This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

no idea where to start?

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

You can either split the log into as many posts as necessary or if there are loads of entries under snapshot like below,you can leave them out as I do not need to see them. ((((((((((((((((((((((((((((( SnapShot@2012-05-02_20.45.49 ))))))))))))))))))))))))))))))))))))))))) . - 2012-05-02 20:29 . 2012-05-02 20:29 13342 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat + 2012-05-05 18:30 . 2012-05-05 18:30 13342 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat + 2010-10-21 00:42 . 2012-05-02 20:46 52040 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
ComboFix 12-05-06.04 - Owner 05/06/2012 22:55:16.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.362 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *Disabled/Outdated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Anti-Virus *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} . . ((((((((((((((((((((((((( Files Created from 2012-04-07 to 2012-05-07 ))))))))))))))))))))))))))))))) . . 2012-05-05 14:35 . 2012-05-05 14:35 ——– d-s—w- c:\documents and settings\Owner\UserData 2012-05-05 14:03 . 2008-04-14 09:42 412160 ——w- c:\windows\system32\photometadatahandler.dll 2012-05-05 13:54 . 2008-04-14 09:41 4255 ——w- c:\windows\system32\drivers\adv01nt5.dll 2012-05-05 13:54 . 2008-04-14 09:41 3967 ——w- c:\windows\system32\drivers\adv02nt5.dll 2012-05-05 13:54 . 2008-04-14 09:41 3775 ——w- c:\windows\system32\drivers\adv11nt5.dll 2012-05-05 13:54 . 2008-04-14 09:41 3711 ——w- c:\windows\system32\drivers\adv09nt5.dll 2012-05-05 13:54 . 2008-04-14 09:41 3647 ——w- c:\windows\system32\drivers\adv07nt5.dll 2012-05-05 13:54 . 2008-04-14 09:41 3615 ——w- c:\windows\system32\drivers\adv05nt5.dll 2012-05-05 13:54 . 2008-04-14 09:41 3135 ——w- c:\windows\system32\drivers\adv08nt5.dll 2012-05-05 13:52 . 2006-12-29 04:31 19569 —-a-w- c:\windows\002776_.tmp 2012-05-05 12:41 . 2012-05-05 12:41 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache 2012-05-04 01:24 . 2012-05-04 01:24 ——– d—–w- c:\program files\ESET 2012-05-04 01:00 . 2012-05-04 01:00 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes 2012-05-04 01:00 . 2012-05-04 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-05-04 01:00 . 2012-05-04 01:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-05-04 01:00 . 2012-04-04 19:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-05-02 22:48 . 2012-05-02 22:48 ——– d—–w- c:\program files\Mozilla Maintenance Service 2012-05-02 22:47 . 2012-05-02 22:47 157352 —-a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-05-02 22:47 . 2012-05-02 22:47 129976 —-a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-30 12:05 . 2012-04-30 12:05 ——– d—–w- c:\documents and settings\Owner\Application Data\ElevatedDiagnostics 2012-04-11 02:07 . 2012-02-29 12:17 174080 —-a-w- c:\windows\system32\dllcache\SET106.tmp . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-05-02 22:47 . 2011-10-08 11:28 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll [-] 2005-08-03 22:29 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll [-] 2005-08-03 22:29 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll [7] 2004-08-10 10:00 . 6EAA72FD9EF993EC1FA9A06DE65105DA . 25088 . . [10.0.3790.3646] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll .
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}]
2010-06-15 13:46 86696 —-a-w- c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RDReminder"="c:\program files\RegClean Pro\RegCleanPro.exe" [2010-11-27 2564480]
"GM4IE"="c:\program files\GreaseMonkey4IE\gm4ie.exe" [2006-07-23 61440]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-30 339968]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2009-11-10 443728]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2010-01-14 378128]
"SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-07-21 208616]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2011-7-30 815104]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\MRI_DISABLED
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-9-7 24576]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 09:08 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
2005-09-07 07:43 61440 —-a-w- c:\dell\bldbubg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarboniteSetupLite]
2009-07-31 22:38 283792 —-a-w- c:\program files\Carbonite\CarbonitePreinstaller.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 09:42 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-12-06 06:05 127035 —-a-w- c:\windows\system32\dla\tfswctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 21:50 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 21:50 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 18:03 292128 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 09:42 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
2004-11-11 15:26 26112 —-a-w- c:\program files\Intuit\QuickBooks 2005\Atom\QBReminder.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 09:23 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"WZCSVC"=2 (0x2)
"VSS"=3 (0x3)
"MCVSRte"=2 (0x2)
"Fax"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"Browser"=2 (0x2)
"Bonjour Service"=2 (0x2)
"BITS"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\Juniper Networks\\Juniper Terminal Services Client\\dsTermServ.exe"=
.
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 5:29 PM 33808]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [7/13/2010 9:32 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [7/13/2010 9:32 PM 59664]
R1 NEOFLTR_650_17087;Juniper Networks TDI Filter Driver (NEOFLTR_650_17087);c:\windows\system32\drivers\NEOFLTR_650_17087.SYS [6/23/2011 7:59 AM 85360]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/3/2012 9:00 PM 654408]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 5:06 PM 24592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/3/2012 9:00 PM 22344]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [7/13/2010 9:32 PM 33552]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [12/26/2009 10:54 AM 18560]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/2/2012 6:48 PM 129976]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - EHRECVR
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
2012-05-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\zwyjp8hu.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=panda&type=panda1_0yatb&p=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{7b13ec3e-999a-4b70-b9cb-2617b8323822} - REG_SZ
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-06 23:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-972015860-1495475270-2089886836-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1540)
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'lsass.exe'(1668)
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'explorer.exe'(116)
c:\program files\ThreatFire\TfWah.dll
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Brmfrmps.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LeapFrog\LeapFrog Connect\CommandService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\ThreatFire\TFService.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2012-05-06 23:47:13 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-07 03:46
ComboFix2.txt 2012-05-05 00:45
ComboFix3.txt 2012-05-03 23:26
.
Pre-Run: 100,532,219,904 bytes free
Post-Run: 100,441,620,480 bytes free
.
- - End Of File - - D5F0ADED5588C78D2A6EE69E001E2538
Can you please check that you posted all the entries like these below under sigcheck,what problems are you having now? —— Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll [-] 2005-08-03 22:29 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll [-] 2005-08-03 22:29 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll [7] 2004-08-10 10:00 . 6EAA72FD9EF993EC1FA9A06DE65105DA . 25088 . . [10.0.3790.3646] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll .
——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll [-] 2005-08-03 22:29 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll [-] 2005-08-03 22:29 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll [7] 2004-08-10 10:00 . 6EAA72FD9EF993EC1FA9A06DE65105DA . 25088 . . [10.0.3790.3646] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll . ((((((((((((((((((((((((((((( SnapShot@2012-05-03_11.47.09 )))))))))))))))))))))))))))))))))))))))))
what problems are you having now?



Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: c:\windows\system32\mspmsnsv.dll
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

  • Please provide the results from the scans in your next reply.
java from firefox doesnt seem to be working today like it did on saturday (to log into work remotely, there is some sort of i think java thing that pops open a new window, it worked on saturday but not today) and IE also acting funny when i type an address in the bar or try a bookmarked link, i get this: "this file does not have a program associated with it…"
× Cookies are disabled! This site requires cookies to be enabled to work properly * * Community * Statistics * Documentation * FAQ * About * Join our community * Sign in VirusTotal Analysis completed. SHA256: f776d2680bd3407307b7072626f78460361fc5bc38623c9e16f394d300ab25de SHA1: c61095f51df41e64b3f034458958c918f0d6f8a8 MD5: c51b4a5c05a5475708e3c81c7765b71d File size: 26.5 KB ( 27136 bytes ) File name: mspmsnsv.dll File type: Win32 DLL Detection ratio: 0 / 42 Analysis date: 2012-05-07 18:06:09 UTC ( 3 minutes ago ) 1 0 More details Antivirus Result Update AhnLab-V3 - 20120507 AntiVir - 20120507 Antiy-AVL - 20120507 Avast - 20120507 AVG - 20120507 BitDefender - 20120507 ByteHero - 20120507 CAT-QuickHeal - 20120507 ClamAV - 20120507 Commtouch - 20120507 Comodo - 20120507 DrWeb - 20120507 Emsisoft - 20120507 eSafe - 20120506 eTrust-Vet - 20120507 F-Prot - 20120507 F-Secure - 20120507 Fortinet - 20120507 GData - 20120507 Ikarus - 20120507 Jiangmin - 20120507 K7AntiVirus - 20120507 Kaspersky - 20120507 McAfee - 20120507 McAfee-GW-Edition - 20120507 Microsoft - 20120507 NOD32 - 20120507 Norman - 20120507 nProtect - 20120507 Panda - 20120507 PCTools - 20120507 Rising - 20120507 Sophos - 20120507 SUPERAntiSpyware - 20120411 Symantec - 20120507 TheHacker - 20120507 TrendMicro - 20120507 TrendMicro-HouseCall - 20120507 VBA32 - 20120507 VIPRE - 20120507 ViRobot - 20120507 VirusBuster - 20120507 * Comments * Votes * Additional information No comments More comments Leave your comment… ? Rich Text Area Toolbar Bold (Ctrl+B) Italic (Ctrl+I) Underline (Ctrl+U) Undo (Ctrl+Z) Redo (Ctrl+Y) StylesStyles ▼ Remove Formatting Post comment You have not signed in. Only registered users can leave comments, sign in and have a voice! Sign in Join the community No votes More votes An error occurred Blog | Twitter | [removed] | Google groups | TOS & Privacy Policy × Recover your password Enter the email address associated to your VirusTotal Community account and we'll send you a message so you can setup a new password. Email: loading Recover password Cancel × Join VirusTotal Community Interact with other VirusTotal users and have an active voice when fighting today's Internet threats. Find out more about VirusTotal Community. First name Last name Username * Email * Password * Confirm password * * Required field loading Sign up Cancel × Sign in Username or email Password Forgot your password? loading Sign in Cancel
ssdeep 768:DQrdsm8STScNCFnyXESZ9AAWng/WVRf+TSp+C:DQrdsm8STSXFncyAyoM+T9C TrID Win32 Executable MS Visual C++ (generic) (65.2%) Win32 Executable Generic (14.7%) Win32 Dynamic Link Library (generic) (13.1%) Generic Win/DOS Executable (3.4%) DOS Executable Generic (3.4%) ExifTool UninitializedDataSize….: 0 InitializedDataSize……: 6144 ImageVersion………….: 6.0 ProductName…………..: Windows Media Device Manager FileVersionNumber……..: 11.0.5721.5145 LanguageCode………….: English (U.S.) FileFlagsMask…………: 0x0000 FileDescription……….: Microsoft Media Device Service Provider CharacterSet………….: Unicode LinkerVersion…………: 8.0 OriginalFilename………: MsPMSNSv.dll MIMEType……………..: application/octet-stream Subsystem…………….: Windows GUI FileVersion…………..: 11.0.5721.5145 TimeStamp…………….: 2006:10:19 07:48:19+02:00 FileType……………..: Win32 DLL PEType……………….: PE32 InternalName………….: MsPMSNSv.dll OLESelfRegister……….: ProductVersion………..: 11.0.5721.5145 SubsystemVersion………: 5.1 OSVersion…………….: 6.0 FileOS……………….: Windows NT 32-bit LegalCopyright………..: © Microsoft Corporation. All rights reserved. MachineType…………..: Intel 386 or later, and compatibles CompanyName…………..: Microsoft Corporation CodeSize……………..: 20992 FileSubtype…………..: 0 ProductVersionNumber…..: 11.0.5721.5145 EntryPoint……………: 0x3b1e ObjectFileType………..: Dynamic link library Sigcheck publisher…………….: Microsoft Corporation product………………: Windows Media Device Manager internal name…………: MsPMSNSv.dll copyright…………….: © Microsoft Corporation. All rights reserved. original name…………: MsPMSNSv.dll file version………….: 11.0.5721.5145 description…………..: Microsoft Media Device Service Provider Portable Executable structural information Compilation timedatestamp…..: 2006-10-19 05:48:19 Target machine…………….: 0x14C (Intel 386 or later processors and compatible processors) Entry point address………..: 0x00003B1E PE Sections……………….: Name Virtual Address Virtual Size Raw Size Entropy MD5 .text 4096 20935 20992 6.53 fe7844e8d31ea87cacf25b675f903c2c .data 28672 1676 1024 5.83 05e48ce95c056451a34b5764dd77504f .rsrc 32768 2040 2048 3.36 376cc5d3206409d33610ff4a71293149 .reloc 36864 1836 2048 4.27 a977a9009663c9ef81e9d15c87be2eec PE Imports………………..: ADVAPI32.dll StartServiceA, TraceMessage, CreateServiceA, RegSetValueExA, RegCreateKeyA, RegQueryValueExW, RegSetValueExW, RegCloseKey, ControlService, DeleteService, RegDeleteKeyA, QueryServiceStatus, GetSecurityInfo, SetSecurityInfo, RegisterServiceCtrlHandlerA, AllocateAndInitializeSid, SetEntriesInAclA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, ImpersonateNamedPipeClient, RevertToSelf, SetServiceStatus, RegisterEventSourceA, ReportEventA, DeregisterEventSource, OpenSCManagerA, OpenServiceA, CloseServiceHandle KERNEL32.dll WideCharToMultiByte, WaitNamedPipeW, CreateFileA, CreateFileW, DeviceIoControl, CompareStringA, GetVersionExA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, QueryPerformanceCounter, RtlUnwind, InterlockedCompareExchange, InterlockedExchange, GetModuleFileNameA, FormatMessageA, LoadLibraryExA, GetProcAddress, FormatMessageW, FreeLibrary, LeaveCriticalSection, EnterCriticalSection, GetDriveTypeW, GetLastError, CreateEventA, DisconnectNamedPipe, WaitForSingleObject, CancelIo, CloseHandle, SetEvent, ConnectNamedPipe, ReadFile, WriteFile, WaitForMultipleObjects, GetOverlappedResult, ResetEvent, LocalFree, CreateNamedPipeA, LocalAlloc, DeleteCriticalSection, DisableThreadLibraryCalls, InitializeCriticalSection, SetLastError, Sleep, GetTickCount msvcrt.dll _adjust_fdiv, _amsg_exit, _initterm, free, malloc, _XcptFilter, ___U@YAPAXI@Z, ___V@YAXPAX@Z, __2@YAPAXI@Z, memmove, memset, memcpy, __3@YAXPAX@Z, _purecall PE Exports………………..: DllMain, DllRegisterServer, DllUnregisterServer, ServiceMain Symantec Reputation Suspicious.Insight First seen by VirusTotal 2007-11-15 00:44:57 UTC ( 4 years, 5 months ago ) Last seen by VirusTotal 2012-05-07 18:06:09 UTC ( 4 minutes ago ) File names (max. 25) 1. DPVPWSILBS-163.pms.dll.SVD 2. C51B4A5C05A5475708E3C81C7765B71D 3. MsPMSNSv.dll 4. DPYGMALALM-993.pms.dll.SVD 5. bak.dll 6. file-228919_dll 7. mspmsnsv.dll 8. 20719196 9. DPYWEISKBT-707.pms.dll.SVD 10. F82E387E009585B66A440052C05A4E0090AF0C84.dll 11. svanneste.200.156 12. file-2959691_dll 13. minint-e8q9q1o.1.151 14. c61095f51df41e64b3f034458958c918f0d6f8a8
I don't see any more malware in the logs that could be causing these problems,I would avise you to do this.

1.Install IE9
2.Uninstall/reinstall Firefox.
3.Update Java http://java.com/en/download/index.jsp

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI