UNSOLVED

renleamse

updated

17 years ago

R

renleamse

24 Posts

0

4181

February 1st, 2010 11:00

.exe files are not running

Hi, I recently had a problem with a 'trojan spm/lx". I posted a thread and began recieving assistance. However, after running the OTL, something seemingly went wrong during the procedure and I had a bit of trouble to log back into windows. I inserted the windows xp cd, did the repair, and managed to get partial control of my computer. Now, I can't open any .exe files. My mcafee antivirus won't run, so I'm at a point that I don't know what to do next.

 

I would've continued posting in the former thread i created, but as I recall, if I did not reply in 3 days, the support team would consider the thread closed. This problem is somewhat similar to the previous one but now I constantly get a pop up about  'Msfeedssync.exe- Application error' and other .exe files not working.

 

below is the thread I posted about the 'trojan spm/lx'

 

http://en.community.dell.com/forums/t/19318583.aspx

  • Bugbatter

    4 Apprentice

    20487 Posts

    1893

    0

    Posted February 1st, 2010 13:00

    You may have one of those infections that likes to break things even further when someone tries to clean it.

    You disabled your McAfee before the fix, so perhaps that is why it is not running.

    We downloaded a program to make a restore point for you to go to if anything happened during the fix. Are you able to use that? If so, see if you can do a System Restore. Even though the malware will be on there, we can start again with another cleaning  tool.

    Let me know if you can get back to that beginning point.

  • renleamse

    24 Posts

    1893

    0

    Posted February 1st, 2010 14:00

    I managed to do the system restore. It did go back to the beginning point.

  • Bugbatter

    4 Apprentice

    20487 Posts

    1893

    0

    Posted February 1st, 2010 16:00

    McAfee interferes with many of our tools. We'll need to disable McAfee.

    • Please open McAfee Security Centre
    • Under Common Tasks click on Home
    • Click Computer Files
    • Click Configure
    • Make sure the following are disabled by ticking the "Off" button.
    • Virus protection
      Spyware protection
      System Guards Protection
      Script Scanning Protection (you may have to scroll down to see it)
    • Next, select never for "When to re-enable real time scanning"
    • and click OK.

    Further info on disabling and re-enabling McAfee: http://help.aol.com/help/microsites/microsite.do?cmd=displayKCPopup&docType=kc&externalID=222820

    If that does not work, please uninstall McAfee. (If you have the CD's, or use McAfee Support,  you can re-install it once we have verified that the computer is clean.)

    Let's see if you can post the following logs. (This scan will not change or fix anything, but it will show me more information about what is running on your computer.)

    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explanation about the tool.
    • Click Yes at the prompt for Optional Scan.
    • When done, DDS will open two (2) logs
    • 1. DDS.txt
      2. Attach.txt

    • Save both reports to your desktop.
    • Copy/paste both logs to your reply on the forum. (At this time we cannot attach logs at Dell.)
    • Close the program window, and delete the program from your desktop.
    • Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.

       

  • renleamse

    24 Posts

    1892

    0

    Posted February 1st, 2010 16:00

    Below are the logs.

     


    DDS (Ver_09-12-01.01) - NTFSx86 
    Run by Warren at 19:38:42.06 on Mon 02/01/2010
    Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_18
    Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1022.397 [GMT -5:00]

    AV: McAfee VirusScan *On-access scanning disabled* (Updated)   {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled*   {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\msfeedssync.exe
    C:\WINDOWS\system32\dwwin.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Documents and Settings\Warren\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = about:blank
    uSearch Page = hxxp://www.google.com
    uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJxdm128YYUS&fl=0&ptb=p6rMQ81L12sOJhCuV36ePQ&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\winlogon32.exe
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
    TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
    uRun: [SetDefaultMIDI] MIDIDef.exe
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
    uRun: [Zinio DLM] c:\program files\zinio\ZinioReader.exe /autostart
    uRun: [Veoh] "c:\program files\veoh networks\veoh\VeohClient.exe" /VeohHide
    uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
    uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [ehTray] c:\windows\ehome\ehtray.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
    mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
    mRun: [CTSysVol] c:\program files\creative\sbaudigy\surround mixer\CTSysVol.exe /r
    mRun: [MBMon] Rundll32 CTMBHA.DLL,MBMon
    mRun: [UpdReg] c:\windows\UpdReg.EXE
    mRun: [VoiceCenter] "c:\program files\creative\voicecenter\AndreaVC.exe" /tray
    mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [HostManager] c:\program files\common files\aol\1169843107\ee\AOLSoftware.exe
    mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe"  -osboot
    mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
    mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [gunosewon] Rundll32.exe "c:\windows\system32\yofamoyu.dll",a
    dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
    StartupFolder: c:\docume~1\warren\startm~1\programs\startup\wkcalrem.lnk - c:\program files\common files\microsoft shared\works shared\WkCalRem.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpobnz08.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ymetray.lnk - c:\program files\yahoo!\yahoo! music jukebox\ymetray.exe
    IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-us\local\search.html
    IE: &Search
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    IE: Open in new background tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/229?c90312ade43e4c379b20037b32e75c17
    IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/230?c90312ade43e4c379b20037b32e75c17
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
    IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
    IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    AppInit_DLLs: c:\windows\system32\wevejaga.dll zebelivu.dll c:\windows\system32\kazuzori.dll c:\windows\system32\rojatesu.dll c:\windows\system32\yofamoyu.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SSODL: luvujaluh - {25b8c039-9992-4f18-a1a6-3769aca24c0f} - c:\windows\system32\wevejaga.dll
    SSODL: yanugesar - {c5325995-0127-4fe6-b7a9-d03d472f147d} - c:\windows\system32\rojatesu.dll
    SSODL: husamemed - {c84170c6-8ac4-420c-9b8f-05286e75beed} - c:\windows\system32\yofamoyu.dll
    SSODL: junonoven - {68aa594f-97a3-4d2b-9aec-8609b2774db6} - c:\windows\system32\yofamoyu.dll
    SSODL: rumikazed - {2ff8e8ff-19eb-41c8-8f67-c7cabf6bad09} - c:\windows\system32\kazuzori.dll
    STS: kupuhivus: {25b8c039-9992-4f18-a1a6-3769aca24c0f} - c:\windows\system32\wevejaga.dll
    STS: tokatiluy: {c5325995-0127-4fe6-b7a9-d03d472f147d} - c:\windows\system32\rojatesu.dll
    STS: kupuhivus: {c84170c6-8ac4-420c-9b8f-05286e75beed} - c:\windows\system32\yofamoyu.dll
    STS: kupuhivus: {68aa594f-97a3-4d2b-9aec-8609b2774db6} - c:\windows\system32\yofamoyu.dll
    STS: kupuhivus: {2ff8e8ff-19eb-41c8-8f67-c7cabf6bad09} - c:\windows\system32\yofamoyu.dll
    LSA: Notification Packages = scecli nomadani.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\warren\applic~1\mozilla\firefox\profiles\9hg2gm2m.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - AOL Search
    FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
    FF - prefs.js: keyword.URL - hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query=
    FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
    FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
    FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
    FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
    FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
    FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service

    ============= SERVICES / DRIVERS ===============

    R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-10-7 214664]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-20 54752]
    R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-10-7 359952]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2007-10-7 144704]
    R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-10-7 79816]
    R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-10-7 35272]
    R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-10-7 34248]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
    S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-10-7 40552]
    S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2007-10-7 606736]

    =============== Created Last 30 ================

    2010-02-01 22:03:06    0    d-----w-    c:\windows\system32\wbem\Repository
    2010-02-01 22:02:50    0    d-----w-    c:\program files\Malwarebytes' Anti-Malware
    2010-01-29 18:59:10    73728    -c--a-w-    c:\windows\system32\dllcache\ehresja.dll
    2010-01-29 18:59:10    69632    -c--a-w-    c:\windows\system32\dllcache\ehresko.dll
    2010-01-29 18:59:10    69632    -c--a-w-    c:\windows\system32\dllcache\ehresfr.dll
    2010-01-29 18:59:09    69632    -c--a-w-    c:\windows\system32\dllcache\ehresde.dll
    2010-01-29 18:59:05    61440    -c--a-w-    c:\windows\system32\dllcache\ehreschs.dll
    2010-01-29 18:57:59    53248    -c--a-w-    c:\windows\system32\dllcache\nextlink.dll
    2010-01-29 18:56:59    97792    -c--a-w-    c:\windows\system32\dllcache\chtmbx.dll
    2010-01-29 18:48:32    488    ---ha-r-    c:\windows\system32\logonui.exe.manifest
    2010-01-29 18:48:27    749    ---ha-r-    c:\windows\WindowsShell.Manifest
    2010-01-29 18:48:27    749    ---ha-r-    c:\windows\system32\wuaucpl.cpl.manifest
    2010-01-29 18:48:27    749    ---ha-r-    c:\windows\system32\sapi.cpl.manifest
    2010-01-29 18:48:27    749    ---ha-r-    c:\windows\system32\nwc.cpl.manifest
    2010-01-29 18:48:27    749    ---ha-r-    c:\windows\system32\ncpa.cpl.manifest
    2010-01-29 06:54:11    16384    -c--a-w-    c:\windows\system32\dllcache\isignup.exe
    2010-01-29 06:12:05    7334    -c--a-w-    c:\windows\system32\dllcache\wmerrenu.cat
    2010-01-29 01:01:33    0    d-----w-    c:\windows\dell
    2010-01-28 05:18:33    0    d-----w-    C:\_OTL
    2010-01-25 21:48:15    72272    ---ha-w-    c:\windows\system32\mlfcache.dat
    2010-01-21 22:07:25    73728    ----a-w-    c:\windows\system32\javacpl.cpl
    2010-01-21 20:29:32    0    d-sha-r-    C:\cmdcons
    2010-01-21 20:28:02    98816    ----a-w-    c:\windows\sed.exe
    2010-01-21 20:28:02    77312    ----a-w-    c:\windows\MBR.exe
    2010-01-21 20:28:02    261632    ----a-w-    c:\windows\PEV.exe
    2010-01-21 20:28:02    161792    ----a-w-    c:\windows\SWREG.exe
    2010-01-21 20:27:35    0    d-----w-    C:\ComboFix
    2010-01-21 05:40:11    0    d-----w-    c:\docume~1\warren\applic~1\Malwarebytes
    2010-01-21 05:40:03    0    d-----w-    c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-01-21 02:31:58    0    d-----w-    c:\program files\TrendMicro

    ==================== Find3M  ====================

    2010-01-29 18:43:41    34380    ----a-w-    c:\windows\system32\emptyregdb.dat
    2010-01-25 16:37:02    2516    --sha-w-    c:\windows\system32\KGyGaAvL.sys
    2010-01-21 22:06:58    411368    ----a-w-    c:\windows\system32\deploytk.dll
    2010-01-19 08:24:49    39234    ----a-w-    c:\docume~1\warren\applic~1\wklnhst.dat
    2009-12-30 01:40:03    256    ----a-w-    c:\documents and settings\warren\pool.bin
    2007-03-22 04:49:56    251    ----a-w-    c:\program files\wt3d.ini
    1601-01-01 00:03:52    51712    --sha-w-    c:\windows\system32\nomadani.dll
    1601-01-01 00:03:28    91648    --sha-w-    c:\windows\system32\yofamoyu.dll
    1601-01-01 00:03:52    51712    --sha-w-    c:\windows\system32\zebelivu.dll
    2009-10-16 10:20:57    245760    --sha-w-    c:\windows\system32\config\systemprofile\ietldcache\index.dat
    2009-09-17 06:26:02    32768    --sha-w-    c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009091720090918\index.dat

    ============= FINISH: 19:42:20.18 ===============

     

     

     

     

     

     

     

     

     

     

     

     

     

     

     

     

     


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-12-01.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 1/29/2010 1:59:13 PM
    System Uptime: 2/1/2010 5:04:28 PM (2 hours ago)

    Motherboard: Dell Inc.           |  | 0WG864
    Processor:               Intel(R) Pentium(R) D CPU 2.80GHz | Microprocessor | 2793/800mhz
    Processor:               Intel(R) Pentium(R) D CPU 2.80GHz | Microprocessor | 2793/800mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 293 GiB total, 223.523 GiB free.
    D: is CDROM (CDFS)

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
    Description: Terminal Server Device Redirector
    Device ID: ROOT\RDPDR\0000
    Manufacturer: (Standard system devices)
    Name: Terminal Server Device Redirector
    PNP Device ID: ROOT\RDPDR\0000
    Service: rdpdr

    ==== System Restore Points ===================

    RP1: 1/29/2010 7:15:45 PM - System Checkpoint
    RP2: 1/29/2010 7:53:27 PM - OTL Restore Point
    RP3: 2/1/2010 5:00:58 PM - Restore Operation

    ==== Installed Programs ======================


    Adobe Flash Player 10 Plugin
    Adobe Reader 7.1.0
    Adobe Shockwave Player
    Advanced Decoder Patch
    Andrea VoiceCenter
    AOL Coach Version 1.0(Build:20040229.1 en)
    AOL Toolbar 5.0
    AOL Uninstaller (Choose which Products to Remove)
    AOLIcon
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    BlackBerry Desktop Software 4.3
    BlackBerry Device Software Updater
    Bonjour
    CardRd81
    CCScore
    Compatibility Pack for the 2007 Office system
    Conexant D850 56K V.9x DFVc Modem
    Corel Snapfire Plus
    CR2
    Creative Audio Pack
    Creative MediaSource 5
    Dell CinePlayer
    Dell Driver Reset Tool
    Dell Game Console
    Dell Support 3.2.1
    Dell System Restore
    Digital Content Portal
    Digital Line Detect
    Documentation & Support Launcher
    EarthLink Setup Files
    ESPNMotion
    ESSBrwr
    ESSCDBK
    ESScore
    ESSgui
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTOOLS
    essvatgt
    Form Fill (Windows Live Toolbar)
    FxBear MOV Video Converter
    Games, Music, & Photos Launcher
    GemMaster Mystic
    Google Toolbar for Internet Explorer
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Memories Disc
    HP Photo and Imaging 2.0 - All-in-One
    HP Photo and Imaging 2.0 - All-in-One Drivers
    HP Photo and Imaging 2.0 - hp psc 2200 series
    hp psc 2200 series
    ICatch (VI) PC Camera
    Intel(R) Matrix Storage Manager
    Intel(R) PRO Network Connections
    iTunes
    Java Auto Updater
    Java(TM) 6 Update 18
    Junk Mail filter update
    kgcbase
    Kodak EasyShare software
    Learn2 Player (Uninstall Only)
    Map Button (Windows Live Toolbar)
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft ActiveSync 4.0
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office Live Add-in 1.3
    Microsoft Office Outlook Connector
    Microsoft Office Small Business Edition 2003
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Microsoft WSE 3.0 Runtime
    Modem Helper
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.17)
    MSN
    MSVCRT
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB954459)
    netbrdg
    NetWaiting
    NVIDIA Drivers
    OfotoXMI
    OneCare Advisor (Windows Live Toolbar)
    Otto
    Perfect Typing Pro English
    Popup Blocker (Windows Live Toolbar)
    Presto! ImageFolio 4.2
    Presto! Mr. Photo
    QuickTime
    RealPlayer
    Roxio DLA
    Roxio Media Manager
    Roxio MyDVD LE
    Roxio RecordNow Audio
    Roxio RecordNow Copy
    Roxio RecordNow Data
    SearchAssist
    Security Update for CAPICOM (KB931906)
    Segoe UI
    SFR
    SHASTA
    skin0001
    SKINXSDK
    Smart Menus (Windows Live Toolbar)
    Sonic Activation Module
    Sonic Encoders
    Sonic Update Manager
    Sound Blaster ADVANCED MB Drivers
    Sound Blaster Audigy ADVANCED MB
    Sound Blaster Audigy ADVANCED MB Product Registration
    staticcr
    Tabbed Browsing (Windows Live Toolbar)
    The KMPlayer (remove only)
    The Sims™ 3
    The Sims™ 3 World Adventures
    tooltips
    Unity Web Player
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    URL Assistant
    VeohTV BETA
    Viewpoint Media Player
    VPRINTOL
    WebFldrs XP
    WildTangent Web Driver
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live Favorites for Windows Live Toolbar
    Windows Live Mail
    Windows Live Messenger
    Windows Live Outlook Toolbar (Windows Live Toolbar)
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Toolbar Extension (Windows Live Toolbar)
    Windows Live Toolbar Feed Detector (Windows Live Toolbar)
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Format 11 runtime
    Windows Media Format Runtime
    Windows Media Player 10
    Windows Media Player 11
    Windows Presentation Foundation
    Windows XP Media Center Edition 2005 KB908246
    WIRELESS
    XML Paper Specification Shared Components Pack 1.0
    Yahoo! Browser Services
    Yahoo! Install Manager
    Yahoo! Internet Mail
    Yahoo! Messenger
    Yahoo! Music Jukebox
    Yahoo! Toolbar
    Zinio Reader

    ==== Event Viewer Messages From Past Week ========

    1/29/2010 2:04:02 AM, error: Setup [60055]  - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.

    ==== End Of File ===========================

  • Bugbatter

    4 Apprentice

    20487 Posts

    1892

    0

    Posted February 1st, 2010 18:00

    Please print these instructions if possible so you can follow  them exactly.

    Please visit this webpage for download links, and instructions for running ComboFix:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    * IMPORTANT! 
    Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.



    Double click on ComboFix.exe & follow the prompts.






    • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.




    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.




    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:





    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you.
    Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log for further review.











     

    Notes:

    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

    2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

    3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.

    4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.

    5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    * Additional information on A/V control HERE. * ComboFix is not intended for use with servers.

  • Bugbatter

    4 Apprentice

    20487 Posts

    1892

    0

    Posted February 1st, 2010 19:00

    Please run HijackThis and place a checkmark next to the following:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    Close all other windows and click "Fix Checked". Close HijackThis.

    Please enable McAfee again.

    Download and scan each user profile with CCleaner (a good utility to keep and use regularly.):

    http://www.ccleaner.com/download/builds

    ** Select to download the SLIM version.

    ** Because CCleaner removes everything in temp folders, if you have anything saved in a temp folder, back it up or move it to a permanent folder prior to running CCleaner.

    ** We will be cleaning cookies as well. Make a note of any passwords, etc. that you want to save. If you do not want to delete cookies, simply uncheck that option.

    1. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

    2. Then select the items you wish to clean up. In the Windows Tab:

    • Clean all entries in the "Internet Explorer" section.
    • Clean all the entries in the "Windows Explorer" section
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose. In the Applications Tab:
    • Clean all in the Firefox/Mozilla section if you use it.
    • Clean all in the Opera section if you use it.
    • Clean Sun Java in the Internet Section.
    • Clean any others that you choose.

    3. Click the "Analyze" button. When the list of files comes up, click the "Run Cleaner" button.

    4. A pop up box will appear advising this process will permanently delete files from your system.

    5. Click "OK" and it will scan and clean your system.

    6. Click "exit" when done. REBOOT.

    Let me know how  things are running after that. If everything is back to normal we'll remove DDS, ComboFix, and reset System Restore.

  • renleamse

    24 Posts

    1892

    0

    Posted February 1st, 2010 19:00

    Below are the two logs.

     

    ComboFix 10-02-01.02 - Warren 02/01/2010  21:34:00.2.2 - x86
    Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.1022.436 [GMT -5:00]
    Running from: c:\documents and settings\Warren\Desktop\ComboFix.exe
    AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\kazuzori.dll
    c:\windows\system32\nomadani.dll
    c:\windows\system32\yofamoyu.dll
    c:\windows\system32\zebelivu.dll
    c:\windows\Tasks\dkmayeqz.job

    .
    (((((((((((((((((((((((((   Files Created from 2010-01-02 to 2010-02-02  )))))))))))))))))))))))))))))))
    .

    2010-02-01 22:03 . 2010-02-01 22:03    --------    d-----w-    c:\windows\system32\wbem\Repository
    2010-02-01 22:02 . 2010-02-01 22:02    --------    d-----w-    c:\program files\Malwarebytes' Anti-Malware
    2010-01-29 18:59 . 2004-08-10 09:13    73728    -c--a-w-    c:\windows\system32\dllcache\ehresja.dll
    2010-01-29 18:59 . 2004-08-10 09:13    69632    -c--a-w-    c:\windows\system32\dllcache\ehresko.dll
    2010-01-29 18:59 . 2004-08-10 09:13    69632    -c--a-w-    c:\windows\system32\dllcache\ehresfr.dll
    2010-01-29 18:59 . 2004-08-10 09:13    69632    -c--a-w-    c:\windows\system32\dllcache\ehresde.dll
    2010-01-29 18:59 . 2004-08-10 09:13    61440    -c--a-w-    c:\windows\system32\dllcache\ehreschs.dll
    2010-01-29 18:57 . 2004-08-10 11:00    53248    -c--a-w-    c:\windows\system32\dllcache\nextlink.dll
    2010-01-29 18:56 . 2004-08-10 11:00    97792    -c--a-w-    c:\windows\system32\dllcache\chtmbx.dll
    2010-01-29 18:20 . 2004-08-10 11:00    24661    -c--a-w-    c:\windows\system32\dllcache\spxcoins.dll
    2010-01-29 18:20 . 2004-08-10 11:00    24661    ----a-w-    c:\windows\system32\spxcoins.dll
    2010-01-29 18:20 . 2004-08-10 11:00    13312    -c--a-w-    c:\windows\system32\dllcache\irclass.dll
    2010-01-29 18:20 . 2004-08-10 11:00    13312    ----a-w-    c:\windows\system32\irclass.dll
    2010-01-29 06:54 . 2004-08-10 11:00    16384    -c--a-w-    c:\windows\system32\dllcache\isignup.exe
    2010-01-29 06:11 . 2010-01-29 06:11    --------    d-s---w-    c:\windows\system32\config\systemprofile\History
    2010-01-29 01:01 . 2010-01-29 01:01    --------    d-----w-    c:\windows\dell
    2010-01-28 05:18 . 2010-01-28 05:18    --------    d-----w-    C:\_OTL
    2010-01-25 21:48 . 2010-01-25 21:48    72272    ---ha-w-    c:\windows\system32\mlfcache.dat
    2010-01-21 22:08 . 2010-01-21 22:08    --------    d-----w-    c:\program files\Common Files\Java
    2010-01-21 05:40 . 2010-01-21 05:40    --------    d-----w-    c:\documents and settings\Warren\Application Data\Malwarebytes
    2010-01-21 05:40 . 2010-01-21 05:40    --------    d-----w-    c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-01-21 02:31 . 2010-01-21 02:31    --------    d-----w-    c:\program files\TrendMicro
    2010-01-11 17:35 . 2010-01-11 17:35    --------    d-----w-    c:\documents and settings\Warren\Local Settings\Application Data\Temp

    .
    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-01-29 18:43 . 2005-08-16 09:38    34380    ----a-w-    c:\windows\system32\emptyregdb.dat
    2010-01-29 18:43 . 2010-01-29 18:43    1663    ----a-w-    c:\windows\inf\COMDB.tmp
    2010-01-26 00:57 . 2010-01-26 00:57    503808    ----a-w-    c:\documents and settings\Antonio\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-390a65a0-n\msvcp71.dll
    2010-01-26 00:57 . 2010-01-26 00:57    499712    ----a-w-    c:\documents and settings\Antonio\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-390a65a0-n\jmc.dll
    2010-01-26 00:57 . 2010-01-26 00:57    348160    ----a-w-    c:\documents and settings\Antonio\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-390a65a0-n\msvcr71.dll
    2010-01-26 00:57 . 2010-01-26 00:57    61440    ----a-w-    c:\documents and settings\Antonio\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-450b2ddb-n\decora-sse.dll
    2010-01-26 00:57 . 2010-01-26 00:57    12800    ----a-w-    c:\documents and settings\Antonio\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-450b2ddb-n\decora-d3d.dll
    2010-01-25 16:37 . 2007-01-26 21:07    2516    --sha-w-    c:\windows\system32\KGyGaAvL.sys
    2010-01-25 16:07 . 2007-01-26 20:56    --------    d-----w-    c:\documents and settings\Warren\Application Data\Corel
    2010-01-25 15:53 . 2007-01-26 21:07    88    --sha-r-    c:\windows\system32\260B5B68B1.sys
    2010-01-23 16:52 . 2007-01-24 06:58    --------    d-----w-    c:\program files\Google
    2010-01-21 22:07 . 2010-01-21 22:07    503808    ----a-w-    c:\documents and settings\Warren\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-24dd4b86-n\msvcp71.dll
    2010-01-21 22:07 . 2010-01-21 22:07    348160    ----a-w-    c:\documents and settings\Warren\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-24dd4b86-n\msvcr71.dll
    2010-01-21 22:07 . 2010-01-21 22:07    61440    ----a-w-    c:\documents and settings\Warren\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5c1f2bdb-n\decora-sse.dll
    2010-01-21 22:07 . 2010-01-21 22:07    499712    ----a-w-    c:\documents and settings\Warren\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-24dd4b86-n\jmc.dll
    2010-01-21 22:07 . 2010-01-21 22:07    12800    ----a-w-    c:\documents and settings\Warren\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5c1f2bdb-n\decora-d3d.dll
    2010-01-21 22:06 . 2009-04-07 06:27    411368    ----a-w-    c:\windows\system32\deploytk.dll
    2010-01-21 22:06 . 2007-01-24 06:42    --------    d-----w-    c:\program files\Java
    2010-01-21 21:58 . 2009-01-08 02:51    --------    d-----w-    c:\program files\QuickTime
    2010-01-21 21:57 . 2009-06-27 18:00    --------    d-----w-    c:\program files\FxBear MOV Video Converter
    2010-01-21 00:29 . 2007-04-29 22:36    --------    d-----w-    c:\program files\LimeWire
    2010-01-20 04:10 . 2009-09-21 01:18    --------    d-----w-    c:\program files\Microsoft Silverlight
    2010-01-19 08:24 . 2007-03-06 05:45    39234    ----a-w-    c:\documents and settings\Warren\Application Data\wklnhst.dat
    2010-01-07 20:11 . 2007-04-29 22:36    --------    d-----w-    c:\documents and settings\Warren\Application Data\LimeWire
    2009-12-30 17:18 . 2008-02-04 02:30    --------    d-----w-    c:\documents and settings\Antonio\Application Data\Apple Computer
    2009-12-30 14:39 . 2009-03-09 06:06    256    ----a-w-    c:\windows\system32\pool.bin
    2009-12-30 01:40 . 2009-09-13 06:41    256    ----a-w-    c:\documents and settings\Warren\pool.bin
    2009-12-29 05:54 . 2007-05-09 01:48    --------    d-----w-    c:\documents and settings\Warren\Application Data\Apple Computer
    2009-12-29 05:22 . 2009-12-29 05:20    --------    d-----w-    c:\program files\iTunes
    2009-12-29 05:22 . 2009-12-29 05:20    --------    d-----w-    c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2009-12-29 05:21 . 2009-12-29 05:21    --------    d-----w-    c:\program files\iPod
    2009-12-29 05:21 . 2007-07-16 23:32    --------    d-----w-    c:\program files\Common Files\Apple
    2009-12-29 05:17 . 2009-12-29 05:17    --------    d-----w-    c:\program files\Bonjour
    2009-12-29 05:08 . 2007-07-16 23:32    --------    d-----w-    c:\documents and settings\All Users\Application Data\Apple
    2009-12-29 05:02 . 2009-12-29 05:02    79144    ----a-w-    c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
    2009-12-26 08:38 . 2009-12-26 08:38    79488    ----a-w-    c:\documents and settings\Warren\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
    2009-12-16 23:48 . 2009-07-21 23:40    --------    d-----w-    c:\program files\Electronic Arts
    2009-12-16 23:48 . 2007-01-24 06:47    --------    d--h--w-    c:\program files\InstallShield Installation Information
    2009-12-16 19:42 . 2010-01-25 06:01    872960    ----a-w-    c:\documents and settings\Maria\Application Data\Mozilla\Firefox\Profiles\dzv36gvz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
    2009-12-16 19:42 . 2010-01-25 06:01    43008    ----a-w-    c:\documents and settings\Maria\Application Data\Mozilla\Firefox\Profiles\dzv36gvz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
    2009-12-16 19:42 . 2010-01-25 06:01    340480    ----a-w-    c:\documents and settings\Maria\Application Data\Mozilla\Firefox\Profiles\dzv36gvz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
    2009-12-16 19:41 . 2010-01-25 06:01    346624    ----a-w-    c:\documents and settings\Maria\Application Data\Mozilla\Firefox\Profiles\dzv36gvz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
    2009-12-09 08:11 . 2007-01-24 07:00    --------    d-----w-    c:\program files\Microsoft ActiveSync
    2009-12-07 04:44 . 2009-08-24 21:27    --------    d-----w-    c:\documents and settings\All Users\Application Data\Electronic Arts
    2009-11-19 16:48 . 2009-12-01 21:40    872960    ----a-w-    c:\documents and settings\Antonio\Application Data\Mozilla\Firefox\Profiles\9keze31z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
    2009-11-19 16:48 . 2009-12-01 21:40    43008    ----a-w-    c:\documents and settings\Antonio\Application Data\Mozilla\Firefox\Profiles\9keze31z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
    2009-11-19 16:48 . 2009-12-01 21:40    340480    ----a-w-    c:\documents and settings\Antonio\Application Data\Mozilla\Firefox\Profiles\9keze31z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
    2009-11-19 16:48 . 2009-12-01 21:40    346624    ----a-w-    c:\documents and settings\Antonio\Application Data\Mozilla\Firefox\Profiles\9keze31z.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
    2007-03-22 04:49 . 2007-03-22 04:49    251    ----a-w-    c:\program files\wt3d.ini
    .

    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 24576]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-26 68856]
    "Zinio DLM"="c:\program files\Zinio\ZinioReader.exe" [2007-05-04 3756102]
    "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
    "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-10-17 4347120]
    "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]
    "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
    "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
    "CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
    "MBMon"="CTMBHA.DLL" [2006-06-29 1355042]
    "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
    "VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2006-02-16 1118208]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
    "HostManager"="c:\program files\Common Files\AOL\1169843107\ee\AOLSoftware.exe" [2008-06-24 41824]
    "AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-23 185896]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
    "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 282624]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-10 44544]

    c:\documents and settings\Warren\Start Menu\Programs\Startup\
    wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2006-6-4 21504]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-1-24 24576]
    hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-5 323646]
    hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
    Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-9-19 282624]
    ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
    "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
    "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1169843107\\ee\\aolsoftware.exe"=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\AOL 9.1\\waol.exe"=
    "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
    "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\McAfee\\VirusScan\\mcsysmon.exe"=
    "c:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [9/20/2009 8:18 PM 54752]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-12-18 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]

    2007-07-03 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 2200 series5E771253C1676EBED677BF361FDFC537825E15B8173601507.job
    - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 04:52]

    2010-01-15 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-10-07 16:22]

    2010-01-01 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-10-07 16:22]

    2010-02-02 c:\windows\Tasks\User_Feed_Synchronization-{25646F00-84A9-441D-AA58-3B53EEE9CFD9}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uSearch Page = hxxp://www.google.com
    uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJxdm128YYUS&fl=0&ptb=p6rMQ81L12sOJhCuV36ePQ&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
    IE: &Search
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c90312ade43e4c379b20037b32e75c17
    IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c90312ade43e4c379b20037b32e75c17
    FF - ProfilePath - c:\documents and settings\Warren\Application Data\Mozilla\Firefox\Profiles\9hg2gm2m.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - AOL Search
    FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
    FF - prefs.js: keyword.URL - hxxp://aolsearch.aol.com/aol/search?invocationType=client_searchbox&query=
    FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
    FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
    FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
    FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
    FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{80655e38-0f08-4818-8269-87e05c207a1c} - dazetaha.dll
    HKLM-Run-gunosewon - c:\windows\system32\yofamoyu.dll
    HKLM-Run-lobamopage - nomadani.dll
    SharedTaskScheduler-{25b8c039-9992-4f18-a1a6-3769aca24c0f} - c:\windows\system32\wevejaga.dll
    SharedTaskScheduler-{c5325995-0127-4fe6-b7a9-d03d472f147d} - c:\windows\system32\rojatesu.dll
    SharedTaskScheduler-{c84170c6-8ac4-420c-9b8f-05286e75beed} - c:\windows\system32\yofamoyu.dll
    SharedTaskScheduler-{68aa594f-97a3-4d2b-9aec-8609b2774db6} - c:\windows\system32\yofamoyu.dll
    SharedTaskScheduler-{2ff8e8ff-19eb-41c8-8f67-c7cabf6bad09} - c:\windows\system32\yofamoyu.dll
    SSODL-luvujaluh-{25b8c039-9992-4f18-a1a6-3769aca24c0f} - c:\windows\system32\wevejaga.dll
    SSODL-yanugesar-{c5325995-0127-4fe6-b7a9-d03d472f147d} - c:\windows\system32\rojatesu.dll
    SSODL-husamemed-{c84170c6-8ac4-420c-9b8f-05286e75beed} - c:\windows\system32\yofamoyu.dll
    SSODL-junonoven-{68aa594f-97a3-4d2b-9aec-8609b2774db6} - c:\windows\system32\yofamoyu.dll
    SSODL-rumikazed-{2ff8e8ff-19eb-41c8-8f67-c7cabf6bad09} - c:\windows\system32\yofamoyu.dll



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-01 21:45
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ... 

    scanning hidden autostart entries ...

    scanning hidden files ... 


    c:\windows\system32\wuaucpl.cpl.wusetup.215203.bak 162304 bytes executable
    c:\windows\system32\wuaueng.dll.wusetup.218703.bak 1134592 bytes executable

    scan completed successfully
    hidden files: 2

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(5808)
    c:\windows\system32\ieframe.dll
    c:\windows\system32\shdoclc.dll
    c:\windows\IME\SPGRMR.DLL
    c:\program files\Common Files\Microsoft Shared\INK\PENUSA.DLL
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    c:\windows\system32\CTsvcCDA.exe
    c:\windows\eHome\ehRecvr.exe
    c:\windows\eHome\ehSched.exe
    c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\McAfee\MPF\MPFSrv.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\windows\wanmpsvc.exe
    c:\windows\ehome\mcrdsvc.exe
    c:\windows\system32\dllhost.exe
    c:\progra~1\mcafee.com\agent\mcagent.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\Rundll32.exe
    c:\docume~1\Warren\LOCALS~1\Temp\clclean.0001
    c:\windows\stsystra.exe
    c:\windows\system32\Rundll32.exe
    c:\windows\system32\Rundll32.exe
    c:\program files\Microsoft ActiveSync\wcescomm.exe
    c:\progra~1\MI3AA1~1\rapimgr.exe
    c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
    c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
    c:\windows\system32\dwwin.exe
    .
    **************************************************************************
    .
    Completion time: 2010-02-01  21:54:28 - machine was rebooted
    ComboFix-quarantined-files.txt  2010-02-02 02:54

    Pre-Run: 239,973,466,112 bytes free
    Post-Run: 240,005,914,624 bytes free

    - - End Of File - - 3A699B147CCF4AC9D57914A36B7FC695

     

     

     

     

     

     

     

     

     

     

     

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 10:12:30 PM, on 2/1/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\DOCUME~1\Warren\LOCALS~1\Temp\clclean.0001
    C:\Program Files\Common Files\AOL\1169843107\ee\AOLSoftware.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Zinio\ZinioReader.exe
    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
    C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\WINDOWS\system32\msfeedssync.exe
    C:\WINDOWS\system32\dwwin.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\MsiExec.exe
    C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5070124
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1169843107\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [Zinio DLM] C:\Program Files\Zinio\ZinioReader.exe /autostart
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
    O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?c90312ade43e4c379b20037b32e75c17
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?c90312ade43e4c379b20037b32e75c17
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    --
    End of file - 16365 bytes

  • renleamse

    24 Posts

    1892

    0

    Posted February 1st, 2010 20:00

    Before I run the cleaner, I just want to mention that my mcafee still is not operating properly so I can't enable it. When I click to open it, I get an empty window. Should I delete and then reninstall mcafee, or should i go ahead with the CCleaner?

  • Bugbatter

    4 Apprentice

    20487 Posts

    1892

    0

    Posted February 2nd, 2010 09:00

    See if you can remove McAfee per instructions with McAfee's Removal Tool.

    Step 1 - Download and run the McAfee Removal tool

    Note: You should first attempt to remove your McAfee consumer products using Add/Remove Programs in the Windows Control Panel (Programs and Features, in Windows Vista). This is the best method. After uninstalling using Windows Add/Remove Programs, run the McAfee Consumer Removal Tool (MCPR.EXE) to ensure successful removal of all McAfee references.

       1. Download the removal tool from:

     http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe
          
       2. Click Save and save the file to any folder on your computer.
       3. Navigate to the folder where the file is saved.
       4. Make sure all McAfee windows are closed.
       5. Double-click MCPR.EXE to run the removal tool.
       6. Restart your computer after receiving the message CleanUp Successful.

          Your McAfee product will not be fully removed until the system is restarted.
    If the message Cleanup Unsuccessful is displayed, you can view and save your MCPR log files for analysis by Technical Support.

    All McAfee products are now removed from your computer.
    Step 2 - Reinstall your McAfee Products

    Following that, run CCleaner. That will clean up any temps that McAfee may have added while it was doing its thing.

  • renleamse

    24 Posts

    496

    0

    Posted February 2nd, 2010 10:00

    For some reason I can't install mcafee, I'm still getting the blank window when I try to reinstall.