This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware Defense removal help

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

got Malware Defense virus on desktop. followed directions for manual removal at: www.2-spyware.com/remove-malware-defense.html but that didn't get rid of it mbam will download, but not run in safe mode, even if renamed did AFT cleaner, could not access/download/run SysRestorePoint, ERUNT, or GMER , not could I disable McAfee, though it seems the virus is doing a great job with that part already. (I tried all this in safe mode because computer freezes quickly if booted normally) DDS (Ver_09-06-26.01) - NTFSx86 NETWORK Run by [removed] at 13:49:01.82 on Mon 01/25/2010 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_03 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1718 [GMT -7:00] AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9} AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Administrator\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uInternet Connection Wizard,ShellNext = hxxp://www.dozentop.com/ac.php?aid=216&sid;=new BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll uRun: [A_M_P_NET] c:\program files\antimalware_pro\AntiMalware_Pro.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SoundMan] SOUNDMAN.EXE mRun: [WinFast Schedule] c:\program files\winfast\wftvfm\WFWIZ.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [D-Link RangeBooster G WDA-2320] c:\program files\d-link\rangebooster g wda-2320\AirPlusCFG.exe mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\policy~1.lnk - c:\program files\impulse\PolicyKey.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{14fcfe7c-ab86-428a-9d2e-bfb6f5a7aa6e}\Icon3E5562ED7.ico IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\npjpi160_03.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\nkuv76o6.default\ FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll FF - plugin: c:\documents and settings\alisa\application data\move networks\plugins\npqmp071505000011.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-1-18 207792] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2009-8-13 547744] R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2009-8-15 57376] S1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-2-27 214664] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-20 135664] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-2-27 93320] S2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-2-27 359952] S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-2-27 144704] S2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;c:\windows\system32\drivers\wf88vcap.sys [2005-7-2 208851] S2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;c:\windows\system32\drivers\WF88XBAR.sys [2005-7-2 10324] S2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;c:\windows\system32\drivers\wf88tune.sys [2005-7-2 34789] S3 AC2003;AC2003;c:\windows\system32\drivers\AC2003.sys [2005-6-15 4224] S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\d-link\rangebooster g wda-2320\jswutil\jswpsapi.exe [2009-8-15 352338] S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-2-27 606736] S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-2-27 79816] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-2-27 35272] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-2-27 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-2-27 40552] S3 WFIOCTL;WFIOCTL;c:\program files\winfast\wftvfm\WFIOCTL.sys [2005-7-2 9446] =============== Created Last 30 ================ 2010-01-25 13:37 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-25 13:37 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-01-25 13:37 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-01-25 13:37 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-01-18 18:15 –d—– c:\documents and settings\all users\AVP 2009 2010-01-18 02:11 233,136 a——- c:\windows\system32\drivers\pctgntdi.sys 2010-01-18 02:11 7,387 a——- c:\windows\system32\drivers\pctgntdi.cat 2010-01-18 02:11 207,792 a——- c:\windows\system32\drivers\PCTCore.sys 2010-01-18 02:11 87,784 a——- c:\windows\system32\drivers\PCTAppEvent.sys 2010-01-18 02:11 7,412 a——- c:\windows\system32\drivers\PCTAppEvent.cat 2010-01-18 02:11 7,383 a——- c:\windows\system32\drivers\pctcore.cat 2010-01-18 02:11 70,408 a——- c:\windows\system32\drivers\pctplsg.sys 2010-01-18 02:11 7,383 a——- c:\windows\system32\drivers\pctplsg.cat 2010-01-18 02:11 –d—– c:\program files\Spyware Doctor 2010-01-18 02:11 –d—– c:\docume~1\alluse~1\applic~1\PC Tools 2010-01-18 01:38 –d—– c:\program files\common files\PC Tools 2010-01-18 01:20 –d—– c:\documents and settings\Administrator 2010-01-18 01:08 8,212 a——- c:\windows\mfebcdata 2010-01-13 10:18 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll ==================== Find3M ==================== 2009-11-21 08:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2009-10-28 22:38 667,136 a——- c:\windows\system32\wininet.dll 2009-02-27 15:45 1,230,368 a——- c:\program files\DMSetup.exe 2009-02-27 15:40 608,344 a——- c:\program files\MCPR.exe 2009-02-19 17:49 21,878,064 a——- c:\program files\QuickTimeInstaller.exe 2008-05-27 06:49 904,912 a——- c:\program files\Google Updater.exe 2007-11-28 16:42 1,164,456 a——- c:\program files\install_flash_player.exe 2007-11-19 14:45 10,746,636 a——- c:\program files\UAvpn-5.0.01.0600-2K-XP-Vista.exe 2007-08-12 23:02 778,192 a——- c:\program files\WallpaperMasterV2.16.exe ============= FINISH: 13:49:37.90 ===============

Attachments:

Hello there, azbsn

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hi,

Please have your computer boot into Safe Mode and download the following :

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
exeHelper by Raktor Build 20091220 Run at 12:23:31 on 01/27/10 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
Ok, so I rebooted in normal mode and double clicked on MBAM. Nothing happened, but eventually a Program Not Responding box popped up and the computer froze. I tried it in safe mode, but again, nothing happened when I clicked on MBAM…
Hi,

Download Combofix from any of the links below but rename it to ConspireCF before saving it to your desktop.

Link 1
Link 2


==================================

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

===================================================

On your next reply please post :
ComboFix log

Good Day!
Never mind, I was able to find it. I downloaded and renamed it, but it is giving me a warning since my McAfee Virus scan is still enabled. I cannot open McAfee to disable that, though. Should I still run ComboFix?
If you can open task manager by pressing Alt+Ctrl+Del, try to end process that is running the McAfee. Otherwise, just carry on with ComboFix. Thanks.
ComboFix 10-01-29.02 - Alisa 01/30/2010 12:50:12.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1635 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ConspireCF.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active

.
PEV Error: ProgramsFolder

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\h8srtkrl32mainweq.dll
c:\documents and settings\All Users\Application Data\h8srtmainqt.dll
c:\documents and settings\All Users\Start Menu\Programs\Startup\PolicyKey.lnk
c:\windows\system32\drivers\H8SRTodovtvvctn.sys
c:\windows\system32\H8SRTbotxjypbid.dll
c:\windows\system32\H8SRTcrrruxbqji.dll
c:\windows\system32\H8SRTijegwlqrxv.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\H8SRTmlhbmcuxht.dat
c:\windows\system32\H8SRTorgcljkopq.dll
c:\windows\system32\h8srtshsyst.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys


((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-29 20:17 . 2010-01-29 20:17 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2010-01-29 18:50 . 2010-01-29 18:50 ——– d—–w- C:\ConspireCF
2010-01-28 16:41 . 2009-08-07 02:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-01-28 16:41 . 2009-08-07 02:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-01-27 19:23 . 2010-01-27 19:23 ——– d-s—w- c:\documents and settings\Administrator\UserData
2010-01-25 20:37 . 2010-01-07 23:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-25 20:37 . 2010-01-25 20:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-25 20:37 . 2010-01-25 20:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-25 20:37 . 2010-01-07 23:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-19 01:15 . 2010-01-19 01:24 ——– d—–w- c:\documents and settings\All Users\AVP 2009
2010-01-18 09:11 . 2009-10-30 18:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-01-18 09:11 . 2009-11-09 18:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-01-18 09:11 . 2009-10-06 23:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-01-18 09:11 . 2009-09-03 16:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-01-18 09:11 . 2010-01-18 09:12 ——– d—–w- c:\program files\Spyware Doctor
2010-01-18 09:11 . 2010-01-18 09:11 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-18 09:11 . 2010-01-18 09:11 ——– d—–w- c:\documents and settings\Alisa\Application Data\PC Tools
2010-01-18 08:38 . 2010-01-18 09:07 ——– d—–w- c:\program files\Common Files\PC Tools
2010-01-18 08:38 . 2010-01-19 00:59 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-18 08:24 . 2010-01-18 08:24 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-01-15 06:02 . 2010-01-15 06:02 144160 —-a-w- c:\documents and settings\Alisa\Application Data\Move Networks\uninstall.exe
2010-01-15 06:02 . 2010-01-15 06:02 1438976 —-a-w- c:\documents and settings\Alisa\Application Data\Move Networks\MoveMediaPlayerWin_071505000011.exe
2010-01-13 17:18 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 19:48 . 2008-05-27 13:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-19 00:43 . 2006-08-18 01:23 ——– d—–w- c:\program files\Impulse
2010-01-15 17:21 . 2008-01-14 02:19 ——– d—–w- c:\documents and settings\Alisa\Application Data\Move Networks
2010-01-15 06:02 . 2009-12-10 19:26 4187512 —-a-w- c:\documents and settings\Alisa\Application Data\Move Networks\plugins\npqmp071505000011.dll
2009-12-26 02:13 . 2005-12-15 17:08 ——– d—–w- c:\program files\Google
2009-12-20 22:52 . 2009-02-27 22:53 ——– d—–w- c:\program files\McAfee
2009-12-10 19:27 . 2009-12-10 19:27 97144 —-a-w- c:\documents and settings\Alisa\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-11-21 15:51 . 2004-08-04 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-02-27 22:45 . 2007-07-26 16:46 1230368 —-a-w- c:\program files\DMSetup.exe
2009-02-27 22:40 . 2009-02-27 22:40 608344 —-a-w- c:\program files\MCPR.exe
2009-02-20 00:49 . 2009-02-20 00:49 21878064 —-a-w- c:\program files\QuickTimeInstaller.exe
2008-05-27 13:49 . 2008-05-27 13:50 904912 —-a-w- c:\program files\Google Updater.exe
2007-11-28 23:42 . 2007-11-28 23:42 1164456 —-a-w- c:\program files\install_flash_player.exe
2007-11-19 21:45 . 2007-11-19 21:44 10746636 —-a-w- c:\program files\UAvpn-5.0.01.0600-2K-XP-Vista.exe
2007-08-13 06:02 . 2007-08-13 06:03 778192 —-a-w- c:\program files\WallpaperMasterV2.16.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe" [2005-02-01 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2001-12-31 3756032]
"nwiz"="nwiz.exe" [2001-12-31 831488]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2001-12-31 46080]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 67072]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2005-03-02 278528]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-02 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"D-Link RangeBooster G WDA-2320"="c:\program files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe" [2007-08-29 1662976]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2007-11-19 6144]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\ElectricSheep.scr"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/18/2010 2:11 AM 207792]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2/27/2009 3:56 PM 93320]
R2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;c:\windows\system32\drivers\wf88vcap.sys [7/2/2005 11:42 AM 208851]
R2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;c:\windows\system32\drivers\WF88XBAR.sys [7/2/2005 11:51 AM 10324]
R2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;c:\windows\system32\drivers\wf88tune.sys [7/2/2005 11:42 AM 34789]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [8/13/2009 8:59 PM 547744]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [8/15/2009 11:58 AM 57376]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [7/2/2005 11:47 AM 9446]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 5:06 PM 135664]
S3 AC2003;AC2003;c:\windows\system32\drivers\AC2003.sys [6/15/2005 8:25 PM 4224]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\RangeBooster G WDA-2320\JSWUtil\jswpsapi.exe [8/15/2009 11:58 AM 352338]
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-27 03:15]

2010-01-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 00:06]

2010-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 00:06]

2009-02-27 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-27 19:22]

2009-02-27 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-27 19:22]

2007-07-14 c:\windows\Tasks\{42787FB4-0F57-4722-B226-366116892383}_SUNRAY_Alisa.job
- c:\windows\system32\mobsync.exe [2004-08-04 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.windowsupdate.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Alisa\Application Data\Mozilla\Firefox\Profiles\49e9b5m0.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Alisa\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
AddRemove-Malware Defense - c:\program files\Malware Defense\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-30 12:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3480)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\University of Arizona Software\U of A VPN Client\cvpnd.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\SOUNDMAN.EXE
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2010-01-30 13:03:40 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-30 20:03

Pre-Run: 48,330,485,760 bytes free
Post-Run: 48,297,598,976 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - C46456EFE2688BBCF0EB015B97C2F9A8
Hi,

Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
===================================================

On your next reply please post :
How is she running? Can you get MBAM start?
ESET log

Good Day!
ESET log: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=e397167035545d4dbdb2ffbfe161ba17 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-01-31 04:33:00 # local_time=2010-01-31 09:33:00 (-0700, US Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=5121 16776533 100 96 6028410 17787195 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=19738 # found=1 # cleaned=0 # scan_time=1511 C:\Documents and Settings\Administrator\My Documents\Downloads\anti-malware-application.exe a variant of Win32/Adware.RegistryDoktor application 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=e397167035545d4dbdb2ffbfe161ba17 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-02-02 12:42:56 # local_time=2010-02-01 05:42:56 (-0700, US Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=5121 16776533 100 96 6141942 17900727 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=57201 # found=1 # cleaned=0 # scan_time=3775 C:\Documents and Settings\Administrator\My Documents\Downloads\anti-malware-application.exe a variant of Win32/Adware.RegistryDoktor application 00000000000000000000000000000000 I The computer seems to be running fine. No more pop ups. I still cannot run MBAM. When I click on it, it gives me a "Run-Time Error 0" and "Run-Time Error 440: Automation Error"
Hi,

If you are having any problems with Malwarebytes' Anti-Malware protection please do the following.
  • Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel.
  • Restart your computer (very important).
  • Download and run this utility.
  • It will ask to restart your computer (please allow it to).
  • After the computer restarts, install the latest version from here.
===================================================

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Files
C:\Documents and Settings\Administrator\My Documents\Downloads\anti-malware-application.exe

:Commands
[purity]
[emptytemp]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


===================================================

On your next reply please post :
Can you run MBAM now?
OTM log

Good Day!
All processes killed ========== FILES ========== File/Folder C:\Documents and Settings\Administrator\My Documents\Downloads\anti-malware-application.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes ->FireFox cache emptied: 32325950 bytes User: Alisa ->Temp folder emptied: 2045 bytes ->Temporary Internet Files folder emptied: 4096781 bytes ->Java cache emptied: 29769784 bytes ->FireFox cache emptied: 57906662 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32969 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2162283 bytes %systemroot%\System32 .tmp files removed: 1162769 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1065732 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 123.00 mb OTM by OldTimer - Version 3.1.7.1 log created on 02022010_125732 Files moved on Reboot… Registry entries deleted on Reboot… I got MBAM to run. Here is the log from that: Malwarebytes' Anti-Malware 1.44 Database version: 3680 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 2/2/2010 12:49:59 PM mbam-log-2010-02-02 (12-49-59).txt Scan type: Quick Scan Objects scanned: 116294 Time elapsed: 6 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\AVP 2009 (Malware.Trace) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Administrator\My Documents\downloads\anti-malware-application.exe (Rogue.Installer) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\AVP 2009\1.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\sysReserve.ini (Malware.Trace) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI