This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

winlogon error messages [Closed]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=c876774b93c7d348b63bf968f874eee8 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-12-02 09:29:19 # local_time=2011-12-03 08:29:19 (+1000, AUS Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8198 22379929 100 100 87582631 124664848 0 0 # scanned=134480 # found=11 # cleaned=0 # scan_time=7236 # nod_component=V3 Build:0x30000000 C:\Documents and Settings\All Users\Start Menu\winlogon.exe Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Start Menu\Programs\winlogon.exe Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\164796E65735\winlogon.exe Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\164796E65735\wlo.exe Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\Application Data\Mozilla\Firefox\Profiles\8jtin39r.default\prefs.js Win32/AutoRun.VB.UG worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\Application Data\Mozilla\Firefox\Profiles\8jtin39r.default\prefs.js.BAK Win32/AutoRun.VB.UG worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\16\1062ec90-76f5db00 Java/Exploit.Agent.NAO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\22\7339ab16-451309d2 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\Start Menu\winlogon.exe Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Sunita\Start Menu\Programs\winlogon.exe Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I C:\RECYCLER\S-1-5-21-3999197343-1343777-328208992-1005\Dc1\winlogon.exe.vir Win32/AutoRun.VB.XW worm (unable to clean) 00000000000000000000000000000000 I
Hello sunoly :),

A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use. Do not mouse click on ComboFix while it is running. That may cause it to stall.

Run ComboFix script
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily when running ComboFix. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Open Notepad. Copy and paste the following text into it:
    http://forums.whatthetech.com/index.php?showtopic=121237
    Collect::
    C:\Documents and Settings\All Users\Start Menu\winlogon.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\winlogon.exe
    
    File::
    c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
    C:\Documents and Settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\16\1062ec90-76f5db00
    C:\Documents and Settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\22\7339ab16-451309d2
    C:\Documents and Settings\Sunita\Start Menu\winlogon.exe
    C:\Documents and Settings\Sunita\Start Menu\Programs\winlogon.exe
    
    Folder::
    c:\documents and settings\Sunita\164796E65735
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiSpyWareDisableNotify"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000000
    
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusDisableNotify"=dword:00000000
    "FirewallDisableNotify"=dword:00000000
    "UpdatesDisableNotify"=dword:00000000
    "UacDisableNotify"=dword:00000000
    
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Documents and Settings\\Sunita\\164796E65735\\winlogon.exe"=-
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Sunita\Application Data\Mozilla\Firefox\Profiles\8jtin39r.default\
    FF - prefs.js: browser.startup.homepage - hxxp://1ef5156153z3xd4.directorio-w.com
    
    DDS::
    uLocal Page = hxxp://jo4y770w7vsy4e5.directorio-w.com
    uDefault_Search_URL = hxxp://vz2k046v98318q8.directorio-w.com
    mLocal Page = hxxp://vlz87cz398s45eq.directorio-w.com
    mStart Page = hxxp://9x496t0ibe1q002.directorio-w.com
  • Save it as CFScript.txt at the desktop. Make sure the Save as type: is All Files (*.*).

    [external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update, please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • ComboFix will also ask to upload some bad files for analysis. Please follow the steps accordingly.
  • When finished, a log will be produced as C:\ComboFix.txt. Copy and paste the contents of the log in your next reply.
  • If you lose Internet connection after running ComboFix, right click on the network icon at the system tray and select Repair, or you can reboot the computer.
  • Enable back your security softwares as soon as you completed the ComboFix steps.
——————–

I want you to update MBAM and run a scan.
  • Open MBAM and click on the Update tab, then Check for Updates.
  • When completed, go to back to the Scanner tab and select Perform full scan. Click Scan.
  • Leave the default options as it is and click on Start Scan.
  • If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Check (tick) all items except items in the C:\System Volume Information folder and click on Remove Selected.
  • After it has removed the items, a log in Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware. If you receive an (Error Loading) error on reboot, please reboot a second time . It is normal for this error to occur once and does not need to be reported unless it returns on future reboots.

——————–

Please post back:
1. ComboFix log
2. MBAM report
Below is the combofix log. Can you provide me the link for running MBAM?


ComboFix 11-12-05.04 - Sunita 12/05/2011 22:39:38.2.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sunita\Desktop\CFScript.txt
* Resident AV is active
.
.
FILE ::
"c:\documents and settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\16\1062ec90-76f5db00"
"c:\documents and settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\22\7339ab16-451309d2"
"c:\documents and settings\Sunita\Start Menu\Programs\winlogon.exe"
"c:\documents and settings\Sunita\Start Menu\winlogon.exe"
"c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP"
.
file zipped: c:\documents and settings\All Users\Start Menu\Programs\winlogon.exe
file zipped: c:\documents and settings\All Users\Start Menu\winlogon.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Start Menu\Programs\winlogon.exe
c:\documents and settings\All Users\Start Menu\winlogon.exe
c:\documents and settings\Sunita\164796E65735
c:\documents and settings\Sunita\164796E65735\winlogon.exe
c:\documents and settings\Sunita\164796E65735\wlo.exe
c:\documents and settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\16\1062ec90-76f5db00
c:\documents and settings\Sunita\Application Data\Sun\Java\Deployment\cache\6.0\22\7339ab16-451309d2
c:\documents and settings\Sunita\Start Menu\Programs\winlogon.exe
c:\documents and settings\Sunita\Start Menu\winlogon.exe
c:\windows\CSC\d6
c:\windows\EventSystem.log
.
.
((((((((((((((((((((((((( Files Created from 2011-11-05 to 2011-12-05 )))))))))))))))))))))))))))))))
.
.
2011-12-18 11:52 . 2010-09-08 00:23 114432 —-a-r- c:\windows\system32\drivers\ewusbnet.sys
2011-12-18 11:52 . 2009-10-12 04:21 100736 —-a-w- c:\windows\system32\drivers\ewusbdev.sys
2011-12-18 11:52 . 2007-08-08 17:13 24448 —-a-w- c:\windows\system32\drivers\ewdcsc.sys
2011-12-18 11:51 . 2011-12-18 11:51 ——– d—–w- c:\program files\Tata Photon+
2011-12-05 12:00 . 2011-12-05 12:00 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1CB8E101-F6E7-4EE5-9636-64137AD84CB3}\offreg.dll
2011-12-05 09:59 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{1CB8E101-F6E7-4EE5-9636-64137AD84CB3}\mpengine.dll
2011-11-25 11:41 . 2011-11-26 10:35 111872 —-a-w- c:\windows\system32\drivers\TrueSight.sys
2011-11-22 12:16 . 2011-11-22 12:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 12:05 . 2011-11-26 10:23 ——– d—–w- c:\documents and settings\Sunita\Application Data\Systweak
2011-11-22 12:05 . 2011-07-07 02:26 17280 —-a-w- c:\windows\system32\roboot.exe
2011-11-20 11:50 . 2011-11-26 10:24 ——– d—–w- C:\sh4ldr
2011-11-20 11:50 . 2011-11-20 11:50 ——– d—–w- c:\program files\Enigma Software Group
2011-11-20 11:50 . 2011-11-26 10:24 ——– d—–w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
2011-11-20 11:50 . 2011-11-20 11:50 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2011-11-20 08:56 . 2011-11-26 10:27 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2008-06-16 11:17 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2006-03-16 04:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2006-03-16 04:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 00:41 . 2008-07-29 09:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 00:41 . 2006-03-16 04:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 00:41 . 2006-03-16 04:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-03-16 04:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2007-12-09 11:05 . 2007-12-09 11:05 6026816 —-a-w- c:\program files\Firefox Setup 2.0.0.11.exe
2008-08-16 06:42 . 2008-08-16 06:42 13112 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 06:42 . 2008-08-16 06:42 70456 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 06:42 . 2008-08-16 06:42 91448 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 06:42 . 2008-08-16 06:42 20800 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 06:43 . 2008-08-16 06:43 206136 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 06:42 . 2008-08-16 06:42 31032 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 06:42 . 2008-08-16 06:42 40248 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-20 21:41 . 2008-05-20 21:41 479232 —-a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-20 21:41 . 2008-05-20 21:41 548864 —-a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-20 21:41 . 2008-05-20 21:41 626688 —-a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 02:58 . 2008-06-05 02:58 648504 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 06:42 . 2008-08-16 06:42 23864 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2011-04-14 16:26 . 2011-05-20 01:02 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-27_11.00.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-05 12:00 . 2011-12-05 12:00 16384 c:\windows\Temp\Perflib_Perfdata_5c8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-20 86016]
"nwiz"="nwiz.exe" [2006-07-20 1519616]
"MsmqIntCert"="mqrt.dll" [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-15 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-03-15 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-15 455168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-03 413696]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-08 155648]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-06-30 1447168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-18 198160]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"BCSSync"="c:\program files\Microsoft Office\Microsoft Office Professional edition 2003\Office14\BCSSync.exe" [2010-03-13 91520]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-09-08 272384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-27 519584]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Microsoft Office Professional edition 2003\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Sunita\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-07-07 195336]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-09-08 114432]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 135664]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-10-12 100736]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-09-08 100736]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Microsoft Office Professional edition 2003\Office14\GROOVE.EXE [2011-06-12 31125880]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [2011-11-26 111872]
S2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [2011-06-15 249648]
S2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-20 468224]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-09-08 8704]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 11:43]
.
2011-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 11:43]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3999197343-1343777-328208992-1005Core.job
- c:\documents and settings\Sunita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-28 11:11]
.
2011-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3999197343-1343777-328208992-1005UA.job
- c:\documents and settings\Sunita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-28 11:11]
.
2011-12-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 09:20]
.
2011-12-05 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
2011-12-05 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_AU&c=64&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\MICROS~1\Office14\ONBttnIE.dll/105
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Sunita\Application Data\Mozilla\Firefox\Profiles\8jtin39r.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - prefs.js: network.proxy.type - 1
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-05 23:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ??? T??????`?@?????L?@
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2292)
c:\windows\system32\WININET.dll
c:\program files\ESET\ESET Smart Security\eplgHooks.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~4\MICROS~1\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\msdtc.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\eHome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Yahoo!\Widgets\YahooWidgets.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Yahoo!\Widgets\YahooWidgets.exe
c:\program files\Yahoo!\Widgets\YahooWidgets.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2011-12-05 23:12:30 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-05 12:12
ComboFix2.txt 2011-11-27 11:04
.
Pre-Run: 51,323,199,488 bytes free
Post-Run: 51,610,587,136 bytes free
.
- - End Of File - - DF4F0C05441FD7B77B6258E1725D45E1
Upload was successful
Hello sunoly :),

Please delete these:
c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
c:\program files\Firefox Setup 2.0.0.11.exe

——————–

I guess you must have uninstalled MBAM.

Please download Malwarebytes' Anti-Malware (MBAM)© from Malwarebytes and save it to your desktop. Click here.

Run MBAM
  • Double click on mbam-setup.exe and follow the prompts to install the program.
  • At the end of installation, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • MBAM will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update mirror, select one of the websites and click on Check for Updates.
  • Upon completion of update and loading, select the Scanner tab. Click on Perform full scan, then click on Scan.
  • Leave the default options as it is and click on Start Scan.
  • If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Check (tick) all items except items in the C:\System Volume Information folder and click on Remove Selected.
  • After it has removed the items, a log in Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware. If you receive an (Error Loading) error on reboot, please reboot a second time . It is normal for this error to occur once and does not need to be reported unless it returns on future reboots.

——————–

Please post back:
1. MBAM report
2. how is the computer behaving now?
Hello sunoly :), I usually close the topic after 3 days without any reply, and it has already been 3 days since my last post. Do you still need help? Any problems following my instructions? Need more time? If I do not get any response within the next 24 hours, this topic will be closed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI