This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] seem to be lockout out of my computer

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'll repost my first message… just in case it didn't go through… This time i'll put my hijackthis log into an attachment. Maybe then it won't be redirected back to me. Hi, Yesturday, I tried going into McAfee and realized I could not access McAfee, System Restore, most windows programs, etc. Computer tells me 'System could not find the environment option that was entered" or that I'm missing a "system32" file. I tried opening System Restore in Safe Mode. No go. I tried to run Windows Defender… same thing ('System could not find the environment option that was entered" ). Tried McAfee Stinger. That program works but finds nothing wrong. Went on the Microsoft windows Site and got the Malicious Software Removal Tool. My system won't run it ('System could not find the environment option that was entered" ). In my C:/users directory, I now have a sub-directory called McAfeeMVSUser that I can't access. My computer tells me I don't have permission to access this directory. I use Vista on my portable laptop. It is connected to the Internet but to no other network. I do not have an administrator and there should be only one account on the computer. If anybody can help, I would appreciate it. I've now reached the limit of my computer knowledge.

Attachments:

  • [attachment removed: This_is_my_Hijackthis_log.doc]
Hi, I'm starting over with this request for help. This is my third message to this forum regarding my possible infected computer. MY FIRST MESSAGE WENT SOMETHING LIKE THIS: Yesturday, I tried going into McAfee and realized I could not access McAfee, System Restore, most windows programs, etc. Computer tells me 'System could not find the environment option that was entered" or that I'm missing a "system32" file. I tried opening System Restore in Safe Mode. No go. I tried to run Windows Defender… same thing ('System could not find the environment option that was entered" ). Tried McAfee Stinger. That program works but finds nothing wrong. Went on the Microsoft windows Site and got the Malicious Software Removal Tool. My system won't run it ('System could not find the environment option that was entered" ). In my C:/users directory, I now have a sub-directory called McAfeeMVSUser that I can't access. My computer tells me I don't have permission to access this directory. I use Vista on my portable laptop. It is connected to the Internet but to no other network. I do not have an administrator and there should be only one account on the computer. If anybody can help, I would appreciate it. I've now reached the limit of my computer knowledge. (The message also included my hijackthis log, which you will find as an attachment this time). I immediately got a message back stating that your server had detected that I was not using the last version of hijackthis… and that I needed to do so before proceeding. SO I TRIED THAT AND SENT THE FOLLOWING: I just sent a message with the same title. Got a message from Blair to download the newest Hijackthis. Can't download it onto C:… seems I don't have permission. Can't run it either. I get this message : c:/UsersDenise.Denise-PCAppDatalocal/Microsoft Windows/temporary Internet FilesContent.IE58CR21TGVHHJTInsall.exe Èthe syustem could not find the environment entered". Forgot to say also… I tried to turn off the "user account controls" but nothing happens. Please help. So, to summarize. I've given you in attachment form a hijackthis log usin a old hijackthis program. Ive tried running a newer version, as you have asked, but my computer won't let me do that. I am not using fowl language, I am not trying to spam or otherwise injure this forum. I'm just trying to fix my computer so I can get on with my work. Please help. DPar

Attachments:

  • [attachment removed: This_is_my_Hijackthis_log.doc]
DPar,

Welcome to the forum. Please reply to this thread only and do not start any new topics. We get so busy on this forum that most times we don't get to new logs for 3 or 4 days.

Run both these programs, if they won't run try running them in Safemode

To Enter Safemode

  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode






Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.






Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Firstly, thanks Ken for your hep. This service is a godsent to on-techies like me.

I tried to follow your instructions as best I could.

Had to go to safemode since Malwarebytes and Combofix would not open in regular Vista. After running Malwarebytes, I still couldn't open Mcafee to disengage and run combofix… but all of a sudden, I could open System Restore. So I did and restored to November 11. After that, I seem to be able to open everything again, except Mcafee. Even video resolution problems that I was having and thought unrelated were no longer. Ran malwarebytes and combofix a couple of times.

Ran into problems when system rebooted after running combofix. Seemed to be caught in a loop of shuttingdown-rebooting-telling me to be patient while it entered the upgrades-shutting down again. Had to run system restore (from F8 screen) a few times to get out of the loop.

When I could turn on the computer again, I removed Malwarebytes and Combofix to see if they were interfering with Mcafee. McAfee ran perfectly after that. Ran Mcafee and found 2 trojans, which I removed, as well as cookies (which I also removed through Control Panel).
Everything seems to work fine this morning… but will still run Mcafee one more time (with system restore off).

Let me know if I should do something else… And again thANK YOU.

DPAr

HIJACKTHIS LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:16, on 2008-12-04
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtTry.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\OEM13Mon.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\System32\BKEXVGA.exe
C:\Windows\System32\HIDDAEMON.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Le Robert\Le Petit Robert\PRHYPER.EXE
C:\Program Files\Le Robert\Le Robert & Collins\rcwinHyper.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\sdclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://partnerpage.google.com/smallbiz.del…amp;ibd=6080709
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [MVS Splash] "C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe"
O4 - HKLM\..\Run: [McAfee Managed Services Tray] C:\Program Files\McAfee\Managed VirusScan\Agent\StartMyAgtTry.Exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [BKEXVGA] C:\Windows\system32\BKEXVGA.exe
O4 - HKLM\..\Run: [HIDDAEMON] C:\Windows\system32\HIDDAEMON.exe
O4 - HKLM\..\Run: [WHITNEY_S2P] C:\Program Files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Le Petit Robert Hyperappel] C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
O4 - HKCU\..\Run: [rcwinHyper] C:\Program Files\Le Robert\Le Robert & Collins\rcwinHyper.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
O23 - Service: EngineServer - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\VScan\EngineServer.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\VScan\McShield.exe
O23 - Service: MCT_SERVICE - Unknown owner - C:\Windows\system32\MCTService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 9847 bytes


MALWAREBYTES LOG:
Malwarebytes' Anti-Malware 1.30
Database version: 1454
Windows 6.0.6001 Service Pack 1

2008-12-03 12:07:55
mbam-log-2008-12-03 (12-07-55).txt

Scan type: Quick Scan
Objects scanned: 49684
Time elapsed: 3 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


COMBOFIXLOG (UNFORTUNATELY, i CAN'T FIND LATER ONE):
ComboFix 08-12-02.02 - Denise 2008-12-03 11:02:22.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1757 [GMT -5:00]
Lancé depuis: c:\users\Denise.Denise-PC\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\x64

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_PACKET
——-\Service_Packet
——-\Legacy_PACKET
——-\Service_Packet


((((((((((((((((((((((((((((( Fichiers créés du 2008-11-03 au 2008-12-03 ))))))))))))))))))))))))))))))))))))
.

2008-12-03 10:40 . 2008-10-22 16:28 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2008-12-03 10:40 . 2008-10-22 16:28 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2008-12-03 10:22 . 2008-10-16 16:13 1,809,944 –a—— c:\windows\System32\wuaueng.dll
2008-12-03 10:22 . 2008-10-16 15:56 1,524,736 –a—— c:\windows\System32\wucltux.dll
2008-12-03 10:22 . 2008-10-16 16:09 51,224 –a—— c:\windows\System32\wuauclt.exe
2008-12-03 10:22 . 2008-10-16 16:09 43,544 –a—— c:\windows\System32\wups2.dll
2008-12-03 10:21 . 2008-10-16 14:08 162,064 –a—— c:\windows\System32\wuwebv.dll
2008-12-03 10:21 . 2008-10-16 13:56 31,232 –a—— c:\windows\System32\wuapp.exe
2008-12-03 10:02 . 2008-12-03 10:02 d——– c:\users\Denise.Denise-PC\WPDNSE
2008-12-03 09:52 . 2008-12-03 09:52 d——– c:\users\Denise.Denise-PC\AppData\Roaming\PeerNetworking
2008-12-03 09:23 . 2008-12-03 09:23 d——– c:\users\Denise.Denise-PC\AppData\Roaming\Malwarebytes
2008-12-03 09:23 . 2008-12-03 09:23 d——– c:\users\All Users\Malwarebytes
2008-12-03 09:23 . 2008-12-03 10:40 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-03 09:23 . 2008-12-03 09:23 d——– c:\progra~2\Malwarebytes
2008-11-30 15:21 . 2008-11-30 15:21 d——– c:\users\Denise.Denise-PC\Adobe
2008-11-30 11:04 . 2008-11-30 11:04 d——– c:\users\Denise.Denise-PC\Google Toolbar
2008-11-27 10:56 . 2008-12-02 19:45 d——– c:\users\Denise.Denise-PC\msohtml1
2008-11-27 10:55 . 2008-11-27 10:55 d——– c:\users\Denise.Denise-PC\VBE
2008-11-26 19:35 . 2008-12-03 09:51 d——– c:\users\Denise.Denise-PC\Low
2008-11-26 19:31 . 2008-11-26 19:31 d——– c:\users\Denise.Denise-PC\Log
2008-11-26 19:31 . 2008-12-03 09:39 d——– c:\users\Denise.Denise-PC\Acrobat Distiller 9
2008-11-19 15:05 . 2008-11-19 15:05 d——– c:\program files\Real
2008-11-19 15:05 . 2008-11-19 15:06 d——– c:\program files\Common Files\Real
2008-11-10 15:33 . 2008-11-11 10:13 d——– c:\users\Denise.Denise-PC\gestion
2008-11-06 12:58 . 2008-11-06 12:58 d——– c:\program files\MSECache

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 16:07 ——— d—a-w c:\progra~2\TEMP
2008-12-03 15:14 ——— d—–w c:\program files\Windows Mail
2008-12-03 15:14 ——— d—–w c:\progra~2\FLEXnet
2008-11-27 00:21 ——— d–h–w c:\users\Denise.Denise-PC\AppData\Roaming\GTek
2008-11-26 21:00 ——— d—–w c:\program files\LogiTerm
2008-11-07 15:13 ——— d—–w c:\program files\Common Files\Adobe
2008-10-30 20:40 53,752 —-a-w c:\users\Denise.Denise-PC\AppData\Roaming\GDIPFONTCACHEV1.DAT
2008-10-29 16:33 ——— d—–w c:\users\Denise.Denise-PC\AppData\Roaming\ArcSoft
2008-10-29 16:22 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-29 16:22 ——— d—–w c:\program files\INITIO
2008-10-29 16:21 ——— d—–w c:\program files\ArcSoft
2008-10-20 14:16 ——— d—–w c:\program files\Readiris
2008-10-20 14:06 ——— d—–w c:\program files\Samsung
2008-10-13 18:06 ——— d–h–w c:\progra~2\CanonBJ
2008-10-02 03:49 827,392 —-a-w c:\windows\System32\wininet.dll
2008-09-18 05:09 3,601,464 —-a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 —-a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 04:56 147,456 —-a-w c:\windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 —-a-w c:\windows\System32\wersvc.dll
2008-09-18 02:16 2,032,640 —-a-w c:\windows\System32\win32k.sys
2008-01-21 02:57 174 –sha-w c:\program files\desktop.ini
2005-05-26 18:35 1,422 —-a-w c:\program files\ReadMe.txt
2008-07-27 21:58 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2007-09-19 05:41 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007091920070920\index.dat
2008-07-27 21:42 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008071420080721\index.dat
2008-07-28 20:09 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008072120080728\index.dat
2008-07-29 02:27 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008072820080729\index.dat
2008-07-30 02:20 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008072920080730\index.dat
2008-07-31 03:14 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008073020080731\index.dat
2008-08-10 03:12 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008080920080810\index.dat
2008-08-11 03:58 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081020080811\index.dat
2008-08-12 00:43 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081120080812\index.dat
2008-08-14 19:06 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081420080815\index.dat
2008-08-25 13:04 49,152 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008081820080825\index.dat
2008-09-01 20:47 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008082520080901\index.dat
2008-09-01 20:47 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008090120080902\index.dat
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-09 68856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Le Petit Robert Hyperappel"="c:\program files\Le Robert\Le Petit Robert\prhyper.exe" [2001-10-11 22560]
"rcwinHyper"="c:\program files\Le Robert\Le Robert & Collins\rcwinHyper.exe" [2005-08-09 155648]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-02-22 159744]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-02-22 36864]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-16 3444736]
"DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-09 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\Agent\Splash.exe" [2008-02-23 468288]
"McAfee Managed Services Tray"="c:\program files\McAfee\Managed VirusScan\Agent\StartMyAgtTry.Exe" [2008-02-23 87360]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"BKEXVGA"="c:\windows\system32\BKEXVGA.exe" [2007-05-25 12570624]
"HIDDAEMON"="c:\windows\system32\HIDDAEMON.exe" [2007-05-02 233472]
"WHITNEY_S2P"="c:\program files\Samsung\Samsung SCX-4x21 Series\PSU\Scan2pc.exe" [2007-01-08 274432]
"RtHDVCpl"="RtHDVCpl.exe" [2008-02-22 c:\windows\RtHDVCpl.exe]

c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-07-09 7168]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-02-22 1193240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-361828355-4230574815-1074167733-1001]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{807872DC-9CFE-449E-A0E6-A9558F8586DC}"= TCP:10421:SingleClick Discovery Protocol
"{D61C0187-6F48-43E8-BC34-1AB07A73065B}"= UDP:139:NetBIOS File/Printer Sharing
"{E8D130D3-F94B-4618-9699-32EC02221735}"= TCP:10426:SingleClick ICC
"{E3A56BF9-2187-4620-9062-44180C74D934}"= UDP:445:Microsoft Directory Services
"{B2703D94-7335-4BE0-A140-328B08C236D2}"= TCP:138:NetBIOS Datagram Service
"{F88A10CA-858D-4870-A634-B937BBF05095}"= TCP:137:NetBIOS Name Service
"{18996B5F-5E51-4056-87A4-2E45398BB8C8}"= UDP:c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:Managed Services Agent
"{A228DFA6-FCAF-4E82-8B7A-3B482C1723CB}"= TCP:c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:Managed Services Agent
"{FA251E79-5463-4053-B210-0997334E5F2F}"= c:\program files\CyberLink\PowerDVD DX\PowerDVD.exe:CyberLink PowerDVD DX
"{6025F5F8-BB32-4BE9-B33E-A9A133CDDCF6}"= c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:CyberLink PowerDVD DX Resident Program
"{8D395617-05CE-432D-BA9C-3EB8F5DF8EC6}"= UDP:c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:Managed Services Agent
"{62561C57-DCB5-4B6F-8B43-34C062A3FBD3}"= TCP:c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe:Managed Services Agent
"{AB0530F4-31CF-4098-9D54-CD4D7FEC33E4}"= TCP:10421:SingleClick Discovery Protocol
"{26D12054-60B8-4CD1-9834-ADF6008C91AB}"= TCP:10426:SingleClick ICC
"{588CB97F-60F1-4DCD-98E2-F5F9DE7C5F26}"= UDP:c:\program files\Dell Network Assistant\ezi_hnm2.exe:Dell Network Assistant
"{C29DC72A-26B9-494D-AC5E-CFF6D4AE8523}"= TCP:c:\program files\Dell Network Assistant\ezi_hnm2.exe:Dell Network Assistant
"{E0951550-7057-4E8E-BC81-4144212D12D8}"= UDP:c:\program files\Dell Network Assistant\ezi_hnm2.exe:Dell Network Assistant
"{9129808E-EA13-4C1C-8F92-E503E2E5EB16}"= TCP:c:\program files\Dell Network Assistant\ezi_hnm2.exe:Dell Network Assistant

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\DRIVERS\datunidr.sys [2007-08-23 5376]
R3 BLKPCIEVGAEX;BLKPCIEVGAEX;c:\windows\system32\DRIVERS\blkgrpex.sys [2008-10-10 254848]
R3 BLKPCIEVGAMR;BLKPCIEVGAMR;c:\windows\system32\DRIVERS\blkgrpmr.sys [2008-10-10 253824]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-07-09 48472]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2008-07-09 43480]
R3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [2008-07-09 7424]
R3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [2008-07-09 235200]
S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\system32\DRIVERS\ADM851X.SYS [2008-10-10 22144]
S3 CM1063264;C-Media CM106 Like Sound UDAX Interface;c:\windows\system32\drivers\CM106.sys [2008-10-10 1298944]
S3 XGIGraphics;XGIGraphics;c:\windows\system32\DRIVERS\xg20grp.sys [2008-10-10 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e741fb4-aba2-11dd-8da7-001c235b78d4}]
\shell\AutoRun\command - F:\t1ypkh.exe
\shell\explore\Command - F:\t1ypkh.exe
\shell\open\Command - F:\t1ypkh.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80fcddd3-4d72-11dd-8374-806e6f6e6963}]
\shell\AutoRun\command - E:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{af6d5f6e-5ce7-11dd-a2b6-001c235b78d4}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-03 11:06:36
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cachés …

Recherche d'éléments en démarrage automatique cachés …

Recherche de fichiers cachés …


c:\windows\TEMP\TMP0000000B55DE08137B430055 524288 bytes executable

Scan terminé avec succès
Fichiers cachés: 1

**************************************************************************
.
———————— Autres processus actifs ————————
.
c:\windows\System32\audiodg.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\wlanext.exe
c:\windows\System32\BCMWLTRY.EXE
c:\windows\System32\AERTSrv.exe
c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Common Files\McAfee\HackerWatch\HWAPI.exe
c:\windows\System32\MCTService.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
c:\program files\McAfee\Managed VirusScan\VScan\McShield.exe
c:\windows\System32\conime.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\McAfee\Managed VirusScan\Agent\myAgtTry.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\McAfee\Managed VirusScan\Agent\myAgtTry.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuauclt.exe
.
**************************************************************************
.
2008-12-03 09:32:51 A——- 162 C:\Qoobox\Quarantine\catchme.log
2008-12-03 09:35:50 A——- 1,108 C:\Qoobox\Quarantine\Registry_backups\Legacy_PACKET.reg.dat
2008-12-03 09:35:50 A——- 9,086 C:\Qoobox\Quarantine\Registry_backups\Service_Packet.reg.dat
2008-12-03 11:03:51 A——- 7,295 C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2008-12-03 11:09:03 A——- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-CFSServ.exe.reg.dat
2008-12-03 11:09:03 A——- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NDSTray.exe.reg.dat
2008-12-03 11:09:03 A——- 0 C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFncKy.reg.dat



Heure de fin: 2008-12-03 11:10:27 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-03 16:10:13

Avant-CF: 178 120 966 144 bytes free
Après-CF: 178,279,723,008 bytes free

226 — E O F — 2008-11-01 02:10:02
Hello,


C:\Program Files\Le Robert\Le Petit Robert <—What can you tell me about this program????


Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


File::
F:\t1ypkh.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e741fb4-aba2-11dd-8da7-001c235b78d4}]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI