PDA

View Full Version : Infected?



c_anthony_bailey
2009-12-15, 05:46
Suspect that wife's PC is infected now... (this forum was very helpful in fixing problems I had a year or two ago.. thank you thank you)

Symptoms: very slow startup/shutdown, blue screen when booting to safe mode, virus scan caught infection on camera sd card, etc..


HJT log... (note, HJT generates a log file, but it also gives a run-time error "unexpected error has occurred at procedure: modMain_StartScan() Error #6 Overflow" so it is possible the log file is suspect...)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:29:03 PM, on 12/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [EPSON Stylus Photo R800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB003" /M "Stylus Photo R800"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm025YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab67031.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) - http://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/cpucheck_1_0_0_4.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - http://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/Entriq_3_4_0_15_Silent.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - http://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/NBCUniversal_1_0_0_3.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab

--
End of file - 8455 bytes

Blade81
2009-12-19, 15:03
Hi,

Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.


Download GMER (http://www.gmer.net) here by clicking download exe -button and then saving it your desktop:
Double-click .exe that you downloaded
Click rootkit-tab and then scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log (or attach if it's very long) in your reply.

c_anthony_bailey
2009-12-19, 16:37
Here are DDS files. GMER still running...

Detect.Txt
---------------------------


DDS (Ver_09-12-01.01) - NTFSx86
Run by Trica at 10:19:06.62 on Sat 12/19/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.519 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

svchost.exe
C:\WINDOWS\System32\svchost -k DComLaunch
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE
svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tony\My Documents\fixes\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.yahoo.com/
uDefault_Page_URL = hxxp://www.dell4me.com/myway
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_10\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.5.0_10\bin\jusched.exe"
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler
mRun: [EPSON Stylus Photo R800] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2J1.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB003" /M "Stylus Photo R800"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 4.0\apdproxy.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dlbcserv.lnk - c:\program files\dell photo printer 720\dlbcserv.exe
IE: &Search - ?p=ZJxdm025YYUS
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_10\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab67031.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/cpucheck_1_0_0_4.cab
DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/Entriq_3_4_0_15_Silent.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/NBCUniversal_1_0_0_3.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\trica\applic~1\mozilla\firefox\profiles\fts2mc7j.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-12-15 03:10:10 0 d-----w- c:\windows\pss
2009-12-14 21:50:12 0 d-----w- c:\program files\Spybot - Search & Destroy
2009-12-14 21:50:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-07 23:35:57 8725 ----a-w- c:\windows\system32\Config.MPF
2009-12-07 23:31:37 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-07 23:31:37 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-07 23:31:37 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-07 23:31:30 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-07 23:29:18 0 d-----w- c:\program files\common files\McAfee
2009-12-07 23:23:36 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys

==================== Find3M ====================

2009-11-04 21:54:12 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-31 17:59:06 10752 ----a-w- c:\windows\DCEBoot.exe
2009-09-25 05:49:02 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:49:02 668672 ------w- c:\windows\system32\dllcache\wininet.dll
2009-09-25 05:49:02 628224 ------w- c:\windows\system32\dllcache\urlmon.dll
2009-09-25 05:49:02 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll
2009-09-25 05:49:02 1509888 ------w- c:\windows\system32\dllcache\shdocvw.dll
2009-09-25 05:49:01 532480 ------w- c:\windows\system32\dllcache\mstime.dll
2009-09-25 05:49:01 449024 ------w- c:\windows\system32\dllcache\mshtmled.dll
2009-09-25 05:49:01 39424 ------w- c:\windows\system32\dllcache\pngfilt.dll
2009-09-25 05:49:01 3070976 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-09-25 05:49:01 146432 ------w- c:\windows\system32\dllcache\msrating.dll
2009-09-25 05:48:59 96256 ------w- c:\windows\system32\dllcache\inseng.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-09-25 05:48:59 55808 ------w- c:\windows\system32\dllcache\extmgr.dll
2009-09-25 05:48:59 251904 ------w- c:\windows\system32\dllcache\iepeers.dll
2009-09-25 05:48:59 16384 ------w- c:\windows\system32\dllcache\jsproxy.dll
2009-09-25 05:48:58 357888 ------w- c:\windows\system32\dllcache\dxtmsft.dll
2009-09-25 05:48:58 205312 ------w- c:\windows\system32\dllcache\dxtrans.dll
2009-09-25 05:48:58 151040 ------w- c:\windows\system32\dllcache\cdfview.dll
2009-09-25 05:48:58 1054208 ------w- c:\windows\system32\dllcache\danim.dll
2009-09-25 05:48:57 1024000 ------w- c:\windows\system32\dllcache\browseui.dll
2007-08-23 19:20:30 332 -c--a-w- c:\program files\ANG_Demo.log
2007-06-15 17:49:16 16344 -c--a-w- c:\program files\setuplog.txt
2007-06-15 17:49:14 16645 -c--a-w- c:\program files\uninstal.log
2006-05-12 03:09:31 56 -csh--r- c:\windows\system32\277220F470.sys
2006-05-12 03:09:31 3402 -csha-w- c:\windows\system32\KGyGaAvL.sys

============= FINISH: 10:21:04.44 ===============










Attach.txt
--------------

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume3
Install Date: 12/26/2005 1:26:46 PM
System Uptime: 12/14/2009 11:17:22 PM (107 hours ago)

Motherboard: Dell Inc. | | 0RD203
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2992/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 70 GiB total, 30.622 GiB free.
D: is CDROM ()
E: is FIXED (FAT32) - 19 GiB total, 2.026 GiB free.
F: is FIXED (NTFS) - 373 GiB total, 305.722 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 12/14/2009 11:25:21 PM - System Checkpoint
RP2: 12/16/2009 8:24:32 AM - System Checkpoint
RP3: 12/17/2009 8:35:53 AM - System Checkpoint
RP4: 12/18/2009 9:21:42 AM - System Checkpoint

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 4.0
Adobe Reader 7.0.9
Adobe Shockwave Player
AMP Font Viewer
AOLIcon
ATI Control Panel
ATI Display Driver
Barbie(TM) In The 12 Dancing Princesses
Card and Board Games
Conexant D850 56K V.9x DFVc Modem
Coupon Printer for Windows
Creative Lettering Combo
Creative Lettering Super Combo
Critical Update for Windows Media Player 11 (KB959772)
Cutting Master 2 for CraftROBO 1.30
Cutting Plotter Controller
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Photo Printer 720
Dell Photo Printer 720 Logger
Dell Support Center
Dell System Restore
DellSupport
EPSON Printer Software
FontViewer 1.2
Free Ultra Video Editor 3.1.0.0
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hoyle Card Games 2007
Inkscape 0.46
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet for Wired Connections
InterActual Player
Internet Explorer Default Page
iTunes
J2SE Runtime Environment 5.0 Update 10
Java 2 Runtime Environment, SE v1.4.2_03
Juniper Networks Cache Cleaner 5.5.0
Juniper Networks Cache Cleaner 6.0.0
Juniper Terminal Services Client
Macromedia Flash Player
McAfee SecurityCenter
McAfee Uninstaller
MCU
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.5)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
Musicmatch for Windows Media Player
Napster
Napster Burn Engine
QuickTime
RealPlayer Basic
ROBO Master
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Sonic Encoders
Spybot - Search & Destroy
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live installer
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB888310
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890927
Windows XP Hotfix - KB891781
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Wishblade Advanced
Wishblade Advanced Controller
Wishblade Designs

==== Event Viewer Messages From Past Week ========

12/14/2009 12:28:40 AM, error: Service Control Manager [7000] - The Par1284 service failed to start due to the following error: The system cannot find the device specified.
12/14/2009 11:25:18 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
12/14/2009 11:25:18 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

==== End Of File ===========================

c_anthony_bailey
2009-12-19, 16:38
thank you thank you :)

c_anthony_bailey
2009-12-19, 21:06
GMER started scanning as soon as I clicked the .exe file, ran for a very long time. When I came back pc was non-responsive and I had to cycle power. found this in the event log....


Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 12/19/2009
Time: 10:27:35 AM
User: N/A
Computer: MINEY
Description:
Hanging application nmeyk5r6.exe, version 1.0.15.15281, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 6e 6d 65 79 6b 35 nmeyk5
0018: 72 36 2e 65 78 65 20 31 r6.exe 1
0020: 2e 30 2e 31 35 2e 31 35 .0.15.15
0028: 32 38 31 20 69 6e 20 68 281 in h
0030: 75 6e 67 61 70 70 20 30 ungapp 0
0038: 2e 30 2e 30 2e 30 20 61 .0.0.0 a
0040: 74 20 6f 66 66 73 65 74 t offset
0048: 20 30 30 30 30 30 30 30 0000000
0050: 30 0


Going to try and re-run it now...

Blade81
2009-12-19, 21:29
If it still hangs make sure that protection software is disabled and de-select devices and sections in GMER options before the scan.

c_anthony_bailey
2009-12-20, 04:58
blue screen of death this time ..... but I had not disabled McAfee.. have done so now and restarted GMER

There's no chance for me to "uncheck" anything in GMER. It starts executing scan as soon as I click the .exe file. Note, GMER GUI shows it scanning through HKLM\System\CurrentControlSet\Services\<random number>.sys.... lots and lots of em...

Blade81
2009-12-20, 11:09
Hi,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

c_anthony_bailey
2009-12-20, 19:29
ComboFix 09-12-19.03 - Trica 12/20/2009 12:13:15.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.456 [GMT -5:00]
Running from: c:\documents and settings\Tony\My Documents\fixes\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\CONFLICT.1\poPCaploader.dll
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\kb913800.exe
c:\windows\system32\lowsec
c:\windows\system32\rotscxsjkdppxu.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_rotscxlfhmyayh
-------\Service_rotscxlfhmyayh


((((((((((((((((((((((((( Files Created from 2009-11-20 to 2009-12-20 )))))))))))))))))))))))))))))))
.

2009-12-19 19:39 . 2009-12-19 19:39 -------- d-----w- C:\spoolerlogs
2009-12-14 21:50 . 2009-12-14 22:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-14 21:50 . 2009-12-14 21:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-07 23:31 . 2009-11-04 21:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-07 23:31 . 2009-11-04 21:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-07 23:31 . 2009-11-04 21:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-07 23:31 . 2009-07-16 17:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-07 23:29 . 2009-12-07 23:31 -------- d-----w- c:\program files\Common Files\McAfee
2009-12-07 23:23 . 2009-11-04 21:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-14 22:42 . 2005-12-08 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-14 05:28 . 2005-12-08 16:28 -------- d-----w- c:\program files\McAfee
2009-12-13 18:24 . 2006-01-04 02:19 -------- d-----w- c:\program files\Napster
2009-12-07 23:42 . 2005-12-08 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-12-07 23:42 . 2005-12-08 16:26 -------- d-----w- c:\program files\McAfee.com
2009-11-10 20:38 . 2009-10-15 12:26 130 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-11-04 21:54 . 2009-11-04 21:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-31 17:59 . 2009-10-31 17:59 10752 ----a-w- c:\windows\DCEBoot.exe
2009-10-18 21:55 . 2005-12-26 18:31 133776 ----a-w- c:\documents and settings\Trica\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-25 05:49 . 2005-08-16 10:18 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:48 . 2005-08-16 10:18 81920 ----a-w- c:\windows\system32\ieencode.dll
2007-08-23 19:20 . 2007-08-23 19:20 332 -c--a-w- c:\program files\ANG_Demo.log
2007-06-15 17:49 . 2007-06-15 17:49 16344 -c--a-w- c:\program files\setuplog.txt
2007-06-15 17:49 . 2007-06-15 17:49 16645 -c--a-w- c:\program files\uninstal.log
2006-05-12 03:09 . 2005-12-26 18:30 56 -csh--r- c:\windows\system32\277220F470.sys
2006-05-12 03:09 . 2005-12-26 18:30 3402 -csha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-08 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"NapsterShell"="c:\program files\Napster\napster.exe" [2006-06-29 319488]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-07 267064]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 86960]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"EPSON Stylus Photo R800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE" [2003-08-07 99840]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 57344]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2005-12-26 315392]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=


--- Other Services/Drivers In Memory ---

*Deregistered* - AFD
*Deregistered* - ASCTRM
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - Cdfs
*Deregistered* - dmboot
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - DSproct
*Deregistered* - dsunidrv
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - HTTP
*Deregistered* - i2omgmt
*Deregistered* - IpFilterDriver
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - Kbdclass
*Deregistered* - KSecDD
*Deregistered* - mdmxsdk
*Deregistered* - mfeavfk
*Deregistered* - mfebopk
*Deregistered* - mfehidk
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MPFP
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - sr
*Deregistered* - Srv
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - Wanarp
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
IE: &Search - ?p=ZJxdm025YYUS
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Trica\Application Data\Mozilla\Firefox\Profiles\fts2mc7j.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-20 13:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2868)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\stsystra.exe
c:\windows\eHome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre1.5.0_10\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-12-20 13:21:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-20 18:21

Pre-Run: 33,572,614,144 bytes free
Post-Run: 39,649,423,360 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 4AF668DC4D52CE48864802C8E2409E40

c_anthony_bailey
2009-12-20, 19:31
DDS (Ver_09-12-01.01) - NTFSx86
Run by Trica at 13:25:21.48 on Sun 12/20/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.498 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

svchost.exe
C:\WINDOWS\System32\svchost -k DComLaunch
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Tony\My Documents\fixes\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_10\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.5.0_10\bin\jusched.exe"
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler
mRun: [EPSON Stylus Photo R800] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2J1.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB003" /M "Stylus Photo R800"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 4.0\apdproxy.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dlbcserv.lnk - c:\program files\dell photo printer 720\dlbcserv.exe
IE: &Search - ?p=ZJxdm025YYUS
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_10\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab67031.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/cpucheck_1_0_0_4.cab
DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/Entriq_3_4_0_15_Silent.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/NBCUniversal_1_0_0_3.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\trica\applic~1\mozilla\firefox\profiles\fts2mc7j.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-12-7 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-12-7 144704]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-12-7 606736]

=============== Created Last 30 ================

2009-12-20 17:07:37 0 d-sha-r- C:\cmdcons
2009-12-20 17:06:19 98816 ----a-w- c:\windows\sed.exe
2009-12-20 17:06:19 77312 ----a-w- c:\windows\MBR.exe
2009-12-20 17:06:19 261632 ----a-w- c:\windows\PEV.exe
2009-12-20 17:06:19 161792 ----a-w- c:\windows\SWREG.exe
2009-12-19 19:39:12 0 d-----w- C:\spoolerlogs
2009-12-15 03:10:10 0 d-----w- c:\windows\pss
2009-12-14 21:50:12 0 d-----w- c:\program files\Spybot - Search & Destroy
2009-12-14 21:50:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-07 23:35:57 8875 ----a-w- c:\windows\system32\Config.MPF
2009-12-07 23:31:37 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-07 23:31:37 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-07 23:31:37 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-07 23:31:30 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-07 23:29:18 0 d-----w- c:\program files\common files\McAfee
2009-12-07 23:23:36 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys

==================== Find3M ====================

2009-11-04 21:54:12 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-31 17:59:06 10752 ----a-w- c:\windows\DCEBoot.exe
2009-09-25 05:49:02 668672 ------w- c:\windows\system32\wininet.dll
2009-09-25 05:49:02 668672 ------w- c:\windows\system32\dllcache\wininet.dll
2009-09-25 05:49:02 628224 ------w- c:\windows\system32\dllcache\urlmon.dll
2009-09-25 05:49:02 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll
2009-09-25 05:49:02 1509888 ------w- c:\windows\system32\dllcache\shdocvw.dll
2009-09-25 05:49:01 532480 ------w- c:\windows\system32\dllcache\mstime.dll
2009-09-25 05:49:01 449024 ------w- c:\windows\system32\dllcache\mshtmled.dll
2009-09-25 05:49:01 39424 ------w- c:\windows\system32\dllcache\pngfilt.dll
2009-09-25 05:49:01 3070976 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-09-25 05:49:01 146432 ------w- c:\windows\system32\dllcache\msrating.dll
2009-09-25 05:48:59 96256 ------w- c:\windows\system32\dllcache\inseng.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-09-25 05:48:59 55808 ------w- c:\windows\system32\dllcache\extmgr.dll
2009-09-25 05:48:59 251904 ------w- c:\windows\system32\dllcache\iepeers.dll
2009-09-25 05:48:59 16384 ------w- c:\windows\system32\dllcache\jsproxy.dll
2009-09-25 05:48:58 357888 ------w- c:\windows\system32\dllcache\dxtmsft.dll
2009-09-25 05:48:58 205312 ------w- c:\windows\system32\dllcache\dxtrans.dll
2009-09-25 05:48:58 151040 ------w- c:\windows\system32\dllcache\cdfview.dll
2009-09-25 05:48:58 1054208 ------w- c:\windows\system32\dllcache\danim.dll
2009-09-25 05:48:57 1024000 ------w- c:\windows\system32\dllcache\browseui.dll
2007-08-23 19:20:30 332 -c--a-w- c:\program files\ANG_Demo.log
2007-06-15 17:49:16 16344 -c--a-w- c:\program files\setuplog.txt
2007-06-15 17:49:14 16645 -c--a-w- c:\program files\uninstal.log
2006-05-12 03:09:31 56 -csh--r- c:\windows\system32\277220F470.sys
2006-05-12 03:09:31 3402 -csha-w- c:\windows\system32\KGyGaAvL.sys

============= FINISH: 13:26:18.18 ===============

Blade81
2009-12-20, 23:13
Hi again,


Uninstall old Adobe Reader versions and get the latest one (9.2) here (http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here (http://pdfreaders.org/).

Uninstall your current Adobe shockwave player and get the fresh one here (http://get.adobe.com/shockwave/) if needed.

Uninstall vulnerable Flash versions by following instructions here (http://kb2.adobe.com/cps/141/tn_14157.html). Fresh version can be obtained here (http://get.adobe.com/flashplayer/).

Uninstall Macromedia Flash Player.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 17 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report & a fresh dds.txt log. How's the system running?

c_anthony_bailey
2009-12-21, 17:38
So it still takes the PC a long time to reboot. 12 minutes just now.....


Click "shutdown on menu... between ~2 minutes before the "standby, turnoff, restart" pop-up comes up.

Then UI shutsdown, get to blue "windows is shutting down" message where it sits for another ~2 minutes.

And again on startup, after "black" windows XP logo screen, the monitor goes to complete black (with only mouse pointer) and sits there for ~2 minutes before I get to the blue "windows is starting up"


During these "pauses" no disk activity or anything, kinda makes me think it waiting on some sort of time out.. and I found these entries in the error log...

I clicked "shutdown" on menu around 11:11 so this first error would have been around that first pause. and the second during the second... and both are prior to the "event log stopping" event


Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 12/21/2009
Time: 11:13:27 AM
User: MINEY\Trica
Computer: MINEY
Description:
The server {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} did not register with DCOM within the required timeout.



and


Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 12/21/2009
Time: 11:16:15 AM
User: NT AUTHORITY\SYSTEM
Computer: MINEY
Description:
The server {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} did not register with DCOM within the required timeout.



This is the only error on the startup side..


Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 12/21/2009
Time: 11:20:37 AM
User: N/A
Computer: MINEY
Description:
The Par1284 service failed to start due to the following error:
The system cannot find the device specified.



Note this was after removing all the stuff from last post. only re-adding JRE for now. running ATF and Kapersky momentarily and will post results

c_anthony_bailey
2009-12-22, 03:59
running a really long time, wife had to kill it to do some work on PC. will re-run it overnight tonight.

Did find some info on the DCOM errors, seems to be related to windows automatic update.


http://www.windowsbbs.com/windows-xp/47229-problems-shutdown-reboot-logoff-dcom-automatic-updates.html
......

Searching regedit for "9B1F122C-2982-4E91-AA8B-E071D54F2A4D", gave me
default : CAutoUpdate Class 1.0
AppId : 653C5148-4DCE-4905-9CFD-1B23662D3D9E

Searching regedit for "653C5148-4DCE-4905-9CFD-1B23662D3D9E", gave me
653C5148-4DCE-4905-9CFD-1B23662D3D9E
Automatic Updates


.....


Copy/paste the following, between but not including the asterisks, into the
Notepad window:

*********************
net stop wuauserv

regsvr32 /s wuapi.dll

regsvr32 /s wups.dll

regsvr32 /s wuaueng.dll

regsvr32 /s wuaueng1.dll

regsvr32 /s wucltui.dll

regsvr32 /s wuweb.dll

regsvr32 /s jscript.dll

regsvr32 /s atl.dll

regsvr32 /s softpub.dll

regsvr32 /s msxml3.dll

net start wuauserv
**********************

When finished pasting the above commands into the Notepad window, go to
File>Save then File>Exit.

Back in the Command Prompt window, key in:
registerit.cmd
Then hit ENTER

When the file is done running, and you're back at the C: prompt, key in:
exit
Then hit ENTER


....


After creating the script and runnining it, I was able to reboot, restart, and log off my computer again without any problems from DCOM.





gonna try this after wife done working

Blade81
2009-12-22, 09:51
Good to hear DCOM issue is under control :)

Shall wait for those reports.

c_anthony_bailey
2009-12-22, 14:42
Kaspersky shows clean now... Still need to try the DCOM fixes (was waiting for kaspersky to finish) will post how it comes out.




KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, December 22, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, December 22, 2009 05:15:12
Records in database: 3397860
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Objects scanned: 160322
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 02:57:19

No threats found. Scanned area is clean.

Selected area has been scanned.


----

DDS log




DDS (Ver_09-12-01.01) - NTFSx86
Run by Trica at 8:26:59.31 on Tue 12/22/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.575 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

svchost.exe
C:\WINDOWS\System32\svchost -k DComLaunch
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2J1.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE
C:\Documents and Settings\Tony\My Documents\fixes\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.yahoo.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler
mRun: [EPSON Stylus Photo R800] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2J1.EXE /P23 "EPSON Stylus Photo R800" /O6 "USB003" /M "Stylus Photo R800"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop elements 4.0\apdproxy.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dlbcserv.lnk - c:\program files\dell photo printer 720\dlbcserv.exe
IE: &Search - ?p=ZJxdm025YYUS
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} - hxxp://zone.msn.com/bingame/zpagames/zpa_hrtz.cab67031.cab
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/cpucheck_1_0_0_4.cab
DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/Entriq_3_4_0_15_Silent.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} - hxxp://entriq.vo.llnwd.net/o1/NBCUniversal/cabs/NBCUniversal_1_0_0_3.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://myvpn.ford.com/dana-cached/setup/JuniperSetupSP1.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\trica\applic~1\mozilla\firefox\profiles\fts2mc7j.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-12-7 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-12-7 144704]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-12-7 606736]

=============== Created Last 30 ================

2009-12-21 16:25:25 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-12-21 16:25:25 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-20 17:07:37 0 d-sha-r- C:\cmdcons
2009-12-20 17:06:19 98816 ----a-w- c:\windows\sed.exe
2009-12-20 17:06:19 77312 ----a-w- c:\windows\MBR.exe
2009-12-20 17:06:19 261632 ----a-w- c:\windows\PEV.exe
2009-12-20 17:06:19 161792 ----a-w- c:\windows\SWREG.exe
2009-12-19 19:39:12 0 d-----w- C:\spoolerlogs
2009-12-15 03:10:10 0 d-----w- c:\windows\pss
2009-12-14 21:50:12 0 d-----w- c:\program files\Spybot - Search & Destroy
2009-12-14 21:50:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-07 23:35:57 9727 ----a-w- c:\windows\system32\Config.MPF
2009-12-07 23:31:37 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-07 23:31:37 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-12-07 23:31:37 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-07 23:31:30 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-12-07 23:29:18 0 d-----w- c:\program files\common files\McAfee
2009-12-07 23:23:36 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys

==================== Find3M ====================

2009-11-04 21:54:12 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-31 17:59:06 10752 ----a-w- c:\windows\DCEBoot.exe
2009-09-25 05:49:02 668672 ------w- c:\windows\system32\wininet.dll
2009-09-25 05:49:02 668672 ------w- c:\windows\system32\dllcache\wininet.dll
2009-09-25 05:49:02 628224 ------w- c:\windows\system32\dllcache\urlmon.dll
2009-09-25 05:49:02 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll
2009-09-25 05:49:02 1509888 ------w- c:\windows\system32\dllcache\shdocvw.dll
2009-09-25 05:49:01 532480 ------w- c:\windows\system32\dllcache\mstime.dll
2009-09-25 05:49:01 449024 ------w- c:\windows\system32\dllcache\mshtmled.dll
2009-09-25 05:49:01 39424 ------w- c:\windows\system32\dllcache\pngfilt.dll
2009-09-25 05:49:01 3070976 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-09-25 05:49:01 146432 ------w- c:\windows\system32\dllcache\msrating.dll
2009-09-25 05:48:59 96256 ------w- c:\windows\system32\dllcache\inseng.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-09-25 05:48:59 55808 ------w- c:\windows\system32\dllcache\extmgr.dll
2009-09-25 05:48:59 251904 ------w- c:\windows\system32\dllcache\iepeers.dll
2009-09-25 05:48:59 16384 ------w- c:\windows\system32\dllcache\jsproxy.dll
2009-09-25 05:48:58 357888 ------w- c:\windows\system32\dllcache\dxtmsft.dll
2009-09-25 05:48:58 205312 ------w- c:\windows\system32\dllcache\dxtrans.dll
2009-09-25 05:48:58 151040 ------w- c:\windows\system32\dllcache\cdfview.dll
2009-09-25 05:48:58 1054208 ------w- c:\windows\system32\dllcache\danim.dll
2009-09-25 05:48:57 1024000 ------w- c:\windows\system32\dllcache\browseui.dll
2007-08-23 19:20:30 332 -c--a-w- c:\program files\ANG_Demo.log
2007-06-15 17:49:16 16344 -c--a-w- c:\program files\setuplog.txt
2007-06-15 17:49:14 16645 -c--a-w- c:\program files\uninstal.log
2006-05-12 03:09:31 56 -csh--r- c:\windows\system32\277220F470.sys
2006-05-12 03:09:31 3402 -csha-w- c:\windows\system32\KGyGaAvL.sys

============= FINISH: 8:27:56.64 ===============

Blade81
2009-12-22, 15:27
Ok. Logs themselves looks ok.

c_anthony_bailey
2009-12-22, 15:40
OK, running the script above definitely fixed the slow shutdown. PC shut's down quickly now with no errors.

Still takes a very long time to boot up (sitting at a black screen for ~2 mins doing nothing) Any idea where to find the windows "boot up logs" to see if I can find what it is doing between the windows logo and the blue logon screen?

Note, with clean logs, I question if it is even malware related ... Is this an appropriate forum to continue pursuing this?


A couple other questions,...

Was I even infected in the first place? Hard to decipher the logs to tell ...

Where can i get info to help decipher the DDS/ComboFix logs (i.e. what is Find3M section, and what does stuff there mean, what does "de-registered" mean for drivers in memory) A users manual would be great

Do I need to be worried about these entries in the DDS log/Find3M section?

2006-05-12 03:09:31 56 -csh--r- c:\windows\system32\277220F470.sys
2006-05-12 03:09:31 3402 -csha-w- c:\windows\system32\KGyGaAvL.sys

They are old but <random chars>.sys files look suspiscious...


And again thank you very much...

c_anthony_bailey
2009-12-22, 16:08
Was able to get a bit of boot information (pick the "enable boot logging" from the boot menu ...duh /chuckle)

Anyway, there are a couple hundred (thousand??) lines like this... that seem very suspiscious...


Did not load driver \??\C:\WINDOWS\System32\drivers\fffeb480.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fffab47d.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fffa7c40.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fff87c3f.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fff67c3d.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fff47c3b.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fff37c3a.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\fff0b472.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\ffedb46f.sys
........

Did not load driver \??\C:\WINDOWS\System32\drivers\00127c58.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00117c57.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00107c56.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\000c7c52.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\000bb48c.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\000b7c51.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\000a7c4f.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00097446.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\0008b489.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00057443.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00057442.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00037c49.sys
Did not load driver \??\C:\WINDOWS\System32\drivers\00023c04.sys


Normal entries seem to look like


Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys

Blade81
2009-12-22, 16:21
Are you able to run GMER now? Also, please attach bootlog file to your post.

c_anthony_bailey
2009-12-23, 01:06
running, but very slow, 3-4 hours now. still cycling through SYSTEM\CurrentControlSet\Services\nnnnnnnn.sys and getting progressively slower as it goes up to 943448b6.sys and so slow its not responding.

... as I speak it ended (but maybe because I was trying to click cancel...) here's what I was able to save....


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2009-12-22 19:05:40
Windows 5.1.2600 Service Pack 2
Running: nmeyk5r6.exe; Driver: C:\DOCUME~1\Trica\LOCALS~1\Temp\fxtdypow.sys


---- System - GMER 1.0.15 ----

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xEEA1A78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xEEA1A821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xEEA1A738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xEEA1A74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xEEA1A835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xEEA1A861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xEEA1A8CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xEEA1A8B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xEEA1A7CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xEEA1A8FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xEEA1A80D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xEEA1A710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xEEA1A724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xEEA1A79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xEEA1A937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xEEA1A8A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xEEA1A88D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xEEA1A84B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xEEA1A923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xEEA1A90F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xEEA1A776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xEEA1A762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xEEA1A877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xEEA1A7F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xEEA1A8E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xEEA1A7E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xEEA1A7B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

---- EOF - GMER 1.0.15 ----


ntbtlog.txt is failing to upload, maybe too big 5M (and no zip tool on wifes pc at the moment)

c_anthony_bailey
2009-12-23, 03:15
restarted GMER and got blue screen of death...

Blade81
2009-12-23, 10:05
Hi,

XP has archiving functionality inbuilt. You may follow instructions here (http://www.bleepingcomputer.com/tutorials/tutorial105.html).

c_anthony_bailey
2009-12-29, 16:15
sorry, lots of family Christmas celebrations recently, so haven't been able to look further, will do more this afternoon. Thanks for your patience

Blade81
2009-12-29, 16:17
Ok. Thanks for the heads up :)

c_anthony_bailey
2009-12-29, 16:36
note, contains three different boot ups... two on 12/22 and a third this morning on 12/29.

c_anthony_bailey
2009-12-29, 16:53
came back... not sure when (as pc doesnt get reboot all the time) but noticed it last night. re-ran registry script from my previous replies and it cleared up the problem again (shuts down ok, still starts up slow)

Will need to figure out how it came back

Blade81
2009-12-29, 17:42
Let's run a scan with Malwarebytes' Anti-Malware.

Please download Malwarebytes' Anti-Malware (http://www.besttechie.net/tools/mbam-setup.exe) to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location.
Please post contents of that file in your next reply.

c_anthony_bailey
2009-12-29, 18:38
Malwarebytes' Anti-Malware 1.42
Database version: 3450
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

12/29/2009 12:36:08 PM
mbam-log-2009-12-29 (12-36-08).txt

Scan type: Quick Scan
Objects scanned: 138542
Time elapsed: 13 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Blade81
2009-12-29, 18:51
As a next step, uninstall all old programs that you don't need anymore.

Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop.
@ECHO OFF
DIR /a/s C:\WINDOWS\system32\drivers >"%userprofile%\desktop\Log.txt"
DEL %0

Double-click on fixes.bat file to execute it. Log.txt file should appear to your desktop. Attach it to your post.

c_anthony_bailey
2009-12-29, 19:50
Volume in drive C has no label.
Volume Serial Number is 24FD-74B7

Directory of C:\WINDOWS\system32\drivers

12/29/2009 11:55 AM <DIR> .
12/29/2009 11:55 AM <DIR> ..
09/14/2009 08:12 AM 16 .sys
12/08/2005 10:54 AM 6,136 1028_Dell_DIM_DM051.mrk
08/17/2001 02:52 PM 23,552 ABP480N5.SYS
08/10/2004 06:00 AM 187,776 acpi.sys
08/10/2004 06:00 AM 11,648 acpiec.sys
08/17/2001 03:07 PM 101,888 adpu160m.sys
02/14/2006 07:22 PM 142,464 aec.sys
08/14/2008 04:51 AM 138,368 afd.sys
08/04/2004 12:07 AM 42,368 AGP440.SYS
08/04/2004 12:07 AM 44,928 AGPCPQ.SYS
08/17/2001 02:52 PM 12,800 aha154x.sys
08/17/2001 03:07 PM 55,168 aic78u2.sys
08/17/2001 03:07 PM 56,960 aic78xx.sys
08/17/2001 02:51 PM 5,248 aliide.sys
08/04/2004 12:07 AM 42,752 ALIM1541.SYS
08/04/2004 12:07 AM 43,008 AMDAGP.SYS
08/10/2004 06:00 AM 36,992 amdk6.sys
08/10/2004 06:00 AM 37,376 amdk7.sys
08/17/2001 02:52 PM 12,032 amsint.sys
08/10/2004 06:00 AM 60,800 arp1394.sys
08/17/2001 02:52 PM 26,496 asc.sys
08/17/2001 02:52 PM 22,400 asc3350p.sys
08/17/2001 02:51 PM 14,848 asc3550.sys
12/08/2005 11:19 AM 8,552 asctrm.sys
08/10/2004 06:00 AM 14,336 asyncmac.sys
08/03/2004 11:59 PM 95,360 atapi.sys
08/04/2005 04:08 AM 40,960 ati2erec.dll
08/04/2005 05:10 AM 1,273,344 ati2mtag.sys
07/11/2005 10:12 PM 524,850 ativcaxx.cpa
07/11/2005 10:12 PM 929 ativcaxx.vp
06/08/2005 09:45 PM 58,560 ativckxx.vp
08/04/2005 08:20 AM 21,712 ativvpxx.vp
08/10/2004 06:00 AM 59,904 atmarpc.sys
08/10/2004 06:00 AM 31,360 atmepvc.sys
08/10/2004 06:00 AM 55,936 atmlane.sys
08/10/2004 06:00 AM 352,256 atmuni.sys
08/17/2001 02:59 PM 3,072 audstub.sys
05/16/2005 10:40 AM 359,552 BCMWL5.SYS
08/10/2004 06:00 AM 4,224 beep.sys
08/10/2004 06:00 AM 71,552 bridge.sys
06/13/2008 08:10 AM 272,128 bthport.sys
08/17/2001 02:52 PM 13,952 cbidf2k.sys
08/17/2001 02:52 PM 7,680 cd20xrnt.sys
08/10/2004 06:00 AM 18,688 cdaudio.sys
08/10/2004 06:00 AM 63,744 cdfs.sys
08/10/2004 06:00 AM 49,536 cdrom.sys
08/10/2004 06:00 AM 262,528 cinemst2.sys
08/10/2004 06:00 AM 49,664 classpnp.sys
08/17/2001 02:51 PM 6,656 cmdide.sys
08/17/2001 02:52 PM 14,976 cpqarray.sys
08/10/2004 06:00 AM 11,776 cpqdap01.sys
08/10/2004 06:00 AM 36,480 crusoe.sys
08/17/2001 02:52 PM 179,584 dac2w2k.sys
08/17/2001 02:52 PM 14,720 dac960nt.sys
11/19/2003 09:15 AM 128,398 del200f.cty
08/16/2005 05:22 AM <DIR> disdn
08/10/2004 06:00 AM 36,352 disk.sys
08/10/2004 06:00 AM 14,208 diskdump.sys
08/10/2004 06:00 AM 799,744 dmboot.sys
08/10/2004 06:00 AM 153,344 dmio.sys
08/10/2004 06:00 AM 5,888 dmload.sys
08/04/2004 12:07 AM 52,864 DMusic.sys
08/17/2001 03:07 PM 20,192 dpti2o.sys
08/03/2004 10:08 PM 60,288 drmk.sys
08/04/2004 12:07 AM 2,944 drmkaud.sys
02/25/2007 11:10 AM 5,376 dsunidrv.sys
08/10/2004 06:00 AM 10,496 dxapi.sys
08/10/2004 06:00 AM 71,040 dxg.sys
08/10/2004 06:00 AM 3,328 dxgthk.sys
10/14/2004 10:30 PM 155,648 e100b325.sys
12/20/2009 01:09 PM <DIR> etc
08/10/2004 06:00 AM 143,360 fastfat.sys
08/10/2004 06:00 AM 27,392 fdc.sys
08/10/2004 06:00 AM 34,944 fips.sys
08/10/2004 06:00 AM 20,480 flpydisk.sys
08/21/2006 04:14 AM 128,896 fltmgr.sys
08/10/2004 06:00 AM 12,160 fsvga.sys
08/10/2004 06:00 AM 7,936 fs_rec.sys
08/17/2001 02:52 PM 125,056 ftdisk.sys
09/19/2006 01:44 PM 15,664 GEARAspiWDM.sys
08/10/2004 06:00 AM 3,440,660 gm.dls
08/10/2004 06:00 AM 646 gmreadme.txt
08/12/2004 06:45 PM 137,728 Hdaudbus.sys
08/12/2004 06:45 PM 113,664 Hdaudio.sys
08/10/2004 06:00 AM 36,224 hidclass.sys
06/28/2005 12:43 PM 19,200 hidir.sys
08/10/2004 06:00 AM 24,960 hidparse.sys
08/17/2001 03:02 PM 9,600 hidusb.sys
08/17/2001 03:07 PM 25,952 hpn.sys
11/17/2003 10:59 PM 212,224 HSFHWBS2.sys
11/17/2003 10:58 PM 680,704 HSF_CNXT.sys
11/17/2003 10:56 PM 1,042,432 HSF_DP.sys
03/16/2006 07:33 PM 262,784 http.sys
08/04/2004 12:00 AM 8,192 i2omgmt.sys
08/04/2004 12:00 AM 18,560 i2omp.sys
08/10/2004 06:00 AM 52,736 i8042prt.sys
08/10/2004 06:00 AM 41,856 imapi.sys
08/17/2001 02:52 PM 16,000 ini910u.sys
08/03/2004 11:59 PM 5,504 intelide.sys
08/10/2004 06:00 AM 36,096 intelppm.sys
08/10/2004 06:00 AM 29,056 ip6fw.sys
08/10/2004 06:00 AM 32,896 ipfltdrv.sys
08/10/2004 06:00 AM 20,992 ipinip.sys
09/29/2004 05:28 PM 134,912 ipnat.sys
08/10/2004 06:00 AM 74,752 ipsec.sys
11/02/2004 04:12 PM 19,456 iqvw32.sys
06/28/2005 12:43 PM 46,592 irbus.sys
08/10/2004 06:00 AM 11,264 irenum.sys
08/17/2001 02:58 PM 35,840 isapnp.sys
08/03/2004 11:58 PM 24,576 kbdclass.sys
08/03/2004 11:58 PM 14,848 kbdhid.sys
06/14/2006 03:47 AM 172,416 kmixer.sys
08/03/2004 10:15 PM 140,928 ks.sys
06/22/2009 06:34 AM 92,544 ksecdd.sys
12/03/2009 04:13 PM 19,160 mbam.sys
12/03/2009 04:14 PM 38,224 mbamswissarmy.sys
08/10/2004 06:00 AM 7,680 mcd.sys
04/09/2003 07:48 PM 11,043 mdmxsdk.sys
08/10/2004 06:00 AM 63,744 mf.sys
11/04/2009 04:54 PM 79,816 mfeavfk.sys
11/04/2009 04:54 PM 35,272 mfebopk.sys
11/04/2009 04:54 PM 214,664 mfehidk.sys
11/04/2009 04:53 PM 34,248 mferkdk.sys
11/04/2009 04:54 PM 40,552 mfesmfk.sys
08/10/2004 04:45 AM 11,008 mhndrv.sys
08/10/2004 06:00 AM 4,224 mnmdd.sys
08/10/2004 06:00 AM 30,080 modem.sys
08/17/2001 02:57 PM 16,128 MODEMCSA.sys
08/03/2004 11:58 PM 23,040 mouclass.sys
08/17/2001 02:48 PM 12,160 mouhid.sys
08/10/2004 06:00 AM 42,240 mountmgr.sys
04/17/2008 10:57 AM 3,768 MovRVDrv32.sys
07/16/2009 12:32 PM 120,136 Mpfp.sys
06/22/2009 06:48 AM 91,776 mqac.sys
08/17/2001 02:52 PM 17,280 mraid35x.sys
12/18/2007 04:51 AM 179,584 mrxdav.sys
10/24/2008 06:10 AM 453,632 mrxsmb.sys
08/10/2004 06:00 AM 19,072 msfs.sys
08/10/2004 06:00 AM 35,072 msgpc.sys
08/03/2004 11:58 PM 7,552 MSKSSRV.sys
08/03/2004 11:58 PM 5,376 MSPCLOCK.sys
08/03/2004 11:58 PM 4,992 MSPQM.sys
08/04/2004 12:07 AM 15,488 mssmbios.sys
08/10/2004 06:00 AM 107,904 mup.sys
08/10/2004 06:00 AM 182,912 ndis.sys
08/10/2004 06:00 AM 9,600 ndistapi.sys
06/20/2005 02:52 PM 14,592 ndisuio.sys
08/10/2004 06:00 AM 91,776 ndiswan.sys
08/10/2004 06:00 AM 38,016 ndproxy.sys
08/10/2004 06:00 AM 34,560 netbios.sys
08/10/2004 06:00 AM 162,816 netbt.sys
08/10/2004 06:00 AM 61,824 nic1394.sys
08/10/2004 06:00 AM 12,032 nikedrv.sys
08/10/2004 06:00 AM 40,320 nmnt.sys
08/10/2004 06:00 AM 30,848 npfs.sys
02/09/2007 06:10 AM 574,464 ntfs.sys
08/10/2004 06:00 AM 2,944 null.sys
08/03/2004 11:29 PM 1,897,408 nv4_mini.sys
08/10/2004 06:00 AM 12,416 nwlnkflt.sys
08/10/2004 06:00 AM 32,512 nwlnkfwd.sys
08/10/2004 06:00 AM 88,448 nwlnkipx.sys
08/10/2004 06:00 AM 63,232 nwlnknb.sys
08/10/2004 06:00 AM 55,936 nwlnkspx.sys
10/13/2006 05:23 AM 163,584 nwrdr.sys
08/10/2004 06:00 AM 3,456 oprghdlr.sys
08/10/2004 06:00 AM 42,496 p3.sys
08/10/2004 06:00 AM 80,128 parport.sys
08/10/2004 06:00 AM 18,688 partmgr.sys
08/10/2004 06:00 AM 6,784 parvdm.sys
08/04/2004 12:07 AM 68,224 pci.sys
08/17/2001 02:51 PM 3,328 pciide.sys
08/03/2004 11:59 PM 25,088 pciidex.sys
08/10/2004 06:00 AM 119,936 pcmcia.sys
08/17/2001 03:07 PM 27,296 perc2.sys
08/17/2001 03:07 PM 5,504 perc2hib.sys
03/16/2004 12:58 PM 136,960 portcls.sys
08/10/2004 06:00 AM 35,328 processr.sys
08/10/2004 06:00 AM 69,120 psched.sys
08/10/2004 06:00 AM 17,792 ptilink.sys
04/25/2005 03:03 AM 20,640 pxhelp20.sys
09/13/2009 05:27 PM 16 pZ.sys
08/17/2001 02:52 PM 40,320 ql1080.sys
08/17/2001 02:52 PM 33,152 ql10wnt.sys
08/17/2001 02:52 PM 45,312 ql12160.sys
08/17/2001 02:52 PM 40,448 ql1240.sys
08/17/2001 02:52 PM 49,024 ql1280.sys
08/10/2004 06:00 AM 8,832 rasacd.sys
08/10/2004 06:00 AM 51,328 rasl2tp.sys
08/10/2004 06:00 AM 41,472 raspppoe.sys
08/10/2004 06:00 AM 48,384 raspptp.sys
08/10/2004 06:00 AM 16,512 raspti.sys
08/10/2004 06:00 AM 34,432 rawwan.sys
05/05/2006 04:47 AM 174,592 rdbss.sys
08/10/2004 06:00 AM 4,224 rdpcdd.sys
08/04/2004 12:01 AM 196,864 rdpdr.sys
06/09/2005 11:09 PM 139,528 rdpwd.sys
08/03/2004 11:59 PM 57,472 redbook.sys
08/10/2004 06:00 AM 12,032 rio8drv.sys
08/10/2004 06:00 AM 12,032 riodrv.sys
05/08/2008 07:28 AM 202,752 rmcast.sys
11/30/2004 07:28 PM 30,464 rndismp.sys
08/10/2004 06:00 AM 5,888 rootmdm.sys
08/10/2004 06:00 AM 96,256 scsiport.sys
08/10/2004 06:00 AM 67,584 sdbus.sys
11/13/2007 05:25 AM 20,480 secdrv.sys
08/10/2004 06:00 AM 15,488 serenum.sys
08/10/2004 06:00 AM 64,896 serial.sys
08/10/2004 06:00 AM 11,136 sffdisk.sys
08/10/2004 06:00 AM 10,240 sffp_sd.sys
08/10/2004 06:00 AM 11,392 sfloppy.sys
08/04/2004 12:07 AM 41,088 SISAGP.SYS
08/10/2004 06:00 AM 14,592 smclib.sys
04/17/2008 10:57 AM 508,544 SndTDriverV32.sys
08/10/2004 06:00 AM 25,472 sonydcam.sys
08/17/2001 01:56 PM 7,552 SONYPVU1.SYS
08/17/2001 03:07 PM 19,072 sparrow.sys
06/14/2006 03:47 AM 6,400 splitter.sys
08/10/2004 06:00 AM 73,472 sr.sys
12/11/2008 06:57 AM 333,184 srv.sys
06/14/2005 11:40 PM 180,864 sthda.sys
08/03/2004 10:08 PM 48,640 stream.sys
08/03/2004 11:58 PM 4,352 swenum.sys
08/17/2001 03:00 PM 54,272 swmidi.sys
08/17/2001 03:07 PM 16,256 symc810.sys
08/17/2001 03:07 PM 32,640 symc8xx.sys
08/17/2001 03:07 PM 28,384 sym_hi.sys
08/17/2001 03:07 PM 30,688 sym_u3.sys
08/04/2004 12:15 AM 60,800 sysaudio.sys
08/10/2004 06:00 AM 14,976 tape.sys
06/20/2008 05:45 AM 360,320 tcpip.sys
06/20/2008 04:52 AM 225,920 tcpip6.sys
08/10/2004 06:00 AM 18,560 tdi.sys
08/10/2004 06:00 AM 12,040 tdpipe.sys
08/10/2004 06:00 AM 21,896 tdtcp.sys
08/04/2004 02:01 AM 40,840 termdd.sys
08/10/2004 06:00 AM 51,712 tosdvd.sys
08/17/2001 02:51 PM 4,992 toside.sys
08/10/2004 06:00 AM 21,376 tsbvcap.sys
08/10/2004 06:00 AM 12,416 tunmp.sys
08/10/2004 06:00 AM 66,176 udfs.sys
08/17/2001 02:52 PM 36,736 ultra.sys
06/30/2007 11:02 PM <DIR> UMDF
04/23/2007 05:32 AM 364,160 update.sys
12/08/2004 10:34 AM 12,800 usb8023.sys
08/10/2004 06:00 AM 23,808 usbcamd.sys
08/10/2004 06:00 AM 23,936 usbcamd2.sys
08/04/2004 12:08 AM 31,616 usbccgp.sys
08/10/2004 06:00 AM 4,736 usbd.sys
08/10/2004 06:00 AM 26,624 usbehci.sys
08/04/2004 12:08 AM 57,600 usbhub.sys
08/10/2004 06:00 AM 16,000 usbintel.sys
08/04/2004 12:08 AM 142,976 usbport.sys
08/03/2004 11:01 PM 25,856 usbprint.sys
08/03/2004 09:58 PM 15,104 usbscan.sys
08/03/2004 11:08 PM 26,496 USBSTOR.SYS
08/04/2004 12:08 AM 20,480 usbuhci.sys
08/10/2004 06:00 AM 58,112 vdmindvd.sys
08/10/2004 06:00 AM 20,992 vga.sys
08/04/2004 12:07 AM 42,240 VIAAGP.SYS
08/03/2004 11:59 PM 5,376 viaide.sys
08/10/2004 06:00 AM 79,744 videoprt.sys
08/10/2004 06:00 AM 52,352 volsnap.sys
08/10/2004 06:00 AM 34,560 wanarp.sys
06/14/2006 04:00 AM 82,944 wdmaud.sys
08/10/2004 06:00 AM 4,352 wmilib.sys
10/18/2006 07:00 PM 38,528 wpdusb.sys
08/10/2004 06:00 AM 12,032 ws2ifsl.sys
09/28/2006 05:55 PM 77,568 WudfPf.sys
09/28/2006 06:00 PM 82,944 WudfRd.sys
09/13/2009 02:42 PM 16 ?????????????????.sys
267 File(s) 25,474,046 bytes

Directory of C:\WINDOWS\system32\drivers\disdn

08/16/2005 05:22 AM <DIR> .
08/16/2005 05:22 AM <DIR> ..
0 File(s) 0 bytes

Directory of C:\WINDOWS\system32\drivers\etc

12/20/2009 01:09 PM <DIR> .
12/20/2009 01:09 PM <DIR> ..
12/20/2009 01:09 PM 27 hosts
08/10/2004 06:00 AM 3,683 lmhosts.sam
08/10/2004 06:00 AM 407 networks
08/10/2004 06:00 AM 799 protocol
08/10/2004 06:00 AM 7,116 services
5 File(s) 12,032 bytes

Directory of C:\WINDOWS\system32\drivers\UMDF

06/30/2007 11:02 PM <DIR> .
06/30/2007 11:02 PM <DIR> ..
06/30/2007 11:01 PM 0 MsftWdf_user_01_00_00.Wdf
10/18/2006 08:47 PM 671,232 wpdmtpdr.dll
2 File(s) 671,232 bytes

Total Files Listed:
274 File(s) 26,157,310 bytes
11 Dir(s) 38,895,964,160 bytes free

Blade81
2009-12-29, 21:34
Download suspicious file packer from here (http://www.safer-networking.org/files/sfp.zip)

Unzip it to desktop, open it & paste in the list of files below, press next & it will create an archive (zip/cab file) on desktop

C:\WINDOWS\system32\drivers\.sys
C:\WINDOWS\system32\drivers\pZ.sys

Go here (http://www.bleepingcomputer.com/submit-malware.php?channel=76) and upload the archive there. Kindly include a link to this topic.

Have you tried to reboot into safe mode now? See if you're able to boot there and run GMER (unselect devices & sections before hitting scan).

c_anthony_bailey
2009-12-30, 17:35
submitted packed file...

able to boot to safe mode, but GMER still behaves the same. Starts automatically and runs VERY slow scanning thorugh HKLM\System\CurrentControlSet\... and does not respond when trying to click cancel or anything.

I can try letting it run overnight tonight, but expect the same kind of blue screen/failures...


Any reason I shouldn't try and remove the bogus driver entries from the registry?

Blade81
2009-12-30, 17:47
Hi,

Yes, those will be removed but better do it carefully or system may turn up non bootable.

Archive c:\windows\system32\erdnt\hiv-backup\system into a zip file and upload here (http://www.bleepingcomputer.com/submit-malware.php?channel=22) with a link to this topic. Let me know when that's been done.

c_anthony_bailey
2009-12-30, 18:13
The directory c:\windows\system32\erdnt\ does not exist... do I need to create a registry backup first??

The only "system" file I found under c:\windows\system32\ was c:\windows\system32\erdnt\config\system and is about 75M.

Please let me know.

Odd note, when in windows explorer and clicking the "search" button. The search companion side bar comes up but it is completely blank except for the little dog animation... no drop downs/fill ins for specifying search options...

c_anthony_bailey
2009-12-30, 18:40
correction, the file I found was c:\windows\system32\config\system

Blade81
2009-12-30, 19:17
Sorry, try this location:
c:\windows\erdnt\hiv-backup\system

c_anthony_bailey
2009-12-30, 19:44
found it, but get error when trying to upload it to bleeping computer site. Could it be size? original file is 79M, zipped file is still 11M.

Blade81
2009-12-30, 19:49
Could be the size limit.

Go to spykiller (http://www.thespykiller.co.uk/index.php?board=1.0)

Press new topic, make threads title
Files for Blade81

Include to your message a link to this topic.

c_anthony_bailey
2009-12-30, 20:01
done http://thespykiller.co.uk/index.php/topic,9047.new.html#new

Blade81
2009-12-31, 09:41
Hi,

Download tool here (http://noahdfear.net/downloads/drvsrch.exe) to your desktop. Close all other programs first and then run the tool.

Kindly note that tool needs time to run since there's a lot of stuff it needs to process with.

After run has finished, reboot the system. When system is back to desktop after reboot, open registry editor and check if bad driver keys of controlsets under hkey_local_machine\system key are gone.

Note: If system fails to start normally after reboot use Last Known Good Configuration -option.

c_anthony_bailey
2009-12-31, 21:47
tool ran as described and appears to have cleaned up the registry entries.

PC now boots up much faster (basically no wait now between "black windows logo" screen and "blue windows starting up" screen.

GMER also starts up cleaner now within seconds, and scan is running at the moment. Will post results when it completes

Blade81
2010-01-01, 13:24
Great. I'll wait for the results :)

c_anthony_bailey
2010-01-01, 16:25
says text/file was to big, zipped and attached

Blade81
2010-01-01, 16:44
Looks good. Are there any issues left now?

c_anthony_bailey
2010-01-02, 06:18
All the major problems seems to be resolved now thanks!

The only two minor things I have left, is the "blank search panel" and fixing windows update (which is currently disabled because of the DCOM errors it is creating). Though I am guessing, neither of these is malware related, and I will just have to keep digging.

Thanks for all your help!

Blade81
2010-01-02, 16:33
Hi,

For that search issue try this:

Go to Start>> Run. Type/copy-paste in:
regsvr32 /i "%systemroot%\srchasst\srchui.dll" [Enter]

Let me know how it goes.

That DCOM issue is probably something you have to ask about on some forum that deals with general troubleshooting.

c_anthony_bailey
2010-01-02, 17:21
registering srchui.dll didn't seem to fix it.

However, I found this article http://support.microsoft.com/?kbid=831430 that said to Re-register Jscript.dll. That seems to have fixed the issue.

Thanks again and again. Have a very happy new year!

Blade81
2010-01-02, 19:38
Glad to hear that search issue got resolved.

ComboFix can be uninstalled now:

Click START then RUN
Now copy-paste Combofix /uninstall in the runbox and click OK


Happy New Year :)

Blade81
2010-01-09, 12:51
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.