Unsolved
This post is more than 5 years old
11 Posts
0
2019
December 2nd, 2009 12:00
System Defender popups stopped but problems remain
Hi,
A HijackThis log is pasted in below. I am trying to fix things myself to avoid having to pay McAfee the 90 bucks. Any help would be greatly appreciated
Heres what happened:
1. Something called System Defender got onto my Windows XP Dell Inspiron E1705 and started giving me unwanted popups.
2. I found (I think) the location of the System Defender files and deleting them stopped the popups. During this process I rebooted several times.
3. Current known remaining problems are:
a. McAfee won't run -- McAfee does not appear to start on boot as it did before (the usual splash does not appear), and nothing happens then I try to start any McAfee application, either through the Start menu or by going to the program folder and trying to Open them from there. The HijackThis log file shows some items with "McAfee" but I see no other evidence that it is running. The McAfee icon does not appear on the task bar like before, and the little green check marks for good and red Xs for bad that McAffe used to put on Google search results are no longer there.
b. Cntrl-Alt-Delete does not work - e.g. the task manager screen does not appear.
c. Any attempt to go to google.com from either browser (MSIE 6 or Firefox) takes me to google.nl instead. The only exception is that the google "homepage" that came came set up on my dell still works. Attempt to go to my gmail account work, but only after saying OK on an invalid certificate message that did not appear before.
4. After some research I found and downloaded HijackThis. Upon running it it told me that it could not open the "host "file so I would have to edit that myself, However I found no host file in the indicated location. through Hijack this I found a line that had System Defender in it and deleted it with Fix. After rebooting the problems still remained so I ran Hijack this again, the log for which is pasted in below.
Thank in advance for any help offered.
Regards,
Tom
------
HijackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:26:37 PM, on 12/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpserver.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpACtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpCCtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpkbinst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 89.248.168.187 google.ae
O1 - Hosts: 89.248.168.187 google.as
O1 - Hosts: 89.248.168.187 google.at
O1 - Hosts: 89.248.168.187 google.az
O1 - Hosts: 89.248.168.187 google.ba
O1 - Hosts: 89.248.168.187 google.be
O1 - Hosts: 89.248.168.187 google.bg
O1 - Hosts: 89.248.168.187 google.bs
O1 - Hosts: 89.248.168.187 google.ca
O1 - Hosts: 89.248.168.187 google.cd
O1 - Hosts: 89.248.168.187 google.com.gh
O1 - Hosts: 89.248.168.187 google.com.hk
O1 - Hosts: 89.248.168.187 google.com.jm
O1 - Hosts: 89.248.168.187 google.com.mx
O1 - Hosts: 89.248.168.187 google.com.my
O1 - Hosts: 89.248.168.187 google.com.na
O1 - Hosts: 89.248.168.187 google.com.nf
O1 - Hosts: 89.248.168.187 google.com.ng
O1 - Hosts: 89.248.168.187 google.ch
O1 - Hosts: 89.248.168.187 google.com.np
O1 - Hosts: 89.248.168.187 google.com.pr
O1 - Hosts: 89.248.168.187 google.com.qa
O1 - Hosts: 89.248.168.187 google.com.sg
O1 - Hosts: 89.248.168.187 google.com.tj
O1 - Hosts: 89.248.168.187 google.com.tw
O1 - Hosts: 89.248.168.187 google.dj
O1 - Hosts: 89.248.168.187 google.de
O1 - Hosts: 89.248.168.187 google.dk
O1 - Hosts: 89.248.168.187 google.dm
O1 - Hosts: 89.248.168.187 google.ee
O1 - Hosts: 89.248.168.187 google.fi
O1 - Hosts: 89.248.168.187 google.fm
O1 - Hosts: 89.248.168.187 google.fr
O1 - Hosts: 89.248.168.187 google.ge
O1 - Hosts: 89.248.168.187 google.gg
O1 - Hosts: 89.248.168.187 google.gm
O1 - Hosts: 89.248.168.187 google.gr
O1 - Hosts: 89.248.168.187 google.ht
O1 - Hosts: 89.248.168.187 google.ie
O1 - Hosts: 89.248.168.187 google.im
O1 - Hosts: 89.248.168.187 google.in
O1 - Hosts: 89.248.168.187 google.it
O1 - Hosts: 89.248.168.187 google.ki
O1 - Hosts: 89.248.168.187 google.la
O1 - Hosts: 89.248.168.187 google.li
O1 - Hosts: 89.248.168.187 google.lv
O1 - Hosts: 89.248.168.187 google.ma
O1 - Hosts: 89.248.168.187 google.ms
O1 - Hosts: 89.248.168.187 google.mu
O1 - Hosts: 89.248.168.187 google.mw
O1 - Hosts: 89.248.168.187 google.nl
O1 - Hosts: 89.248.168.187 google.no
O1 - Hosts: 89.248.168.187 google.nr
O1 - Hosts: 89.248.168.187 google.nu
O1 - Hosts: 89.248.168.187 google.pl
O1 - Hosts: 89.248.168.187 google.pn
O1 - Hosts: 89.248.168.187 google.pt
O1 - Hosts: 89.248.168.187 google.ro
O1 - Hosts: 89.248.168.187 google.ru
O1 - Hosts: 89.248.168.187 google.rw
O1 - Hosts: 89.248.168.187 google.sc
O1 - Hosts: 89.248.168.187 google.se
O1 - Hosts: 89.248.168.187 google.sh
O1 - Hosts: 89.248.168.187 google.si
O1 - Hosts: 89.248.168.187 google.sm
O1 - Hosts: 89.248.168.187 google.sn
O1 - Hosts: 89.248.168.187 google.st
O1 - Hosts: 89.248.168.187 google.tl
O1 - Hosts: 89.248.168.187 google.tm
O1 - Hosts: 89.248.168.187 google.tt
O1 - Hosts: 89.248.168.187 google.us
O1 - Hosts: 89.248.168.187 google.vu
O1 - Hosts: 89.248.168.187 google.ws
O1 - Hosts: 89.248.168.187 google.co.ck
O1 - Hosts: 89.248.168.187 google.co.id
O1 - Hosts: 89.248.168.187 google.co.il
O1 - Hosts: 89.248.168.187 google.co.in
O1 - Hosts: 89.248.168.187 google.co.jp
O1 - Hosts: 89.248.168.187 google.co.kr
O1 - Hosts: 89.248.168.187 google.co.ls
O1 - Hosts: 89.248.168.187 google.co.ma
O1 - Hosts: 89.248.168.187 google.co.nz
O1 - Hosts: 89.248.168.187 google.co.tz
O1 - Hosts: 89.248.168.187 google.co.ug
O1 - Hosts: 89.248.168.187 google.co.uk
O1 - Hosts: 89.248.168.187 google.co.za
O1 - Hosts: 89.248.168.187 google.co.zm
O1 - Hosts: 89.248.168.187 google.com
O1 - Hosts: 89.248.168.187 google.com.af
O1 - Hosts: 89.248.168.187 google.com.ag
O1 - Hosts: 89.248.168.187 google.com.ar
O1 - Hosts: 89.248.168.187 google.com.au
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe" /m
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5817/mcfscan.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CyberPatrol UpdateService - CyberPatrol LLC - C:\Program Files\CyberPatrol LLC\CyberPatrol\UpdateService.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9ef7861b920aa) (gupdate1c9ef7861b920aa) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15565 bytes


bamajim
10.4K Posts
0
December 3rd, 2009 06:00
1. We need to temporarily disable McAfee
If you have McAfee Virus Only
Step 1: Move your mouse pointer to the toolbar at the lower right corner of your computer's desktop. Click on the arrow button facing towards the left to expand the system tray area.
Step 2: The System IconFind the red "M" icon for the McAfee Anti-Virus program in the expanded system tray. Right-click on it.
Step 3: Look for an option in the new menu that will pop up that says either "Exit" or "Disable" and click on it.
Step 4: Click "Yes" on the pop up box that will appear asking if you are sure you want to disable the McAfee Anti-Virus program. Double-click on the McAfee desktop icon, or re-start the computer entirely to enable the program again.
If you have McAffee Security Center
Step 1: Locate the red "M" icon in the system tray at the bottom right corner of the desktop. Double click on it to open the Security Center program.
Step 2: Click on the "Advanced" tab and then choose the option labeled as "Configure."
Step 3: Click on the "Files" button on the top toolbar. Click on the "Disable" button at the center of the screen.
Step 4: Enter in a time for the program to automatically turn back on in the text field at the right or, instead, re-start the computer to turn it back on.
2. Rerun Hijackthis (scan only) and place checks beside the following entries
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 89.248.168.187 google.ae
O1 - Hosts: 89.248.168.187 google.as
O1 - Hosts: 89.248.168.187 google.at
O1 - Hosts: 89.248.168.187 google.az
O1 - Hosts: 89.248.168.187 google.ba
O1 - Hosts: 89.248.168.187 google.be
O1 - Hosts: 89.248.168.187 google.bg
O1 - Hosts: 89.248.168.187 google.bs
O1 - Hosts: 89.248.168.187 google.ca
O1 - Hosts: 89.248.168.187 google.cd
O1 - Hosts: 89.248.168.187 google.com.gh
O1 - Hosts: 89.248.168.187 google.com.hk
O1 - Hosts: 89.248.168.187 google.com.jm
O1 - Hosts: 89.248.168.187 google.com.mx
O1 - Hosts: 89.248.168.187 google.com.my
O1 - Hosts: 89.248.168.187 google.com.na
O1 - Hosts: 89.248.168.187 google.com.nf
O1 - Hosts: 89.248.168.187 google.com.ng
O1 - Hosts: 89.248.168.187 google.ch
O1 - Hosts: 89.248.168.187 google.com.np
O1 - Hosts: 89.248.168.187 google.com.pr
O1 - Hosts: 89.248.168.187 google.com.qa
O1 - Hosts: 89.248.168.187 google.com.sg
O1 - Hosts: 89.248.168.187 google.com.tj
O1 - Hosts: 89.248.168.187 google.com.tw
O1 - Hosts: 89.248.168.187 google.dj
O1 - Hosts: 89.248.168.187 google.de
O1 - Hosts: 89.248.168.187 google.dk
O1 - Hosts: 89.248.168.187 google.dm
O1 - Hosts: 89.248.168.187 google.ee
O1 - Hosts: 89.248.168.187 google.fi
O1 - Hosts: 89.248.168.187 google.fm
O1 - Hosts: 89.248.168.187 google.fr
O1 - Hosts: 89.248.168.187 google.ge
O1 - Hosts: 89.248.168.187 google.gg
O1 - Hosts: 89.248.168.187 google.gm
O1 - Hosts: 89.248.168.187 google.gr
O1 - Hosts: 89.248.168.187 google.ht
O1 - Hosts: 89.248.168.187 google.ie
O1 - Hosts: 89.248.168.187 google.im
O1 - Hosts: 89.248.168.187 google.in
O1 - Hosts: 89.248.168.187 google.it
O1 - Hosts: 89.248.168.187 google.ki
O1 - Hosts: 89.248.168.187 google.la
O1 - Hosts: 89.248.168.187 google.li
O1 - Hosts: 89.248.168.187 google.lv
O1 - Hosts: 89.248.168.187 google.ma
O1 - Hosts: 89.248.168.187 google.ms
O1 - Hosts: 89.248.168.187 google.mu
O1 - Hosts: 89.248.168.187 google.mw
O1 - Hosts: 89.248.168.187 google.nl
O1 - Hosts: 89.248.168.187 google.no
O1 - Hosts: 89.248.168.187 google.nr
O1 - Hosts: 89.248.168.187 google.nu
O1 - Hosts: 89.248.168.187 google.pl
O1 - Hosts: 89.248.168.187 google.pn
O1 - Hosts: 89.248.168.187 google.pt
O1 - Hosts: 89.248.168.187 google.ro
O1 - Hosts: 89.248.168.187 google.ru
O1 - Hosts: 89.248.168.187 google.rw
O1 - Hosts: 89.248.168.187 google.sc
O1 - Hosts: 89.248.168.187 google.se
O1 - Hosts: 89.248.168.187 google.sh
O1 - Hosts: 89.248.168.187 google.si
O1 - Hosts: 89.248.168.187 google.sm
O1 - Hosts: 89.248.168.187 google.sn
O1 - Hosts: 89.248.168.187 google.st
O1 - Hosts: 89.248.168.187 google.tl
O1 - Hosts: 89.248.168.187 google.tm
O1 - Hosts: 89.248.168.187 google.tt
O1 - Hosts: 89.248.168.187 google.us
O1 - Hosts: 89.248.168.187 google.vu
O1 - Hosts: 89.248.168.187 google.ws
O1 - Hosts: 89.248.168.187 google.co.ck
O1 - Hosts: 89.248.168.187 google.co.id
O1 - Hosts: 89.248.168.187 google.co.il
O1 - Hosts: 89.248.168.187 google.co.in
O1 - Hosts: 89.248.168.187 google.co.jp
O1 - Hosts: 89.248.168.187 google.co.kr
O1 - Hosts: 89.248.168.187 google.co.ls
O1 - Hosts: 89.248.168.187 google.co.ma
O1 - Hosts: 89.248.168.187 google.co.nz
O1 - Hosts: 89.248.168.187 google.co.tz
O1 - Hosts: 89.248.168.187 google.co.ug
O1 - Hosts: 89.248.168.187 google.co.uk
O1 - Hosts: 89.248.168.187 google.co.za
O1 - Hosts: 89.248.168.187 google.co.zm
O1 - Hosts: 89.248.168.187 google.com
O1 - Hosts: 89.248.168.187 google.com.af
O1 - Hosts: 89.248.168.187 google.com.ag
O1 - Hosts: 89.248.168.187 google.com.ar
O1 - Hosts: 89.248.168.187 google.com.au
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
oancient1
11 Posts
0
December 3rd, 2009 10:00
bamajim,
Thanks for the help.
I have McAfee Security Center, and before this problem occured the M icon was indeed displayed on the taskbar where you said to look. But since the first reboot after the current problem occured, the M icon is no longer displayed there, so I cannot perform the steps you gave me for disabling the McAfee. Even when I try to start Security Center manually, either from the Start menu or using Open from the indicated start file location (C:\Program Files\McAfee\MSC\mcshell.exe), nothing happens other than an extremely brief hourglass display.
Perhaps it is also worth repeating that Control-Alt-Delete also does not work to bring up Window Task Manager. However, I am now able to see processes running at the beginning of the HijackThis log file and through the HijackThis process manager tool. Comparing HijackThis results from before and after manual attempts to start Mcafee, there appears to no change. Both logs shows one only one McAfee process running -- not the mcshell.exe one i mentioned before, but instead a differnet application (C:\Program Files\McAfee\MSK\MskSrver.exe) that, according to the file "properties" is the McAfee antispam filter.
So ... to me this raised two immediate questions:
1. As I can not disable McAfee but normal methods, would it be harmful and/or possibly effective to do a HijackThis scan and fix the lines you per your instructions given the current status as described above?
2. As there appears to be a means of killing a process through the Hijackthis process manager tool, would using this to kill the indicated mcafee process before doing the above be be potentially harmful?.
Thanks again for the help.
Tom
bamajim
10.4K Posts
0
December 3rd, 2009 13:00
Proceed on with part 2 of the fix and let's see what kind of results we get.
Then we can decide what to do about McAfee
oancient1
11 Posts
0
December 4th, 2009 08:00
oancient1
11 Posts
0
December 4th, 2009 10:00
Hi bamajim,
I did as you instructed but all previously described problems remain. The HijackThis log (paste in at the end of this post) appears to leave all the host items unfixed while the other two items I checked were gone. Could this be related to the fact that, as previously mentioned in my original post, I get a message that Hijack this cannot open my hosts file and I must edit open the host file myself to edit it. If so, per my original post, I could find a file named "hosts" file in the indicated folder (C:\WINDOWS\system32\drivers\etc) when I first ran hijack, but a file named host.new is now there with a time stamp indicating it was created this morning at 11:35, or right about the time I was running the hijack scan before fixing. The contents of that new hosts,new file are paste in directly below -- the unbolded lines correspond to items shown in in both the pre- and post-HijackThis scan logs, and bolded are those that are do not appear in either
74.125.45.100 safebrowsing-cache.google.com
74.125.45.100 urs.microsoft.com
74.125.45.100 www.securesoftwarebill.com
74.125.45.100 secure-plus-payments.com
74.125.45.100 www.getantivirusplusnow.com
74.125.45.100 www.secure-plus-payments.com
74.125.45.100 secure.paysecuresystem.com
74.125.45.100 paysoftbillsolution.com
74.125.45.100 protected.maxisoftwaremart.com
74.125.45.100 4-open-davinci.com
74.125.45.100 securitysoftwarepayments.com
74.125.45.100 privatesecuredpayments.com
74.125.45.100 secure.privatesecuredpayments.com
74.125.45.100 www.getavplusnow.com
Note that properties of the hosts.new file indicate creation at 11:27 this morning and last modification at 11:35.
Thanks again for all the help.
Best Regards,
Tom
---------
HijackThis log file after fix and reboot
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:59:43 AM, on 12/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpserver.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpACtrl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpCCtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpkbinst.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 89.248.168.187 google.ae
O1 - Hosts: 89.248.168.187 google.as
O1 - Hosts: 89.248.168.187 google.at
O1 - Hosts: 89.248.168.187 google.az
O1 - Hosts: 89.248.168.187 google.ba
O1 - Hosts: 89.248.168.187 google.be
O1 - Hosts: 89.248.168.187 google.bg
O1 - Hosts: 89.248.168.187 google.bs
O1 - Hosts: 89.248.168.187 google.ca
O1 - Hosts: 89.248.168.187 google.cd
O1 - Hosts: 89.248.168.187 google.com.gh
O1 - Hosts: 89.248.168.187 google.com.hk
O1 - Hosts: 89.248.168.187 google.com.jm
O1 - Hosts: 89.248.168.187 google.com.mx
O1 - Hosts: 89.248.168.187 google.com.my
O1 - Hosts: 89.248.168.187 google.com.na
O1 - Hosts: 89.248.168.187 google.com.nf
O1 - Hosts: 89.248.168.187 google.com.ng
O1 - Hosts: 89.248.168.187 google.ch
O1 - Hosts: 89.248.168.187 google.com.np
O1 - Hosts: 89.248.168.187 google.com.pr
O1 - Hosts: 89.248.168.187 google.com.qa
O1 - Hosts: 89.248.168.187 google.com.sg
O1 - Hosts: 89.248.168.187 google.com.tj
O1 - Hosts: 89.248.168.187 google.com.tw
O1 - Hosts: 89.248.168.187 google.dj
O1 - Hosts: 89.248.168.187 google.de
O1 - Hosts: 89.248.168.187 google.dk
O1 - Hosts: 89.248.168.187 google.dm
O1 - Hosts: 89.248.168.187 google.ee
O1 - Hosts: 89.248.168.187 google.fi
O1 - Hosts: 89.248.168.187 google.fm
O1 - Hosts: 89.248.168.187 google.fr
O1 - Hosts: 89.248.168.187 google.ge
O1 - Hosts: 89.248.168.187 google.gg
O1 - Hosts: 89.248.168.187 google.gm
O1 - Hosts: 89.248.168.187 google.gr
O1 - Hosts: 89.248.168.187 google.ht
O1 - Hosts: 89.248.168.187 google.ie
O1 - Hosts: 89.248.168.187 google.im
O1 - Hosts: 89.248.168.187 google.in
O1 - Hosts: 89.248.168.187 google.it
O1 - Hosts: 89.248.168.187 google.ki
O1 - Hosts: 89.248.168.187 google.la
O1 - Hosts: 89.248.168.187 google.li
O1 - Hosts: 89.248.168.187 google.lv
O1 - Hosts: 89.248.168.187 google.ma
O1 - Hosts: 89.248.168.187 google.ms
O1 - Hosts: 89.248.168.187 google.mu
O1 - Hosts: 89.248.168.187 google.mw
O1 - Hosts: 89.248.168.187 google.nl
O1 - Hosts: 89.248.168.187 google.no
O1 - Hosts: 89.248.168.187 google.nr
O1 - Hosts: 89.248.168.187 google.nu
O1 - Hosts: 89.248.168.187 google.pl
O1 - Hosts: 89.248.168.187 google.pn
O1 - Hosts: 89.248.168.187 google.pt
O1 - Hosts: 89.248.168.187 google.ro
O1 - Hosts: 89.248.168.187 google.ru
O1 - Hosts: 89.248.168.187 google.rw
O1 - Hosts: 89.248.168.187 google.sc
O1 - Hosts: 89.248.168.187 google.se
O1 - Hosts: 89.248.168.187 google.sh
O1 - Hosts: 89.248.168.187 google.si
O1 - Hosts: 89.248.168.187 google.sm
O1 - Hosts: 89.248.168.187 google.sn
O1 - Hosts: 89.248.168.187 google.st
O1 - Hosts: 89.248.168.187 google.tl
O1 - Hosts: 89.248.168.187 google.tm
O1 - Hosts: 89.248.168.187 google.tt
O1 - Hosts: 89.248.168.187 google.us
O1 - Hosts: 89.248.168.187 google.vu
O1 - Hosts: 89.248.168.187 google.ws
O1 - Hosts: 89.248.168.187 google.co.ck
O1 - Hosts: 89.248.168.187 google.co.id
O1 - Hosts: 89.248.168.187 google.co.il
O1 - Hosts: 89.248.168.187 google.co.in
O1 - Hosts: 89.248.168.187 google.co.jp
O1 - Hosts: 89.248.168.187 google.co.kr
O1 - Hosts: 89.248.168.187 google.co.ls
O1 - Hosts: 89.248.168.187 google.co.ma
O1 - Hosts: 89.248.168.187 google.co.nz
O1 - Hosts: 89.248.168.187 google.co.tz
O1 - Hosts: 89.248.168.187 google.co.ug
O1 - Hosts: 89.248.168.187 google.co.uk
O1 - Hosts: 89.248.168.187 google.co.za
O1 - Hosts: 89.248.168.187 google.co.zm
O1 - Hosts: 89.248.168.187 google.com
O1 - Hosts: 89.248.168.187 google.com.af
O1 - Hosts: 89.248.168.187 google.com.ag
O1 - Hosts: 89.248.168.187 google.com.ar
O1 - Hosts: 89.248.168.187 google.com.au
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe" /m
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5817/mcfscan.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CyberPatrol UpdateService - CyberPatrol LLC - C:\Program Files\CyberPatrol LLC\CyberPatrol\UpdateService.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9ef7861b920aa) (gupdate1c9ef7861b920aa) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15555 bytes
bamajim
10.4K Posts
0
December 7th, 2009 07:00
It may take a couple of runs at this to completely remove it.
Lets do this
1. Go HERE and download File Lister.
Copy and paste the contents of that log in your reply.
oancient1
11 Posts
0
December 8th, 2009 12:00
bamajim,
Sorry I was away for a day. Snowstorm took out a cable and left me without the internet temporarily.
I downloaded and ran File Lister as instructed. The contents of C:/Files.txt are pasted in below. Note that the application left a cmd.exe window open after completing
-------
Contents of Files.txt
+++++++++++++++++++++++++++++++++
+ File Lister Version 1.1.1 +
+ +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++++++++
Report ran on --->>> 12/8/2009 3:41:54 PM
====== Running Processes ======
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpserver.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpACtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpCCtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpkbinst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
====== BHO's ======
BHO: (NO NAME) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
BHO: (NO NAME) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
BHO: (NO NAME) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: (NO NAME) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
BHO: (NO NAME) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
====== HKLM\~\Run Keys ======
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[ehTray] = C:\WINDOWS\ehome\ehtray.exe
[igfxtray] = C:\WINDOWS\system32\igfxtray.exe
[igfxhkcmd] = C:\WINDOWS\system32\hkcmd.exe
[igfxpers] = C:\WINDOWS\system32\igfxpers.exe
[SynTPEnh] = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[Broadcom Wireless Manager UI] = C:\WINDOWS\system32\WLTRAY.exe
[SigmatelSysTrayApp] = stsystra.exe
[DVDLauncher] = "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
[dla] = C:\WINDOWS\system32\dla\tfswctrl.exe
[ISUSPM Startup] = "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
[ISUSScheduler] = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[Google Desktop Search] = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[DLCCCATS] = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
[dlccmon.exe] = "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
[REGSHAVE] = C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
[dscactivate] = "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
[QuickTime Task] = "C:\Program Files\QuickTime\qttask.exe" -atboottime
[iTunesHelper] = "C:\Program Files\iTunes\iTunesHelper.exe"
[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[mcagent_exe] = "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
[MaxMenuMgr] = "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
[CyberPatrolNew] = "C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe" /m
====== HKCU\~\Run Keys ======
[ModemOnHold] = C:\Program Files\NetWaiting\netWaiting.exe
[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe
[swg] = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[MSMSGS] = "C:\Program Files\Messenger\msmsgs.exe" /background
[DellSupport] = "C:\Program Files\DellSupport\DSAgnt.exe" /startup
====== DNS Info (List may be empty) ======
HKEY_LOCAL_MACHINE\CCS\~\{0F7BF4CA-2A11-436D-BAAB-57BAA18E3561}\ NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}\ NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{4A1E062A-2F57-40CC-BEA1-AE6B04F228E4}\ NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{84E578D6-BA0B-4BB4-8872-9515B4D1E756}\ NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{C4696536-EA80-4C71-BC57-1FF580E2180A}\ NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{0F7BF4CA-2A11-436D-BAAB-57BAA18E3561}\ NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}\ NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{4A1E062A-2F57-40CC-BEA1-AE6B04F228E4}\ NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{84E578D6-BA0B-4BB4-8872-9515B4D1E756}\ NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{C4696536-EA80-4C71-BC57-1FF580E2180A}\ NameServer=
HKEY_LOCAL_MACHINE\CS002\~\{0F7BF4CA-2A11-436D-BAAB-57BAA18E3561}\ NameServer=
HKEY_LOCAL_MACHINE\CS002\~\{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}\ NameServer=
HKEY_LOCAL_MACHINE\CS002\~\{4A1E062A-2F57-40CC-BEA1-AE6B04F228E4}\ NameServer=
HKEY_LOCAL_MACHINE\CS002\~\{84E578D6-BA0B-4BB4-8872-9515B4D1E756}\ NameServer=
HKEY_LOCAL_MACHINE\CS002\~\{C4696536-EA80-4C71-BC57-1FF580E2180A}\ NameServer=
HKEY_LOCAL_MACHINE\CS003\~\{0F7BF4CA-2A11-436D-BAAB-57BAA18E3561}\ NameServer=
HKEY_LOCAL_MACHINE\CS003\~\{2F9FBC39-C724-4E7B-AEFD-EDFE1FAC9BF8}\ NameServer=
HKEY_LOCAL_MACHINE\CS003\~\{4A1E062A-2F57-40CC-BEA1-AE6B04F228E4}\ NameServer=
HKEY_LOCAL_MACHINE\CS003\~\{84E578D6-BA0B-4BB4-8872-9515B4D1E756}\ NameServer=
HKEY_LOCAL_MACHINE\CS003\~\{C4696536-EA80-4C71-BC57-1FF580E2180A}\ NameServer=
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
12/8/2009 3:41:54 PM 8056 32 C:\Files.txt
10/14/2009 1:26:18 PM 9746659 C:\WINDOWS\$NtUninstallKB953295$
10/14/2009 1:26:18 PM 598523 C:\WINDOWS\$NtUninstallKB953295$\spuninst
10/14/2009 1:28:21 PM 1228624 C:\WINDOWS\$NtUninstallKB954155_WM9$
10/14/2009 1:28:21 PM 624976 C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst
10/14/2009 1:31:02 PM 624885 C:\WINDOWS\$NtUninstallKB958869$
10/14/2009 1:31:02 PM 624885 C:\WINDOWS\$NtUninstallKB958869$\spuninst
10/14/2009 1:28:29 PM 2060925 C:\WINDOWS\$NtUninstallKB969059$
10/14/2009 1:28:29 PM 625277 C:\WINDOWS\$NtUninstallKB969059$\spuninst
11/11/2009 6:24:49 AM 2472725 C:\WINDOWS\$NtUninstallKB969947$
11/11/2009 6:24:49 AM 625557 C:\WINDOWS\$NtUninstallKB969947$\spuninst
10/14/2009 1:26:46 PM 13221299 C:\WINDOWS\$NtUninstallKB971486$
10/14/2009 1:26:46 PM 627763 C:\WINDOWS\$NtUninstallKB971486$\spuninst
10/14/2009 1:26:31 PM 751042 C:\WINDOWS\$NtUninstallKB973525$
10/14/2009 1:26:31 PM 624066 C:\WINDOWS\$NtUninstallKB973525$\spuninst
11/25/2009 6:05:02 AM 3040728 C:\WINDOWS\$NtUninstallKB973687$
11/25/2009 6:05:02 AM 626136 C:\WINDOWS\$NtUninstallKB973687$\spuninst
10/14/2009 1:28:15 PM 872597 C:\WINDOWS\$NtUninstallKB974112$
10/14/2009 1:28:15 PM 625271 C:\WINDOWS\$NtUninstallKB974112$\spuninst
10/14/2009 1:31:10 PM 7259592 C:\WINDOWS\$NtUninstallKB974455$
10/14/2009 1:31:10 PM 630728 C:\WINDOWS\$NtUninstallKB974455$\spuninst
10/14/2009 1:27:57 PM 682441 C:\WINDOWS\$NtUninstallKB974571$
10/14/2009 1:27:57 PM 625097 C:\WINDOWS\$NtUninstallKB974571$\spuninst
10/14/2009 1:28:07 PM 919735 C:\WINDOWS\$NtUninstallKB975025$
10/14/2009 1:28:07 PM 624823 C:\WINDOWS\$NtUninstallKB975025$\spuninst
10/14/2009 1:25:17 PM 761172 C:\WINDOWS\$NtUninstallKB975467$
10/14/2009 1:25:17 PM 624980 C:\WINDOWS\$NtUninstallKB975467$\spuninst
11/25/2009 6:05:15 AM 831768 C:\WINDOWS\$NtUninstallKB976098-v2$
11/25/2009 6:05:15 AM 642328 C:\WINDOWS\$NtUninstallKB976098-v2$\spuninst
11/4/2009 5:47:57 PM 4002082 C:\WINDOWS\$NtUninstallKB976749$
11/4/2009 5:47:57 PM 628002 C:\WINDOWS\$NtUninstallKB976749$\spuninst
11/30/2009 3:18:50 AM 79881205 C:\WINDOWS\McAfee.com
11/30/2009 3:18:50 AM 79881205 C:\WINDOWS\McAfee.com\FreeScan
12/1/2009 6:04:40 PM 0 C:\WINDOWS\PIF
10/14/2009 1:25:28 PM 11431 32 C:\WINDOWS\KB953295.log
10/14/2009 1:28:20 PM 7260 32 C:\WINDOWS\KB954155.log
10/14/2009 1:31:01 PM 6777 32 C:\WINDOWS\KB958869.log
10/14/2009 9:21:10 AM 15286 32 C:\WINDOWS\KB969059.log
11/11/2009 6:13:20 AM 14730 32 C:\WINDOWS\KB969947.log
10/14/2009 1:26:38 PM 10336 32 C:\WINDOWS\KB971486.log
10/14/2009 1:26:29 PM 8693 32 C:\WINDOWS\KB973525.log
11/25/2009 6:04:08 AM 10124 32 C:\WINDOWS\KB973687.log
10/14/2009 9:21:04 AM 15294 32 C:\WINDOWS\KB974112.log
10/14/2009 9:21:26 AM 18885 32 C:\WINDOWS\KB974455.log
10/14/2009 9:20:57 AM 15593 32 C:\WINDOWS\KB974571.log
10/14/2009 9:21:01 AM 15230 32 C:\WINDOWS\KB975025.log
10/14/2009 9:18:44 AM 15491 32 C:\WINDOWS\KB975467.log
11/25/2009 6:05:14 AM 5084 32 C:\WINDOWS\KB976098-v2.log
11/4/2009 5:24:11 PM 15671 32 C:\WINDOWS\KB976749.log
11/25/2009 6:03:20 AM 320056 32 C:\WINDOWS\msxml4-KB973688-enu.LOG
11/30/2009 2:20:02 AM 10 32 C:\WINDOWS\run.log
11/30/2009 2:20:09 AM 12 32 C:\WINDOWS\srun.log
11/10/2009 4:40:46 PM 25 32 C:\WINDOWS\SW32.INI
12/2/2009 2:01:57 PM 3629692 C:\WINDOWS\system32\GroupPolicy
12/4/2009 4:53:15 PM 3629347 C:\WINDOWS\system32\GroupPolicy\Adm
12/2/2009 2:01:57 PM 0 C:\WINDOWS\system32\GroupPolicy\Machine
12/2/2009 2:01:57 PM 190 C:\WINDOWS\system32\GroupPolicy\User
11/30/2009 2:10:54 AM 117272 32 C:\WINDOWS\system32\gVsFeD.exe
11/30/2009 2:20:18 AM 36800 32 C:\WINDOWS\system32\net.net
====== Files under "\Administrator\Startup" Last 60 Days======
====== Files under "\All Users\Startup" Last 60 Days======
====== Files and Folders under "\Program Files" Last 60 Days======
12/2/2009 10:53:47 AM 1093997 C:\Program Files\Trend Micro
====== Files under "\System32\Drivers" Last 60 Days======
====== Files Deleted under "%Temp%" ======
935 Files deleted
====== Files and Folders under "All Users\Application Data" Last 60 Days======
11/30/2009 2:20:59 AM 0 C:\Documents and Settings\All Users\Application Data\10eee58
11/30/2009 2:21:28 AM 30852 C:\Documents and Settings\All Users\Application Data\WSDDSys
====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\
====== Services ( Services that are Whitelisted are not shown) ======
APPDRV (APPDRV)- C:\WINDOWS\system32\DRIVERS\APPDRV.SYS - System/Running
ASCTRM (ASCTRM)- C:\WINDOWS\system32\drivers\ASCTRM.sys - Auto/Running
BCM43XX (Dell Wireless WLAN Card Driver)- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys - Manual/Running
drvmcdb (drvmcdb)- C:\WINDOWS\system32\drivers\drvmcdb.sys - Boot/Running
drvnddm (drvnddm)- C:\WINDOWS\system32\drivers\drvnddm.sys - Auto/Running
DSproct (DSproct)- \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys - Manual/Running
dsunidrv (DellSupport UniDriver)- C:\WINDOWS\system32\DRIVERS\dsunidrv.sys - Auto/Running
E100B (Intel(R) PRO Adapter Driver)- C:\WINDOWS\system32\DRIVERS\e100b325.sys - Manual/Stopped
HSF_DPV (HSF_DPV)- C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys - Manual/Running
HSXHWAZL (HSXHWAZL)- C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys - Manual/Running
MASPINT (MASPINT)- C:\WINDOWS\system32\drivers\MASPINT.sys - Auto/Running
MCSTRM (MCSTRM)- - Auto/Stopped
MHNDRV (MHN driver)- C:\WINDOWS\system32\DRIVERS\mhndrv.sys - Manual/Stopped
nsm1bus (Nokia Handset USB Composite Device driver (WDM))- C:\WINDOWS\system32\DRIVERS\nsm1bus.sys - Manual/Stopped
nsm1mdfl (Nokia Handset Filter)- C:\WINDOWS\system32\DRIVERS\nsm1mdfl.sys - Manual/Stopped
nsm1mdm (Nokia Handset Drivers)- C:\WINDOWS\system32\DRIVERS\nsm1mdm.sys - Manual/Stopped
nsm1serd (Nokia Handset Diagnostic Serial Port (WDM))- C:\WINDOWS\system32\DRIVERS\nsm1serd.sys - Manual/Stopped
NuidFltr (NUID filter driver)- C:\WINDOWS\system32\DRIVERS\NuidFltr.sys - Manual/Running
omci (OMCI WDM Device Driver)- C:\WINDOWS\system32\DRIVERS\omci.sys - System/Running
PCD5SRVC{FBEA8B78-1B22F121-05040000} (PCD5SRVC{FBEA8B78-1B22F121-05040000} - PCDR Kernel Mode Service Helper Driver)- \??\C:\PROGRA~1\DELLSU~2\HWDiag\bin\PCD5SRVC.pkms - Manual/Stopped
rimmptsk (rimmptsk)- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys - Manual/Running
rimsptsk (rimsptsk)- C:\WINDOWS\system32\DRIVERS\rimsptsk.sys - Manual/Running
rismxdp (Ricoh xD-Picture Card Driver)- C:\WINDOWS\system32\DRIVERS\rixdptsk.sys - Manual/Running
sdbus (sdbus)- C:\WINDOWS\system32\DRIVERS\sdbus.sys - Manual/Running
sffdisk (SFF Storage Class Driver)- C:\WINDOWS\system32\DRIVERS\sffdisk.sys - Manual/Stopped
sffp_sd (SFF Storage Protocol Driver for SDBus)- C:\WINDOWS\system32\DRIVERS\sffp_sd.sys - Manual/Stopped
sscdbhk5 (sscdbhk5)- C:\WINDOWS\system32\drivers\sscdbhk5.sys - System/Running
ssrtln (ssrtln)- C:\WINDOWS\system32\drivers\ssrtln.sys - System/Running
STHDA (SigmaTel High Definition Audio CODEC)- C:\WINDOWS\system32\drivers\sthda.sys - Manual/Running
SynTP (Synaptics TouchPad Driver)- C:\WINDOWS\system32\DRIVERS\SynTP.sys - Manual/Running
tfsnboio (tfsnboio)- C:\WINDOWS\system32\dla\tfsnboio.sys - Auto/Running
tfsncofs (tfsncofs)- C:\WINDOWS\system32\dla\tfsncofs.sys - Auto/Running
tfsndrct (tfsndrct)- C:\WINDOWS\system32\dla\tfsndrct.sys - Auto/Running
tfsndres (tfsndres)- C:\WINDOWS\system32\dla\tfsndres.sys - Auto/Running
tfsnifs (tfsnifs)- C:\WINDOWS\system32\dla\tfsnifs.sys - Auto/Running
tfsnopio (tfsnopio)- C:\WINDOWS\system32\dla\tfsnopio.sys - Auto/Running
tfsnpool (tfsnpool)- C:\WINDOWS\system32\dla\tfsnpool.sys - Auto/Running
tfsnudf (tfsnudf)- C:\WINDOWS\system32\dla\tfsnudf.sys - Auto/Running
tfsnudfa (tfsnudfa)- C:\WINDOWS\system32\dla\tfsnudfa.sys - Auto/Running
USBAAPL (Apple Mobile USB Driver)- C:\WINDOWS\system32\Drivers\usbaapl.sys - Manual/Stopped
usbbus (LGE CDMA Composite USB Device)- C:\WINDOWS\system32\DRIVERS\lgusbbus.sys - Manual/Stopped
UsbDiag (LGE CDMA USB Serial Port)- C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys - Manual/Stopped
USBModem (LGE CDMA USB Modem)- C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys - Manual/Stopped
wanatw (WAN Miniport (ATW))- C:\WINDOWS\system32\DRIVERS\wanatw4.sys - Manual/Stopped
Wdf01000 (Wdf01000)- C:\WINDOWS\system32\DRIVERS\Wdf01000.sys - Manual/Running
WmiAcpi (Microsoft Windows Management Interface for ACPI)- C:\WINDOWS\system32\DRIVERS\wmiacpi.sys - System/Running
WpdUsb (WpdUsb)- C:\WINDOWS\system32\Drivers\wpdusb.sys - Manual/Stopped
====== Uninstall List ======
GemMaster Mystic
Polar Golfer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Shockwave Player
ASIO4ALL
Anvil Studio
Audacity 1.2.6
Otto
Dell Wireless WLAN Card
Conexant HDA D110 MDC V.92 Modem
Collab
Dell Digital Jukebox Driver
Dell Game Console
Dell Photo AIO Printer 924
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
ESPNMotion
FL Studio 8
Google Desktop
Google Updater
LoudMo Contextual Ad Assistant
HijackThis 2.0.2
IL Download Manager
Rosetta Stone 2.1.5.3A
FinePixViewer Ver.3.2
Seagate Manager Installer
High Definition Audio Driver Package - KB835221
Windows Installer 3.1 (KB893803)
Update Rollup 2 for Windows XP Media Center Edition 2005
Hotfix for Windows Media Player 10 (KB903157)
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB908250
Update for Windows Media Player 10 (KB910393)
Security Update for Windows Media Player (KB911564)
Windows XP Media Center Edition 2005 KB912067
Update for Windows Media Player 10 (KB913800)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows Media Player 6.4 (KB925398)
Update for Windows Media Player 10 (KB926251)
Hotfix for Windows Media Format 11 SDK (KB929399)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Update for Windows XP (KB951072-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Update for Windows XP (KB951978)
Security Update for Windows XP (KB952004)
Security Update for Windows Media Player (KB952069)
Hotfix for Windows XP (KB952287)
Security Update for Windows XP (KB952954)
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows Media Player (KB954155)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Update for Windows XP (KB955839)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Security Update for Windows XP (KB968537)
Security Update for Windows Media Player (KB968816)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Hotfix for Windows XP (KB970653-v3)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows Media Player (KB973540)
Update for Windows XP (KB973687)
Windows XP Media Center Edition 2005 KB973768
Update for Windows XP (KB973815)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Hotfix for Windows XP (KB976098-v2)
Update for Windows XP (KB976749)
LAME v3.98.2 for Audacity
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 1.1
Mozilla Firefox (3.0.15)
McAfee SecurityCenter
MSN
MicroStaff WINASPI
Advertisement Service
Nokia USB Drivers
PoiZone
RealPlayer Basic
SmartMusic 11
MidiPlayer
Learn2 Player (Uninstall Only)
Synaptics Pointing Device Driver
Toxic Biohazard
V CAST Music with Rhapsody
Viewpoint Media Player
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
WebCyberCoach 3.2 Dell
Windows Genuine Advantage Notifications (KB905474)
WildTangent Web Driver
Windows Media Format 11 runtime
Windows XP Service Pack 3
Windows Media Format 11 runtime
Microsoft User-Mode Driver Framework Feature Pack 1.0
Yahoo! Music Jukebox
Rosetta Stone 2.1.5.3A
Sonic RecordNow Data
CyberPatrol (Remove Only)
Microsoft Plus! Photo Story 2 LE
Qualxserve Service Agreement
Sonic DLA
QuickTime
Google Toolbar for Internet Explorer
Sonic MyDVD LE
Google Toolbar for Internet Explorer
FinePixViewer Ver.3.2
Seagate Manager Installer
Broadcom Management Programs
Sonic Update Manager
J2SE Runtime Environment 5.0 Update 6
Windows Media Player 10
WebFldrs XP
NetZeroInstallers
MSXML 4.0 SP2 (KB927978)
URL Assistant
NetWaiting
Apple Mobile Device Support
ELIcon
McAfee Virtual Technician
DellConnect
FUJIFILM USB Driver
iTunes
AOLIcon
PowerDVD 5.7
Apple Software Update
Digital Content Portal
Microsoft Plus! Digital Media Edition Installer
EarthLink setup files
Dell System Restore
Get High Speed Internet!
DellSupport
Modem Helper
MSXML 4.0 SP2 (KB954430)
Intel(R) Graphics Media Accelerator Driver
Corel Photo Album 6
Google Earth
Microsoft Office Professional Edition 2003
924PLC32
Sonic Encoders
MSXML 6.0 Parser
Microsoft Visual C++ 2005 Redistributable
EducateU
Google Update Helper
Sonic RecordNow Audio
Adobe Reader 7.0.8
ABBYY FineReader 6.0 Sprint
Documentation & Support Launcher
Sonic RecordNow Copy
Games, Music, & Photos Launcher
Microsoft Office Outlook 2003 with Business Contact Manager Update
MSXML 4.0 SP2 (KB936181)
LG USB Modem driver
QuickSet
Microsoft .NET Framework 1.1
MCU
ImageMixer VCD for FinePix
Search Assist
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Dell Support Center (Support Software)
Internet Service Offers Launcher
Digital Line Detect
MSXML 4.0 SP2 (KB973688)
Review Questions and Answers for Veterinary Technicians 3e
======== Other Info ========
TOTAL PHYSICAL RAM: 1064 MB
Boot Info
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
OS Type: Microsoft Windows XP Professional
Build: 5.1.2600
Service Pack: 3.0
====== Files with Hidden Attributes======
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\NTDETECT.COM
C:\Documents and Settings\Administrator\NTUSER.DAT
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
==End of Report==
bamajim
10.4K Posts
0
December 9th, 2009 07:00
1. Please download The Avenger by Swandog46 to your Desktop.
2. Copy all the text contained in the bold below to your Clipboard by highlighting it and pressing (Ctrl+C):
Files to Delete:
C:\WINDOWS\run.log
C:\WINDOWS\srun.log
C:\WINDOWS\system32\gVsFeD.exe
C:\WINDOWS\system32\net.net
Folders to Delete:
C:\Documents and Settings\All Users\Application Data\10eee58
C:\Documents and Settings\All Users\Application Data\WSDDSys
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
4. The Avenger will automatically do the following:
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log
oancient1
11 Posts
0
December 9th, 2009 10:00
bamajim
oancient1
11 Posts
0
December 9th, 2009 11:00
bamajim,
I downloaded and ran avenger per your instructions, and immediately ran an HJT scan afterward. All problems appear to remain - mcaffe and tack manager still will not start, and trying to go to google.com sens me instead to qwww.google.nl. The requested logs are below:
-------
Avenger Log:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\WINDOWS\run.log" deleted successfully.
File "C:\WINDOWS\srun.log" deleted successfully.
File "C:\WINDOWS\system32\gVsFeD.exe" deleted successfully.
File "C:\WINDOWS\system32\net.net" deleted successfully.
Folder "C:\Documents and Settings\All Users\Application Data\10eee58" deleted successfully.
Folder "C:\Documents and Settings\All Users\Application Data\WSDDSys" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
---------
HJT Log:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
File "C:\WINDOWS\run.log" deleted successfully.
File "C:\WINDOWS\srun.log" deleted successfully.
File "C:\WINDOWS\system32\gVsFeD.exe" deleted successfully.
File "C:\WINDOWS\system32\net.net" deleted successfully.
Folder "C:\Documents and Settings\All Users\Application Data\10eee58" deleted successfully.
Folder "C:\Documents and Settings\All Users\Application Data\WSDDSys" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
bamajim
10.4K Posts
0
December 9th, 2009 13:00
I thought it would take a couple of runs at this to remove.
Please download Combofix and save to your desktop:
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.
oancient1
11 Posts
0
December 9th, 2009 16:00
bamajim
RESULTS!!!!!
I ran combofix per your instructions. the log is pasted in at the end. Afterward I rebooted and found that McAfee and Task Manager both appear to be working normally. Both browsers (IE6 and Firefox 3.0 ) still go to www.google.nl when I try to go to google.com.
I am not sure what normally happens when comfix runs, but for the record:
1. Early on it asked me to disable McAfee, which I couldn't do per what we talked about earlier. So I said to run it anyway, regardless of the risk.
2. After describing the recover console, it said it had found "rootkit activity" and had to reboot -- I said OK
3. When I pasted the text of the Combofix log in below, I got a dialog box asking if I want to allow "this page" to paste info from my clipboard. I have never seen this before, and have not yet checked to see if such boxes appear when pasting into other applications.
Anyway ... That leaves the google browser problem to be solved, which also includes questioning of certificates when I go to gmail that never occured before. (If I respond to go ahead gmail operates normally. There may be other such browser misdirections but I have not discovered any as I have not done much browsing since these problems occured. Perhaps this problem is not related to the others. Should I post a new thread or shall we continue on here?
Thanks again for the help.
Tom
--------
Combofix Log:
ComboFix 09-12-09.04 - Tom 12/09/2009 18:42:20.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.575 [GMT -5:00]
Running from: c:\documents and settings\Tom\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sam\Application Data\Microsoft\Internet Explorer\Quick Launch\Anti Virus Pro spyware remover.lnk
c:\documents and settings\Tom\Application Data\System Defender
c:\documents and settings\Tom\Application Data\System Defender\cookies.sqlite
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\windows\kb913800.exe
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.
2009-12-09 13:52 . 2009-12-09 13:52 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2009-12-08 23:49 . 2009-11-04 21:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-08 23:49 . 2009-11-04 21:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-08 23:49 . 2009-11-04 21:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-08 23:49 . 2009-07-16 17:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-08 23:48 . 2009-12-08 23:49 -------- d-----w- c:\program files\Common Files\McAfee
2009-12-08 23:44 . 2009-11-04 21:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-12-08 22:38 . 2009-12-08 22:38 -------- d-----w- c:\program files\Citrix
2009-12-08 22:38 . 2009-12-08 22:38 61224 ----a-w- c:\documents and settings\Tom\GoToAssistDownloadHelper.exe
2009-12-08 22:38 . 2009-12-08 22:38 -------- d-----w- c:\documents and settings\Tom\Local Settings\Application Data\Citrix
2009-12-02 19:01 . 2009-12-04 21:53 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-12-02 15:53 . 2009-12-02 15:53 -------- d-----w- c:\program files\Trend Micro
2009-12-01 23:04 . 2009-12-01 23:04 -------- d--h--w- c:\windows\PIF
2009-11-30 14:14 . 2009-09-30 17:11 288096 ----a-r- c:\documents and settings\Tom\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-11-30 14:13 . 2009-11-30 14:13 -------- d-----w- c:\documents and settings\Tom\Application Data\McAfee
2009-11-30 08:18 . 2009-11-30 08:18 -------- d-----w- c:\windows\McAfee.com
2009-11-26 01:44 . 2009-11-26 01:44 -------- d-----w- c:\documents and settings\Sam\Local Settings\Application Data\jbesgt
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 23:40 . 2006-09-05 01:43 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-09 23:08 . 2006-09-13 01:08 -------- d-----w- c:\program files\Dl_cats
2009-12-09 01:34 . 2008-09-28 16:37 -------- d-----w- c:\program files\McAfee
2009-12-08 23:48 . 2006-09-05 01:41 -------- d-----w- c:\program files\McAfee.com
2009-12-01 23:36 . 2004-08-04 03:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-12-01 14:28 . 2006-09-05 01:43 -------- d-----w- c:\program files\Google
2009-11-30 07:24 . 2008-09-28 15:02 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-11-30 01:06 . 2006-10-13 11:36 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-11-30 01:06 . 2006-10-13 11:36 88 --sh--r- c:\windows\system32\49CA7921BA.sys
2009-11-04 21:54 . 2009-11-04 21:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-30 17:11 . 2008-09-28 15:19 288096 ----a-r- c:\documents and settings\Schanna\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-09-25 05:37 . 2005-08-16 09:18 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2005-08-16 09:18 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:18 . 2005-08-16 09:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-05-12 14:03 . 2009-05-12 14:03 6637816 ----a-w- c:\program files\cyberpatrol77.exe
2007-04-11 02:28 . 2007-04-11 02:28 251 ----a-w- c:\program files\wt3d.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-15 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe -startup"
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe -start"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime"
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-09-05 169984]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-13 73728]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-07-17 177448]
"CyberPatrolNew"="c:\program files\CyberPatrol LLC\CyberPatrol\cphq.exe" [2008-12-19 1975552]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-9-4 24576]
Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2002-1-9 200704]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-3 54776]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Documents and Settings\\Sam\\Application Data\\MySpace\\IM\\bin\\MySpaceIM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [7/17/2008 4:12 PM 161064]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/8/2009 6:52 PM 210216]
S2 gupdate1c9ef7861b920aa;Google Update Service (gupdate1c9ef7861b920aa);c:\program files\Google\Update\GoogleUpdate.exe [6/17/2009 1:21 PM 133104]
S3 CyberPatrol UpdateService;CyberPatrol UpdateService;c:\program files\CyberPatrol LLC\CyberPatrol\UpdateService.exe [5/12/2009 9:12 AM 144704]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: c:\windows\system32\cplsp.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\jpuratpc.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\McAfee\Supportability\MVT\NPMVTPlugin.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-gVsFeD - c:\windows\system32\gVsFeD.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 18:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-12-09 18:57:29
ComboFix-quarantined-files.txt 2009-12-09 23:57
Pre-Run: 24,220,815,360 bytes free
Post-Run: 27,515,662,336 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 957F6507CD364960050E46CDF7BF0334
oancient1
11 Posts
0
December 15th, 2009 06:00
Bump...
Per my last post, thanks to help from bamajim the major problems of McAfee and Task Manager being disabled seem fixed, but the following problems remain:
1. Attempts to go to google.com are redirected to google.nl
2. Invalid certificate warnings and "going to an insecure site" warnings are coming up in for several websites (including google gmail.com) where where no such warnings appeared before.
3. When I paste text into the reply window on this site, I must approve the pasting on a dialog box that did not appear
I do not know if the above are something to be greatly concerned about, but would like to fix them. A new Hijackthis log is pasted in below.
Thanks,
Tom
---
Hijack This Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:19:28 AM, on 12/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpserver.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpACtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpCCtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpkbinst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 89.248.168.187 google.ae
O1 - Hosts: 89.248.168.187 google.as
O1 - Hosts: 89.248.168.187 google.at
O1 - Hosts: 89.248.168.187 google.az
O1 - Hosts: 89.248.168.187 google.ba
O1 - Hosts: 89.248.168.187 google.be
O1 - Hosts: 89.248.168.187 google.bg
O1 - Hosts: 89.248.168.187 google.bs
O1 - Hosts: 89.248.168.187 google.ca
O1 - Hosts: 89.248.168.187 google.cd
O1 - Hosts: 89.248.168.187 google.com.gh
O1 - Hosts: 89.248.168.187 google.com.hk
O1 - Hosts: 89.248.168.187 google.com.jm
O1 - Hosts: 89.248.168.187 google.com.mx
O1 - Hosts: 89.248.168.187 google.com.my
O1 - Hosts: 89.248.168.187 google.com.na
O1 - Hosts: 89.248.168.187 google.com.nf
O1 - Hosts: 89.248.168.187 google.com.ng
O1 - Hosts: 89.248.168.187 google.ch
O1 - Hosts: 89.248.168.187 google.com.np
O1 - Hosts: 89.248.168.187 google.com.pr
O1 - Hosts: 89.248.168.187 google.com.qa
O1 - Hosts: 89.248.168.187 google.com.sg
O1 - Hosts: 89.248.168.187 google.com.tj
O1 - Hosts: 89.248.168.187 google.com.tw
O1 - Hosts: 89.248.168.187 google.dj
O1 - Hosts: 89.248.168.187 google.de
O1 - Hosts: 89.248.168.187 google.dk
O1 - Hosts: 89.248.168.187 google.dm
O1 - Hosts: 89.248.168.187 google.ee
O1 - Hosts: 89.248.168.187 google.fi
O1 - Hosts: 89.248.168.187 google.fm
O1 - Hosts: 89.248.168.187 google.fr
O1 - Hosts: 89.248.168.187 google.ge
O1 - Hosts: 89.248.168.187 google.gg
O1 - Hosts: 89.248.168.187 google.gm
O1 - Hosts: 89.248.168.187 google.gr
O1 - Hosts: 89.248.168.187 google.ht
O1 - Hosts: 89.248.168.187 google.ie
O1 - Hosts: 89.248.168.187 google.im
O1 - Hosts: 89.248.168.187 google.in
O1 - Hosts: 89.248.168.187 google.it
O1 - Hosts: 89.248.168.187 google.ki
O1 - Hosts: 89.248.168.187 google.la
O1 - Hosts: 89.248.168.187 google.li
O1 - Hosts: 89.248.168.187 google.lv
O1 - Hosts: 89.248.168.187 google.ma
O1 - Hosts: 89.248.168.187 google.ms
O1 - Hosts: 89.248.168.187 google.mu
O1 - Hosts: 89.248.168.187 google.mw
O1 - Hosts: 89.248.168.187 google.nl
O1 - Hosts: 89.248.168.187 google.no
O1 - Hosts: 89.248.168.187 google.nr
O1 - Hosts: 89.248.168.187 google.nu
O1 - Hosts: 89.248.168.187 google.pl
O1 - Hosts: 89.248.168.187 google.pn
O1 - Hosts: 89.248.168.187 google.pt
O1 - Hosts: 89.248.168.187 google.ro
O1 - Hosts: 89.248.168.187 google.ru
O1 - Hosts: 89.248.168.187 google.rw
O1 - Hosts: 89.248.168.187 google.sc
O1 - Hosts: 89.248.168.187 google.se
O1 - Hosts: 89.248.168.187 google.sh
O1 - Hosts: 89.248.168.187 google.si
O1 - Hosts: 89.248.168.187 google.sm
O1 - Hosts: 89.248.168.187 google.sn
O1 - Hosts: 89.248.168.187 google.st
O1 - Hosts: 89.248.168.187 google.tl
O1 - Hosts: 89.248.168.187 google.tm
O1 - Hosts: 89.248.168.187 google.tt
O1 - Hosts: 89.248.168.187 google.us
O1 - Hosts: 89.248.168.187 google.vu
O1 - Hosts: 89.248.168.187 google.ws
O1 - Hosts: 89.248.168.187 google.co.ck
O1 - Hosts: 89.248.168.187 google.co.id
O1 - Hosts: 89.248.168.187 google.co.il
O1 - Hosts: 89.248.168.187 google.co.in
O1 - Hosts: 89.248.168.187 google.co.jp
O1 - Hosts: 89.248.168.187 google.co.kr
O1 - Hosts: 89.248.168.187 google.co.ls
O1 - Hosts: 89.248.168.187 google.co.ma
O1 - Hosts: 89.248.168.187 google.co.nz
O1 - Hosts: 89.248.168.187 google.co.tz
O1 - Hosts: 89.248.168.187 google.co.ug
O1 - Hosts: 89.248.168.187 google.co.uk
O1 - Hosts: 89.248.168.187 google.co.za
O1 - Hosts: 89.248.168.187 google.co.zm
O1 - Hosts: 89.248.168.187 google.com
O1 - Hosts: 89.248.168.187 google.com.af
O1 - Hosts: 89.248.168.187 google.com.ag
O1 - Hosts: 89.248.168.187 google.com.ar
O1 - Hosts: 89.248.168.187 google.com.au
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe" /m
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5817/mcfscan.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CyberPatrol UpdateService - CyberPatrol LLC - C:\Program Files\CyberPatrol LLC\CyberPatrol\UpdateService.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9ef7861b920aa) (gupdate1c9ef7861b920aa) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15771 bytes
--------
bamajim
10.4K Posts
0
December 15th, 2009 17:00
1. Rerun Hijackthis (scan only) and place checks beside the following entries
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 89.248.168.187 google.ae
O1 - Hosts: 89.248.168.187 google.as
O1 - Hosts: 89.248.168.187 google.at
O1 - Hosts: 89.248.168.187 google.az
O1 - Hosts: 89.248.168.187 google.ba
O1 - Hosts: 89.248.168.187 google.be
O1 - Hosts: 89.248.168.187 google.bg
O1 - Hosts: 89.248.168.187 google.bs
O1 - Hosts: 89.248.168.187 google.ca
O1 - Hosts: 89.248.168.187 google.cd
O1 - Hosts: 89.248.168.187 google.com.gh
O1 - Hosts: 89.248.168.187 google.com.hk
O1 - Hosts: 89.248.168.187 google.com.jm
O1 - Hosts: 89.248.168.187 google.com.mx
O1 - Hosts: 89.248.168.187 google.com.my
O1 - Hosts: 89.248.168.187 google.com.na
O1 - Hosts: 89.248.168.187 google.com.nf
O1 - Hosts: 89.248.168.187 google.com.ng
O1 - Hosts: 89.248.168.187 google.ch
O1 - Hosts: 89.248.168.187 google.com.np
O1 - Hosts: 89.248.168.187 google.com.pr
O1 - Hosts: 89.248.168.187 google.com.qa
O1 - Hosts: 89.248.168.187 google.com.sg
O1 - Hosts: 89.248.168.187 google.com.tj
O1 - Hosts: 89.248.168.187 google.com.tw
O1 - Hosts: 89.248.168.187 google.dj
O1 - Hosts: 89.248.168.187 google.de
O1 - Hosts: 89.248.168.187 google.dk
O1 - Hosts: 89.248.168.187 google.dm
O1 - Hosts: 89.248.168.187 google.ee
O1 - Hosts: 89.248.168.187 google.fi
O1 - Hosts: 89.248.168.187 google.fm
O1 - Hosts: 89.248.168.187 google.fr
O1 - Hosts: 89.248.168.187 google.ge
O1 - Hosts: 89.248.168.187 google.gg
O1 - Hosts: 89.248.168.187 google.gm
O1 - Hosts: 89.248.168.187 google.gr
O1 - Hosts: 89.248.168.187 google.ht
O1 - Hosts: 89.248.168.187 google.ie
O1 - Hosts: 89.248.168.187 google.im
O1 - Hosts: 89.248.168.187 google.in
O1 - Hosts: 89.248.168.187 google.it
O1 - Hosts: 89.248.168.187 google.ki
O1 - Hosts: 89.248.168.187 google.la
O1 - Hosts: 89.248.168.187 google.li
O1 - Hosts: 89.248.168.187 google.lv
O1 - Hosts: 89.248.168.187 google.ma
O1 - Hosts: 89.248.168.187 google.ms
O1 - Hosts: 89.248.168.187 google.mu
O1 - Hosts: 89.248.168.187 google.mw
O1 - Hosts: 89.248.168.187 google.nl
O1 - Hosts: 89.248.168.187 google.no
O1 - Hosts: 89.248.168.187 google.nr
O1 - Hosts: 89.248.168.187 google.nu
O1 - Hosts: 89.248.168.187 google.pl
O1 - Hosts: 89.248.168.187 google.pn
O1 - Hosts: 89.248.168.187 google.pt
O1 - Hosts: 89.248.168.187 google.ro
O1 - Hosts: 89.248.168.187 google.ru
O1 - Hosts: 89.248.168.187 google.rw
O1 - Hosts: 89.248.168.187 google.sc
O1 - Hosts: 89.248.168.187 google.se
O1 - Hosts: 89.248.168.187 google.sh
O1 - Hosts: 89.248.168.187 google.si
O1 - Hosts: 89.248.168.187 google.sm
O1 - Hosts: 89.248.168.187 google.sn
O1 - Hosts: 89.248.168.187 google.st
O1 - Hosts: 89.248.168.187 google.tl
O1 - Hosts: 89.248.168.187 google.tm
O1 - Hosts: 89.248.168.187 google.tt
O1 - Hosts: 89.248.168.187 google.us
O1 - Hosts: 89.248.168.187 google.vu
O1 - Hosts: 89.248.168.187 google.ws
O1 - Hosts: 89.248.168.187 google.co.ck
O1 - Hosts: 89.248.168.187 google.co.id
O1 - Hosts: 89.248.168.187 google.co.il
O1 - Hosts: 89.248.168.187 google.co.in
O1 - Hosts: 89.248.168.187 google.co.jp
O1 - Hosts: 89.248.168.187 google.co.kr
O1 - Hosts: 89.248.168.187 google.co.ls
O1 - Hosts: 89.248.168.187 google.co.ma
O1 - Hosts: 89.248.168.187 google.co.nz
O1 - Hosts: 89.248.168.187 google.co.tz
O1 - Hosts: 89.248.168.187 google.co.ug
O1 - Hosts: 89.248.168.187 google.co.uk
O1 - Hosts: 89.248.168.187 google.co.za
O1 - Hosts: 89.248.168.187 google.co.zm
O1 - Hosts: 89.248.168.187 google.com
O1 - Hosts: 89.248.168.187 google.com.af
O1 - Hosts: 89.248.168.187 google.com.ag
O1 - Hosts: 89.248.168.187 google.com.ar
O1 - Hosts: 89.248.168.187 google.com.au
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
oancient1
11 Posts
0
December 18th, 2009 13:00
bamajim,
I tried "fixing" the host items as you instructed and then ran Hijack after reboot (log pasted in at the end). But the problems still remain - http://google.com take me to http://www.google.nl/ig?hl=nl instead and the unusual certificate warnings continue to pop up.
I have mentioned before that certain error message pop up whenever I run HJT - one very early in the scan saying that the hosts file can not be written to, and one after the scan is complete suggesting that the host file be deleted. I have inserted partial screen caps below showing the messages. I finally found the host file (never knew before about system files being more invisible than simply hidden ones). I can look at the host contents in notepad -- it appears to contain only the items you say to have HJT fix. But attempts to edit, overwrite, or delete it fail (access denied), as have attempt to change its attributes, including using ATTRIB cmd in safe mode.
Thanks for your help so far.
Regards,
Tom
-----
HJT Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:00:50 PM, on 12/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpserver.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpACtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpCCtrl.exe
C:\Program Files\CyberPatrol LLC\CyberPatrol\cpkbinst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 89.248.168.187 google.ae
O1 - Hosts: 89.248.168.187 google.as
O1 - Hosts: 89.248.168.187 google.at
O1 - Hosts: 89.248.168.187 google.az
O1 - Hosts: 89.248.168.187 google.ba
O1 - Hosts: 89.248.168.187 google.be
O1 - Hosts: 89.248.168.187 google.bg
O1 - Hosts: 89.248.168.187 google.bs
O1 - Hosts: 89.248.168.187 google.ca
O1 - Hosts: 89.248.168.187 google.cd
O1 - Hosts: 89.248.168.187 google.com.gh
O1 - Hosts: 89.248.168.187 google.com.hk
O1 - Hosts: 89.248.168.187 google.com.jm
O1 - Hosts: 89.248.168.187 google.com.mx
O1 - Hosts: 89.248.168.187 google.com.my
O1 - Hosts: 89.248.168.187 google.com.na
O1 - Hosts: 89.248.168.187 google.com.nf
O1 - Hosts: 89.248.168.187 google.com.ng
O1 - Hosts: 89.248.168.187 google.ch
O1 - Hosts: 89.248.168.187 google.com.np
O1 - Hosts: 89.248.168.187 google.com.pr
O1 - Hosts: 89.248.168.187 google.com.qa
O1 - Hosts: 89.248.168.187 google.com.sg
O1 - Hosts: 89.248.168.187 google.com.tj
O1 - Hosts: 89.248.168.187 google.com.tw
O1 - Hosts: 89.248.168.187 google.dj
O1 - Hosts: 89.248.168.187 google.de
O1 - Hosts: 89.248.168.187 google.dk
O1 - Hosts: 89.248.168.187 google.dm
O1 - Hosts: 89.248.168.187 google.ee
O1 - Hosts: 89.248.168.187 google.fi
O1 - Hosts: 89.248.168.187 google.fm
O1 - Hosts: 89.248.168.187 google.fr
O1 - Hosts: 89.248.168.187 google.ge
O1 - Hosts: 89.248.168.187 google.gg
O1 - Hosts: 89.248.168.187 google.gm
O1 - Hosts: 89.248.168.187 google.gr
O1 - Hosts: 89.248.168.187 google.ht
O1 - Hosts: 89.248.168.187 google.ie
O1 - Hosts: 89.248.168.187 google.im
O1 - Hosts: 89.248.168.187 google.in
O1 - Hosts: 89.248.168.187 google.it
O1 - Hosts: 89.248.168.187 google.ki
O1 - Hosts: 89.248.168.187 google.la
O1 - Hosts: 89.248.168.187 google.li
O1 - Hosts: 89.248.168.187 google.lv
O1 - Hosts: 89.248.168.187 google.ma
O1 - Hosts: 89.248.168.187 google.ms
O1 - Hosts: 89.248.168.187 google.mu
O1 - Hosts: 89.248.168.187 google.mw
O1 - Hosts: 89.248.168.187 google.nl
O1 - Hosts: 89.248.168.187 google.no
O1 - Hosts: 89.248.168.187 google.nr
O1 - Hosts: 89.248.168.187 google.nu
O1 - Hosts: 89.248.168.187 google.pl
O1 - Hosts: 89.248.168.187 google.pn
O1 - Hosts: 89.248.168.187 google.pt
O1 - Hosts: 89.248.168.187 google.ro
O1 - Hosts: 89.248.168.187 google.ru
O1 - Hosts: 89.248.168.187 google.rw
O1 - Hosts: 89.248.168.187 google.sc
O1 - Hosts: 89.248.168.187 google.se
O1 - Hosts: 89.248.168.187 google.sh
O1 - Hosts: 89.248.168.187 google.si
O1 - Hosts: 89.248.168.187 google.sm
O1 - Hosts: 89.248.168.187 google.sn
O1 - Hosts: 89.248.168.187 google.st
O1 - Hosts: 89.248.168.187 google.tl
O1 - Hosts: 89.248.168.187 google.tm
O1 - Hosts: 89.248.168.187 google.tt
O1 - Hosts: 89.248.168.187 google.us
O1 - Hosts: 89.248.168.187 google.vu
O1 - Hosts: 89.248.168.187 google.ws
O1 - Hosts: 89.248.168.187 google.co.ck
O1 - Hosts: 89.248.168.187 google.co.id
O1 - Hosts: 89.248.168.187 google.co.il
O1 - Hosts: 89.248.168.187 google.co.in
O1 - Hosts: 89.248.168.187 google.co.jp
O1 - Hosts: 89.248.168.187 google.co.kr
O1 - Hosts: 89.248.168.187 google.co.ls
O1 - Hosts: 89.248.168.187 google.co.ma
O1 - Hosts: 89.248.168.187 google.co.nz
O1 - Hosts: 89.248.168.187 google.co.tz
O1 - Hosts: 89.248.168.187 google.co.ug
O1 - Hosts: 89.248.168.187 google.co.uk
O1 - Hosts: 89.248.168.187 google.co.za
O1 - Hosts: 89.248.168.187 google.co.zm
O1 - Hosts: 89.248.168.187 google.com
O1 - Hosts: 89.248.168.187 google.com.af
O1 - Hosts: 89.248.168.187 google.com.ag
O1 - Hosts: 89.248.168.187 google.com.ar
O1 - Hosts: 89.248.168.187 google.com.au
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\CyberPatrol LLC\CyberPatrol\cphq.exe" /m
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5817/mcfscan.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CyberPatrol UpdateService - CyberPatrol LLC - C:\Program Files\CyberPatrol LLC\CyberPatrol\UpdateService.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Update Service (gupdate1c9ef7861b920aa) (gupdate1c9ef7861b920aa) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15678 bytes