Services and controller app has stopped working
40 min read
Dear Friends,
Once connected to internet, I am immediately getting the message "Services and controller app has stopped working" ." and also second message "Windows has encountered a critical problem and will restart automatically in one minute.Please save your work now" . Today Morning, I executed an .exe file also executed a registry file that came with it. Because of this, I think some virus/trojans/malware attacked my system. I did SFC scan and also tried Malwarebytes anti Malware. But couldn't fix it. Everytime I open the internet, the same problem is coming. But the problem won't come, If I am not connected to the internet. Could you please guide me to fix it…
Regards,
Sathia
Hi Guys,
Could you please help me. There is an urgency to fix it,..
Regards,
Sathia
Can you tell us what version of Windows Vista you're using?
Is it 32 or 64 bit?
Can you tell us what version of Windows Vista you're using?
Is it 32 or 64 bit?
Hi,
I am using 32 bit Vista OS. Could you please help. Btw, I am much desperate to fix it
Regards,
Sathia
First we need to find out if it's an infection or a OS issue.
Beings the pc won't stay connected to the net, you'll need to download the tools to a USB device like a flash / thumb drive.
You also have Vista so:
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
I'm going to have you download Combofix to the USB device, after the download, plug the device into the non working pc and run it from the device.
Download ComboFix from one of these locations to the USB device.
Link 1
Link 2 If using this link, Right Click and select Save As.
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
- Double click on ComboFix.exe & follow the prompts.
Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please do not attach the scan results from Combofx. Use copy/paste.
Also please describe how your computer behaves at the moment.
Thanks a lot for the reply. As advised, I ran combofix. First time, After running for 5 min, system pops up a message "combofix has detected the presence of rookkit activity and needs to reboot the machine". I clicked "ok" and system restarted. once re-booted, I waited for combofix to again start its operation but it has not started. So I double clicked combofix . It started Scanning again. After 15 min, a log file is created. I am copy pasting it here. Thanks again for all the help and awaiting your reply eagerly
ComboFix 10-07-31.01 - sathia.gamesh 08/01/2010 0:26.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3573.2558 [GMT 5.5:30]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\st325614.dll
.
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.
2010-07-31 19:05 . 2010-07-31 19:05 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\temp
2010-07-31 19:05 . 2010-07-31 19:05 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2010-07-31 19:05 . 2010-07-31 19:05 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-07-30 20:01 . 2010-07-30 20:01 0 —-a-w- c:\windows\nsreg.dat
2010-07-30 20:01 . 2010-07-30 20:01 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Mozilla
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\programdata\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 15:41 . 2010-07-30 15:41 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Microsoft Help
2010-07-30 15:41 . 2010-07-30 20:40 ——– d—–w- c:\programdata\Microsoft Help
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut106_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut104_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut102_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut101_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut107_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut103_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 ——– d—–w- c:\program files\WebEx
2010-07-24 18:25 . 2010-07-24 18:25 ——– d—–w- c:\programdata\muvee Technologies
2010-07-24 18:25 . 2010-07-24 18:37 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\muvee Technologies
2010-07-24 17:07 . 2010-07-24 17:07 ——– d—–w- c:\programdata\Seagate
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Downloaded Installations
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\program files\Carbonite
2010-07-24 17:06 . 2010-07-24 17:06 ——– d-sh–w- c:\windows\ftpcache
2010-07-24 17:05 . 2010-07-24 17:07 ——– d—–w- c:\program files\Seagate
2010-07-24 17:05 . 2010-07-24 17:05 ——– d—–w- c:\program files\Common Files\muvee Technologies
2010-07-24 17:02 . 2010-07-24 17:02 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Leadertech
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 17:15 . 2010-06-25 16:55 12 —-a-w- c:\windows\bthservsdp.dat
2010-07-31 14:34 . 2010-03-18 13:04 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\vlc
2010-07-30 20:40 . 2010-03-18 14:57 ——– d—–w- c:\program files\Microsoft Works
2010-07-30 18:17 . 2010-03-29 12:46 ——– d—–w- c:\program files\Elecard
2010-07-30 15:56 . 2010-03-16 18:34 101216 —-a-w- c:\users\sathia.gamesh\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-29 17:15 . 2010-05-21 15:02 ——– d—–w- c:\program files\AmiBroker
2010-07-24 17:08 . 2010-03-19 14:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-13 14:22 . 2010-06-13 14:17 ——– d—–w- c:\programdata\Yahoo! Companion
2010-06-13 14:18 . 2010-06-13 14:17 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:17 262144 —-a-w- C:\ntuser.dat
2010-06-13 14:17 . 2010-06-13 13:54 ——– d—–w- c:\program files\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:16 ——– d—–w- c:\programdata\Yahoo!
2010-06-02 17:24 . 2010-06-02 17:23 ——– d—–w- c:\program files\Real Alternative
2010-06-02 14:37 . 2010-06-02 14:37 ——– d—–w- c:\program files\K-Lite Codec Pack
2010-06-01 04:58 . 2010-06-13 14:16 607544 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2007-02-21 19:49 . 2007-02-21 19:49 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-01 1180976]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-29 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-12-18 197928]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
R1 zjoibxppqe7;zjoibxppqe7; [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-04-27 83496]
R3 PCD5SRVC{0F020303-306A84E7-05040104};PCD5SRVC{0F020303-306A84E7-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-04-27 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-04-27 160720]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-12-18 189736]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-04-27 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-04-27 141792]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-04-27 55456]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-04-27 312616]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-03-19 4233728]
— Other Services/Drivers In Memory —
*Deregistered* - ldkxkff
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2010-03-18 c:\windows\Tasks\Uniblue DiskRescue 2009.job
- c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://in.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\sathia.gamesh\AppData\Roaming\Mozilla\Firefox\Profiles\6wjualy4.default\
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-01 00:35
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{0F020303-306A84E7-05040104}]
"ImagePath"="\??\c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-08-01 00:38:43
ComboFix-quarantined-files.txt 2010-07-31 19:08
Pre-Run: 43,000,909,824 bytes free
Post-Run: 43,292,721,152 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 29016F53E0450E165C5B252539C178C5
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
File:: Driver:: zjoibxppqe7 Registry:: [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
File:: Driver:: zjoibxppqe7 Registry:: [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
Hi LD,
It works !!!..Even before doing this, I just plugged in network card after the first log file was created…Surprisingly the error didnt came and everything works normal as like earlier, before to this problem. Thanks a lot for all the help. You are a gem !!!…You saved my life
Regards,
Sathia
Did you run my last fix?
We're NOT finished.
Did you run my last fix?
Hi LD,
I did not ran your last fix…I will run it now and update you shorty.
Regards,
Sathia
Stay with this topic until I give you the all clean post.
Okie LD….Sorry for a being a half dumbed vessel
Regards,
Sathia
Stay with this topic until I give you the all clean post.
Hi LD,
Here is the copy paste of second log file after your last fix was done. Please let me know your view.
ComboFix 10-07-31.01 - sathia.gamesh 08/01/2010 1:28.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3573.2443 [GMT 5.5:30]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\sathia.gamesh\Desktop\CFscript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_zjoibxppqe7
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.
2010-07-31 20:07 . 2010-07-31 20:11 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\temp
2010-07-31 20:07 . 2010-07-31 20:07 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2010-07-31 20:07 . 2010-07-31 20:07 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-07-31 20:07 . 2010-07-31 20:07 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-07-30 20:01 . 2010-07-30 20:01 0 —-a-w- c:\windows\nsreg.dat
2010-07-30 20:01 . 2010-07-30 20:01 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Mozilla
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\programdata\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 15:41 . 2010-07-30 15:41 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Microsoft Help
2010-07-30 15:41 . 2010-07-30 20:40 ——– d—–w- c:\programdata\Microsoft Help
2010-07-29 18:09 . 2010-07-29 18:09 ——– d—–w- c:\program files\WebEx
2010-07-24 18:25 . 2010-07-24 18:25 ——– d—–w- c:\programdata\muvee Technologies
2010-07-24 18:25 . 2010-07-24 18:37 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\muvee Technologies
2010-07-24 17:07 . 2010-07-24 17:07 ——– d—–w- c:\programdata\Seagate
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Downloaded Installations
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\program files\Carbonite
2010-07-24 17:06 . 2010-07-24 17:06 ——– d-sh–w- c:\windows\ftpcache
2010-07-24 17:05 . 2010-07-24 17:07 ——– d—–w- c:\program files\Seagate
2010-07-24 17:05 . 2010-07-24 17:05 ——– d—–w- c:\program files\Common Files\muvee Technologies
2010-07-24 17:02 . 2010-07-24 17:02 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Leadertech
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 20:08 . 2010-06-25 16:55 12 —-a-w- c:\windows\bthservsdp.dat
2010-07-31 19:49 . 2010-05-21 15:02 ——– d—–w- c:\program files\AmiBroker
2010-07-31 14:34 . 2010-03-18 13:04 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\vlc
2010-07-30 20:40 . 2010-03-18 14:57 ——– d—–w- c:\program files\Microsoft Works
2010-07-30 18:17 . 2010-03-29 12:46 ——– d—–w- c:\program files\Elecard
2010-07-30 15:56 . 2010-03-16 18:34 101216 —-a-w- c:\users\sathia.gamesh\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut106_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut104_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut102_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut101_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut107_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut103_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-24 17:08 . 2010-03-19 14:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-13 14:22 . 2010-06-13 14:17 ——– d—–w- c:\programdata\Yahoo! Companion
2010-06-13 14:18 . 2010-06-13 14:17 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:17 262144 —-a-w- C:\ntuser.dat
2010-06-13 14:17 . 2010-06-13 13:54 ——– d—–w- c:\program files\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:16 ——– d—–w- c:\programdata\Yahoo!
2010-06-02 17:24 . 2010-06-02 17:23 ——– d—–w- c:\program files\Real Alternative
2010-06-02 14:37 . 2010-06-02 14:37 ——– d—–w- c:\program files\K-Lite Codec Pack
2010-06-01 04:58 . 2010-06-13 14:16 607544 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2007-02-21 19:49 . 2007-02-21 19:49 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-01 1180976]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-29 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-12-18 197928]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-04-27 83496]
R3 PCD5SRVC{0F020303-306A84E7-05040104};PCD5SRVC{0F020303-306A84E7-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-04-27 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-04-27 160720]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-12-18 189736]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-04-27 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-04-27 141792]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-04-27 55456]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-04-27 312616]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-03-19 4233728]
— Other Services/Drivers In Memory —
*Deregistered* - ldkxkff
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2010-03-18 c:\windows\Tasks\Uniblue DiskRescue 2009.job
- c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://in.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-01 01:40
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{0F020303-306A84E7-05040104}]
"ImagePath"="\??\c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(2472)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\STacSV.exe
c:\program files\Uniblue\DiskRescue\UBDiskRescueSrv.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2010-08-01 01:48:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-31 20:17
ComboFix2.txt 2010-07-31 19:08
Pre-Run: 42,668,998,656 bytes free
Post-Run: 42,240,462,848 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 3EB4626AC996F2B48D664A414A0C8904
- Click START run
- Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
Now please run a MBAM (Malwarebytes' Anti-Malware) scan and post the results.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI