\HP\KBD\KBD.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\DISC\DISCover.exe C:\Program Files\DISC\DiscUpdMgr.exe C:\Program Files\DISC\DiscStreamHub.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\WINDOWS\system32\SNDVOL32.EXE C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [gStart] c:\garmin\gStart.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode mRun: [RTHDCPL] RTHDCPL.EXE mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe mRun: [DMAScheduler] "c:\program files\hp digitalmedia archive\DMAScheduler.exe" mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [] mRun: [PCDrProfiler] mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run mRun: [Reminder] "c:\windows\creator\Remind_XP.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: Google Sidewikiโ€ฆ - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: trymedia.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-8 214664] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-8-28 93320] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-6-29 359952] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-6-29 144704] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-6-29 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-6-29 35272] R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-8-15 34248] S2 0076031261622494mcinstcleanup;McAfee Application Installer Cleanup (0076031261622494);c:\windows\temp\007603~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service โ€“> c:\windows\temp\007603~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-6-29 40552] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-6-29 606736] =============== Created Last 30 ================ 2010-01-03 06:13 1,089,593 โ€”โ€”โ€“ c:\windows\system32\dllcache\ntprint.cat 2010-01-02 09:57 โ€“dโ€”โ€“ c:\windows\system32\XPSViewer 2010-01-02 09:56 โ€“dโ€”โ€“ C:\78a22e5d28aa0eb362 2010-01-02 09:56 1,676,288 โ€”โ€”โ€“ c:\windows\system32\xpssvcs.dll 2010-01-02 09:56 1,676,288 โ€”โ€”โ€“ c:\windows\system32\dllcache\xpssvcs.dll 2010-01-02 09:56 597,504 โ€”โ€”โ€“ c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-01-02 09:56 575,488 โ€”โ€”โ€“ c:\windows\system32\xpsshhdr.dll 2010-01-02 09:56 575,488 โ€”โ€”โ€“ c:\windows\system32\dllcache\xpsshhdr.dll 2010-01-02 09:56 117,760 โ€”โ€”โ€“ c:\windows\system32\prntvpt.dll 2010-01-02 09:56 89,088 โ€”โ€”โ€“ c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-01-01 21:21 โ€“dโ€”โ€“ c:\docume~1\alluse~1\applic~1\McAfee Security Scan 2010-01-01 21:21 โ€“dโ€”โ€“ c:\program files\McAfee Security Scan 2009-12-28 13:53 โ€“dโ€”โ€“ c:\program files\Shared 2009-12-26 16:07 43,664 aโ€”hโ€” c:\windows\system32\mlfcache.dat 2009-12-26 09:12 107,368 aโ€”โ€”- c:\windows\system32\GEARAspi.dll 2009-12-26 09:12 26,600 aโ€”โ€”- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-12-26 09:12 โ€“dโ€”โ€“ c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-12-26 09:09 2,065,696 aโ€”โ€”- c:\windows\system32\usbaaplrc.dll 2009-12-26 09:09 40,448 aโ€”โ€”- c:\windows\system32\drivers\usbaapl.sys ==================== Find3M ==================== 2009-12-30 14:55 38,224 aโ€”โ€”- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-30 14:54 19,160 aโ€”โ€”- c:\windows\system32\drivers\mbam.sys 2009-10-28 08:40 173,056 โ€”โ€”โ€“ c:\windows\system32\dllcache\ie4uinit.exe 2009-10-20 23:38 75,776 aโ€”โ€”- c:\windows\system32\strmfilt.dll 2009-10-20 23:38 25,088 aโ€”โ€”- c:\windows\system32\httpapi.dll 2009-10-20 23:38 75,776 โ€”โ€”โ€“ c:\windows\system32\dllcache\strmfilt.dll 2009-10-20 23:38 25,088 โ€”โ€”โ€“ c:\windows\system32\dllcache\httpapi.dll 2009-10-20 10:20 265,728 โ€”โ€”โ€“ c:\windows\system32\dllcache\http.sys 2009-10-13 04:30 270,336 aโ€”โ€”- c:\windows\system32\oakley.dll 2009-10-13 04:30 270,336 โ€”โ€”โ€“ c:\windows\system32\dllcache\oakley.dll 2009-10-12 07:38 149,504 aโ€”โ€”- c:\windows\system32\rastls.dll 2009-10-12 07:38 149,504 โ€”โ€”โ€“ c:\windows\system32\dllcache\rastls.dll 2009-10-12 07:38 79,872 aโ€”โ€”- c:\windows\system32\raschap.dll 2009-10-12 07:38 79,872 โ€”โ€”โ€“ c:\windows\system32\dllcache\raschap.dll 2009-10-11 04:17 411,368 aโ€”โ€”- c:\windows\system32\deploytk.dll 2009-09-05 13:57 53,976 aโ€”โ€”- c:\docume~1\hp_adm~1.you\applic~1\GDIPFONTCACHEV1.DAT 2009-08-20 19:20 0 aโ€”โ€”- c:\documents and settings\hp_administrator.your-4dacd0ea75\settings.dat 2008-01-30 21:51 61,480 aโ€”โ€”- c:\documents and settings\hp_administrator.your-4dacd0ea75\GoToAssistDownloadHelper.exe 2009-08-20 21:07 32,768 aโ€“shโ€” c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009081020090817\index.dat 2009-08-20 21:07 32,768 aโ€“shโ€” c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082020090821\index.dat ============= FINISH: 20:21:18.81 ===============
All the problems are improved since I did the scans. The last thing I had going on was gmer causing the computer to restart when I tried to run it and since that nothing unusual has happened and its running normal. Maybe what I had was easy to get rid of?
Hi Wilma1313,

I don't see anything in the logs, perhaps you just picked up a litttle something and caught it before it blossomed.

When you ran GMER were these the settings you used?

  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
  • Sections
  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically C:\)
  • Show All (don't miss this one)

Was your antvirus program disabled?
Yes, I had even compared the little picture on directions to what I had checked and unchecked on GMER and did disable all my antivirus stuff. Was thinking I would try it again one more time but figured I would wait and see if you actually want me to.
Hi wilma1313, Are you experiencing any problems with the computer? Any indications that you may be infected, like slowness, browser/search redirects? You could trying running it again if you wish, just for your peace of mind. Running it in safe mode may work a little better. Thanks
Hi, The computer is running great with no signs/symptoms of infection. I still can't get GMER to work. It restarted immediately the first try and in safemode I thought it would work. It was so slow though. 7 hours later still scanning. Then I went to bed, when I got up it had shut the computer down, so no log or anything.. Quite disappointed to say the least. I'm gone for the weekend but will check for response Sunday when get home. Thanks so much, Lori
Hi wilma1313,

We can try a couple of diferent things to see if we can get GMER to run if you wish.

Delete the copy of GMER you now have including the zip if that is how you downloaded it.

Go HERE to get a new copy. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scanโ€ฆclick on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following โ€ฆ
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<โ€” ROOKIT" entries


If GMER still will not run, uncheck the following items also, Registry and Files and try again.

Thanks
I shall do this tonight or tomorrow night once I get settled back in and have a block of time I dont' want to use the computer. When I turned it on today after returning I had a box that said a registry file that was removed was restored. Makes me a bit nervous, no further info or options, just the message box.
Hi wilma1313,


When I turned it on today after returning I had a box that said a registry file that was removed was restored.

That is strange. Was that the exact message?

Go ahead with the GMER when you get a chance.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI