This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

stop 0x8E, can only use safe mode

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I was running MS AntiSpyware last week. It had caught several things, and was attempting to fix them when I got the BSOD. Upon restarting then, and each time since then, after clicking my user account I get another BSOD and the computer restarts. I can only get into Windows by running in safe mode. Here's the BSOD error code:

*** STOP : 0x0000008E (0xC0000005,0x7FFA1090,0xAA7ECC58,0x00000000)

There had been several different spyware problems that MSAS kept finding and trying to remove, but that kept reappearing. I ran Adaware too, with the same repetitive result. Then finally the total freeze as MSAS was trying to clean off what it found.

In safe mode I ran Housecall from trendmicro.com. It found just over 16,000 viruses. The guy at Medion USA (my laptop brand) was impressed, since he hadn't seen over 3700 before. I think Limewire is involved. Most of the 'viruses' Housecall found were in C:\complete (not my normal Limewire downloads folder) and … well I can't remmber right now what the other folder was. But it was thousands of folders named somehow using the names of movies from imdb.com. This is my guess anyway, as the folders were always named with a movie title and the year in parentheses, titles in English, German, Japanese, etc. Inside each folder was a small zip file with the same name as the folder, if I recall correctly. All those were found by Housecall. It deleted 600 or so, and I manually deleted the rest. Prior to the BSOD, Limewire had been starting itself repeatedly, until I just uninstalled it, and left it uninstalled. The other folder was similar, though with far fewer files and they were named after software titles, I think.

I downloaded AVG 7.0 on the suggestion of Medion customer service, but it won't install in safe mode. So I have no antivirus software installed that might deal with whatever the problem is. I had mistakenly thought Microsoft was also going after viruses with the AntiSpyware beta, since I just couldn't imagine them still ignoring the need to be able to fix these problems in their operating system. I used to have Symantec Corporate, but had removed it when I installed MSAS. Now if I can get back in, I'll go back to something more reliable and covering more problems.

I ran HijackThis, and got an obviously virus infested log. Since the names of the folders and files in Windows\System32 are random, searching online for matches hasn't helped. So I don't know what virus(es) I have. And I'd like to make sure what exactly I can delete.

I also ran MemTest and my ram seems healthy. None of the other 0x8E errors I found discussed online seem to fit the problem, and especially with the HJT log, I'm convinced the computer's got viruses.

Here's the HJT log:


Logfile of HijackThis v1.99.1
Scan saved at 8:57:15 PM, on 10/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\lncdvy.exe
C:\Documents and Settings\patrick\Desktop\newPrograms\web\hijackThis\hijackthis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [agvs] C:\WINDOWS\system32\vafrwg\agvs.exe
O4 - HKLM\..\Run: [kicd] C:\WINDOWS\system32\ybllqu\kicd.exe
O4 - HKLM\..\Run: [knugtwd] C:\WINDOWS\system32\niuor\knugtwd.exe
O4 - HKLM\..\Run: [etfur] C:\WINDOWS\system32\bactalvh\etfur.exe
O4 - HKLM\..\Run: [ispiovlj] C:\WINDOWS\system32\nooa\ispiovlj.exe
O4 - HKLM\..\Run: [uxpwgb] C:\WINDOWS\system32\jrcdgp\uxpwgb.exe
O4 - HKLM\..\Run: [gxevwr] C:\WINDOWS\system32\ibmb\gxevwr.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [xftnchxr] C:\WINDOWS\system32\ynkkaw\xftnchxr.exe
O4 - HKLM\..\Run: [ieuamx] C:\WINDOWS\system32\powxnp\ieuamx.exe
O4 - HKLM\..\Run: [sanmhip] C:\WINDOWS\system32\ioafsvi\sanmhip.exe
O4 - HKLM\..\Run: [qditibh] C:\WINDOWS\system32\kpgrbo\qditibh.exe
O4 - HKLM\..\Run: [juoy] C:\WINDOWS\system32\rpwnyy\juoy.exe
O4 - HKLM\..\Run: [vqrrmmjt] C:\WINDOWS\system32\nvhe\vqrrmmjt.exe
O4 - HKLM\..\Run: [hguevjc] C:\WINDOWS\system32\wnyd\hguevjc.exe
O4 - HKLM\..\Run: [obdapacn] C:\WINDOWS\system32\obdapacn.exe
O4 - HKLM\..\Run: [xngk] C:\WINDOWS\system32\raqqxfy\xngk.exe
O4 - HKLM\..\Run: [lhmpop] C:\WINDOWS\system32\jccucwsg\lhmpop.exe
O4 - HKLM\..\Run: [onochbln] C:\WINDOWS\system32\eflxumq\onochbln.exe
O4 - HKLM\..\Run: [oobg] C:\WINDOWS\system32\nbeqxt\oobg.exe
O4 - HKLM\..\Run: [uimpdum] C:\WINDOWS\system32\xogmbbxg\uimpdum.exe
O4 - HKLM\..\Run: [lpsmaaw] C:\WINDOWS\system32\spulu\lpsmaaw.exe
O4 - HKLM\..\Run: [pwfwsiif] C:\WINDOWS\system32\swwx\pwfwsiif.exe
O4 - HKLM\..\Run: [ldnsjei] C:\WINDOWS\system32\ajtjnqo\ldnsjei.exe
O4 - HKLM\..\Run: [acbhleb] C:\WINDOWS\system32\rfycpa\acbhleb.exe
O4 - HKLM\..\Run: [tjwvnoqu] C:\WINDOWS\system32\dokcon\tjwvnoqu.exe
O4 - HKLM\..\Run: [qchueph] C:\WINDOWS\system32\svqf\qchueph.exe
O4 - HKLM\..\Run: [MsUpdate] C:\Program Files\MsUpdate\MsUpdate.exe /auto
O4 - HKLM\..\Run: [dngojs] C:\WINDOWS\system32\rxrpr\dngojs.exe
O4 - HKLM\..\Run: [tcrdtr] C:\WINDOWS\system32\edlkm\tcrdtr.exe
O4 - HKLM\..\Run: [stluku] C:\WINDOWS\system32\feyvy\stluku.exe
O4 - HKLM\..\Run: [mjtm] C:\WINDOWS\system32\dcnvrvpr\mjtm.exe
O4 - HKLM\..\Run: [vwkjfva] C:\WINDOWS\system32\jame\vwkjfva.exe
O4 - HKLM\..\Run: [csjy] C:\WINDOWS\system32\rquse\csjy.exe
O4 - HKLM\..\Run: [akbjyaly] C:\WINDOWS\system32\uhwh\akbjyaly.exe
O4 - HKLM\..\Run: [jlefx] C:\WINDOWS\system32\jkrakj\jlefx.exe
O4 - HKLM\..\Run: [nymd] C:\WINDOWS\system32\oqab\nymd.exe
O4 - HKLM\..\Run: [pjquhcaf] C:\WINDOWS\system32\wcsdwr\pjquhcaf.exe
O4 - HKLM\..\Run: [jirqirj] C:\WINDOWS\system32\myau\jirqirj.exe
O4 - HKLM\..\Run: [dipb] C:\WINDOWS\system32\lvthheru\dipb.exe
O4 - HKLM\..\Run: [omcgqa] C:\WINDOWS\system32\kpjcsg\omcgqa.exe
O4 - HKLM\..\Run: [tlpswp] C:\WINDOWS\system32\aghycxrn\tlpswp.exe
O4 - HKLM\..\Run: [gjsjwedi] C:\WINDOWS\system32\swkjpg\gjsjwedi.exe
O4 - HKLM\..\Run: [efrmaog] C:\WINDOWS\system32\tweipxv\efrmaog.exe
O4 - HKLM\..\Run: [mubfcjdi] C:\WINDOWS\system32\lnol\mubfcjdi.exe
O4 - HKLM\..\Run: [gyicighb] C:\WINDOWS\system32\esqwws\gyicighb.exe
O4 - HKLM\..\Run: [jbdginrv] C:\WINDOWS\system32\eawj\jbdginrv.exe
O4 - HKLM\..\Run: [xopfdfkc] C:\WINDOWS\system32\rods\xopfdfkc.exe
O4 - HKLM\..\Run: [apeybq] C:\WINDOWS\system32\rngf\apeybq.exe
O4 - HKLM\..\Run: [plpllkeh] C:\WINDOWS\system32\sesg\plpllkeh.exe
O4 - HKLM\..\Run: [evjdhvs] C:\WINDOWS\system32\eydqkb\evjdhvs.exe
O4 - HKLM\..\Run: [rsdmx] C:\WINDOWS\system32\gqpm\rsdmx.exe
O4 - HKLM\..\Run: [synje] C:\WINDOWS\system32\picy\synje.exe
O4 - HKLM\..\Run: [cglvwqku] C:\WINDOWS\system32\moosc\cglvwqku.exe
O4 - HKLM\..\Run: [ifnm] C:\WINDOWS\system32\lyhbxnu\ifnm.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [gozlnyr] C:\WINDOWS\system32\lncdvy.exe r
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [GIANTAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000140.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000140.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121035336328
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: hguevjcwnyd - Unknown owner - C:\WINDOWS\system32\wnyd\hguevjc.exe
O23 - Service: ispiovljnooa - Unknown owner - C:\WINDOWS\system32\nooa\ispiovlj.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: mubfcjdilnol - Unknown owner - C:\WINDOWS\system32\lnol\mubfcjdi.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: xngkraqqxfy - Unknown owner - C:\WINDOWS\system32\raqqxfy\xngk.exe



Thanks for whatever help I can get. I can still get some work done in safe mode, but it's getting obnoxious!
I'm terribly sorry. Circumstances out of my control delayed me.

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please download Nailfix from here:
http://www.noidea.us/easyfile/file.php?dow…050515010747824
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Once in Safe Mode, please double-click on Nailfix.bat. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Then please run Ewido, and run a full scan. Post the log from the scan here for me.

Then please run HijackThis, click Scan, and check:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Close all open windows except for HijackThis and click Fix Checked.

Next:
Right-click on My Computer
Select Properties
Select Advanced
In the Start up and Recovery section, select Settings; this displays the Startup and Recovery dialog box
In the Write debugging information section, select kernel memory dump

Attempt to start your computer in normal mode. You should get a BSOD.
Then, restart in safe mode.
Email me this file:
c:\Windows\MEMORY.DMP (might wanna zip it up to make it smaller)
you can email me here:
wng_z3r0 (at) spywarewarrior (dot) com

You are emailing me the memory dump when the computer crashed, and what I will attempt to do is debug the file to figure out what's wrong.


Restart your computer in and please post a new HijackThis log, as well as the log from the Ewido scan. (and that memory.dmp file to my email address)

wng
Ewido is now installed. Here's the log from it: ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 7:38:06 PM, 10/25/2005 + Report-Checksum: A343201D + Scan result: [1796] C:\WINDOWS\system32\cmtelzb.exe -> Trojan.Agent.cp : Cleaned with backup :mozilla.6:C:\Documents and Settings\patrick\Application Data\Mozilla\Firefox\Profiles\ycnf4sec.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\WINDOWS\system32\cmtelzb.exe -> TrojanDropper.Paradrop.a : Cleaned with backup ::Report End
Here a new HijackThis log, after running Ewido:

Logfile of HijackThis v1.99.1
Scan saved at 7:43:07 PM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ladpiye.exe
C:\Documents and Settings\patrick\Desktop\newPrograms\web\hijackThis\hijackthis\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [kicd] C:\WINDOWS\system32\ybllqu\kicd.exe
O4 - HKLM\..\Run: [knugtwd] C:\WINDOWS\system32\niuor\knugtwd.exe
O4 - HKLM\..\Run: [etfur] C:\WINDOWS\system32\bactalvh\etfur.exe
O4 - HKLM\..\Run: [ispiovlj] C:\WINDOWS\system32\nooa\ispiovlj.exe
O4 - HKLM\..\Run: [uxpwgb] C:\WINDOWS\system32\jrcdgp\uxpwgb.exe
O4 - HKLM\..\Run: [gxevwr] C:\WINDOWS\system32\ibmb\gxevwr.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [xftnchxr] C:\WINDOWS\system32\ynkkaw\xftnchxr.exe
O4 - HKLM\..\Run: [ieuamx] C:\WINDOWS\system32\powxnp\ieuamx.exe
O4 - HKLM\..\Run: [sanmhip] C:\WINDOWS\system32\ioafsvi\sanmhip.exe
O4 - HKLM\..\Run: [juoy] C:\WINDOWS\system32\rpwnyy\juoy.exe
O4 - HKLM\..\Run: [vqrrmmjt] C:\WINDOWS\system32\nvhe\vqrrmmjt.exe
O4 - HKLM\..\Run: [hguevjc] C:\WINDOWS\system32\wnyd\hguevjc.exe
O4 - HKLM\..\Run: [obdapacn] C:\WINDOWS\system32\obdapacn.exe
O4 - HKLM\..\Run: [xngk] C:\WINDOWS\system32\raqqxfy\xngk.exe
O4 - HKLM\..\Run: [lhmpop] C:\WINDOWS\system32\jccucwsg\lhmpop.exe
O4 - HKLM\..\Run: [onochbln] C:\WINDOWS\system32\eflxumq\onochbln.exe
O4 - HKLM\..\Run: [oobg] C:\WINDOWS\system32\nbeqxt\oobg.exe
O4 - HKLM\..\Run: [uimpdum] C:\WINDOWS\system32\xogmbbxg\uimpdum.exe
O4 - HKLM\..\Run: [pwfwsiif] C:\WINDOWS\system32\swwx\pwfwsiif.exe
O4 - HKLM\..\Run: [ldnsjei] C:\WINDOWS\system32\ajtjnqo\ldnsjei.exe
O4 - HKLM\..\Run: [acbhleb] C:\WINDOWS\system32\rfycpa\acbhleb.exe
O4 - HKLM\..\Run: [qchueph] C:\WINDOWS\system32\svqf\qchueph.exe
O4 - HKLM\..\Run: [MsUpdate] C:\Program Files\MsUpdate\MsUpdate.exe /auto
O4 - HKLM\..\Run: [dngojs] C:\WINDOWS\system32\rxrpr\dngojs.exe
O4 - HKLM\..\Run: [stluku] C:\WINDOWS\system32\feyvy\stluku.exe
O4 - HKLM\..\Run: [mjtm] C:\WINDOWS\system32\dcnvrvpr\mjtm.exe
O4 - HKLM\..\Run: [vwkjfva] C:\WINDOWS\system32\jame\vwkjfva.exe
O4 - HKLM\..\Run: [akbjyaly] C:\WINDOWS\system32\uhwh\akbjyaly.exe
O4 - HKLM\..\Run: [jlefx] C:\WINDOWS\system32\jkrakj\jlefx.exe
O4 - HKLM\..\Run: [nymd] C:\WINDOWS\system32\oqab\nymd.exe
O4 - HKLM\..\Run: [pjquhcaf] C:\WINDOWS\system32\wcsdwr\pjquhcaf.exe
O4 - HKLM\..\Run: [omcgqa] C:\WINDOWS\system32\kpjcsg\omcgqa.exe
O4 - HKLM\..\Run: [tlpswp] C:\WINDOWS\system32\aghycxrn\tlpswp.exe
O4 - HKLM\..\Run: [gjsjwedi] C:\WINDOWS\system32\swkjpg\gjsjwedi.exe
O4 - HKLM\..\Run: [efrmaog] C:\WINDOWS\system32\tweipxv\efrmaog.exe
O4 - HKLM\..\Run: [mubfcjdi] C:\WINDOWS\system32\lnol\mubfcjdi.exe
O4 - HKLM\..\Run: [gyicighb] C:\WINDOWS\system32\esqwws\gyicighb.exe
O4 - HKLM\..\Run: [jbdginrv] C:\WINDOWS\system32\eawj\jbdginrv.exe
O4 - HKLM\..\Run: [xopfdfkc] C:\WINDOWS\system32\rods\xopfdfkc.exe
O4 - HKLM\..\Run: [apeybq] C:\WINDOWS\system32\rngf\apeybq.exe
O4 - HKLM\..\Run: [plpllkeh] C:\WINDOWS\system32\sesg\plpllkeh.exe
O4 - HKLM\..\Run: [evjdhvs] C:\WINDOWS\system32\eydqkb\evjdhvs.exe
O4 - HKLM\..\Run: [rsdmx] C:\WINDOWS\system32\gqpm\rsdmx.exe
O4 - HKLM\..\Run: [synje] C:\WINDOWS\system32\picy\synje.exe
O4 - HKLM\..\Run: [cglvwqku] C:\WINDOWS\system32\moosc\cglvwqku.exe
O4 - HKLM\..\Run: [ifnm] C:\WINDOWS\system32\lyhbxnu\ifnm.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [dvbztyq] C:\WINDOWS\system32\ladpiye.exe r
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [GIANTAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000140.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000140.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121035336328
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: hguevjcwnyd - Unknown owner - C:\WINDOWS\system32\wnyd\hguevjc.exe
O23 - Service: ispiovljnooa - Unknown owner - C:\WINDOWS\system32\nooa\ispiovlj.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: mubfcjdilnol - Unknown owner - C:\WINDOWS\system32\lnol\mubfcjdi.exe
O23 - Service: xngkraqqxfy - Unknown owner - C:\WINDOWS\system32\raqqxfy\xngk.exe
Ok: I believe you have a rootkit on your system :(

Please download this:
http://www.sysinternals.com/Files/RootkitRevealer.zip

then extract the file.
Next doubleclick on rootkitrevealer.exe
hit the scan button.
When it's done, go up to File > Save. Choose to save it to your desktop.
Open rootkitrevealer.txt on your desktop and copy the entire contents and paste them here.


Also give me a HJT startup log by opening hijackthis
then click on 'open misc tools'
put a check mark next to list also minor sections (full)
put a check mark next to list empty sections (complete)

Then click "generate startup log"


and also paste that log as a reply.



The removal of all this carp** is going to take awhile, and with all rootkits, I cannot guarantee the cleanliness of your computer. I absolutely hate recommending to reformat, but in this case it is an option to be considered.

wng
Ok, no problem…
1. Do you have access to a computer with a cd burner?
2. Do you have your XP cd?
3. Try running this tool:
http://www.f-secure.com/blacklight/try.shtml

It is in Beta, so there is always the chance that it will make things worse, but I have used the tool in the past w/o problems. You should back up your data first just in case.

Also, what are you using this computer for mostly? Are you doing any banking etc?
wng
Alright, many dozens of GB are now backed up. 1. Yes, I have access to a computer with a cd burner. 2. Yes, I have my xp cd. 3. Blacklight can't be run in safe mode. I do some online transactions once in a while on this computer, but mostly on a different one. Mostly it's for xml /xslt programming, imaging processing, etc. It's been fired as a downloading computer - I now have one dedicated just to that. Any hope still? I'm close to formatting, but I never really can spare two days of reinstalling!!! Thanks.
it will probably take longer than 2 days to clean this out… this is a really nasty infection.

If you do decide to reformat, please let me know beforehand :)

if you'd like to continue trying to clean the computer out, please go to start->run->msconfig
Select diagnostic startup.
hit 'ok'
now try to reboot your computer in normal mode. does it work?


Also run this (in normal mode if you get there, otherwise in safe mode)
Download Silentrunners.zip from here and unzip it a new folder on your desktop.
  • Run the SilentRunners.vbs file.
  • You will receive a prompt: "Do you want to skip supplementary searches?" - click NO
  • If your antivirus has a script blocker, you will get a warning asking if you want to allow SilentRunners.vbs to run.
  • This script is not malicious so please allow it.
  • A text file will appear in the folder - it's not done, let it run (it won't appear to be doing anything!)
  • Once the "All Done!" prompt flashes up, open the text file and copy & paste it in your next reply.
wng
it was also suggested to try this:
Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click Remove to remove any items found.

Exit Spy Sweeper.
Spy Sweeper found about 50 items, 600 traces and removed them.

Msconfig didn't help starting in normal mode - still got the bsod.

Here's the tet file from Silentrunners:

"Silent Runners.vbs", revision 41, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Google Desktop Search" = ""C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup" [null data]
"Exodus" = "C:\Program Files\Exodus\Exodus.exe" ["Jabber.org"]
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"KernelFaultCheck" = "%systemroot%\system32\dumprep 0 -k" [MS]
"winupdate" = "C:\Program Files\winupdate\winupdate.exe /auto" [file not found]
"uxpwgb" = "C:\WINDOWS\system32\jrcdgp\uxpwgb.exe" [null data]
"SynTPLpr" = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" ["Synaptics, Inc."]
"SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" ["Sun Microsystems, Inc."]
"SpySweeper" = ""C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray" ["Webroot Software, Inc."]
"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
"snss Launcher" = ""C:\Program Files\snss\snss.exe"" [file not found]
"pwfwsiif" = "C:\WINDOWS\system32\swwx\pwfwsiif.exe" [null data]
"pjquhcaf" = "C:\WINDOWS\system32\wcsdwr\pjquhcaf.exe" [null data]
"PHIME2002ASync" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC" [MS]
"PHIME2002A" = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName" [MS]
"obdapacn" = "C:\WINDOWS\system32\obdapacn.exe" [file not found]
"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
"MSPY2002" = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC" [null data]
"juoy" = "C:\WINDOWS\system32\rpwnyy\juoy.exe" [null data]
"IMJPMIG8.1" = ""C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32" [MS]
"IgfxTray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
"gcasServ" = ""C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"" [MS]
"FineReader7NewsReaderPro" = "C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe" ["ABBYY (BIT Software)"]
"AGRSMMSG" = "AGRSMMSG.exe" ["Agere Systems"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ {++}
"WIAWizardMenu" = "RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu" [MS]
"MicrosoftAntiSpywareCleaner" = "C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe" [MS]
"GIANTAntiSpywareCleaner" = "C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{A46332A0-DB1E-11CF-B26A-0020AF9D1559}" = "Imaging Flow"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\IMAGIN~1\FloShExt.dll" ["Eastman Software, Inc., A Kodak Business"]
"{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
"{63AFBDFB-5EF8-4791-AF79-9A3C0DE48974}" = "EditPlus Context Menu Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EditPlus 2\eppshell.dll" [null data]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{9EF34FF2-3396-4527-9D27-04C8C1C67806}" = "Microsoft AntiSpyware Service Hook"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft AntiSpyware\shellextension.dll" [MS]
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: "]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
INFECTION WARNING! WRNotifier\DLLName = "WRLogonNTF.dll" ["Webroot Software, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
EditPlus\(Default) = "{63AFBDFB-5EF8-4791-AF79-9A3C0DE48974}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\EditPlus 2\eppshell.dll" [null data]
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
FineReader\(Default) = "{AC0DD14A-8F29-4F88-BE1D-0F0ED1B06C9F}"
-> {CLSID}\InProcServer32\(Default) = "c:\program files\abbyy finereader 7.0 professional edition\fecmenu.dll" ["ABBYY (BIT Software)"]
SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" ["Webroot Software, Inc."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Active Desktop and Wallpaper:
—————————–

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\WINDOWS\Firefox Wallpaper.bmp"


Enabled Screen Saver:
———————

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]


Startup items in "patrick" & "All Users" startup folders:
———————————————————

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork1.dll [null data], 01 - 02, 18
%SystemRoot%\system32\mswsock.dll [MS], 03 - 05, 08 - 17
%SystemRoot%\system32\rsvpsp.dll [MS], 06 - 07


Toolbars, Explorer Bars, Extensions:
————————————

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll" ["Sun Microsystems, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


All Non-Disabled Services (Display Name, Service Name, Path {Service DLL}):
—————————————————————————

Adobe LM Service, Adobe LM Service, ""C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"" [null data]
Application Management, AppMgmt, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\appmgmts.dll" [file not found]}
ASP.NET State Service, aspnet_state, "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe" [MS]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]}
KFFI, KFFI, "C:\DOCUME~1\patrick\LOCALS~1\Temp\KFFI.exe" ["Sysinternals - www.sysinternals.com"]
LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
Logical Disk Manager Administrative Service, dmadmin, "C:\WINDOWS\System32\dmadmin.exe /com" ["Microsoft Corp., Veritas Software"]
Network Provisioning Service, xmlprov, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\xmlprov.dll" [MS]}
Office Source Engine, ose, ""C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"" [MS]
PMCZZFE, PMCZZFE, "C:\DOCUME~1\patrick\LOCALS~1\Temp\PMCZZFE.exe" ["Sysinternals - www.sysinternals.com"]
Portable Media Serial Number Service, WmdmPmSN, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system32\MsPMSNSv.dll" [MS]}
Webroot Spy Sweeper Engine, svcWRSSSDK, "C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe" ["Webroot Software, Inc."]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]
WMI Performance Adapter, WmiApSrv, "C:\WINDOWS\system32\wbem\wmiapsrv.exe" [MS]


Print Monitors:
—————

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Dell Network Port\Driver = "LEXLMPM.DLL" ["Lexmark International, Inc."]
Lexmark Z25-35 Color Jetprinter LangMon\Driver = "LXAXSLM.DLL" ["Lexmark"]


———-
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 181 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 5 seconds.
———- (total run time: 211 seconds)
Basically you're gonna follow most of the steps here:
http://ubcd4win.com/howto.htm

don't worry about slipstreaming XP UNLESS it doesn't have SP1 or SP2 already on the disk


You're gonna need to go here:
http://downloads.littlbuger.info/index.php?dir=UBCD4Win/

download these 3 files:
pebuilder313.zip
UBCD4WinDriversV201.exe
UBCD4WinV255.exe

IMPORTANT: put all of these files in the root (aka c:\ )
it makes things run MUCH more smoothly

Then you're gonna extract the pebuilder ZIP file. Do this AFTER you've downloaded all the other files

Once again, make sure to unzip the folder to the root.
(so you should have a folder here: c:\pebuilder )

Open up the c:\pebuilder folder
There will be a folder called "plugin"
delete that folder.

Now, double click on this file that you downloaded:
UBCD4WinV255.exe
Click the accept button.
IMPORTANT: make sure to extract the file here:
c:\pebuilder313

Next, double click on this file that you already downloaded: UBCD4WinDriversV201.exe

Click the accept button.
IMPORTANT: make sure to extract the files here:
C:\pebuilder313\drivers


Next, make a folder in the c:\ drive called XPDISK

Then, go to start->control panel->folder options->view
YOu need to click the radio button "show hidden files and folders"
THen UNCHECK the box that says "hide protected operating system files (recommended)

Then, pop your XP cd into your CD drive
CLose any windows that open up. Right click your CD drive and hit "open"
Highlight everything, and then go to edit->copy

Then, go to c:\xpdisk
go to edit->paste

If you did this right, all the files on the CD should transfer to the folder. This will take some time depending on the speed of your computer.

ONce that is done, you are ready to build the disk

Go to c:\pebuilder313\
doubleclick on PEbuilder.exe
Click the I agree button

In the build box, enter this location:
c:\xpdisk

Leave the custom box blank
for output, leave it as bartPE
MAKE SURE TO CHECK THE BOX THAT SAYS create an ISO image.


do NOT check the box that says burn to a cd
then click the build button. Click yes to create the directory.

Hopefully you will get no errors. If you do, try running pebuilder.exe again and attempting it again. If it still doesn't work, let me know.

Hopefully, you will get an ISO image here:
c:\pebuilder313\bartpe

THen you need to use your cd burning program to burn that ISO to a disk.

I don't wanna post too many instructions at one time, so if you get this far, post back and we'll go from there

GOOD LUCK!!
wng
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI