This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer is acting weird, and constantly freezes.. ple

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

maxwax,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\Documents and Settings\TUNDE KOMOLAFE\Desktop\PopularScreensaversSetup2.2.60.11-2.ZRfox000.exe
    C:\Documents and Settings\TUNDE KOMOLAFE\My Documents\Funny UST Scandal.exe
    C:\Documents and Settings\TUNDE KOMOLAFE\My Documents\Investment Properties\CursorManiaSetup2.3.50.21.ZCman000.exe
    C:\Program Files\Internet Explorer\msimg32.dll
    F:\smss.exe
    
    Folder::
    C:\SDFix
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a6be696-b7df-11dd-9766-00123f78463a}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Also, please also post another HijackThis log.
Tomk,

Below is the contents of the CFScript log

ComboFix 08-11-21.04 - TUNDE KOMOLAFE 2008-11-21 23:28:56.3 - NTFSx86
Running from: f:\virus treatment programs\ComboFix.exe
Command switches used :: c:\documents and settings\TUNDE KOMOLAFE\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\documents and settings\TUNDE KOMOLAFE\Desktop\PopularScreensaversSetup2.2.60.11-2.ZRfox000.exe
c:\documents and settings\TUNDE KOMOLAFE\My Documents\Funny UST Scandal.exe
c:\documents and settings\TUNDE KOMOLAFE\My Documents\Investment Properties\CursorManiaSetup2.3.50.21.ZCman000.exe
c:\program files\Internet Explorer\msimg32.dll
F:\smss.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\TUNDE KOMOLAFE\Desktop\PopularScreensaversSetup2.2.60.11-2.ZRfox000.exe
c:\documents and settings\TUNDE KOMOLAFE\My Documents\Funny UST Scandal.exe
c:\documents and settings\TUNDE KOMOLAFE\My Documents\Investment Properties\CursorManiaSetup2.3.50.21.ZCman000.exe
c:\program files\Internet Explorer\msimg32.dll
C:\SDFix
c:\sdfix\Add_DBFix_RunOnce_key.inf
c:\sdfix\apps\assosfix.reg
c:\sdfix\apps\Cghtme.exe
c:\sdfix\apps\cliptext.exe
c:\sdfix\apps\DBFix.inf
c:\sdfix\apps\download.exe
c:\sdfix\apps\dummy.sys
c:\sdfix\apps\Enable_Command_Prompt.inf
c:\sdfix\apps\Enable_Command_Prompt.reg
c:\sdfix\apps\ERDNT.E_E
c:\sdfix\apps\ERDNTDOS.LOC
c:\sdfix\apps\ERDNTWIN.LOC
c:\sdfix\apps\ERUNT.EXE
c:\sdfix\apps\ERUNT.LOC
c:\sdfix\apps\fix.reg
c:\sdfix\apps\FixBeep.reg
c:\sdfix\apps\FixBH.reg
c:\sdfix\apps\FixComponents.reg
c:\sdfix\apps\FIXCU.reg
c:\sdfix\apps\FIXLM.reg
c:\sdfix\apps\FixPath.exe
c:\sdfix\apps\FixRedir.reg
c:\sdfix\apps\FixSchedule.reg
c:\sdfix\apps\FixWebCheck.reg
c:\sdfix\apps\fixXP.reg
c:\sdfix\apps\FixXPsp2.reg
c:\sdfix\apps\grep.exe
c:\sdfix\apps\HaxdFix.reg
c:\sdfix\apps\HPFix.reg
c:\sdfix\apps\HPFix2.reg
c:\sdfix\apps\HPFix3.reg
c:\sdfix\apps\HPFix4.reg
c:\sdfix\apps\HPFix5.reg
c:\sdfix\apps\HPFix6.reg
c:\sdfix\apps\HPFix7.reg
c:\sdfix\apps\HPFix8.reg
c:\sdfix\apps\HPFix9.reg
c:\sdfix\apps\Installed.txt
c:\sdfix\apps\isadmin.exe
c:\sdfix\apps\leg2.txt
c:\sdfix\apps\legacy.txt
c:\sdfix\apps\legacybk.txt
c:\sdfix\apps\locate.com
c:\sdfix\apps\LS.exe
c:\sdfix\apps\MD5File.exe
c:\sdfix\apps\moveex.exe
c:\sdfix\apps\MyGcpvFix.reg
c:\sdfix\apps\MyGkFix2.reg
c:\sdfix\apps\Process.exe
c:\sdfix\apps\procs.exe
c:\sdfix\apps\psservice.exe
c:\sdfix\apps\Rem.txt
c:\sdfix\apps\Rem2.txt
c:\sdfix\apps\Replace\regedit.exe
c:\sdfix\apps\Replace\w2k\AUTOEXEC.NT
c:\sdfix\apps\Replace\w2k\beep.sys
c:\sdfix\apps\Replace\w2k\command.com
c:\sdfix\apps\Replace\w2k\command.PIF
c:\sdfix\apps\Replace\w2k\CONFIG.NT
c:\sdfix\apps\Replace\w2k\null.sys
c:\sdfix\apps\Replace\xp\AUTOEXEC.NT
c:\sdfix\apps\Replace\xp\beep.sys
c:\sdfix\apps\Replace\xp\command.com
c:\sdfix\apps\Replace\xp\command.PIF
c:\sdfix\apps\Replace\xp\CONFIG.NT
c:\sdfix\apps\Replace\xp\null.sys
c:\sdfix\apps\report.txt
c:\sdfix\apps\Reset_AppInit_DLLs.reg
c:\sdfix\apps\RestartIt!.exe
c:\sdfix\apps\Restore_SafeBoot_Windows2000.reg
c:\sdfix\apps\Restore_SafeBoot_WindowsXP.reg
c:\sdfix\apps\Restore_SafeBoot_WindowsXP_SP2.reg
c:\sdfix\apps\Restore_SafeBoot_WindowsXP_SP3.reg
c:\sdfix\apps\Restore_SecurityCenter.reg
c:\sdfix\apps\Restore_SharedAccess.reg
c:\sdfix\apps\sc.exe
c:\sdfix\apps\sed.exe
c:\sdfix\apps\SF.exe
c:\sdfix\apps\shutdown.exe
c:\sdfix\apps\srv2.txt
c:\sdfix\apps\srv2bk.txt
c:\sdfix\apps\svc.txt
c:\sdfix\apps\svcbk.txt
c:\sdfix\apps\Swreg.exe
c:\sdfix\apps\swsc.exe
c:\sdfix\apps\UnRAR.exe
c:\sdfix\apps\unzip.exe
c:\sdfix\apps\vfind.exe
c:\sdfix\apps\WINMSG.EXE
c:\sdfix\apps\winsec.reg
c:\sdfix\apps\zip.exe
c:\sdfix\backups\backupreg.zip
c:\sdfix\backups\backups.zip
c:\sdfix\backups\catchme.log
c:\sdfix\backups\HOSTS
c:\sdfix\catchme.exe
c:\sdfix\DBFix.bat
c:\sdfix\dummy.sys
c:\sdfix\Report.txt
c:\sdfix\RunThis.bat
c:\sdfix\SDFIX_ReadMe_Online.url
c:\sdfix\W2K_VirusAlert_Repair.inf
c:\sdfix\XP_VirusAlert_Repair.inf

.
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.

2008-11-21 23:04 . 2008-11-21 23:04 0 –a—— c:\windows\VPC32.INI
2008-11-21 21:33 . 2008-11-21 21:33 d——– c:\program files\Symantec_Client_Security
2008-11-21 21:33 . 2008-11-21 21:33 d——– c:\program files\Symantec
2008-11-21 21:33 . 2008-11-21 21:33 d——– c:\documents and settings\All Users\Application Data\Symantec
2008-11-21 21:33 . 2008-11-21 21:32 124,167 –a—— c:\windows\system32\SYMEVNT.386
2008-11-21 21:33 . 2008-11-21 21:32 83,208 –a—— c:\windows\system32\S32EVNT1.DLL
2008-11-21 21:33 . 2008-11-21 21:32 73,496 –a—— c:\windows\system32\drivers\SYMEVENT.SYS
2008-11-21 18:29 . 2008-11-21 18:29 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-21 18:29 . 2008-11-21 18:29 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-21 13:27 . 2008-11-21 13:27 d——– c:\windows\system32\LogFiles
2008-11-21 12:44 . 2008-11-21 12:44 d——– c:\documents and settings\TUNDE KOMOLAFE\Application Data\Viewpoint
2008-11-21 10:44 . 2004-08-10 05:04 59,392 –a—— c:\windows\system32\dllcache\ehtray.exe
2008-11-21 10:44 . 2003-08-11 17:10 32,768 –a—— c:\windows\vsncp106.exe
2008-11-21 09:25 . 2008-11-21 09:25 d——– C:\log
2008-11-21 01:29 . 2008-11-21 01:29 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-21 01:29 . 2008-11-21 01:29 d——– c:\documents and settings\TUNDE KOMOLAFE\Application Data\Malwarebytes
2008-11-21 01:29 . 2008-11-21 01:29 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-21 01:29 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-21 01:29 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-21 00:58 . 2008-11-21 00:58 d——– c:\windows\ERUNT
2008-11-20 22:57 . 2008-11-20 22:57 d——– c:\program files\Trend Micro
2008-11-20 22:42 . 2008-11-20 22:42 d——– c:\program files\ERUNT
2008-11-20 21:47 . 2008-11-20 21:47 d——– c:\program files\CONEXANT
2008-11-20 21:34 . 2001-01-15 02:07 311,824 –a—— c:\windows\eFaxview.exe
2008-11-20 21:23 . 2008-11-20 21:47 4,168 –a—— C:\INFCACHE.1
2008-11-20 21:19 . 2008-11-20 21:19 d——– c:\windows\system32\QuickTime
2008-11-20 21:14 . 2008-11-20 21:14 d——– c:\windows\LastGood(2)
2008-11-20 21:10 . 2008-11-20 21:10 d——– c:\windows\Profiles
2008-11-20 21:10 . 2008-11-20 21:10 d——– c:\program files\ACD Systems
2008-11-20 18:11 . 2008-11-20 18:11 d——– c:\windows\system32\scripting
2008-11-20 18:11 . 2008-11-20 18:11 d——– c:\windows\l2schemas
2008-11-20 18:09 . 2008-11-20 18:11 d——– c:\windows\ServicePackFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 02:33 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-21 23:29 ——— d—–w c:\program files\Java
2008-11-21 23:09 ——— d—–w c:\program files\Yahoo!
2008-11-21 23:09 ——— d—–w c:\documents and settings\All Users\Application Data\YAHOO
2008-11-21 23:08 ——— d—–w c:\program files\WildTangent
2008-11-21 23:01 ——— d—–w c:\program files\MUSICMATCH
2008-11-21 16:31 ——— d—–w c:\program files\QuickTime
2008-11-21 16:31 ——— d—–w c:\program files\DellSupport
2008-11-21 10:08 ——— d—–w c:\program files\McAfee.com
2008-11-21 10:03 ——— d—–w c:\program files\GemMaster
2008-11-21 09:59 ——— d—–w c:\program files\NetZero
2008-11-21 09:59 ——— d—–w c:\program files\ESPNMotion
2008-11-21 09:58 ——— d—–w c:\program files\DIGStream
2008-11-21 09:53 ——— d—–w c:\documents and settings\All Users\Application Data\GTek
2008-11-21 09:51 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-11-21 09:00 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-21 09:00 ——— d—–w c:\program files\Unity
2008-11-21 09:00 ——— d—–w c:\program files\Nick Arcade
2008-11-21 08:57 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee.com
2008-11-21 02:30 ——— d—–w c:\program files\Cartoon Network
2008-11-21 02:20 ——— d—–w c:\program files\Bonjour
2008-11-21 02:19 ——— d—–w c:\program files\Apple Software Update(2)
2008-11-21 02:19 ——— d—–w c:\documents and settings\TUNDE KOMOLAFE\Application Data\mjusbsp
2008-11-21 02:19 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-21 02:14 ——— d—–w c:\program files\Common Files\SupportSoft
2008-11-21 02:10 ——— d—–w c:\program files\Common Files\Adobe
2008-11-21 02:10 ——— d—–w c:\program files\Canon
2008-10-24 11:10 453,632 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2004-08-10 11:00 94,784 -csh–w c:\windows\twain.dll
2004-08-10 11:00 50,688 –sh–w c:\windows\twain_32.dll
2007-11-05 19:28 104 -csh–r c:\windows\system32\10FBA8EB3D.sys
2007-11-05 19:28 4,184 -csha-w c:\windows\system32\KGyGaAvL.sys
2004-08-10 11:00 1,028,096 –sh–w c:\windows\system32\mfc42.dll
2004-08-10 11:00 54,784 –sh–w c:\windows\system32\msvcirt.dll
2004-08-10 11:00 413,696 –sh–w c:\windows\system32\msvcp60.dll
2004-08-10 11:00 343,040 –sh–w c:\windows\system32\msvcrt.dll
2007-12-04 18:38 550,912 –sha-w c:\windows\system32\oleaut32.dll
2004-08-10 11:00 83,456 –sh–w c:\windows\system32\olepro32.dll
2004-08-10 11:00 11,776 –sh–w c:\windows\system32\regsvr32.exe
.

((((((((((((((((((((((((((((( snapshot@2008-11-21_ 9.34.38.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-10 10:04:42 59,392 —-a-w c:\windows\ehome\ehtray.exe
+ 2003-01-10 16:39:26 28,723 —-a-w c:\windows\system32\CBA.DLL
+ 2004-12-06 07:05:00 127,035 —-a-w c:\windows\system32\dla\tfswctrl.exe
- 2003-11-19 22:36:26 24,681 -c–a-w c:\windows\system32\java.exe
+ 2008-11-21 23:29:08 144,792 —-a-w c:\windows\system32\java.exe
- 2003-11-19 22:36:30 28,779 -c–a-w c:\windows\system32\javaw.exe
+ 2008-11-21 23:29:08 144,792 —-a-w c:\windows\system32\javaw.exe
+ 2008-11-21 23:29:08 148,888 —-a-w c:\windows\system32\javaws.exe
+ 2003-01-10 16:39:26 41,017 —-a-w c:\windows\system32\Msgsys.dll
+ 2003-05-21 06:19:00 45,056 —-a-w c:\windows\system32\NavLogon.dll
+ 2003-01-10 16:39:26 77,875 —-a-w c:\windows\system32\NTS.DLL
+ 2003-01-10 16:39:26 65,590 —-a-w c:\windows\system32\PDS.DLL
+ 2008-11-22 04:32:43 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5ac.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-17 4670704]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"cdloader"="c:\documents and settings\TUNDE KOMOLAFE\Application Data\mjusbsp\cdloader2.exe" [2008-07-22 50520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 163840]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 1005096]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-21 136600]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 90112]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 c:\windows\stsystra.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]

c:\documents and settings\TUNDE KOMOLAFE\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-11 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave2"= ev19x8.dll
"midi1"= ev19x8.dll
"mixer1"= ev19x8.dll
"aux"= ev19x8.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\TUNDE KOMOLAFE\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service

S3 SNCP106;PC Camera (6009 CIF);c:\windows\system32\DRIVERS\sncp106.sys [2005-12-07 194688]
.
Contents of the 'Scheduled Tasks' folder

2008-11-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []

2008-11-21 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (D8HKTP81-DIRAN KOMOLAFE).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe [2004-07-01 15:15]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 23:32:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\NavLogon.dll

PROCESS: c:\windows\system32\lsass.exe
-> c:\windows\system32\McRtl32.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\windows\ehome\ehRecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\progra~1\McAfee.com\VSO\mcvsrte.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\progra~1\McAfee.com\VSO\oasclnt.exe
c:\progra~1\SYMANT~1\SYMANT~1\Rtvscan.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2008-11-21 23:35:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-22 04:35:36
ComboFix2.txt 2008-11-21 22:57:30
ComboFix3.txt 2008-11-21 14:35:44

Pre-Run: 53,998,182,400 bytes free
Post-Run: 54,044,860,416 bytes free

328 — E O F — 2008-11-21 08:43:52

—————————————————————————————-

Below is a new HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:40:08 PM, on 11/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll (file missing)
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\TUNDE KOMOLAFE\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: SoftStuff Wallpaper Changer.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…155/mcfscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 9868 bytes
maxwax,

You have traces of McAfee and Symantec (Norton) Anti-Virus. You need to remove one of them. You should be able to uninstall them in Add/Remove programs in your control panel.
Tomk, I have been trying to uninstall McAfee from my computer for a while now , but each time i tried i get a message saying "Could not open Install.Log file." However, I was able to remove Norton Anti-Virus. There are some game applications I tried to remove through Add/Remove but I always get the message… "Could not open Install.Log file. Is there any other way I can remove McAfee from my computer and these game softwares?
maxwax,

You can use this tool: McAfee Removal Tool to remove the McAfee program.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

Also please provide a list of the programs you are trying to uninstall.
Tomk, Here is the contents of the DDS.txt report below DDS (Version 1.0) - NTFSx86 Run by [removed] at 2:13:42.64 on Sat 11/22/2008 ============== Psuedo HJT Report =============== uStart Page = hxxp://www.yahoo.com uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNxmk572YYUS&fl=0&ptb=Xke_TZBFk3GrRGm3_vWLfg&url=http://www.ask.com/web&q={searchTerms}&l=zn&o=sb mStart Page = hxxp://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://www.google.com/search?q=%s uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Yahoo! Pager] "c:\progra~1\yahoo!\messen~1\YAHOOM~1.EXE" -quiet uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [cdloader] "c:\documents and settings\tunde komolafe\application data\mjusbsp\cdloader2.exe" MAGICJACK mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRunOnce: [RunNarrator] Narrator.exe IE: &Search IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSA: Authentication Packages = msv1_0 nwprovau ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2008-11-21 21:33 –d—– c:\program files\Symantec 2008-11-21 21:33 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2008-11-21 18:29 410,976 a——- c:\windows\system32\deploytk.dll 2008-11-21 18:29 73,728 a——- c:\windows\system32\javacpl.cpl 2008-11-21 13:27 –d—– c:\windows\system32\LogFiles 2008-11-21 12:44 –d—– c:\docume~1\tundek~1\applic~1\Viewpoint 2008-11-21 10:44 59,392 a——- c:\windows\system32\dllcache\ehtray.exe 2008-11-21 10:44 32,768 a——- c:\windows\vsncp106.exe 2008-11-21 09:27 a-dshr– C:\cmdcons 2008-11-21 09:25 161,792 a——- c:\windows\SWREG.exe 2008-11-21 09:25 98,816 a——- c:\windows\sed.exe 2008-11-21 09:25 –d—– C:\log 2008-11-21 01:29 –d—– c:\docume~1\tundek~1\applic~1\Malwarebytes 2008-11-21 01:29 15,504 a——- c:\windows\system32\drivers\mbam.sys 2008-11-21 01:29 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2008-11-21 01:29 –d—– c:\program files\Malwarebytes' Anti-Malware 2008-11-21 01:29 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2008-11-21 00:58 –d—– c:\windows\ERUNT 2008-11-20 22:57 –d—– c:\program files\Trend Micro 2008-11-20 21:47 –d—– c:\program files\CONEXANT 2008-11-20 21:34 311,824 a——- c:\windows\eFaxview.exe 2008-11-20 21:23 4,168 a——- C:\INFCACHE.1 2008-11-20 21:19 –d—– c:\windows\system32\QuickTime 2008-11-20 21:14 –d—– c:\windows\LastGood(2) 2008-11-20 21:10 –d—– c:\program files\ACD Systems 2008-11-20 21:10 –d—– c:\windows\Profiles 2008-11-20 18:11 –d—– c:\windows\system32\scripting 2008-11-20 18:11 –d—– c:\windows\l2schemas 2008-11-20 18:09 –d—– c:\windows\ServicePackFiles 2008-11-20 18:07 –d—– c:\windows\network diagnostic ==================== Find3M ==================== 2008-11-22 00:52 –d—– c:\program files\common files\Symantec Shared 2008-11-21 18:09 –d—– c:\program files\Yahoo! 2008-11-21 18:08 –d—– c:\program files\WildTangent 2008-11-21 18:01 –d—– c:\program files\MUSICMATCH 2008-11-21 11:31 –d—– c:\program files\DellSupport 2008-11-21 05:03 –d—– c:\program files\GemMaster 2008-11-21 04:59 –d—– c:\program files\ESPNMotion 2008-11-21 04:59 –d—– c:\program files\NetZero 2008-11-21 04:58 –d—– c:\program files\DIGStream 2008-11-21 04:51 –d—– c:\program files\common files\Sonic Shared 2008-11-21 04:00 –d—– c:\program files\Unity 2008-11-21 04:00 –d—– c:\program files\Nick Arcade 2008-11-20 21:30 –d—– c:\program files\Cartoon Network 2008-11-20 21:20 –d—– c:\program files\Bonjour 2008-11-20 21:19 –d—– c:\docume~1\tundek~1\applic~1\mjusbsp 2008-11-20 21:19 –d—– c:\program files\Apple Software Update(2) 2008-11-20 21:14 –d—– c:\program files\common files\SupportSoft 2008-11-20 21:11 –d—– c:\program files\Windows NT 2008-11-20 21:10 –d—– c:\program files\Messenger 2008-11-20 21:10 –d—– c:\program files\Canon 2008-11-20 18:14 88,699 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2008-10-24 06:10 453,632 ——– c:\windows\system32\dllcache\mrxsmb.sys 2008-10-16 14:13 1,809,944 a——- c:\windows\system32\dllcache\wuaueng.dll 2008-10-16 14:13 202,776 a——- c:\windows\system32\dllcache\wuweb.dll 2008-10-16 14:12 323,608 a——- c:\windows\system32\dllcache\wucltui.dll 2008-10-16 14:12 561,688 a——- c:\windows\system32\dllcache\wuapi.dll 2008-10-16 14:09 92,696 a——- c:\windows\system32\dllcache\cdm.dll 2008-10-16 14:09 51,224 a——- c:\windows\system32\dllcache\wuauclt.exe 2008-10-16 14:08 34,328 a——- c:\windows\system32\dllcache\wups.dll 2008-10-15 11:57 332,800 a——- c:\windows\system32\netapi32(2).dll 2008-10-15 11:57 332,800 ——– c:\windows\system32\dllcache\netapi32.dll 2008-10-03 12:41 6,066,176 ——– c:\windows\system32\dllcache\ieframe.dll 2008-09-30 16:43 1,286,152 a——- c:\windows\system32\msxml4.dll 2008-09-15 06:57 1,846,016 a——- c:\windows\system32\win32k.sys 2008-09-15 06:57 1,846,016 ——– c:\windows\system32\dllcache\win32k.sys 2008-09-04 11:42 1,106,944 a——- c:\windows\system32\msxml3.dll 2008-09-04 11:42 1,106,944 ——– c:\windows\system32\dllcache\msxml3.dll 2008-08-28 05:04 333,056 ——– c:\windows\system32\dllcache\srv.sys 2008-08-27 03:24 3,593,216 ——– c:\windows\system32\dllcache\mshtml.dll 2008-08-25 03:38 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2008-08-25 03:37 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2008-08-15 13:37 –d—– c:\docume~1\alluse~1\applic~1\Intenium 2008-08-15 11:44 –d—– c:\docume~1\tundek~1\applic~1\SBTT 2008-08-15 09:23 –d—– c:\docume~1\tundek~1\applic~1\FrimaStudio 2008-08-14 18:51 –d—– c:\docume~1\tundek~1\applic~1\PlayFirst 2008-08-14 18:51 –d—– c:\docume~1\alluse~1\applic~1\PlayFirst 2008-08-14 17:59 –d—– c:\docume~1\tundek~1\applic~1\Super-Cow 2008-07-30 06:57 –d—– c:\docume~1\tundek~1\applic~1\iMesh 2008-07-27 13:10 –d—– c:\docume~1\tundek~1\applic~1\MySpace 2008-06-07 11:28 –d—– c:\docume~1\alluse~1\applic~1\TVU Networks 2007-09-13 12:33 –d—– c:\docume~1\alluse~1\applic~1\Trymedia 2006-11-15 19:21 –d—– c:\docume~1\tundek~1\applic~1\AOL 2006-07-26 17:28 –d—– c:\docume~1\tundek~1\applic~1\EarthLink Toolbar 2006-07-26 16:44 –d—– c:\docume~1\tundek~1\applic~1\Earthlink 2006-06-15 05:33 –d—– c:\docume~1\tundek~1\applic~1\ACD Systems 2006-01-03 07:09 –d—– c:\docume~1\tundek~1\applic~1\SHARP 2005-12-27 18:33 –d—– c:\docume~1\alluse~1\applic~1\Kodak 2005-12-06 08:04 –d—– c:\docume~1\tundek~1\applic~1\Corel Photo Album 2005-11-08 20:55 –d—– c:\docume~1\alluse~1\applic~1\Intuit 2005-11-08 20:54 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint 2004-08-19 17:22 –d—– c:\docume~1\alluse~1\applic~1\SBSI 2004-08-19 17:16 –d—– c:\docume~1\alluse~1\applic~1\DIGStream 2004-08-10 06:00 94,784 -c-sh— c:\windows\twain.dll 2004-08-10 06:00 50,688 —sh— c:\windows\twain_32.dll 2007-11-05 14:28 104 -c-shr– c:\windows\system32\10FBA8EB3D.sys 2007-11-05 14:28 4,184 ac-sh— c:\windows\system32\KGyGaAvL.sys 2004-08-10 06:00 1,028,096 —sh— c:\windows\system32\mfc42.dll 2004-08-10 06:00 54,784 —sh— c:\windows\system32\msvcirt.dll 2004-08-10 06:00 413,696 —sh— c:\windows\system32\msvcp60.dll 2004-08-10 06:00 343,040 —sh— c:\windows\system32\msvcrt.dll 2007-12-04 13:38 550,912 a–sh— c:\windows\system32\oleaut32.dll 2004-08-10 06:00 83,456 —sh— c:\windows\system32\olepro32.dll 2004-08-10 06:00 11,776 —sh— c:\windows\system32\regsvr32.exe ============= FINISH: 2:14:08.56 =============== I was finally able to remove these programs after deleting them first from my program files, then removed them from Add/Remove. Also, my mouse cursor don't have the hourly glass icon spinning when its loading up a page or a program(I dont know if you understand what I meant). However, I have this icon that looks like a planet with 3 small colored rocks spinning around it (looks like Jupiter). I don't know if I should be concerned about this or just ignore it since my computer looks better. any suggestions?

Attachments:

maxwax,

The icon used while waiting to load a page can be changed. Any of them can. It should not be related to malware.

If you want to change them:
Start> Setting> Control Panel> Mouse
Then select the pointers tab.
You can choose from different schemes and various icons.

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

Please re-enable any security that was disabled.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls

Keep Microsoft Windows Updated - This will ensure your computer has always the latest security updates available installed on your computer. The easiest way to do this is to turn on Automatic Updates. Do this by:
  • From your desktop, right-click on My Computer,
  • click on Properties
  • Select the Automatic Updates tab
  • Click on Automatic
  • Click on Apply button
  • Click on OK to exit.
If there are new updates to install, install them immediately, until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Download and install the free version of WinPatrol - This program protects your computer in a variety of ways and will work well with your existing security software.
Winpatrol


Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.


Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Tomk, Yes, I followed the instructions you suggested and my computer is working like brand new. I installed the latest updates both for windows and my anti-virus protection program and will definately make sure i keep up with all updates as needed. I appreciate your time and effort in bringing my computer back to normal. I thank you and the rest of the what the tech team for all your unending efforts.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI