This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Strange shutdowns

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have Strange shutdowns at random. I get the following messages: To help protect your computer, Windows has closed this program. Name: Generic Host Process for Win32 Services Publisher: Microsoft Corporation and this is a partial message NT AUTHORITY/SYSTEM DCOM SERVICE PROCESS LAUNCHER TERMINATED UNEXSPECTEDLY I ran ATF CLEANER I ran SYSTEM RESTORE I ran ERUNT I ran MALWAREBYTES WITH THE FOLLOWING LOG: Malwarebytes' Anti-Malware 1.44 Database version: 3647 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/27/2010 6:46:06 PM mbam-log-2010-01-27 (18-46-06).txt Scan type: Quick Scan Objects scanned: 115640 Time elapsed: 6 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) I tried to run GMER 6 times but machine would shutdown and reboot before it finished so no log at this time. I ran DDS and here are both logs: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:53:04.28 on Wed 01/27/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1436 [GMT -5:00] AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\McAfee.com\Agent\mcagent.exe C:\WINDOWS\System32\drivers\PhiBtn.exe C:\WINDOWS\System32\drivers\Tray900.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Secunia\PSI\psi.exe svchost.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\MAC\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode mRun: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [PhiBtn] %SystemRoot%\System32\drivers\PhiBtn.exe mRun: [Traymin900] %SystemRoot%\System32\drivers\Tray900.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u StartupFolder: c:\docume~1\mac\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi.exe IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Trusted Zone: intuit.com\ttlc Trusted Zone: turbotax.com DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195341152156 DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://acs.pandasoftware.com/activescan/as5free/asinst.cab DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mac\applic~1\mozilla\firefox\profiles\bmupye1q.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p= FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL FF - plugin: c:\program files\mozilla firefox\plugins\NPcol308.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-4-6 214664] R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2009-9-29 13088] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-7-30 359952] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2007-4-6 144704] R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2009-9-23 935208] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] R3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [2008-4-9 1240576] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-4-6 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-4-6 35272] R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys –> c:\windows\system32\drivers\viasraid.sys [?] S3 cpuz130;cpuz130;\??\c:\docume~1\mac\locals~1\temp\cpuz130\cpuz_x32.sys –> c:\docume~1\mac\locals~1\temp\cpuz130\cpuz_x32.sys [?] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-4-6 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-4-6 40552] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2007-4-6 606736] =============== Created Last 30 ================ 2010-01-24 06:48 –d—– C:\VundoFix Backups 2010-01-22 13:57 664 a——- c:\windows\system32\d3d9caps.dat 2010-01-21 15:41 69 a——- c:\windows\NeroDigital.ini 2010-01-18 17:05 –d—– c:\program files\Nero 2010-01-18 13:14 –d—– c:\program files\Secunia 2010-01-18 12:57 –d—– c:\program files\SpywareBlaster 2010-01-18 12:46 181,120 ——– c:\windows\system32\MpSigStub.exe 2010-01-18 12:31 –ds—- C:\jgh30039j 2010-01-13 13:51 –d—– c:\windows\system32\appmgmt 2010-01-13 13:01 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll 2010-01-12 09:31 –d—– C:\jgh 2010-01-02 17:27 1,414,440 a——- c:\windows\system32\ShellManager310E2D762.dll 2010-01-02 17:27 773,120 a——- c:\windows\system32\NEROINSTAEC43759.DB 2010-01-02 16:06 –d—– c:\docume~1\mac\applic~1\InfraRecorder 2010-01-02 16:05 –d—– c:\program files\InfraRecorder 2010-01-01 20:37 4,767 a——- c:\windows\Irremote.ini 2010-01-01 17:50 –d—– c:\docume~1\alluse~1\applic~1\Nero 2010-01-01 17:31 3,077,416 a——- c:\windows\system32\AdvrCntr2D6E0B790.dll ==================== Find3M ==================== 2010-01-27 16:13 96,512 a——- c:\windows\system32\drivers\atapi.sys 2010-01-07 16:07 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 16:07 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll 2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2009-11-03 11:33 6 a——- c:\windows\fonts\wfonts.key 2008-07-18 21:48 11,114 a——- c:\docume~1\alluse~1\applic~1\MainApp.dll 2007-07-06 20:26 47,360 a——- c:\docume~1\mac\applic~1\pcouffin.sys 2007-04-10 10:40 94,080 a——- c:\docume~1\mac\applic~1\ezplay.sys 2007-04-10 10:40 81,920 a——- c:\docume~1\mac\applic~1\ezpinst.exe ============= FINISH: 20:55:50.85 =============== and UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume3 Install Date: 4/5/2007 6:33:13 PM System Uptime: 1/27/2010 8:50:05 PM (0 hours ago) Motherboard: ASUSTeK Computer Inc. | | A8V Deluxe Processor: AMD Athlon™ 64 X2 Dual Core Processor 4400+ | Socket 939 | 2202/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 112 GiB total, 65.577 GiB free. D: is CDROM () E: is FIXED (NTFS) - 149 GiB total, 65.538 GiB free. F: is FIXED (NTFS) - 298 GiB total, 80.737 GiB free. G: is CDROM () H: is Removable I: is Removable J: is Removable K: is Removable L: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP141: 10/30/2009 5:42:59 PM - System Checkpoint RP142: 10/31/2009 2:14:53 PM - Installed Treasures of the Far East RP143: 10/31/2009 2:33:38 PM - Installed DirectX RP144: 10/31/2009 2:52:23 PM - Installed Treasures of the Far East RP145: 10/31/2009 3:03:10 PM - Before uninstall Treasures of the Far East RP146: 10/31/2009 3:03:33 PM - Removed Treasures of the Far East RP147: 11/1/2009 3:57:27 PM - Installed Treasures of the Far East RP148: 11/1/2009 5:34:52 PM - Installed DirectX RP149: 11/2/2009 6:19:46 PM - System Checkpoint RP150: 11/3/2009 6:37:26 PM - System Checkpoint RP151: 11/4/2009 3:22:05 PM - Software Distribution Service 3.0 RP152: 11/5/2009 8:35:22 PM - System Checkpoint RP153: 11/6/2009 9:26:37 PM - System Checkpoint RP154: 11/7/2009 9:44:11 PM - System Checkpoint RP155: 11/9/2009 9:06:39 AM - System Checkpoint RP156: 11/10/2009 1:36:14 PM - System Checkpoint RP157: 11/11/2009 11:54:23 AM - Software Distribution Service 3.0 RP158: 11/12/2009 1:01:15 PM - System Checkpoint RP159: 11/13/2009 6:01:03 PM - System Checkpoint RP160: 11/15/2009 11:06:01 AM - System Checkpoint RP161: 11/16/2009 11:11:41 AM - System Checkpoint RP162: 11/17/2009 4:16:41 PM - System Checkpoint RP163: 11/17/2009 6:40:54 PM - Removed Nero 7 Ultra Edition RP164: 11/17/2009 6:48:21 PM - Installed Nero 7 Ultra Edition RP165: 11/18/2009 6:21:33 PM - Installed Java™ 6 Update 17 RP166: 11/20/2009 5:45:37 PM - Before uninstall CyberDefender Registry Cleaner RP167: 11/21/2009 7:12:40 PM - System Checkpoint RP168: 11/22/2009 8:17:39 PM - System Checkpoint RP169: 11/25/2009 12:27:24 PM - Software Distribution Service 3.0 RP170: 11/25/2009 7:42:37 PM - Before uninstall Ad-Aware RP171: 11/27/2009 11:58:14 AM - System Checkpoint RP172: 11/28/2009 5:19:00 PM - System Checkpoint RP173: 11/30/2009 7:42:30 AM - System Checkpoint RP174: 12/1/2009 2:10:53 PM - System Checkpoint RP175: 12/1/2009 4:58:14 PM - Installed QuickTime RP176: 12/1/2009 7:57:57 PM - Installed TurboTax 2009 wrapper RP177: 12/1/2009 7:58:15 PM - Installed TurboTax 2009 WinPerReleaseEngine RP178: 12/1/2009 7:59:41 PM - Installed TurboTax 2009 WinPerFedFormset RP179: 12/1/2009 8:00:51 PM - Installed TurboTax 2009 WinPerTaxSupport RP180: 12/3/2009 12:42:29 PM - System Checkpoint RP181: 12/5/2009 11:04:33 AM - System Checkpoint RP182: 12/6/2009 11:31:06 AM - System Checkpoint RP183: 12/6/2009 6:10:14 PM - Before uninstall Malwarebytes' Anti-Malware RP184: 12/7/2009 6:33:17 PM - last good RP185: 12/9/2009 4:46:14 PM - System Checkpoint RP186: 12/10/2009 7:34:20 AM - Software Distribution Service 3.0 RP187: 12/11/2009 5:51:00 PM - System Checkpoint RP188: 12/13/2009 11:09:24 AM - System Checkpoint RP189: 12/20/2009 12:41:39 PM - System Checkpoint RP190: 12/23/2009 9:47:03 AM - System Checkpoint RP191: 12/24/2009 10:57:52 AM - System Checkpoint RP192: 12/25/2009 2:08:43 PM - System Checkpoint RP193: 12/27/2009 3:54:05 PM - System Checkpoint RP194: 12/29/2009 3:41:47 PM - System Checkpoint RP195: 12/30/2009 3:56:23 PM - System Checkpoint RP196: 12/31/2009 5:12:38 PM - System Checkpoint RP197: 1/1/2010 5:20:43 PM - Before uninstall Nero 7 Ultra Edition RP198: 1/1/2010 5:31:48 PM - Removed Nero 7 Ultra Edition RP199: 1/1/2010 5:49:43 PM - Installed Nero 9 Trial 2.0.0.1 RP200: 1/1/2010 8:13:04 PM - Installed Nero 9 Trial 2.0.0.1 RP201: 1/2/2010 6:44:56 AM - Before uninstall Nero 9 Trial RP202: 1/2/2010 6:46:59 AM - Removed Nero 9 Trial 2.0.0.1 RP203: 1/2/2010 11:42:27 AM - Installed Nero 8 RP204: 1/2/2010 12:58:02 PM - Before uninstall Nero 8 RP205: 1/2/2010 1:17:47 PM - Installed Nero 7 Ultra Edition RP206: 1/2/2010 2:05:58 PM - Before uninstall Nero 7 Ultra Edition RP207: 1/2/2010 2:16:55 PM - Removed Nero 7 Ultra Edition RP208: 1/2/2010 4:23:16 PM - Installed Nero 8 RP209: 1/2/2010 5:23:38 PM - Removed Nero 8 RP210: 1/2/2010 6:24:46 PM - Installed Nero 8. Available with Windows Installer version 1.2 and later. RP211: 1/2/2010 9:08:03 PM - Before uninstall Nero 8 RP212: 1/2/2010 9:19:21 PM - Removed Nero 8. Available with Windows Installer version 1.2 and later. RP213: 1/5/2010 3:04:11 PM - System Checkpoint RP214: 1/6/2010 5:05:04 PM - System Checkpoint RP215: 1/8/2010 5:46:24 PM - System Checkpoint RP216: 1/11/2010 10:43:58 AM - System Checkpoint RP217: 1/12/2010 11:15:26 AM - System Checkpoint RP218: 1/13/2010 1:05:52 PM - Software Distribution Service 3.0 RP219: 1/13/2010 1:51:14 PM - Removed Java™ SE Runtime Environment 6 Update 1 RP220: 1/13/2010 1:51:54 PM - Removed Java™ 6 Update 2 RP221: 1/13/2010 1:52:22 PM - Removed Java™ 6 Update 3 RP222: 1/13/2010 1:52:49 PM - Removed Java™ 6 Update 5 RP223: 1/13/2010 1:53:18 PM - Removed Java™ 6 Update 7 RP224: 1/17/2010 5:03:15 AM - System Checkpoint RP225: 1/18/2010 12:32:18 PM - Before uninstall Ad-Aware RP226: 1/18/2010 12:45:54 PM - Installed Windows Defender RP227: 1/18/2010 12:46:45 PM - Software Distribution Service 3.0 RP228: 1/18/2010 5:04:49 PM - Installed Nero 9 4.4.9.0 RP229: 1/20/2010 2:30:46 PM - System Checkpoint RP230: 1/21/2010 4:46:40 PM - System Checkpoint RP231: 1/22/2010 1:38:02 AM - Software Distribution Service 3.0 RP232: 1/22/2010 11:45:09 AM - Software Distribution Service 3.0 RP233: 1/23/2010 3:05:03 PM - Before uninstall WinRAR archiver RP234: 1/24/2010 4:03:45 PM - System Checkpoint RP235: 1/26/2010 3:00:50 PM - System Checkpoint RP236: 1/27/2010 2:14:53 PM - Software Distribution Service 3.0 RP237: 1/27/2010 6:28:50 PM - Automatic Restore Point ==== Installed Programs ====================== Adobe Acrobat 7.0 Professional Adobe Acrobat 7.1.0 Professional Adobe Flash Player 10 Plugin Advertising Center AnswerWorks 4.0 Runtime - English AnswerWorks 5.0 English Runtime Apple Application Support Apple Software Update ASUS Probe V2.23.03 Aussie Slots 4.05 Best of Slots II Blackbeard's Revenge BlindWrite 6.0.0.18 BonusManiaInstaller Canon CanoScan Toolbox 4.1 Canon Easy-WebPrint EX Canon Inkjet Printer/Scanner/Fax Extended Survey Program Canon iP4700 series Printer Driver Canon iP4700 series User Registration Canon PhotoRecord Canon PIXMA iP3000 Canon Utilities Easy-PhotoPrint Canon Utilities Easy-PhotoPrint EX Canon Utilities My Printer Canon Utilities Solution Menu CloneCD CloneDVD [removed] ConvertXtoDVD 2.2.3.258 Coupon Printer for Windows Critical Update for Windows Media Player 11 (KB959772) Data Lifeguard Tools DolbyFiles DVDFab Platinum 3.0.4.0 Ghosthunter release Easy-WebPrint ERUNT 1.1j FlashFXP v3 FlashGet 1.9.0.1012 FlashGet(JetCar) Futuremark SystemInfo Ghost Town GoldRush Google Earth Pro Hijackthis 1.99.1 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) ImagXpress InfraRecorder IrfanView (remove only) Java™ 6 Update 17 Malwarebytes' Anti-Malware Masque IGT Slots Little Green Men Masque IGT Slots Texas Tea McAfee SecurityCenter Menu Templates - Starter Kit Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money Shared Libraries Microsoft National Language Support Downlevel APIs Microsoft Office 2000 SR-1 Premium Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Movie Templates - Starter Kit Mozilla Firefox (3.5.7) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MysticForest Nero 9 Nero Burning ROM Help Nero BurnRights Nero ControlCenter Nero CoverDesigner Nero DiscSpeed Nero DriveSpeed Nero InfoTool Nero Installer Nero PhotoSnap Nero Recode Nero Rescue Agent Nero ShowTime Nero StartSmart Nero Vision Nero WaveEditor NeroBurningROM NeroExpress neroxml NVIDIA Drivers OGA Notifier 2.0.0048.0 Panda ActiveScan Philips SPC 900NC PC Camera Philips VLounge QuickTime RealPlayer Realtek AC'97 Audio Reel Deal Slots 2nd Volume Reel Deal Slots Adventure Rhapsody Player Engine Secunia PSI Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB973704) Security Update for Microsoft Office Excel 2007 (KB973593) Security Update for Microsoft Office Outlook 2007 (KB972363) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) SoundTrax Spybot - Search & Destroy SpywareBlaster 4.2 Super Internet TV v7.11 SuperAVConverter V8.6 Build 5330 Treasures of the Far East TurboTax 2008 TurboTax 2008 WinPerFedFormset TurboTax 2008 WinPerProgramHelp TurboTax 2008 WinPerReleaseEngine TurboTax 2008 WinPerTaxSupport TurboTax 2008 WinPerUserEducation TurboTax 2008 wrapper TurboTax 2009 TurboTax 2009 WinPerFedFormset TurboTax 2009 WinPerReleaseEngine TurboTax 2009 WinPerTaxSupport TurboTax 2009 wrapper Ulead PhotoImpact 11 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office InfoPath 2007 (KB976416) Update for Outlook 2007 Junk Email Filter (kb977839) Update for Windows Internet Explorer 8 (KB971930) Update for Windows Internet Explorer 8 (KB976749) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Vegas 7007 Slots 1.0 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WAV MP3 Converter 3.8 build 968 WebFldrs XP Windows Defender Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Software Update Yahoo! Toolbar Your Uninstaller! 2008 Version 6.0 ==== Event Viewer Messages From Past Week ======== 1/22/2010 5:33:02 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd 1/22/2010 5:32:43 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 1/22/2010 5:32:43 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. 1/22/2010 12:00:27 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: fasttx2k gagp30kx Lbd 1/22/2010 1:57:32 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s). 1/22/2010 1:57:32 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine. ==== End Of File =========================== Will wait for your next set of things to do. This has been a bad day. PS: I almost forget, I also get an ocasional tab open with different web sites and when using yahoo or google search just clicking on the link sometimes takes me to different sites.
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
As requested

ComboFix 10-01-29.09 - MAC 01/30/2010 10:06:49.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1460 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-24 11:48 . 2010-01-24 11:48 ——– d—–w- C:\VundoFix Backups
2010-01-23 01:21 . 2010-01-23 20:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-01-22 18:57 . 2010-01-26 18:14 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-21 20:48 . 2010-01-21 20:48 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\AdobeUM
2010-01-21 20:41 . 2010-01-21 20:41 ——– d—–w- c:\documents and settings\MAC\Local Settings\Application Data\Nero
2010-01-18 22:05 . 2010-01-18 22:50 ——– d—–w- c:\program files\Nero
2010-01-18 18:14 . 2010-01-18 18:14 ——– d—–w- c:\program files\Secunia
2010-01-18 17:57 . 2010-01-27 19:11 ——– d—–w- c:\program files\SpywareBlaster
2010-01-18 17:46 . 2010-01-14 16:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-18 17:45 . 2010-01-18 17:45 ——– d—–w- c:\program files\Windows Defender
2010-01-18 17:31 . 2010-01-18 17:31 ——– d—–w- C:\jgh30039j
2010-01-13 18:01 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 14:31 . 2010-01-12 14:33 ——– d—–w- C:\jgh
2010-01-03 10:58 . 2010-01-22 16:43 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-02 22:27 . 2008-06-24 18:45 1414440 —-a-w- c:\windows\system32\ShellManager310E2D762.dll
2010-01-02 21:31 . 2010-01-24 16:30 ——– d—–w- c:\documents and settings\MAC\Application Data\Nero
2010-01-02 21:23 . 2010-01-18 22:44 ——– d—–w- c:\program files\Common Files\Nero
2010-01-02 21:06 . 2010-01-02 21:11 ——– d—–w- c:\documents and settings\MAC\Application Data\InfraRecorder
2010-01-02 21:05 . 2010-01-02 21:05 ——– d—–w- c:\program files\InfraRecorder
2010-01-02 18:51 . 2010-01-02 18:51 ——– d—–w- c:\documents and settings\MAC\Local Settings\Application Data\Ahead
2010-01-02 18:26 . 2010-01-02 18:49 ——– d—–w- c:\documents and settings\MAC\Application Data\Ahead
2010-01-02 18:25 . 2010-01-02 18:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Ahead
2010-01-02 01:33 . 2010-01-02 11:54 ——– d—–w- c:\program files\Windows Sidebar
2010-01-01 22:50 . 2010-01-18 22:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2010-01-01 22:31 . 2008-05-14 14:34 3077416 —-a-w- c:\windows\system32\AdvrCntr2D6E0B790.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-27 23:30 . 2009-12-05 17:28 ——– d—–w- c:\program files\ERUNT
2010-01-27 21:13 . 2001-08-23 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-27 21:13 . 2001-08-23 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2010-01-27 19:12 . 2007-04-12 03:03 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-26 23:21 . 2007-04-07 23:03 ——– d—–w- c:\program files\FlashFXP
2010-01-26 19:11 . 2007-04-10 23:00 ——– d—–w- c:\program files\FlashGet
2010-01-24 08:54 . 2009-12-02 01:12 2432 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-23 01:22 . 2008-04-09 16:13 ——– d—–w- c:\documents and settings\MAC\Application Data\Yahoo!
2010-01-23 01:21 . 2008-04-09 15:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-23 01:21 . 2008-04-09 15:46 ——– d—–w- c:\program files\Yahoo!
2010-01-22 16:44 . 2009-12-06 23:12 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-18 17:32 . 2009-11-26 00:18 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2010-01-18 17:32 . 2008-01-27 17:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-13 18:53 . 2007-04-29 16:30 ——– d—–w- c:\program files\Java
2010-01-13 18:11 . 2007-11-17 22:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-09 15:13 . 2009-12-09 23:18 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-01-07 21:07 . 2009-12-06 23:12 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-12-06 23:12 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 19:21 . 2007-04-21 00:57 ——– d—–w- c:\program files\Common Files\Ahead
2009-12-29 19:24 . 2007-09-05 13:54 ——– d—–w- c:\program files\Coupons
2009-12-25 21:23 . 2009-12-25 21:23 ——– d—–w- c:\program files\Common Files\Futuremark Shared
2009-12-25 21:23 . 2007-04-05 23:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-21 19:14 . 2007-04-05 22:47 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-10 15:47 . 2009-12-10 15:47 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonIJEPPEX
2009-12-09 23:28 . 2009-12-09 23:28 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonIJSolutionMenu
2009-12-09 23:26 . 2009-12-09 23:26 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonIJEGV
2009-12-09 23:18 . 2009-12-09 23:18 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonIJMyPrinter
2009-12-09 23:18 . 2007-04-06 22:17 ——– d—–w- c:\program files\Canon
2009-12-09 23:18 . 2009-12-09 22:48 ——– d—–w- c:\documents and settings\MAC\Application Data\Canon Easy-WebPrint EX
2009-12-09 22:44 . 2009-12-09 22:44 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2009-12-09 22:44 . 2009-12-09 22:44 ——– d–h–w- c:\program files\CanonBJ
2009-12-02 00:56 . 2008-11-26 22:29 ——– d—–w- c:\program files\TurboTax
2009-12-01 22:00 . 2009-12-01 21:59 ——– d—–w- c:\program files\QuickTime
2009-12-01 21:59 . 2009-12-01 21:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-26 00:28 . 2009-11-26 00:26 54 —-a-w- c:\windows\system32\rp_stats.dat
2009-11-26 00:28 . 2009-11-26 00:26 39 —-a-w- c:\windows\system32\rp_rules.dat
2009-11-26 00:21 . 2009-11-26 00:21 93360 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-21 15:51 . 2007-04-05 22:48 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 23:20 . 2009-11-18 23:20 152576 —-a-w- c:\documents and settings\MAC\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-18 23:20 . 2009-11-18 23:20 79488 —-a-w- c:\documents and settings\MAC\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-03 16:33 . 2009-11-03 16:33 6 —-a-w- c:\windows\Fonts\wfonts.key
2008-07-19 17:04 . 2008-07-19 17:04 0 –sh–w- c:\windows\S6EBB7F0F.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 118784]
"PtiuPbmd"="ptipbm.dll" [2003-01-15 24576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-01-10 5513216]
"nwiz"="nwiz.exe" [2005-01-10 1490944]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-01-10 86016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"PhiBtn"="c:\windows\System32\drivers\PhiBtn.exe" [2005-08-26 155648]
"Traymin900"="c:\windows\System32\drivers\Tray900.exe" [2005-08-26 266240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-24 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]

c:\documents and settings\MAC\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2009-8-21 900816]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=c:\windows\pss\VIA RAID TOOL.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^MAC^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\MAC\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2008-04-23 09:08 483328 —-a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
2006-09-28 19:21 57344 —-a-w- c:\program files\SlySoft\CloneCD\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
2007-06-29 11:44 1990704 —-a-w- c:\program files\FlashGet\flashget.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 18:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-02-26 08:53 65024 —-a-w- c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Phantom EFX\\OnlineCasino\\Bin\\Prelauncher.exe"=
"c:\\Program Files\\Phantom EFX\\OnlineCasino\\Launcher\\OLCLauncher.exe"=
"c:\\Program Files\\Super Internet TV\\OnlineTV.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [4/9/2008 2:17 PM 1240576]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [6/17/2009 7:20 AM 12648]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys –> c:\windows\system32\DRIVERS\viasraid.sys [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\MAC\LOCALS~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\MAC\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-04-06 16:22]

2009-10-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-04-06 16:22]

2010-01-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]

2010-01-30 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
FF - ProfilePath - c:\documents and settings\MAC\Application Data\Mozilla\Firefox\Profiles\bmupye1q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol308.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-30 10:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\TMP000000928CEAFBF72425E41D 524288 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-329068152-1897051121-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2BDF5DBF-B632-6A3D-1A1E-C4AA1C88503A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaildoigjdmcidhola"=hex:6a,61,6a,6f,61,62,64,69,70,6d,63,69,6e,6c,6a,69,65,65,
61,62,00,f2
"haglaejldmbgmodd"=hex:6a,61,6a,6f,61,62,64,69,70,6d,63,69,6e,6c,6a,69,65,65,
61,62,00,f2

[HKEY_USERS\S-1-5-21-329068152-1897051121-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFE1442E-66F1-FD62-197F-E5445B77FF51}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaonlgafegmnbodelf"=hex:6a,61,6e,67,66,62,6f,67,63,6d,6b,6f,62,62,65,6f,62,64,
69,63,00,f2
"haiofabokcjakcgo"=hex:6a,61,6e,67,66,62,6f,67,63,6d,6b,6f,62,62,65,6f,62,64,
69,63,00,f2
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3184)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-30 10:18:50
ComboFix-quarantined-files.txt 2010-01-30 15:18

Pre-Run: 73,436,684,288 bytes free
Post-Run: 73,408,978,944 bytes free

- - End Of File - - BF72D4B8CC8B15F7508BCDBB15C8E3E9

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI