This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus removal ruined my computer?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there! Thanks for taking the time to read this… Im having a serious issue with my computer and am really hoping that you can help with it. Over the last few days my computer has been acting funny, specifically on the internet.. It will freeze up, close down unexpectedly, and sometimes the screen im looking at will go blank… I decided to d/l and use malwarebytes to see if I had somehow recieved viruses onto my computer despite having McAfee. When i did a full scan, it found 4 infections… I clicked the option to remove them, and it said that it successfully removed them but it needed to reboot to finish. I clicked ok, and my computer restarted. After the reboot, my computer loaded up, but about 30 seconds after it loaded the desktop it froze up. The mouse will still move, but im unable to click anything, open anything, ctrl alt delete does nothing, etc. I rebooted my computer again, with the same results. For whatever reason, my computer just basically fails about 30 seconds into loading up. As a resuly, I am unable to run the system scans that you guys typically ask for.. perhaps there is a way around this? Since i am able to get my computer to load up i would hope/assume there is a solution to my problem… any help that you can give would be amazing!
Hi RandAlThor420,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Will your computer operate in safe mode?

Reboot your computer and then start tapping the F8 key until you hear a beep. When the screen opens - use your arrow keys to select Safe Mode with networking.

If successful,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Ok so i was indeed able to log into safe mode with networking… yay! Here is the log you asked for, as well as the file: . DDS (Ver_2011-06-12.02) - NTFSx86 NETWORK Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_25 Run by [removed] at 23:02:05 on 2011-06-17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1645 [GMT -7:00] . AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\ctfmon.exe . ============== Pseudo HJT Report =============== . BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll BHO: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - c:\program files\xfirexo\prxtbXfir.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110513205706.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mi1933~1\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: XfireXO Toolbar: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - c:\program files\xfirexo\prxtbXfir.dll TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngine.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe" mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [Razer Naga Driver] c:\program files\razer\naga\RazerNagaSysTray.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://active.macromedia.com/flash2/cabs/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{E011F3E3-20C6-4F59-818E-A8BAC93FF73C} : DhcpNameServer = [removed] [removed] Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\administrator.owner-91716ebea\application data\mozilla\firefox\profiles\vvyipmus.default\ FF - plugin: c:\progra~1\mi1933~1\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\mi1933~1\office14\NPSPWRAP.DLL FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll . ============= SERVICES / DRIVERS =============== . R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-3-25 387480] R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-8-27 84200] R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2010-8-27 271480] R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-8-27 188136] R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-8-27 141792] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-8-27 314088] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-8-27 88736] R3 RzSynapse;Razer Driver;c:\windows\system32\drivers\RzSynapse.sys [2011-4-4 103424] S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-7-25 366640] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-5-15 88176] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2010-8-27 271480] S2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2010-8-27 271480] S2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-8-27 171168] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-8-27 56064] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2010-1-17 25832] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-7-25 22712] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-7-25 39984] S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-5-15 153280] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-5-15 52320] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-8-27 88736] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-8-27 84488] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-5-15 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-5-15 40552] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] . =============== Created Last 30 ================ . 2011-06-18 05:57:53 ——– d—–w- c:\documents and settings\administrator.owner-91716ebea\local settings\application data\Mozilla 2011-06-18 05:57:30 ——– d-sh–w- c:\documents and settings\administrator.owner-91716ebea\IETldCache 2011-06-15 21:16:42 ——– dc-h–w- c:\windows\ie8 2011-06-15 17:28:58 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-15 10:02:47 ——– d—–w- c:\windows\SxsCaPendDel 2011-06-15 00:48:40 551936 -c—-w- c:\windows\system32\dllcache\oleaut32.dll 2011-06-15 00:47:51 105472 -c—-w- c:\windows\system32\dllcache\mup.sys 2011-06-15 00:47:18 759296 -c–a-w- c:\windows\system32\dllcache\VGX.dll 2011-06-10 09:14:50 ——– d—–w- c:\program files\iPod 2011-06-10 09:08:10 ——– d—–w- c:\program files\Bonjour . ==================== Find3M ==================== . 2011-05-29 16:11:30 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 16:11:20 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-05-10 15:06:08 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-05-10 15:06:08 42496 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2011-05-02 15:31:52 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-04-30 06:11:01 0 —-a-w- c:\windows\system32\ConduitEngine.tmp 2011-04-29 16:19:43 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-21 13:37:43 105472 —-a-w- c:\windows\system32\drivers\mup.sys 2011-04-14 21:01:38 95824 —-a-w- c:\windows\system32\drivers\mfeapfk.sys 2011-04-14 21:01:38 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys 2011-04-14 21:01:38 88736 —-a-w- c:\windows\system32\drivers\mfendisk.sys 2011-04-14 21:01:38 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys 2011-04-14 21:01:38 84200 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys 2011-04-14 21:01:38 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys 2011-04-14 21:01:38 52320 —-a-w- c:\windows\system32\drivers\mfebopk.sys 2011-04-14 21:01:38 387480 —-a-w- c:\windows\system32\drivers\mfehidk.sys 2011-04-14 21:01:38 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys 2011-04-14 21:01:38 153280 —-a-w- c:\windows\system32\drivers\mfeavfk.sys 2011-04-14 12:07:59 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-14 09:40:22 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-04-06 23:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 23:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 23:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 23:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe . ============= FINISH: 23:02:38.50 ===============

Attachments:

RandAlThor420,

Let's give this a try:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ok, heres what i got:

ComboFix 11-06-17.04 - Administrator 06/18/2011 16:08:22.5.4 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1547 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2011-05-18 to 2011-06-18 )))))))))))))))))))))))))))))))
.
.
2011-06-18 05:56 . 2011-06-18 05:57 ——– d—–w- c:\documents and settings\Administrator.OWNER-91716EBEA
2011-06-16 00:23 . 2011-06-16 00:23 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-06-16 00:22 . 2011-06-16 00:22 ——– d-sh–w- c:\documents and settings\Owner\IETldCache
2011-06-15 21:16 . 2011-06-15 21:18 ——– dc-h–w- c:\windows\ie8
2011-06-15 17:28 . 2011-06-15 17:28 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-15 10:02 . 2011-06-15 10:19 ——– d—–w- c:\windows\SxsCaPendDel
2011-06-15 00:48 . 2010-12-20 17:32 551936 -c—-w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-15 00:47 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-15 00:47 . 2009-03-08 11:33 759296 -c–a-w- c:\windows\system32\dllcache\VGX.dll
2011-06-10 09:14 . 2011-06-10 09:14 ——– d—–w- c:\program files\iPod
2011-06-10 09:08 . 2011-06-10 09:08 ——– d—–w- c:\program files\Bonjour
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-29 16:11 . 2010-07-26 03:37 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 16:11 . 2010-07-26 03:37 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-05-10 15:06 . 2009-05-18 03:29 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-05-10 15:06 . 2009-05-18 03:29 42496 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-05-02 15:31 . 2009-05-09 11:23 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-30 06:11 . 2011-04-30 06:11 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-04-29 16:19 . 2007-05-15 06:04 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-21 13:37 . 2007-05-15 06:05 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-04-14 21:01 . 2010-08-27 17:27 9344 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-04-14 21:01 . 2010-08-27 17:27 95824 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-04-14 21:01 . 2010-08-27 17:27 88736 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-04-14 21:01 . 2010-08-27 17:27 84488 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-04-14 21:01 . 2010-08-27 17:27 84200 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-04-14 21:01 . 2010-08-27 17:27 56064 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-04-14 21:01 . 2010-08-27 17:27 314088 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-04-14 21:01 . 2009-05-15 19:16 52320 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-04-14 21:01 . 2009-05-15 19:16 153280 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-04-14 21:01 . 2009-03-25 18:06 387480 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2011-04-14 12:07 . 2010-07-26 20:07 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-04-14 09:40 . 2010-07-26 20:07 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-04-06 23:20 . 2011-04-06 23:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20 . 2011-04-06 23:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 23:20 . 2011-04-06 23:20 197920 —-a-w- c:\windows\system32\dnssdX.dll
2011-04-06 23:20 . 2011-04-06 23:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2011-05-08 05:32 . 2011-05-08 05:32 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 21:01 . 2010-08-27 17:27 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 23:54 175912 —-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]
2011-01-17 23:54 175912 —-a-w- c:\program files\XfireXO\prxtbXfir.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\prxtbXfir.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-26 16851456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-04-05 1195408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-24 233472]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-09 54840]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Razer Naga Driver"="c:\program files\Razer\Naga\RazerNagaSysTray.exe" [2011-02-17 953744]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-08 421160]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2010-6-22 0]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^CurseClientStartup.ccip]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\CurseClientStartup.ccip
backup=c:\windows\pss\CurseClientStartup.ccipStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
m‘|\ü [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\World of Warcraft\\Launcher.exe"=
"f:\\Program Files\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Curse\\CurseClient.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\Old stuff\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\BackgroundDownloader.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\Old stuff\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.patch.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\World of Warcraft Public Test\\LauncherB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Apps\\2.0\\P76R76HL.VBN\\Z8PJ4QKH.3OY\\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\\CurseClient.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:Remote Desktop
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/15/2009 3:24 PM 721904]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [8/27/2010 10:27 AM 84200]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [8/27/2010 10:27 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [8/27/2010 10:27 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [8/27/2010 10:27 AM 141792]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [8/27/2010 10:27 AM 314088]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [8/27/2010 10:27 AM 88736]
R3 RzSynapse;Razer Driver;c:\windows\system32\drivers\RzSynapse.sys [4/4/2011 4:49 PM 103424]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/25/2010 8:37 PM 366640]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [5/15/2009 12:17 PM 88176]
S2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [8/27/2010 10:27 AM 271480]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [8/27/2010 10:27 AM 56064]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [1/17/2010 1:58 PM 25832]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/25/2010 8:37 PM 22712]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [7/25/2010 8:37 PM 39984]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [8/27/2010 10:27 AM 88736]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [8/27/2010 10:27 AM 84488]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
——- Supplementary Scan ——-
.
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Administrator.OWNER-91716EBEA\Application Data\Mozilla\Firefox\Profiles\vvyipmus.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-18 16:12
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(900)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
Completion time: 2011-06-18 16:13:55
ComboFix-quarantined-files.txt 2011-06-18 23:13
ComboFix2.txt 2011-04-29 18:13
.
Pre-Run: 687,101,476,864 bytes free
Post-Run: 687,503,364,096 bytes free
.
- - End Of File - - 8A2570149C7186979EBB270EF4A4D747
It is still doing the same thing that it was doing before… It will b oot up in normal mode, but once it has loaded to the desktop, as all the programs and processes are still loading, it only allows me to do anything for about 30 seconds before it essentially freezes.. I am still ble to move the mouse, but it does not register mouse clicks, my windows key does not work, ctrl-alt-del does not work, etc. I waited HOURS yesterday to see if there was some program that for some reason needed an excessive amount of time to load, but with no luck. As i mentioned above this happened initally RIGHT after i ran malwarebytes, and it said it found 4 viruses, removed them successfully, and needed to reboot in order to finish the process. That is why i posted in this thread, because it certainly seems to be virus related. A friend suggested that perhaps one of the viruses was in an important file which is now damaged, corrupted, or otherwise unable to operate properly.. Im really not sure whats going on with it, but as it is my computer is inoperable in normal mode. Safe mode with networking had no such issues at all though.
In safe mode… start Malwarebytes and then click on the Logs tab. The log of the scan you made before should be listed there as a .txt file. Double click on it to open it and then copy/paste the contents here.
Ok i opened up malwarebytes and clicked on the logs tab, but there were only two logs there, one from the day that this happened and one from yesterday (not sure exactly what that is from to be honest, but i HAVE tried rebooting my computer a fair amount so i think it somehow kicked in yesterday on one attempt…?). Both log files look very similar, and to me the dont look like the log file that you are looking for… however, im not the expert! So hopefully this is what you need: 14:08:33 (null) MESSAGE Protection started successfully 14:08:38 (null) MESSAGE IP Protection started successfully 17:23:57 (null) MESSAGE Protection started successfully 17:24:04 (null) MESSAGE IP Protection started successfully 17:27:34 (null) MESSAGE Protection started successfully 17:28:00 (null) MESSAGE IP Protection started successfully 17:30:49 (null) MESSAGE Protection started successfully 17:31:32 (null) MESSAGE IP Protection started successfully 17:31:32 (null) MESSAGE IP Protection stopped 17:34:40 (null) MESSAGE Protection started successfully 17:35:14 (null) MESSAGE IP Protection started successfully 17:40:26 (null) MESSAGE Protection started successfully 17:44:08 (null) MESSAGE Protection started successfully 17:44:13 (null) MESSAGE IP Protection started successfully 17:48:15 (null) MESSAGE Protection started successfully 17:48:59 (null) MESSAGE IP Protection started successfully 17:49:00 (null) MESSAGE IP Protection stopped 17:52:52 (null) MESSAGE Protection started successfully 17:52:57 (null) MESSAGE IP Protection started successfully 17:56:18 (null) MESSAGE Protection started successfully 18:05:40 (null) MESSAGE IP Protection started successfully
RandAlThor420,

The log should have a header and alot more information. Here is one from my computer:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6/19/2011 06:25:51 AM
mbam-log-2011-06-19 (06-25-51).txt

Scan type: Quick scan
Objects scanned: 1
Time elapsed: 1 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Even with those IP Protection entries it should look something like this:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6773

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

6/5/2011 1:08:05 AM
mbam-log-2011-06-05 (01-08-05).txt

Scan type: Full scan (C:\|K:\|)
Objects scanned: 378482
Time elapsed: 2 hour(s), 8 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


22:28:24 Owner MESSAGE Protection started successfully
22:28:31 Owner MESSAGE IP Protection started successfully
22:41:01 Owner MESSAGE Protection started successfully
22:41:06 Owner MESSAGE IP Protection started successfully
22:56:15 Owner MESSAGE Protection started successfully
22:56:58 Owner MESSAGE IP Protection started successfully


If that is all you have… I must assume that you didn't get a complete scan.

You will probably have to do it in safe mode… but I'd like you to run a quick scan with malwarebytes'. Start malwarebytes', update it, and then run a quick scan and post the results.
OK i did that and i will post the logs in a minute.. Couple things i wanted to mention before i do though… First off, yesterday i tried rebooting my computer regularly, and as soon as it loaded i pulled up taskmanager to try to notice anything funny.. I noticed a process called something along the lines of malwarebytes (may have been slightly different, but i was pretty sure it was malwarebytes) that said it was a system process.. It was using a fair amount of my computers power, so I right clicked and closed it down.. my computer actually froze up part way through, but i went and did other things and came back 15 minutes later and it had closed the process…. My computer was now usable, except that it wouldnt load internet explorer or mozilla.. I opened itunes and it worked, and I would venture to guess that other programs would as well. Im not sure how useful this information is, but I wanted to let you know. Also, on a different note, i see that the log above doesnt list any viruses found, but it DID say it found and removed four on the day that this issue arose, it just appears that for whatever reason it didnt save the log. Anyways, heres the log you asked for from the quick scan: Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 6905 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 6/20/2011 4:32:57 PM mbam-log-2011-06-20 (16-32-57).txt Scan type: Quick scan Objects scanned: 182891 Time elapsed: 2 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
RandAlThor420, What I'm hoping is that something "hung" when you ran Mbam before… and I'm trying to get it to release. All the information you provided is useful… does this mean that you can actually run things in normal mode now? Can you run ComboFix?
OK well it appears to be working properly now, yay! I can run combofix if you would like… The initial problem has been solved, but if you would like to run through some steps to ensure that my computer is A-OK im fine with that :) As a side note, and perhaps this is the wrong forum to post this in but while ive got ya here what the heck: My computer has been unable to properly shut down for over a year. When i choose the option to shut down it closes all programs, including explorer, goes to a pretty little screen that says something along the lines of "shutting down" , and then just stalls there forever, forcing me to manually shut it down. This also happens if i choose to restart my computer. Do you know what would cause this, or how to fix it? Thanks a bunch for your time!!
Yes please. Give Combofix a run and lets see what it sees. As far as the shutdown… I may not be able to help with that. I've got a computer at my office that does the same thing. It's done it every since it got rebuilt after it fried during a lightning storm. However, once we are done here, I'll send you over to the Tech Team who might know a trick to fix it.
hmm so after another reboot it appears that the problem is not really fixed, its still hanging up. Should i perhaps attempt to uninstall malwarebytes in safe mode…? Or..? heh… well as an FYI i will be out of town for nearly a week… Im going to be online tomorrow and ill check in to see what your next step for me is (combofix in safe mode perhaps?) but after that i wont be on until im back in town. I realize thats more then the customary three days, but i WILL check back in here as soon as im back in town!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI