Unsolved
This post is more than 5 years old
10 Posts
0
3432
September 11th, 2010 07:00
Browser is redirected, unable to perform windows update
Computer appears to be infected by malware. Cox Security Suite (McAfee) is running, however still infected.
Ran Windows Defender after manually updating, (1 issue found.fixed) and windows one care live (multiple issues found/ unable to fix 14)
Any help fixing this would be greatly appreciated.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:41:51 AM, on 9/5/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\G.O.M\GCSVR.EXE
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [vvnrnely] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\gsahulupn\bbktqistssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ugwopmfg] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\qbakgsalp\hlgxbabtssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [goqpputl] C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\xirblhqhc\qffnsqxtssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tinhcgos] C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\dfwbryjye\ltsskcjtssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [pmusxhke] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\yrmrqwwlt\mhlqhsatssd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [vvnrnely] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\gsahulupn\bbktqistssd.exe (User 'Default user')
O4 - S-1-5-18 Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe (User 'Default user')
O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1283618653203
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247971955875
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcams.mtu.edu/webcam8/AxisCamControl.ocx
O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - https://install.cox.net/CoxSelfInstall//CoxSelfInstallAx10.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{CAB506A6-E840-49FD-807B-431AA27D1B1D}: NameServer = 68.105.28.11,68.105.29.11
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter hijack: text/html - {86b70cef-5844-4c13-999c-94d7398c0f92} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COM Service - Unknown owner - C:\Program Files\GIGABYTE\G.O.M\GCSVR.EXE
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
--
End of file - 9964 bytes


kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 11th, 2010 07:00
I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE
** If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE
Please proceed as follows :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
O4 - HKUS\S-1-5-18\..\Run: [vvnrnely] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\gsahulupn\bbktqistssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ugwopmfg] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\qbakgsalp\hlgxbabtssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [goqpputl] C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\xirblhqhc\qffnsqxtssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tinhcgos] C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\dfwbryjye\ltsskcjtssd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [pmusxhke] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\yrmrqwwlt\mhlqhsatssd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [vvnrnely] C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\gsahulupn\bbktqistssd.exe (User 'Default user')
O18 - Filter hijack: text/html - {86b70cef-5844-4c13-999c-94d7398c0f92} - (no file)
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot
Step 2
Alernative D/L mirror
Alternative D/L mirror
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Step 3
We need to see some additional information about what is happening in your machine.
Please perform the following scan:
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
Step4
Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
What i`d like in your reply :-
Kevin
WS7757
10 Posts
0
September 11th, 2010 21:00
Kevin,
Completed all steps listed above. Logs included:
°Log from Malwarebytes
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4597
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/11/2010 10:59:18 PM
mbam-log-2010-09-11 (22-59-18).txt
Scan type: Quick scan
Objects scanned: 376808
Time elapsed: 1 hour(s), 8 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\AnVi (Rogue.AnVi) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\7bde84a2-f58f-46ec-9eac-f1f90fead080 (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\SYSTEM32\a.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
°Both logs from DDS
dds.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by Stacy at 23:13:55.92 on Sat 09/11/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2296 [GMT -4:00]
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\G.O.M\GCSVR.EXE
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Stacy.SAVKIT\Desktop\dds.pif
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uWindow Title =
mWindow Title =
uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe"
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\search toolbar\tbhelper.dll
mURLSearchHooks: H - No File
mURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\search toolbar\tbhelper.dll
BHO: TBSB05974 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\search toolbar\tbcore3.dll
TB: Search Toolbar: {0c8413c1-fad1-446c-8584-be50576f863e} - c:\program files\search toolbar\tbcore3.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\stacy~1.sav\startm~1\programs\startup\efax44~1.lnk - c:\program files\efax messenger 4.4\J2GTray.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: mcafee.com
Trusted Zone: microsoft.com\www.update
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {CAB506A6-E840-49FD-807B-431AA27D1B1D} = 68.105.28.11,68.105.29.11
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
============= SERVICES / DRIVERS ===============
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-7-8 214664]
R2 COM Service;COM Service;c:\program files\gigabyte\g.o.m\GCSVR.exe [2009-7-18 16384]
R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2009-7-18 68136]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-9-29 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-9-29 144704]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-9-29 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-9-29 35272]
S1 sijuxay;sijuxay;c:\windows\system32\drivers\sijuxay.sys [2003-7-16 302336]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-1 135664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe [2009-9-29 203280]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2009-7-18 24944]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-9-29 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-9-29 40552]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-9-29 606736]
=============== Created Last 30 ================
2010-09-12 03:09:49 27087 ----a-w- c:\windows\system32\jcsball.dat
2010-09-12 03:09:49 11295 ----a-w- c:\windows\system32\jcsb.new
2010-09-12 03:09:49 10737 ----a-w- c:\windows\system32\jerror.dat
2010-09-12 00:39:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-12 00:39:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-12 00:39:27 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-11 19:50:40 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Toolbar4
2010-09-11 19:50:30 0 d-----w- c:\program files\Search Toolbar
2010-09-11 19:50:25 0 d-----w- c:\program files\FLVTube Player
2010-09-04 17:32:26 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-04 17:01:24 65536 -c----w- c:\windows\system32\dllcache\asycfilt.dll
2010-09-04 16:47:20 0 d-----w- c:\documents and settings\stacy.savkit\SecurityScans
2010-09-04 16:47:05 0 d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2010-09-04 16:12:07 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-09-04 14:23:21 0 d-----w- c:\program files\Trend Micro
2010-09-04 13:59:14 0 d-----w- c:\documents and settings\stacy.savkit\log
2010-09-04 13:32:10 0 ----a-w- c:\windows\system32\8104297.jun
2010-09-04 13:32:03 0 d-----w- c:\program files\Browser Hijack Recover
2010-09-02 00:51:53 0 d-----w- c:\docume~1\stacy~1.sav\applic~1\ElevatedDiagnostics
2010-08-22 19:27:39 629 ----a-w- c:\windows\system32\mapisvc.inf
2010-08-22 19:20:46 0 d-----w- c:\docume~1\alluse~1.win\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-20 22:52:17 0 d-----w- c:\windows\Freecorder
2010-08-20 22:52:17 0 d-----w- c:\program files\Freecorder
==================== Find3M ====================
2010-09-12 03:09:36 16608 ----a-w- c:\windows\gdrv.sys
2010-09-04 13:27:42 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2010-07-15 19:18:22 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-03 21:01:17 262672 ----a-w- c:\program files\common files\noon.dll
2008-01-26 20:26:16 14290 -c--a-w- c:\program files\settings.dat
2006-12-03 01:50:42 18662912 -c--a-w- c:\program files\common files\TaxWise Workstation.msi
============= FINISH: 23:15:49.25 ===============
Attach.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 7/18/2009 10:22:53 PM
System Uptime: 9/11/2010 11:01:32 PM (0 hours ago)
Motherboard: Gigabyte Technology Co., Ltd. | | GA-MA78GM-US2H
Processor: AMD Athlon(tm) 7850 Dual-Core Processor | Socket M2 | 2812/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 19.68 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 298 GiB total, 130.228 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_02\4&36A73F9A&0&0050
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_02\4&36A73F9A&0&0050
Service: RTLE8023xp
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\241D424C43
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\241D424C43
Service: NIC1394
==== System Restore Points ===================
RP1: 9/11/2010 8:30:08 PM - System Checkpoint
==== Installed Programs ======================
@BIOS Ver.2.05
2007 Microsoft Office Suite Service Pack 2 (SP2)
Adobe AIR
Adobe Digital Editions
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.4
AnswerWorks 5.0 English Runtime
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
AutoIt v3.3.0.0
Avery Wizard 3.1
BlackBerry Device Software v4.5.0 for the BlackBerry 8330 smartphone
Bonjour
Browser Configuration Utility
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center HydraVision Full
ccc-core-preinstall
ccc-core-static
ccc-utility
CCC Help English
DMIView B8.0717.01
Easy Tune 6 B09.0216.1
EasySaver B9.0205.1
eFax Messenger
Face_Wizard B08.0908.01
ffdshow [rev 2527] [2008-12-19]
FLVTube Player
Freecorder 4.01 Application
G.O.M
Google Earth
Google Talk Plugin
Google Toolbar for Internet Explorer
Google Update Helper
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Memories Disc
HP Photo and Imaging 2.0 - Scanners
Internet Explorer (Enable DEP)
iTunes
Java(TM) 6 Update 17
LeapFrog Connect
LeapFrog Crammer Plugin
LeapFrog My Pals Plugin
Malwarebytes' Anti-Malware
Map To Atlantis
McAfee SecurityCenter
McAfee Virtual Technician
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Baseline Security Analyzer 2.2
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
MobileMe Control Panel
MSXML 4.0 SP2 (KB954430)
Music Transfer
MY CAMERA
Opera 10.61
PDFCreator
Primo
Q-Share Ver.1.2
QuickTime
RealPlayer
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
RealUpgrade 1.0
Runtime
Search Toolbar
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 8 (KB917734)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980232)
Shutterfly Express Uploader
Skins
Sony Picture Utility
Spell Checker For OE 2.1
Spelling Dictionaries Support For Adobe Reader 9
TurboTax 2008
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax 2008 wvaiper
TurboTax 2009
TurboTax 2009 WinPerFedFormset
TurboTax 2009 WinPerReleaseEngine
TurboTax 2009 WinPerTaxSupport
TurboTax 2009 wrapper
TurboTax 2009 wvaiper
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB981715)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973815)
Update Manager B08.1027.1
Use the entry named LeapFrog Connect to uninstall (LeapFrog Crammer Plugin)
Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)
Vivitar Experience Image Manager
W Photo Studio
WebFldrs XP
Windows 7 Upgrade Advisor
Windows Defender
Windows Driver Package - Camera Maker (MR97310_USB_DUAL_CAMERA) Image (05/02/2006 2.0.1.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live OneCare safety scanner
Windows PowerShell(TM) 1.0
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
9/7/2010 6:53:08 AM, error: Print [6161] - The document https://webmail.east.cox.net/do/mail/message/preview?msgId=trav owned by Stacy failed to print on printer HP DeskJet 840C/841C/842C/843C. Data type: NT EMF 1.008. Size of the spool file in bytes: 458752. Number of bytes printed: 99548. Total number of pages in the document: 3. Number of pages printed: 1. Client machine: \\SAVKIT. Win32 error code returned by the print processor: 0 (0x0).
9/7/2010 6:51:38 AM, error: Print [6161] - The document https://webmail.east.cox.net/do/mail/message/preview?msgId=trav owned by Stacy failed to print on printer HP DeskJet 840C/841C/842C/843C. Data type: NT EMF 1.008. Size of the spool file in bytes: 458752. Number of bytes printed: 388452. Total number of pages in the document: 3. Number of pages printed: 1. Client machine: \\SAVKIT. Win32 error code returned by the print processor: 0 (0x0).
9/4/2010 9:42:42 AM, error: DCOM [10001] - Unable to start a DCOM Server: {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493} as /. The error: "%233" Happened while starting this command: c:\PROGRA~1\mcafee.com\agent\mcagent.exe -Embedding
9/4/2010 9:30:24 AM, error: DCOM [10000] - Unable to start a DCOM Server: {5A90F5EE-16B8-4C2A-81B3-FD5329BA477C}. The error: "%2" Happened while starting this command: "C:\Program Files\McAfee\SiteAdvisor\McSACore.exe" -Embedding
9/4/2010 11:15:26 AM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Workstation service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Wireless Zero Configuration service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Time service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Management Instrumentation service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Audio service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Themes service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Task Scheduler service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the System Restore Service service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Shell Hardware Detection service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Server service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Secondary Logon service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Network Connections service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the McAfee SiteAdvisor Service service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Help and Support service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Fast User Switching Compatibility service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Error Reporting Service service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Distributed Link Tracking Client service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the DHCP Client service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Cryptographic Services service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COM+ Event System service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Background Intelligent Transfer Service service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Automatic Updates service to connect.
9/4/2010 11:15:26 AM, error: Service Control Manager [7001] - The Windows Firewall/Internet Connection Sharing (ICS) service depends on the Network Connections service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7001] - The System Event Notification service depends on the COM+ Event System service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7001] - The Security Center service depends on the Windows Management Instrumentation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7001] - The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Workstation service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Wireless Zero Configuration service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Windows Time service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Windows Audio service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Themes service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Task Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The System Restore Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Network Connections service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The My Web Search Service service failed to start due to the following error: The system cannot find the path specified.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The McAfee SiteAdvisor Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Help and Support service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Fast User Switching Compatibility service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Distributed Link Tracking Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The DHCP Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Cryptographic Services service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The COM+ Event System service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Background Intelligent Transfer Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:26 AM, error: Service Control Manager [7000] - The Automatic Updates service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
9/4/2010 11:15:20 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
9/4/2010 11:14:43 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/4/2010 11:14:38 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
9/4/2010 10:59:27 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
9/4/2010 10:59:18 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
9/4/2010 10:59:03 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
9/4/2010 10:56:02 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/4/2010 10:55:57 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
9/4/2010 10:55:44 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
9/4/2010 10:55:44 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
9/4/2010 10:23:32 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
9/11/2010 6:38:12 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\system32\dskquoui.dll. Reference error message: The operation completed successfully. .
9/11/2010 6:38:12 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\System32\dfsshlex.dll. Reference error message: The operation completed successfully. .
9/11/2010 6:38:11 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\system32\twext.dll. Reference error message: The operation completed successfully. .
9/11/2010 6:34:49 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.Windows.Common-Controls. Reference error message: Insufficient system resources exist to complete the requested service. .
9/11/2010 6:34:49 AM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WindowsShell.manifest. Reference error message: The operation completed successfully. .
9/11/2010 12:29:35 AM, error: DCOM [10005] - DCOM got error "%1450" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
9/11/2010 11:09:07 PM, error: Service Control Manager [7022] - The WebClient service hung on starting.
9/11/2010 11:02:34 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
9/10/2010 11:16:31 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer ZEKESLAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{CAB506A6-E840-49. The master browser is stopping or an election is being forced.
9/10/2010 10:38:52 PM, error: Srv [2019] - The server was unable to allocate from the system nonpaged pool because the pool was empty.
==== End Of File ===========================
°Log from Security Checks
Results of screen317's Security Check version 0.99.5
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:
Windows Security Center service is not running! This report may not be accurate!
McAfee SecurityCenter
McAfee Virtual Technician
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
Java(TM) 6 Update 17
Out of date Java installed!
Adobe Flash Player 10.1.82.76
Adobe Reader 9.3.4
````````````````````````````````
Process Check:
objlist.exe by Laurent
McAfee VIRUSS~1 mcshield.exe
McAfee VIRUSS~1 mcsysmon.exe
````````````````````````````````
DNS Vulnerability Check:
GREAT! (Not vulnerable to DNS cache poisoning)
``````````End of Log````````````
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 12th, 2010 03:00
Please continue as follows :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot
Step 2
Please download OTM by OldTimer.
Alternative Mirror
Save it to your desktop.
Double click OTM.exe to start the tool.
-------------------------------------------------------------------
:Processes
explorer.exe
:Files
c:\windows\system32\drivers\sijuxay.sys
:Services
sijuxay
:Commands
[EmptyFlash]
[EmptyTemp]
[Purity]
[ResetHosts]
[Reboot]
---------------------------------------------------------------------
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
Step 3
Run an online virus scan with Kaspersky from HERE. This scan is very thorough and may take several hours to run, please allow it to complete.
1. At the main page. Press on " Accept". After reading the contents.
2. At the next window Select Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the Scan icon Select My Computer to start the scan.
4. Select Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
The following animation may help.
Kaspersky Gif
What i`d like in your reply :-
Kevin.
WS7757
10 Posts
0
September 12th, 2010 17:00
Log from OTM
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File move failed. c:\windows\system32\drivers\sijuxay.sys scheduled to be moved on reboot.
========== SERVICES/DRIVERS ==========
Service sijuxay stopped successfully!
Service sijuxay deleted successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 31979655 bytes
->Flash cache emptied: 405 bytes
User: Administrator.SAVKIT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 38766 bytes
User: All Users
User: All Users.WINDOWS
User: BILL
->Temp folder emptied: 1043177 bytes
->Temporary Internet Files folder emptied: 8163366 bytes
->Java cache emptied: 10328931 bytes
->FireFox cache emptied: 2731979 bytes
->Flash cache emptied: 405 bytes
User: Bill Saville
User: Bill.SAVKIT
->Temp folder emptied: 4348304 bytes
->Temporary Internet Files folder emptied: 459046 bytes
->Java cache emptied: 7140 bytes
->Opera cache emptied: 1679933 bytes
->Flash cache emptied: 574 bytes
User: CLAYTON
->Temp folder emptied: 617931 bytes
->Temporary Internet Files folder emptied: 25906877 bytes
->Flash cache emptied: 539 bytes
User: Clayton.SAVKIT
->Temp folder emptied: 4116567 bytes
->Temporary Internet Files folder emptied: 6124080 bytes
->Java cache emptied: 10680337 bytes
->Flash cache emptied: 4620 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56504 bytes
User: Guest
->Temp folder emptied: 2982047 bytes
->Temporary Internet Files folder emptied: 90744856 bytes
->Java cache emptied: 809502 bytes
->Flash cache emptied: 300 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 807893 bytes
->Flash cache emptied: 353 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 142945416 bytes
->Java cache emptied: 1107097 bytes
->Flash cache emptied: 102949 bytes
User: NetworkService
->Temp folder emptied: 133985 bytes
->Temporary Internet Files folder emptied: 1597501 bytes
->Flash cache emptied: 353 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 10434 bytes
->Temporary Internet Files folder emptied: 472897356 bytes
->Java cache emptied: 22665 bytes
->Flash cache emptied: 80079 bytes
User: Owner
User: STACY
->Temp folder emptied: 325003642 bytes
->Temporary Internet Files folder emptied: 547624618 bytes
->Java cache emptied: 325590677 bytes
->FireFox cache emptied: 44793648 bytes
->Google Chrome cache emptied: 16824019 bytes
->Apple Safari cache emptied: 1380352 bytes
->Flash cache emptied: 2415797 bytes
User: Stacy.SAVKIT
->Temp folder emptied: 116314060 bytes
->Temporary Internet Files folder emptied: 117374172 bytes
->Java cache emptied: 69358476 bytes
->Google Chrome cache emptied: 331204654 bytes
->Opera cache emptied: 7284865 bytes
->Flash cache emptied: 437779 bytes
User: wsaville
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 62948 bytes
User: ZEKE
->Temp folder emptied: 32441205 bytes
->Temporary Internet Files folder emptied: 105509299 bytes
->Java cache emptied: 991275 bytes
->Flash cache emptied: 33149 bytes
User: Zeke.SAVKIT
->Temp folder emptied: 149 bytes
->Temporary Internet Files folder emptied: 327974 bytes
->Flash cache emptied: 56504 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1310167 bytes
%systemroot%\System32 .tmp files removed: 55428609 bytes
%systemroot%\System32\dllcache .tmp files removed: 1309696 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 166109875 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 12458000 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 4931011 bytes
RecycleBin emptied: 324267257 bytes
Total Files Cleaned = 3,274.00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTM by OldTimer - Version 3.1.16.0 log created on 09122010_074044
Files moved on Reboot...
File move failed. c:\windows\system32\drivers\sijuxay.sys scheduled to be moved on reboot.
File C:\WINDOWS\temp\mcmsc_gnBt2qLThnM81aQ not found!
File C:\WINDOWS\temp\mcmsc_M5JJJV54MR4GdbU not found!
Registry entries deleted on Reboot...
**************************************************************************************************
Log from Kaspersky
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, September 12, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, September 12, 2010 12:39:05
Records in database: 4211323
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
Scan statistics:
Objects scanned: 219336
Threats found: 1
Infected objects found: 0
Suspicious objects found: 2
Scan duration: 04:46:11
File name / Threat / Threats count
C:\Documents and Settings\STACY\Local Settings\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\Microsoft\Outlook Express\Inbox.bak Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\Stacy.SAVKIT\Local Settings\Application Data\Identities\{E0EB975A-A3FD-4713-B454-7CD632CB469A}\Microsoft\Outlook Express\Old Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
Selected area has been scanned.
************************************************************************************************************
Fresh HJT log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:49:58 PM, on 9/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\G.O.M\GCSVR.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\Search Toolbar\tbhelper.dll
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: TBSB05974 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll
O3 - Toolbar: Search Toolbar - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\npwinext.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe (User 'Default user')
O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.intuit.com
O15 - Trusted Zone: http://*.mcafee.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{CAB506A6-E840-49FD-807B-431AA27D1B1D}: NameServer = 68.105.28.11,68.105.29.11
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter hijack: text/html - {86b70cef-5844-4c13-999c-94d7398c0f92} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COM Service - Unknown owner - C:\Program Files\GIGABYTE\G.O.M\GCSVR.EXE
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
--
End of file - 8834 bytes
Let me know how your system is responing, any specific issues
Testing with IE8 and Opera10.61
Entering "http://update.microsoft.com" still results in Connection refused by server (in Opera) and no connection - IE8.
Bing and Google searches still result in some re-directs.
Clicking on the "Post" button below results in connection refused by server because of mis-typed address (in Opera) and a redirect - IE8.
Resorted to booting off a puppy linux live cd, mounting hard drive, copying above log files to puppy desktop, un-mounting hard drives, then detecting and installing ethernet, loading a web browser from the puppy pet site, searching for and responding to this forum from there (actually took less than 2 minutes - puppy linux is extremely fast). No other hard drive access than copying the log files to puppy linux desktop (ram drive).
r/
Bill
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 13th, 2010 03:00
Obviously something still running in the background. Ok we`ll try Combofix, see if it gets us a foothold. CF can be saved to a memory stick or cd and transferred to the infected pc if necessary. It will also run in Safemode.
We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
Combofix
Don`t forget Combofix must be saved to your desktop. <--Very important
Ensure you have disabled your Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <---Very important
Please include the C:\ComboFix.txt in your next reply for further review.
Examples of how to disable realtime protection available at the following link :-
Disable realtime protection
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
*EXTRA NOTES*
Post the log in your reply please,
Kevin
WS7757
10 Posts
0
September 13th, 2010 17:00
Kevin,
Ran Combofix - log below.
Apparenlty found a ? rootkit issue.
Presently, browsers do not appear to be re-directed and window update worked. yippee. I hope to keep it so.
Much thanks for the help. If I don't see a reply post in 72h I'll assume we are done.
Again, thanks for your time.
r/, Bill
ComboFix 10-09-12.04 - Administrator 09/13/2010 7:30.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2556 [GMT -4:00]
Running from: c:\documents and settings\Administrator.SAVKIT\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Application Data\Toolbar4
c:\documents and settings\Stacy.SAVKIT\My Documents\DPE.DUS
c:\program files\Internet Explorer\SET1769.tmp
c:\program files\Internet Explorer\SET176A.tmp
c:\program files\Internet Explorer\SET3D35.tmp
c:\program files\Internet Explorer\SET3D36.tmp
c:\program files\Internet Explorer\SET463.tmp
c:\program files\Internet Explorer\SET464.tmp
c:\program files\Search Toolbar
c:\program files\Search Toolbar\basis.xml
c:\program files\Search Toolbar\bg.bmp
c:\program files\Search Toolbar\bing_logo.png
c:\program files\Search Toolbar\celebrity.png
c:\program files\Search Toolbar\drop_images.png
c:\program files\Search Toolbar\drop_maps.png
c:\program files\Search Toolbar\drop_news.png
c:\program files\Search Toolbar\drop_videos.png
c:\program files\Search Toolbar\drop_web.png
c:\program files\Search Toolbar\facebook.png
c:\program files\Search Toolbar\favicon.png
c:\program files\Search Toolbar\games.png
c:\program files\Search Toolbar\hotmail.png
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\images.png
c:\program files\Search Toolbar\include.xml
c:\program files\Search Toolbar\info.txt
c:\program files\Search Toolbar\lifestyle.png
c:\program files\Search Toolbar\maps.png
c:\program files\Search Toolbar\messenger.png
c:\program files\Search Toolbar\msn.png
c:\program files\Search Toolbar\news.png
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\tbcore3.dll
c:\program files\Search Toolbar\tbhelper.dll
c:\program files\Search Toolbar\twitter.png
c:\program files\Search Toolbar\uninstall.exe
c:\program files\Search Toolbar\update.exe
c:\program files\Search Toolbar\version.txt
c:\program files\Search Toolbar\video.png
c:\program files\Search Toolbar\videos.png
c:\program files\Search Toolbar\weather.png
c:\program files\Search Toolbar\web.png
C:\Thumbs.db
c:\windows\system32\gmail.dll
c:\windows\system32\msconfig32
E:\install.exe
Infected copy of c:\windows\system32\drivers\cdrom.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((( Files Created from 2010-08-13 to 2010-09-13 )))))))))))))))))))))))))))))))
.
2010-09-13 11:50 . 2010-09-13 11:57 26534 ----a-w- c:\windows\system32\jcsball.dat
2010-09-13 11:50 . 2010-09-13 11:57 10934 ----a-w- c:\windows\system32\jerror.dat
2010-09-12 18:06 . 2010-09-12 18:11 38 ----a-w- c:\documents and settings\Administrator.SAVKIT\t.bat
2010-09-12 17:46 . 2010-09-12 17:46 37848 ----a-w- c:\documents and settings\Administrator.SAVKIT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-12 17:46 . 2010-09-12 17:46 -------- d-----w- c:\documents and settings\Administrator.SAVKIT\Local Settings\Application Data\ATI
2010-09-12 17:46 . 2010-09-12 17:46 -------- d-----w- c:\documents and settings\Administrator.SAVKIT\Application Data\ATI
2010-09-12 15:19 . 2010-09-12 15:19 -------- d-sh--w- c:\documents and settings\Administrator.SAVKIT\PrivacIE
2010-09-12 15:18 . 2010-09-12 15:18 -------- d-----w- c:\documents and settings\Administrator.SAVKIT\Local Settings\Application Data\Opera
2010-09-12 14:05 . 2010-09-12 14:05 -------- d-----w- c:\program files\Microsoft
2010-09-12 14:05 . 2010-09-12 14:05 -------- d-----w- c:\program files\MSN Toolbar
2010-09-12 14:04 . 2010-09-12 14:05 -------- d-----w- c:\program files\MSN Toolbar Installer
2010-09-12 14:03 . 2010-09-12 14:12 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-12 11:40 . 2010-09-12 11:40 -------- d-----w- C:\_OTM
2010-09-12 00:39 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-12 00:39 . 2010-09-12 00:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-12 00:39 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-11 22:22 . 2010-09-11 22:22 -------- d-sh--w- c:\documents and settings\Zeke.SAVKIT\IECompatCache
2010-09-11 19:50 . 2010-09-11 19:50 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\PrivacIE
2010-09-11 19:50 . 2010-09-11 19:50 -------- d-----w- c:\program files\FLVTube Player
2010-09-04 17:32 . 2010-06-24 12:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-04 17:01 . 2010-03-05 14:37 65536 -c----w- c:\windows\system32\dllcache\asycfilt.dll
2010-09-04 16:47 . 2010-09-04 23:26 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\SecurityScans
2010-09-04 16:47 . 2010-09-04 16:47 -------- d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2010-09-04 16:12 . 2010-05-21 18:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-09-04 16:07 . 2010-09-04 16:07 -------- d-----w- c:\program files\Windows Defender
2010-09-04 14:23 . 2010-09-04 14:23 -------- d-----w- c:\program files\Trend Micro
2010-09-04 13:59 . 2010-09-04 13:59 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\log
2010-09-04 13:43 . 2010-09-04 13:43 -------- d-sh--w- c:\documents and settings\Bill.SAVKIT\IECompatCache
2010-09-04 13:42 . 2010-09-04 13:42 -------- d-sh--w- c:\documents and settings\Bill.SAVKIT\PrivacIE
2010-09-04 13:32 . 2010-09-11 22:12 -------- d-----w- c:\program files\Browser Hijack Recover
2010-09-04 13:29 . 2010-09-04 13:29 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\Opera
2010-09-03 02:24 . 2010-09-03 02:24 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Local Settings\Application Data\Opera
2010-09-03 02:23 . 2010-09-03 02:23 -------- d-----w- c:\program files\Opera
2010-09-03 02:18 . 2010-09-03 02:18 0 ----a-w- c:\windows\nsreg.dat
2010-09-03 02:18 . 2010-09-03 02:18 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Local Settings\Application Data\Mozilla
2010-09-02 00:51 . 2010-09-02 00:51 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Application Data\ElevatedDiagnostics
2010-08-27 11:56 . 2010-08-27 11:56 -------- d-----w- c:\documents and settings\Clayton.SAVKIT\Application Data\Apple Computer
2010-08-25 10:27 . 2010-08-27 22:56 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\Google
2010-08-22 19:20 . 2010-08-22 19:22 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-22 18:59 . 2010-08-22 18:59 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Application Data\Apple Computer
2010-08-22 18:59 . 2010-08-22 18:59 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\FLVService
2010-08-20 22:52 . 2010-08-25 01:26 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Local Settings\Application Data\Freecorder
2010-08-20 22:52 . 2010-08-20 22:52 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Local Settings\Application Data\FLVService
2010-08-20 22:52 . 2010-08-25 01:26 -------- d-----w- c:\program files\Freecorder
2010-08-20 22:52 . 2010-08-20 22:52 -------- d-----w- c:\windows\Freecorder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-13 11:50 . 2009-07-19 02:30 16608 ----a-w- c:\windows\gdrv.sys
2010-09-13 10:39 . 2010-05-27 02:38 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-12 14:04 . 2004-02-20 15:29 -------- d-----w- c:\program files\Common Files\Java
2010-09-12 14:03 . 2004-02-20 15:29 -------- d-----w- c:\program files\Java
2010-09-11 22:21 . 2010-09-11 22:21 -------- d-----w- c:\documents and settings\Zeke.SAVKIT\Application Data\Apple Computer
2010-09-11 22:21 . 2010-09-11 22:21 -------- d-----w- c:\documents and settings\Zeke.SAVKIT\Application Data\Share-to-Web Upload Folder
2010-09-05 11:14 . 2007-01-20 17:02 -------- d-----w- c:\program files\Windows Live Safety Center
2010-09-04 13:27 . 2009-07-19 03:17 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2010-08-22 19:37 . 2009-04-14 19:54 -------- d-----w- c:\program files\Safari
2010-08-22 19:25 . 2009-04-14 20:04 -------- d-----w- c:\program files\QuickTime
2010-08-22 19:22 . 2009-04-14 20:08 -------- d-----w- c:\program files\iTunes
2010-08-22 19:20 . 2005-04-19 22:48 -------- d-----w- c:\program files\iPod
2010-08-22 18:38 . 2009-04-14 19:53 -------- d-----w- c:\program files\Bonjour
2010-08-10 19:44 . 2010-01-31 02:08 -------- d-----w- c:\program files\Celebrity Toolbar
2010-08-08 12:49 . 2010-08-08 12:49 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Application Data\com.Shutterfly.ExpressUploader
2010-08-08 12:48 . 2010-08-08 12:48 -------- d-----w- c:\program files\Shutterfly
2010-08-08 12:48 . 2010-01-09 20:14 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-29 21:54 . 2008-03-22 10:57 -------- d-----w- c:\program files\McAfee
2010-07-24 10:42 . 2010-07-05 16:13 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\Application Data\vlc
2010-07-21 23:34 . 2009-07-19 02:40 37848 ----a-w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-15 19:18 . 2009-09-29 23:09 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-06-24 12:22 . 2006-06-23 18:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-03 21:01 . 2010-06-03 21:01 262672 ----a-w- c:\program files\Common Files\noon.dll
2008-01-26 20:26 . 2008-01-26 20:26 14290 -c--a-w- c:\program files\settings.dat
2006-12-03 01:50 . 2007-12-07 20:50 18662912 -c--a-w- c:\program files\Common Files\TaxWise Workstation.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-01 202256]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe" [2010-02-12 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\documents and settings\Stacy.SAVKIT\Start Menu\Programs\Startup\
eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\RecvMessage.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Gigabyte\\GBTUpd\\RunUpd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Gigabyte\\EasySaver\\UpdExe.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
S1 sijuxay;sijuxay;c:\windows\system32\drivers\sijuxay.sys --> c:\windows\system32\drivers\sijuxay.sys [?]
S2 COM Service;COM Service;c:\program files\Gigabyte\G.O.M\GCSVR.exe [7/18/2009 10:59 PM 16384]
S2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [7/18/2009 10:31 PM 68136]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/1/2010 9:46 PM 135664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [9/29/2009 7:11 PM 203280]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 GVTDrv;GVTDrv;c:\windows\SYSTEM32\DRIVERS\GVTDrv.sys [7/18/2009 11:17 PM 24944]
.
Contents of the 'Scheduled Tasks' folder
2010-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 01:46]
2010-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 01:46]
2010-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-29 16:22]
2010-09-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-29 16:22]
2010-09-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-117609710-1659004503-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-12 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-117609710-1659004503-839522115-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-1659004503-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-1659004503-839522115-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-13 c:\windows\Tasks\User_Feed_Synchronization-{2C239030-E9ED-402D-8683-05AF3DCCC77F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
mWindow Title =
TCP: {CAB506A6-E840-49FD-807B-431AA27D1B1D} = 68.105.28.11,68.105.29.11
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - c:\program files\Search Toolbar\tbcore3.dll
SafeBoot-mfehidk
SafeBoot-mferkdk
SafeBoot-mfetdik
SafeBoot-mfetdik.sys
SafeBoot-sijuxay
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-13 08:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,76,05,bf,76,fb,c4,4f,ae,c8,3f,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,76,05,bf,76,fb,c4,4f,ae,c8,3f,\
[HKEY_USERS\S-1-5-21-117609710-1659004503-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,e4,ca,e3,be,09,8b,43,bf,3a,bf,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,e4,ca,e3,be,09,8b,43,bf,3a,bf,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]
"DisplayName"="???\16?\11\09"
"DeviceDesc"="???\16?\11\09"
"ProviderName"="???\11?\18?\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.8"
"DeviceInstanceIds"=multi:"d:\\chipset\\7-ser\\xp\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1192)
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2010-09-13 08:12:47 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-13 12:12
Pre-Run: 23,647,801,344 bytes free
Post-Run: 24,311,873,536 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 4F72DC9FF8C5BE808C8836DD2A861E30
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 13th, 2010 18:00
Still some work to do my friend, proceed as follows :-
Step 1
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text between the dotted lines below into it:
------------------------------------------------------------------------------
KillAll::
File::
c:\windows\system32\drivers\sijuxay.sys
Driver::
sijuxay
RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
[HKEY_USERS\S-1-5-21-117609710-1659004503-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
RegNull::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]
------------------------------------------------------------------------------
Save this as CFScript.txt, in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Step 2
Run an online virus scan with Kaspersky from HERE. This scan is very thorough and may take several hours to run, please allow it to complete.
1. At the main page. Press on " Accept". After reading the contents.
2. At the next window Select Update. Allow the Database to update.
Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run.
3. Once the Database has finished, under the Scan icon Select My Computer to start the scan.
4. Select Scan Report.
5. If any threats were found they will appear in the report
6. Select "Save error report as"
Then in the file name just type in kaspersky
Under "save as type" select text .txt
Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
The following animation may help.
Kaspersky Gif
Post the logs from Combofix and Kaspersky into next reply. Give me an update, any specific issues..
Kevin
WS7757
10 Posts
0
September 15th, 2010 04:00
Kevin,
No problem. I'm here till this is cleaned up.
Ran combofix and kaspersky. Logs follow:
ComboFix 10-09-13.02 - Administrator 09/14/2010 6:47.2.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2536 [GMT -4:00]
Running from: c:\documents and settings\Administrator.SAVKIT\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator.SAVKIT\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FILE ::
"c:\windows\system32\drivers\sijuxay.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_sijuxay
((((((((((((((((((((((((( Files Created from 2010-08-14 to 2010-09-14 )))))))))))))))))))))))))))))))
.
2010-09-13 12:49 . 2010-09-14 10:31 11568 ----a-w- c:\windows\system32\jerror.dat
2010-09-13 12:49 . 2010-09-14 10:31 27391 ----a-w- c:\windows\system32\jcsball.dat
2010-09-13 12:21 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-09-12 18:06 . 2010-09-12 18:11 38 ----a-w- c:\documents and settings\Administrator.SAVKIT\t.bat
2010-09-12 17:46 . 2010-09-12 17:46 37848 ----a-w- c:\documents and settings\Administrator.SAVKIT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-12 17:46 . 2010-09-12 17:46 -------- d-----w- c:\documents and settings\Administrator.SAVKIT\Local Settings\Application Data\ATI
2010-09-12 17:46 . 2010-09-12 17:46 -------- d-----w- c:\documents and settings\Administrator.SAVKIT\Application Data\ATI
2010-09-12 15:19 . 2010-09-12 15:19 -------- d-sh--w- c:\documents and settings\Administrator.SAVKIT\PrivacIE
2010-09-12 15:18 . 2010-09-12 15:18 -------- d-----w- c:\documents and settings\Administrator.SAVKIT\Local Settings\Application Data\Opera
2010-09-12 14:05 . 2010-09-12 14:05 -------- d-----w- c:\program files\Microsoft
2010-09-12 14:05 . 2010-09-12 14:05 -------- d-----w- c:\program files\MSN Toolbar
2010-09-12 14:04 . 2010-09-12 14:05 -------- d-----w- c:\program files\MSN Toolbar Installer
2010-09-12 14:03 . 2010-09-12 14:12 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-12 11:40 . 2010-09-12 11:40 -------- d-----w- C:\_OTM
2010-09-12 00:39 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-12 00:39 . 2010-09-12 00:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-12 00:39 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-11 22:22 . 2010-09-11 22:22 -------- d-sh--w- c:\documents and settings\Zeke.SAVKIT\IECompatCache
2010-09-11 19:50 . 2010-09-11 19:50 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\PrivacIE
2010-09-11 19:50 . 2010-09-11 19:50 -------- d-----w- c:\program files\FLVTube Player
2010-09-04 17:32 . 2010-06-24 12:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-09-04 17:01 . 2010-03-05 14:37 65536 -c----w- c:\windows\system32\dllcache\asycfilt.dll
2010-09-04 16:47 . 2010-09-04 23:26 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\SecurityScans
2010-09-04 16:47 . 2010-09-04 16:47 -------- d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2010-09-04 16:12 . 2010-05-21 18:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-09-04 16:07 . 2010-09-04 16:07 -------- d-----w- c:\program files\Windows Defender
2010-09-04 14:23 . 2010-09-04 14:23 -------- d-----w- c:\program files\Trend Micro
2010-09-04 13:59 . 2010-09-04 13:59 -------- d-----w- c:\documents and settings\Stacy.SAVKIT\log
2010-09-04 13:43 . 2010-09-04 13:43 -------- d-sh--w- c:\documents and settings\Bill.SAVKIT\IECompatCache
2010-09-04 13:42 . 2010-09-04 13:42 -------- d-sh--w- c:\documents and settings\Bill.SAVKIT\PrivacIE
2010-09-04 13:32 . 2010-09-11 22:12 -------- d-----w- c:\program files\Browser Hijack Recover
2010-09-04 13:29 . 2010-09-04 13:29 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\Opera
2010-09-03 02:23 . 2010-09-03 02:23 -------- d-----w- c:\program files\Opera
2010-09-03 02:18 . 2010-09-03 02:18 0 ----a-w- c:\windows\nsreg.dat
2010-08-27 11:56 . 2010-08-27 11:56 -------- d-----w- c:\documents and settings\Clayton.SAVKIT\Application Data\Apple Computer
2010-08-25 10:27 . 2010-08-27 22:56 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\Google
2010-08-22 19:20 . 2010-08-22 19:22 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-22 18:59 . 2010-08-22 18:59 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Application Data\Apple Computer
2010-08-22 18:59 . 2010-08-22 18:59 -------- d-----w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\FLVService
2010-08-20 22:52 . 2010-08-25 01:26 -------- d-----w- c:\program files\Freecorder
2010-08-20 22:52 . 2010-08-20 22:52 -------- d-----w- c:\windows\Freecorder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-13 12:49 . 2009-07-19 02:30 16608 ----a-w- c:\windows\gdrv.sys
2010-09-13 12:41 . 2009-07-24 02:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2010-09-13 10:39 . 2010-05-27 02:38 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-12 14:04 . 2004-02-20 15:29 -------- d-----w- c:\program files\Common Files\Java
2010-09-12 14:03 . 2004-02-20 15:29 -------- d-----w- c:\program files\Java
2010-09-11 22:21 . 2010-09-11 22:21 -------- d-----w- c:\documents and settings\Zeke.SAVKIT\Application Data\Apple Computer
2010-09-11 22:21 . 2010-09-11 22:21 -------- d-----w- c:\documents and settings\Zeke.SAVKIT\Application Data\Share-to-Web Upload Folder
2010-09-05 11:14 . 2007-01-20 17:02 -------- d-----w- c:\program files\Windows Live Safety Center
2010-09-04 13:27 . 2009-07-19 03:17 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2010-08-22 19:37 . 2009-04-14 19:54 -------- d-----w- c:\program files\Safari
2010-08-22 19:25 . 2009-04-14 20:04 -------- d-----w- c:\program files\QuickTime
2010-08-22 19:22 . 2009-04-14 20:08 -------- d-----w- c:\program files\iTunes
2010-08-22 19:20 . 2005-04-19 22:48 -------- d-----w- c:\program files\iPod
2010-08-22 18:38 . 2009-04-14 19:53 -------- d-----w- c:\program files\Bonjour
2010-08-10 19:44 . 2010-01-31 02:08 -------- d-----w- c:\program files\Celebrity Toolbar
2010-08-08 12:48 . 2010-08-08 12:48 -------- d-----w- c:\program files\Shutterfly
2010-08-08 12:48 . 2010-01-09 20:14 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-29 21:54 . 2008-03-22 10:57 -------- d-----w- c:\program files\McAfee
2010-07-21 23:34 . 2009-07-19 02:40 37848 ----a-w- c:\documents and settings\Bill.SAVKIT\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-15 19:18 . 2009-09-29 23:09 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-06-30 12:31 . 2003-07-16 20:43 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2006-06-23 18:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2003-07-16 20:51 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2003-07-16 20:46 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2003-07-16 20:29 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-03 21:01 . 2010-06-03 21:01 262672 ----a-w- c:\program files\Common Files\noon.dll
2008-01-26 20:26 . 2008-01-26 20:26 14290 -c--a-w- c:\program files\settings.dat
2006-12-03 01:50 . 2007-12-07 20:50 18662912 -c--a-w- c:\program files\Common Files\TaxWise Workstation.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-01 202256]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0401.0\mswinext.exe" [2010-02-12 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\documents and settings\Stacy.SAVKIT\Start Menu\Programs\Startup\
eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\RecvMessage.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Gigabyte\\GBTUpd\\RunUpd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Gigabyte\\EasySaver\\UpdExe.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
S2 COM Service;COM Service;c:\program files\Gigabyte\G.O.M\GCSVR.exe [7/18/2009 10:59 PM 16384]
S2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [7/18/2009 10:31 PM 68136]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/1/2010 9:46 PM 135664]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [9/29/2009 7:11 PM 203280]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 GVTDrv;GVTDrv;c:\windows\SYSTEM32\DRIVERS\GVTDrv.sys [7/18/2009 11:17 PM 24944]
.
Contents of the 'Scheduled Tasks' folder
2010-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 01:46]
2010-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 01:46]
2010-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-29 16:22]
2010-09-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-29 16:22]
2010-09-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-117609710-1659004503-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-117609710-1659004503-839522115-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-1659004503-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-117609710-1659004503-839522115-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-09-14 c:\windows\Tasks\User_Feed_Synchronization-{2C239030-E9ED-402D-8683-05AF3DCCC77F}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
mWindow Title =
TCP: {CAB506A6-E840-49FD-807B-431AA27D1B1D} = 68.105.28.11,68.105.29.11
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-14 06:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]
"DisplayName"="???\16?\11\09"
"DeviceDesc"="???\16?\11\09"
"ProviderName"="???\11?\18?\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.8"
"DeviceInstanceIds"=multi:"d:\\chipset\\7-ser\\xp\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1280)
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
.
**************************************************************************
.
Completion time: 2010-09-14 07:12:47 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-14 11:12
ComboFix2.txt 2010-09-13 12:12
Pre-Run: 23,087,300,608 bytes free
Post-Run: 23,071,879,168 bytes free
- - End Of File - - 04CA8E18E482C0E1943947FD8A7CAC04
****************************************************************************************************************************************************
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, September 15, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, September 14, 2010 15:29:57
Records in database: 4211169
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
Scan statistics:
Objects scanned: 222880
Threats found: 1
Infected objects found: 0
Suspicious objects found: 2
Scan duration: 04:35:08
File name / Threat / Threats count
C:\Documents and Settings\STACY\Local Settings\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\Microsoft\Outlook Express\Inbox.bak Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\Stacy.SAVKIT\Local Settings\Application Data\Identities\{E0EB975A-A3FD-4713-B454-7CD632CB469A}\Microsoft\Outlook Express\Old Inbox.dbx Suspicious: Trojan-Spy.HTML.Fraud.gen 1
Selected area has been scanned.
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 15th, 2010 05:00
Thanks for the new logs, system is looking a lot better now, lets get those two entries identified by Kaspersky unless you need to keep them? :-
Please download OTM by OldTimer.
Alternative Mirror
Save it to your desktop.
Double click OTM.exe to start the tool.
-------------------------------------------------------------------
:Files
C:\Documents and Settings\STACY\Local Settings\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\Microsoft\Outlook Express\Inbox.bak
C:\Documents and Settings\Stacy.SAVKIT\Local Settings\Application Data\Identities\{E0EB975A-A3FD-4713-B454-7CD632CB469A}\Microsoft\Outlook Express\Old Inbox.dbx
:Commands
[EmptyTemp]
[Reboot]
---------------------------------------------------------------------
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If the machine reboots, the Results log can be found here:
c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log
Where mmddyyyy_hhmmss is the date of the tool run.
Post the OTM Log, if this is OK we`ll clean up our tools and get you back to normal. Let me know if there are any specific issues..
Kevin
WS7757
10 Posts
0
September 15th, 2010 17:00
Hey Kevin,
OK, ran OTM. Log below.
r/ Bill
All processes killed
========== FILES ==========
C:\Documents and Settings\STACY\Local Settings\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\Microsoft\Outlook Express\Inbox.bak moved successfully.
C:\Documents and Settings\Stacy.SAVKIT\Local Settings\Application Data\Identities\{E0EB975A-A3FD-4713-B454-7CD632CB469A}\Microsoft\Outlook Express\Old Inbox.dbx moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Administrator.SAVKIT
->Temp folder emptied: 110573392 bytes
->Temporary Internet Files folder emptied: 1619406 bytes
->Java cache emptied: 128115 bytes
->Opera cache emptied: 1144806 bytes
->Flash cache emptied: 574 bytes
User: All Users
User: All Users.WINDOWS
User: BILL
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Bill Saville
User: Bill.SAVKIT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: CLAYTON
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Clayton.SAVKIT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 5668 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 1142 bytes
User: Owner
User: STACY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Stacy.SAVKIT
->Temp folder emptied: 70406043 bytes
->Temporary Internet Files folder emptied: 35006927 bytes
->Java cache emptied: 78077 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 24468881 bytes
->Flash cache emptied: 5533 bytes
User: wsaville
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: ZEKE
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Zeke.SAVKIT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 34798 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 232.00 mb
OTM by OldTimer - Version 3.1.16.1 log created on 09152010_190523
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 16th, 2010 00:00
We`re just about there my friend, everything is looking good. Please proceed as follows :-
Step 1
Remove Combofix now that we're done with it
The above procedure will delete the following:
Step 2
:emotion-30:Download OTC by OldTimer and save it to your desktop. Alternative mirror
:emotion-30:Double click
If you are using Vista, please right-click and choose run as administrator
:emotion-30:Then Click the big
:emotion-30:You will get a prompt saying " Being Cleanup Process". Please select Yes.
:emotion-30:Restart your computer when prompted.
:emotion-30: This will remove most of the remaining tools and itself, any thing left on the Desktop can be safely deleted.
Step 3
Download and scan with CCleaner
1. Starting with v 1.27.26 (This version no. will differ), CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK " Only delete files in Windows Temp folder older than 24 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
In the Applications Tab:
4. Click the " Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click " OK" and it will scan and clean your system.
7. Click " exit" when done.
CCleaner will keep your system free of clutter, use it weekly. It probably wont find much this run because we`ve already cleaned up.
Let me know if the above went OK, especially the Combofix uninstall. Post back if all OK or any outstanding issues.
Kevin
WS7757
10 Posts
0
September 16th, 2010 18:00
Hey Kevin,
Ran Combofix. They're kinda strict when in comes to syntax: has to be /Uninstall and not /uninstall. Anyway, it uninstalled ok.
Ran OTC cleanup - no errors.
Ran CCleaner - found some stuff, just cookies and web page cache but otherwise if finished ok
So far everything else seems to be working OK. Windows updates are as annoying as always, but are at least working. No odd browser re-directs that I can detect.
Again, Thanks for you time! I really appreciate the help.
If you are able to recommend...is there a better anti-virus suite than McAfee? If you can't recommend anything, I'll understand.
r/
Bill
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 16th, 2010 23:00
Good to here those tasks went ok and you are back to normal. Regarding security, this a difficult one. I used Kaspersky for years, but like most of the big guns it tends to use a lot of resources. My own security set up now is :-
Firewall - Windows own (Free)
AV + Anti-spware - Microsoft Security Essentials (Free)
Anti - Malware - Malwarebytes (Paid for) this was a one off payment £20 for a lifetime licence. The paid for version gives realtime protection.
My operating system is Windows 7 Professional
The best form of defence is common sense. Dont visit dodgy sites, porn etc. If you dont recognize it, dont open it. If it looks too good to be true then it wont be. Avoid P2P applications and associated websites, malware writes take full advantage of both to infect systems.
Keep everything fully updated and patched to avoid vulnerabilities.
Here are some tips to reduce the potential for malware infection in the future; I strongly recommend that you read them and take them to heart so that you don't have to endure the process of cleaning your computer again.
Make proper use of your antivirus and firewall
Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.
You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.
You will have several programs installed, these maybe outdated and vulnerable to exploits also. To be certain, please run the free online scan by Secunia, available Here Before clicking the Start scan button, please check the box for the option Enable thorough system inspection. Just below the "Scan Options:" section, you'll see the status of what's currently processing....
...when the scan completes, the message "Detection completed successfully" will appear in the Programs/Result section. For each problem detected, Secunia will offer a "Solution" option. Please follow those instructions to download updated versions of the programs as recommended by Secunia.
Use a safer web browser
Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
Firefox,
Opera, and
Chrome.
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.
These browser add-ons will help to make your browser safer:
Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:
Available for Firefox and Internet Explorer.
Green to go,
Yellow for caution, and
Red to stop.
Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.
These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.
Here a couple of links by two security experts that will give some excellent tips and advice.
So how did I get infected in the first place by Tony Klein
How to prevent Malware by Miekiemoes
Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.
Please reply so I know you have read this, its been a pleasure to work with you.
Take care,
Kevin
WS7757
10 Posts
0
September 17th, 2010 05:00
Kevin,
Thanks for the reply and ALL of the tips. I will definitely follow them. This is our "family" machine so a week of me keeping - well, trying to keep - everyone off the internet was no fun.
Again,
Thank you!
R/
Bill
kevinf80_1d0ac6
2 Intern
•
1.1K Posts
0
September 17th, 2010 08:00
Since this issue appears to be resolved the topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.