This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possibly infected [Solved]

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Farbar Service Scanner Version: 06-08-2012 Ran by [removed] (administrator) on 04-09-2012 at 13:07:38 Running from "C:\Documents and Settings\Compaq_Owner\Desktop" Microsoft Windows XP Home Edition Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(6) IPSec(4) MDC8021X(9) mfetdi2k(8) NetBT(5) PSched(7) Tcpip(3) 0x090000000400000001000000020000000300000008000000050000000600000007000000090000 00 IpSec Tag value is correct. **** End of log ****
Please delete the current version of Combofix.exe from your desktop and download a new version from here to your desktop.

Disable your AntiVirus and AntiSpyware applications.

Double-click on the Combofix.exe and follow the prombts on your display. When finish, it will create a C:\Combofix.txt. Please post this log for further review.
———
ComboFix 12-09-04.02 - Compaq_Owner 09/04/2012 14:12:01.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.428 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2012-08-04 to 2012-09-04 )))))))))))))))))))))))))))))))
.
.
2012-09-03 20:49 . 2012-09-03 20:49 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\ImgBurn
2012-09-03 20:46 . 2012-09-03 20:46 ——– d—–w- c:\program files\ImgBurn
2012-09-02 20:14 . 2012-09-02 20:14 ——– d—–w- C:\_OTL
2012-09-01 22:52 . 2012-09-01 22:52 73696 —-a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-31 18:09 . 2012-08-31 18:09 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Sun
2012-08-31 14:55 . 2012-08-31 14:55 ——– d—–w- c:\program files\ESET
2012-08-31 14:13 . 2012-08-31 14:13 ——– d—–w- c:\program files\Common Files\Java
2012-08-31 14:13 . 2012-08-31 14:12 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-08-31 14:13 . 2012-08-31 14:12 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-08-31 14:11 . 2012-08-31 14:11 ——– d—–w- c:\program files\Java
2012-08-31 14:06 . 2012-08-31 14:06 ——– d—–w- C:\Sun
2012-08-29 22:41 . 2012-08-29 22:41 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2012-08-29 21:20 . 2012-08-29 21:20 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\McAfee
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-29 18:58 . 2012-07-03 18:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 00:29 . 2012-08-29 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-08-28 00:29 . 2012-08-28 00:29 ——– d—–w- c:\program files\AVAST Software
2012-08-27 15:23 . 2012-08-27 15:23 ——– d—–w- c:\documents and settings\Compaq_Owner\DoctorWeb
2012-08-21 21:30 . 2012-08-30 19:45 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-31 14:12 . 2004-08-09 09:05 93672 -c–a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-31 14:12 . 2010-09-20 14:19 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-17 20:43 . 2012-07-15 12:33 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 20:43 . 2012-02-15 21:16 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2004-08-09 05:41 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 15:07 . 2004-08-09 04:28 832512 —-a-w- c:\windows\system32\wininet.dll
2012-07-03 15:07 . 2004-08-09 04:28 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-07-03 15:07 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-07-03 15:07 . 2004-08-09 04:28 17408 ——w- c:\windows\system32\corpol.dll
2012-07-03 13:40 . 2004-08-09 04:28 1866112 —-a-w- c:\windows\system32\win32k.sys
2005-02-16 17:06 . 2006-11-25 03:30 218112 -c–a-w- c:\program files\HijackThis.exe
2012-09-01 22:52 . 2012-03-24 01:43 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-02-28 22:21 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-30_19.46.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-09-04 17:36 . 2012-09-04 17:36 16384 c:\windows\temp\Perflib_Perfdata_35c.dat
+ 2012-09-03 00:10 . 2012-09-04 13:52 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-08-09 05:47 . 2012-09-04 13:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2012-09-01 16:57 . 2012-09-04 13:52 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-05-26 10:19 . 2012-06-04 22:35 222448 c:\windows\system32\muweb.dll
+ 2012-08-31 14:13 . 2012-08-31 14:12 246760 c:\windows\system32\javaws.exe
+ 2012-08-31 14:13 . 2012-08-31 14:12 174056 c:\windows\system32\javaw.exe
+ 2012-08-31 14:12 . 2012-08-31 14:12 174056 c:\windows\system32\java.exe
+ 2012-08-31 14:13 . 2012-08-31 14:13 176128 c:\windows\Installer\76567.msi
+ 2012-08-31 14:12 . 2012-08-31 14:12 873984 c:\windows\Installer\76562.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-01 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"2wSysTray"="c:\program files\2Wire\2PortalMon.exe" [2004-09-15 393216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1318816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"VTTimer"="VTTimer.exe" [2004-01-16 49152]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-12-18 278528]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2007-6-17 217088]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2003-07-14 19:30 98304 -c–a-w- c:\program files\SBC Yahoo!\Connection Manager\IP Insight\ipmon32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-03-01 03:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/20/2009 7:31 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2/28/2011 5:21 PM 89792]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/29/2012 1:58 PM 655944]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/22/2009 12:51 PM 95200]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [2/28/2011 5:21 PM 161632]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2/28/2011 5:21 PM 151880]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2/28/2011 5:21 PM 57600]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/29/2012 1:58 PM 22344]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2/28/2011 5:21 PM 340920]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S2 0015421346290574mcinstcleanup;McAfee Application Installer Cleanup (0015421346290574);c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 71777363;71777363; [x]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7/15/2012 7:33 AM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2/28/2011 5:21 PM 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/8/2012 11:38 AM 114144]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 20:43]
.
2012-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
2012-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://att.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://att.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\mrook2ld.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-04 14:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(7952)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-09-04 14:24:55
ComboFix-quarantined-files.txt 2012-09-04 19:24
ComboFix2.txt 2012-08-30 21:50
ComboFix3.txt 2012-08-30 19:48
.
Pre-Run: 96,013,795,328 bytes free
Post-Run: 96,001,454,080 bytes free
.
- - End Of File - - C4B3979CB0B5C951039052676E44208D
Hi,
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    uStart Page = hxxp://att.yahoo.com
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    mStart Page = hxxp://att.yahoo.com
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
    uInternet Settings,ProxyOverride = 127.0.0.1
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    
    Driver::
     71777363
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ComboFix 12-09-04.02 - Compaq_Owner 09/04/2012 14:54:54.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.396 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Owner\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_71777363
——-\Service_71777363
.
.
((((((((((((((((((((((((( Files Created from 2012-08-04 to 2012-09-04 )))))))))))))))))))))))))))))))
.
.
2012-09-03 20:49 . 2012-09-03 20:49 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\ImgBurn
2012-09-03 20:46 . 2012-09-03 20:46 ——– d—–w- c:\program files\ImgBurn
2012-09-02 20:14 . 2012-09-02 20:14 ——– d—–w- C:\_OTL
2012-09-01 22:52 . 2012-09-01 22:52 73696 —-a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-31 18:09 . 2012-08-31 18:09 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Sun
2012-08-31 14:55 . 2012-08-31 14:55 ——– d—–w- c:\program files\ESET
2012-08-31 14:13 . 2012-08-31 14:13 ——– d—–w- c:\program files\Common Files\Java
2012-08-31 14:13 . 2012-08-31 14:12 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-08-31 14:13 . 2012-08-31 14:12 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-08-31 14:11 . 2012-08-31 14:11 ——– d—–w- c:\program files\Java
2012-08-31 14:06 . 2012-08-31 14:06 ——– d—–w- C:\Sun
2012-08-29 22:41 . 2012-08-29 22:41 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2012-08-29 21:20 . 2012-08-29 21:20 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\McAfee
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-29 18:58 . 2012-07-03 18:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 00:29 . 2012-08-29 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-08-28 00:29 . 2012-08-28 00:29 ——– d—–w- c:\program files\AVAST Software
2012-08-27 15:23 . 2012-08-27 15:23 ——– d—–w- c:\documents and settings\Compaq_Owner\DoctorWeb
2012-08-21 21:30 . 2012-08-30 19:45 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-31 14:12 . 2004-08-09 09:05 93672 -c–a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-31 14:12 . 2010-09-20 14:19 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-17 20:43 . 2012-07-15 12:33 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 20:43 . 2012-02-15 21:16 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2004-08-09 05:41 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 15:07 . 2004-08-09 04:28 832512 —-a-w- c:\windows\system32\wininet.dll
2012-07-03 15:07 . 2004-08-09 04:28 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-07-03 15:07 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-07-03 15:07 . 2004-08-09 04:28 17408 ——w- c:\windows\system32\corpol.dll
2012-07-03 13:40 . 2004-08-09 04:28 1866112 —-a-w- c:\windows\system32\win32k.sys
2005-02-16 17:06 . 2006-11-25 03:30 218112 -c–a-w- c:\program files\HijackThis.exe
2012-09-01 22:52 . 2012-03-24 01:43 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-02-28 22:21 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-30_19.46.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-09-04 20:06 . 2012-09-04 20:06 16384 c:\windows\temp\Perflib_Perfdata_3b4.dat
+ 2012-09-03 00:10 . 2012-09-04 20:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-08-09 05:47 . 2012-09-04 20:04 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2012-09-04 20:00 . 2012-09-04 20:04 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-05-26 10:19 . 2012-06-04 22:35 222448 c:\windows\system32\muweb.dll
+ 2012-08-31 14:13 . 2012-08-31 14:12 246760 c:\windows\system32\javaws.exe
+ 2012-08-31 14:13 . 2012-08-31 14:12 174056 c:\windows\system32\javaw.exe
+ 2012-08-31 14:12 . 2012-08-31 14:12 174056 c:\windows\system32\java.exe
+ 2012-08-31 14:13 . 2012-08-31 14:13 176128 c:\windows\Installer\76567.msi
+ 2012-08-31 14:12 . 2012-08-31 14:12 873984 c:\windows\Installer\76562.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-01 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"2wSysTray"="c:\program files\2Wire\2PortalMon.exe" [2004-09-15 393216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1318816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"VTTimer"="VTTimer.exe" [2004-01-16 49152]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-12-18 278528]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2007-6-17 217088]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2003-07-14 19:30 98304 -c–a-w- c:\program files\SBC Yahoo!\Connection Manager\IP Insight\ipmon32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-03-01 03:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/20/2009 7:31 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2/28/2011 5:21 PM 89792]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/29/2012 1:58 PM 655944]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/22/2009 12:51 PM 95200]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [2/28/2011 5:21 PM 161632]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2/28/2011 5:21 PM 151880]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2/28/2011 5:21 PM 57600]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/29/2012 1:58 PM 22344]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2/28/2011 5:21 PM 340920]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S2 0015421346290574mcinstcleanup;McAfee Application Installer Cleanup (0015421346290574);c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7/15/2012 7:33 AM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2/28/2011 5:21 PM 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/8/2012 11:38 AM 114144]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 20:43]
.
2012-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
2012-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\mrook2ld.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-04 15:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2508)
c:\windows\system32\WININET.dll
c:\progra~1\SBCSEL~1\SMARTB~1\SBHook.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\VTTimer.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\SBC Self Support Tool\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
.
**************************************************************************
.
Completion time: 2012-09-04 15:18:48 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-04 20:18
ComboFix2.txt 2012-09-04 19:24
ComboFix3.txt 2012-08-30 21:50
ComboFix4.txt 2012-08-30 19:48
.
Pre-Run: 96,008,273,920 bytes free
Post-Run: 95,918,452,736 bytes free
.
- - End Of File - - 0D3FBA44B7CF087215695CF0DD384DB8
Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.09.01.06 Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking) Internet Explorer 7.0.5730.11 Compaq_Owner :: YOUR-22CA86D5C4 [administrator] Protection: Disabled 9/4/2012 9:38:37 PM mbam-log-2012-09-04 (21-38-37).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 294293 Time elapsed: 33 minute(s), 36 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Am having trouble getting the ESET scan to run again.
Let's do this. It may be that McAfee is causing some of this problem. Let's remove McAfee and see if the problem persists. For the time being do not go to any other sites but here until we get your antivirus/firewall back onto your system.

Download the tool found here and run it >> once finished reboot your system and then test out your internet and let me know how it is running.
I removed McAfee and am still having connectivity issues. I have his recovery discs and may just reformat. I've also been looking at new computers for him.
Hi, Ok just let me know so we can continue or we can close out the topic. I have been talking with some colleagues about your topic and they don't see any more malware on your system so there is another problem deeper inside. Sometimes a system will just get sloppy and just won't run right and a fresh install is the best option.
Hi,

No there is not a problem getting those back on there. It may take some time to complete though to download and install them all but Windows Updates will take care of all of that. :)

You can check out the link here and it should help you along.
I read the link you recommended and also watched the HP video regarding formating. I couldn't get the Recovery Discs to work going through PC Help & Tools. I was able to get to them by choosing Microsoft Windows Recovery Console during the startup instead of Microsoft Windows XP Home Edition. Then it says starting recovery console. And that just takes me to DOS. 1: C:\WINDOWS So I typed 1 and clicked enter. Which Windows installation would you like to log onto ? 1 C:\WINDOWS> Not sure what I need to do.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI