Page 1 of 3 123 LastLast
Results 1 to 10 of 22

Thread: Windows update will not run

  1. #1
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default Windows update will not run

    It looks like I got a little behind on my windows updates. The last successful run was May 28th. I didn't notice this until yesterday when my computer was having some problems. Yesterday we had a power outage and the computer was on when the power went out. When I tried to start the computer up again it would boot, but then run very slowly. Realplayer was running multiple times in the task manager. I don't use Realplayer so I attempted to uninstall and after a few attempts I was successful. I attempted to run Windows Update again and it started to run. It got to 3 of 5. I let it run for an hour hoping that it wasn't hung, but it was hung. I did a hard stop (power button for 5 seconds). I started again. It asked for safe mode which I used. It then uninstalled the updates that didn't work and it looks like it reverted back to an old install point. It is also telling me that my copy of windows is not genuine, but I purchased this copy of windows.

    I have also tried a Safe Boot with limited services. I still wasn't able to get the Windows Update to run. I am guessing that I have probably made things worse rather than better at this point, so time to stop and let someone else take a look.

    I originally thought there was just a problem with some files that were corrupted with after the hard power down. I still can't get the windows update to run and I am thinking that there is more going on. I have backed up the registry (erdnt), run dds, and aswMBR.

    Thanks for your help!

    Greg

    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16483
    Run by Home at 8:32:37 on 2013-07-20
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6135.4066 [GMT -5:00]
    .
    AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
    SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\AERTSr64.exe
    C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
    C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
    C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
    C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
    C:\Windows\system32\mfevtps.exe
    C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RAVCpl64.exe
    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    C:\Program Files (x86)\2BrightSparks\SyncBackFree\SyncBackFree.exe
    C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
    C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
    C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\System32\WUDFHost.exe
    C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\sppsvc.exe
    C:\Windows\system32\WerFault.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\SysWOW64\NOTEPAD.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = about:blank
    mWinlogon: Userinit = userinit.exe
    BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120622112818.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    mRun: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
    mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
    mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
    mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
    mRun: [LGODDFU] "C:\Program Files (x86)\lg_fwupdate\lgfw.exe" blrun
    mRun: [KeePass 2 PreLoad] "C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
    mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
    mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB
    DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
    DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: NameServer = 208.67.222.123 208.67.220.123 68.94.156.1
    TCP: Interfaces\{145A7C7A-2B23-4F6E-84FE-14CF120FD804} : DHCPNameServer = 208.67.222.123 208.67.220.123 68.94.156.1
    TCP: Interfaces\{455052A2-CDB3-435F-8343-4EA28D875426} : DHCPNameServer = 68.94.156.1 68.94.157.1 192.168.52.1
    TCP: Interfaces\{455052A2-CDB3-435F-8343-4EA28D875426}\13934393D27657563747 : DHCPNameServer = 68.87.72.134 68.87.77.134 192.168.33.1
    TCP: Interfaces\{455052A2-CDB3-435F-8343-4EA28D875426}\164686F636 : DHCPNameServer = 192.168.0.1
    TCP: Interfaces\{455052A2-CDB3-435F-8343-4EA28D875426}\26C61636B6B696474797 : DHCPNameServer = 68.94.156.1 68.94.157.1
    TCP: Interfaces\{455052A2-CDB3-435F-8343-4EA28D875426}\C696E6B6379737 : DHCPNameServer = 68.87.72.134 68.87.77.134
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    AppInit_DLLs=
    SSODL: WebCheck - <orphaned>
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    x64-BHO: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120622112818.dll
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-Run: [Skytel] Skytel.exe
    x64-Run: [RtHDVCpl] RAVCpl64.exe
    x64-Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
    x64-DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x64/RescueControl.cab
    x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll
    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
    x64-SSODL: WebCheck - <orphaned>
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2011-2-25 771536]
    R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2011-2-25 340216]
    R2 AERTFilters;Andrea RT Filters Service;C:\Windows\System32\AERTSr64.exe [2011-7-22 88576]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-6-27 204288]
    R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2011-9-16 16056]
    R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\System32\drivers\LMIRfsDriver.sys [2012-2-25 72216]
    R3 AE3000;Linksys AE3000 Driver;C:\Windows\System32\drivers\AE3000w764.sys [2012-3-2 1717824]
    R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-3-30 114704]
    R3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service;C:\Windows\System32\drivers\AVerBDA716x_x64.sys [2009-4-30 1353600]
    R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-10 281088]
    R3 LVPr2M64;Logitech LVPr2M64 Driver;C:\Windows\System32\drivers\LVPr2M64.sys [2010-5-7 30304]
    R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2011-2-25 309840]
    R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2011-2-25 515968]
    S2 CLKMSVC10_38F51D56;CyberLink Product - 2012/07/15 19:54:33;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2011-4-20 241648]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2011-2-25 70112]
    S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2011-4-1 341856]
    S3 LVUVC64;Logitech Webcam Pro 9000(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2011-4-1 4184672]
    S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\drivers\mferkdet.sys [2011-2-25 106552]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-3-5 59392]
    .
    =============== Created Last 30 ================
    .
    2013-07-19 07:18:14 -------- d-----w- C:\Windows\9E23819E8AF44D25A7FE7756C9E3DBB9.TMP
    .
    ==================== Find3M ====================
    .
    2013-06-12 16:50:26 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-06-12 16:50:26 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2013-06-12 16:50:22 9089416 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
    2013-06-08 02:21:02 107368 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll
    2013-06-08 02:21:01 35656 ----a-w- C:\Windows\System32\LMIport.dll
    2013-06-08 02:21:01 100680 ----a-w- C:\Windows\System32\LMIinit.dll
    2013-06-01 02:21:05 107368 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll.001.bak
    2013-05-05 21:16:13 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2013-05-05 19:12:55 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    .
    ============= FINISH: 8:33:20.52 ===============
    Attached Files Attached Files

  2. #2
    Malware Team-Emeritus
    Join Date
    Sep 2012
    Location
    Florida, USA
    Posts
    1,161

    Default

    Hi grhull,

    The first way to validate that Windows 7 is genuine is to click on Start, then type in activate windows in the search box.



    If your copy of Windows 7 is activated and genuine, you will ge t a message that says “Activation was successful” and you will see the Microsoft Genuine software logo on the right hand side.



    =========================

    1. Security Check

    Download Security Check by screen317 from here or here.
    • Save it to your Desktop.
    • Right click SecurityCheck.exe, select "Run as Administrator" and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    =========================

    2. OTL

    Download OTL to your desktop.

    Right click and select "Run as Administrator".
    • Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Under Custom Scan paste this in

      netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      explorer.exe
      winlogon.exe
      Userinit.exe
      svchost.exe
      services.exe
      /md5stop
      %systemroot%\*. /rp /s
      %systemdrive%\$Recycle.Bin|@;true;true;true
      %USERPROFILE%\..|smtmp;true;true;true /FP
      %temp%\smtmp\*.* /s >
      BASESERVICES
      DRIVES
      CREATERESTOREPOINT

    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
      • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
        Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
      • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

    In your next post please provide the following:

    • checkup.txt
    • OTL.txt
    • Extras.txt
    • aswMBR.txt (from your previous run)
    • What symptoms are you experiencing?
    OCD
    ----------
    Graduate of WTT Classroom
    Member of UNITE

    Threads will be closed if no response after 5 days

  3. #3
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    I was able to verify that windows is activated. Here is my checkup.txt:

    Results of screen317's Security Check version 0.99.71
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 10
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Security Center service is not running! This report may not be accurate!
    Windows Firewall Enabled!
    McAfee Anti-Virus and Anti-Spyware
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Adobe Flash Player 11.7.700.224
    Adobe Reader 10.1.7 Adobe Reader out of Date!
    Google Chrome 27.0.1453.116
    Google Chrome 28.0.1500.72
    ````````Process Check: objlist.exe by Laurent````````
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````

    aswMBR.txt:

    aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
    Run date: 2013-07-20 08:49:57
    -----------------------------
    08:49:57.768 OS Version: Windows x64 6.1.7601 Service Pack 1
    08:49:57.768 Number of processors: 8 586 0x1A04
    08:49:57.768 ComputerName: MEDIA_01_10 UserName: Home
    08:49:59.063 Initialize success
    08:53:21.200 AVAST engine defs: 13072000
    08:54:36.633 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
    08:54:36.637 Disk 0 Vendor: ST3750528AS CC44 Size: 715404MB BusType: 3
    08:54:36.640 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-3
    08:54:36.642 Disk 1 Vendor: ST32000542AS CC95 Size: 1907729MB BusType: 3
    08:54:36.746 Disk 0 MBR read successfully
    08:54:36.749 Disk 0 MBR scan
    08:54:36.754 Disk 0 Windows 7 default MBR code
    08:54:36.765 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 715402 MB offset 2048
    08:54:36.785 Disk 0 scanning C:\Windows\system32\drivers
    08:54:47.367 Service scanning
    08:55:07.008 Modules scanning
    08:55:07.016 Disk 0 trace - called modules:
    08:55:07.039 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
    08:55:07.045 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006614060]
    08:55:07.050 3 CLASSPNP.SYS[fffff88001a8e43f] -> nt!IofCallDriver -> [0xfffffa80062d6520]
    08:55:07.055 5 ACPI.sys[fffff88000d777a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80062c5060]
    08:55:11.347 AVAST engine scan C:\Windows
    08:55:13.844 AVAST engine scan C:\Windows\system32
    09:00:15.310 Disk 0 MBR has been saved successfully to "C:\Users\Home\Desktop\Fixes_07_20_2013\aswMBR\MBR.dat"
    09:00:15.315 The log file has been saved successfully to "C:\Users\Home\Desktop\Fixes_07_20_2013\aswMBR\aswMBR.txt"

    The system seems to function correctly for a few minutes, but then programs will stop working. For example it took three restarts to download and run checkup. It would run and get to a certain point and then freeze up. When I try to restart windows it will log off and get to a certain point and then stop shutting down. I am then forced to perform a hard power down. I have run a checkdisk with no problems that I can see. If a program freezes I can do other things, but that program does not come back. It is unavailable. If I open up task manager the processor never gets over 5% and nothing is really running.

    When windows starts there is an error message. I have attached a screenshot of this message.

    I have attempted multiple times to run OTL. I will restart again and give it another try.

    Thanks again for the help.

    Greg
    Attached Images Attached Images

  4. #4
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    I have attempted to run OTL five or six times. It seems to get stuck in various places, but twice it has gotten stuck at:

    Scanning driver Tcpip...

    I will continue to try to run OTL unless you have another suggestion.

    Thanks again,

    Greg

  5. #5
    Malware Team-Emeritus
    Join Date
    Sep 2012
    Location
    Florida, USA
    Posts
    1,161

    Default

    Hi grhull,

    You stated you ran chkdsk, please follow the below steps to get the log from that scan.

    1. To view chkdsk results log:
    • Open the Start Menu, and type eventvwr.msc in the search box and press enter.
    • If prompted by UAC, then click on Yes (Windows 7) or Continue (Vista).
    • In the left pane of Event Viewer, double click on Windows Logs to expand it, then right click on Application and click on Find.
    • Copy and paste Chkdsk into the line, and click on Find Next.
    • You will now see the system log for the scan results of Check Disk (chkdsk).
    • In the right had menu select copy, open notepad and paste the chkdsk results into notepad
    • Post in your next reply.

    =========================

    2. System File Checker (SFC)
    • Click on the Start button and in the Search programs and files box type the following:

      • command

    • Don't press Enter, just let the search results populate above.
    • In the search results, locate the Programs section.
    • Locate the Command Prompt shortcut and right-click on it.
    • Select Run as administrator.
    • Click Yes on the User Account Control window that appears.
    • Important: If you are see a User Account Control window but also a message that says To continue, type an administrator password, and then click Yes, then your user account must be a standard account, not an administrator account. Before you can click Yes and open an elevated command prompt, you'll need to type the password of another user on your Windows 7 computer that has administrator level privileges.
    • Note: You will not see this window at all if your User Account Control settings are turned all the way down. See How To Disable User Account Control in Windows 7 for more information.
    • An elevated Command Prompt window will appear.

      • Type: sfc /scannow (There's a space between sfc and /scannow.) , then hit Enter

    • After the scan runs type exit to close the command prompt window
    • Include the findings in your next reply

    =========================

    In your next post please provide the following:

    • chkdsk log
    • Did SFC complete without issue. (do not post the log)
    OCD
    ----------
    Graduate of WTT Classroom
    Member of UNITE

    Threads will be closed if no response after 5 days

  6. #6
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    SFC ran completely and gave the following:

    Windows Resource Protection did not find any integrity violations.

    I cannot get the event viewer to run. It gets stuck loading the Application events.

  7. #7
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    Ok I did get the check disk log:

    Log Name: Application
    Source: Microsoft-Windows-Wininit
    Date: 7/18/2013 11:09:17 PM
    Event ID: 1001
    Task Category: None
    Level: Information
    Keywords: Classic
    User: N/A
    Computer: MEDIA_01_10
    Description:


    Checking file system on C:
    The type of the file system is NTFS.


    One of your disks needs to be checked for consistency. You
    may cancel the disk check, but it is strongly recommended
    that you continue.
    Windows will now check the disk.

    CHKDSK is verifying files (stage 1 of 3)...
    275712 file records processed.

    File verification completed.
    2162 large file records processed.

    0 bad file records processed.

    0 EA records processed.

    60 reparse records processed.

    CHKDSK is verifying indexes (stage 2 of 3)...
    The index bitmap $I30 in file 0xe18 is incorrect.
    Correcting error in index $I30 for file 3608.
    400330 index entries processed.

    Index verification completed.
    CHKDSK is scanning unindexed files for reconnect to their original directory.
    Recovering orphaned file WER3E5~1.TXT (188513) into directory file 3608.
    Recovering orphaned file WER3E56.tmp.appcompat.txt (188513) into directory file 3608.
    Recovering orphaned file WER3EE~1.XML (188530) into directory file 3608.
    Recovering orphaned file WER3EE4.tmp.WERInternalMetadata.xml (188530) into directory file 3608.
    3 unindexed files scanned.

    Recovering orphaned file WER3F1~1.HDM (188531) into directory file 3608.
    Recovering orphaned file WER3F14.tmp.hdmp (188531) into directory file 3608.
    0 unindexed files recovered.

    CHKDSK is verifying security descriptors (stage 3 of 3)...
    275712 file SDs/SIDs processed.

    Cleaning up 418 unused index entries from index $SII of file 0x9.
    Cleaning up 418 unused index entries from index $SDH of file 0x9.
    Cleaning up 418 unused security descriptors.
    Security descriptor verification completed.
    62310 data files processed.

    CHKDSK is verifying Usn Journal...
    33751696 USN bytes processed.

    Usn Journal verification completed.
    CHKDSK discovered free space marked as allocated in the
    master file table (MFT) bitmap.
    Correcting errors in the Volume Bitmap.
    Windows has made corrections to the file system.

    732571647 KB total disk space.
    536216876 KB in 209851 files.
    143092 KB in 62311 indexes.
    0 KB in bad sectors.
    400863 KB in use by the system.
    65536 KB occupied by the log file.
    195810816 KB available on disk.

    4096 bytes in each allocation unit.
    183142911 total allocation units on disk.
    48952704 allocation units available on disk.

    Internal Info:
    00 35 04 00 2e 27 04 00 9f 06 07 00 00 00 00 00 .5...'..........
    8a 45 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 .E..<...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................

    Windows has finished checking your disk.
    Please wait while your computer restarts.

    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Wininit" Guid="{206f6dea-d3c5-4d10-bc72-989f03c8b84b}" EventSourceName="Wininit" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2013-07-19T04:09:17.000000000Z" />
    <EventRecordID>23782</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>MEDIA_01_10</Computer>
    <Security />
    </System>
    <EventData>
    <Data>

    Checking file system on C:
    The type of the file system is NTFS.


    One of your disks needs to be checked for consistency. You
    may cancel the disk check, but it is strongly recommended
    that you continue.
    Windows will now check the disk.

    CHKDSK is verifying files (stage 1 of 3)...
    275712 file records processed.

    File verification completed.
    2162 large file records processed.

    0 bad file records processed.

    0 EA records processed.

    60 reparse records processed.

    CHKDSK is verifying indexes (stage 2 of 3)...
    The index bitmap $I30 in file 0xe18 is incorrect.
    Correcting error in index $I30 for file 3608.
    400330 index entries processed.

    Index verification completed.
    CHKDSK is scanning unindexed files for reconnect to their original directory.
    Recovering orphaned file WER3E5~1.TXT (188513) into directory file 3608.
    Recovering orphaned file WER3E56.tmp.appcompat.txt (188513) into directory file 3608.
    Recovering orphaned file WER3EE~1.XML (188530) into directory file 3608.
    Recovering orphaned file WER3EE4.tmp.WERInternalMetadata.xml (188530) into directory file 3608.
    3 unindexed files scanned.

    Recovering orphaned file WER3F1~1.HDM (188531) into directory file 3608.
    Recovering orphaned file WER3F14.tmp.hdmp (188531) into directory file 3608.
    0 unindexed files recovered.

    CHKDSK is verifying security descriptors (stage 3 of 3)...
    275712 file SDs/SIDs processed.

    Cleaning up 418 unused index entries from index $SII of file 0x9.
    Cleaning up 418 unused index entries from index $SDH of file 0x9.
    Cleaning up 418 unused security descriptors.
    Security descriptor verification completed.
    62310 data files processed.

    CHKDSK is verifying Usn Journal...
    33751696 USN bytes processed.

    Usn Journal verification completed.
    CHKDSK discovered free space marked as allocated in the
    master file table (MFT) bitmap.
    Correcting errors in the Volume Bitmap.
    Windows has made corrections to the file system.

    732571647 KB total disk space.
    536216876 KB in 209851 files.
    143092 KB in 62311 indexes.
    0 KB in bad sectors.
    400863 KB in use by the system.
    65536 KB occupied by the log file.
    195810816 KB available on disk.

    4096 bytes in each allocation unit.
    183142911 total allocation units on disk.
    48952704 allocation units available on disk.

    Internal Info:
    00 35 04 00 2e 27 04 00 9f 06 07 00 00 00 00 00 .5...'..........
    8a 45 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 .E..&lt;...........
    00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................

    Windows has finished checking your disk.
    Please wait while your computer restarts.
    </Data>
    </EventData>
    </Event>

  8. #8
    Malware Team-Emeritus
    Join Date
    Sep 2012
    Location
    Florida, USA
    Posts
    1,161

    Default

    Hi grhull,

    1. rkill

    Print out these instructions as we may need to close every window that is open later in the fix.

    It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

    Do not reboot your computer after running rkill as the malware programs will start again.

    Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
    There are 5 different versions. If one of them won't run then download and try to run the other one.
    Right click and select "Run as Administrator"
    You only need to get one of them to run, not all of them.
    1. rkill.exe
    2. rkill.com
    3. rkill.scr
    4. WiNlOgOn.exe
    5. uSeRiNiT.exe


    Do not reboot your computer after running rkill as the malware programs will start again.

    =========================

    2. ComboFix

    Refer to the ComboFix User's Guide

    • Download ComboFix from the following location:

      Link

      * IMPORTANT !!! Place ComboFix.exe on your Desktop
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
      You can get help on disabling your protection programs here
    • Double click on ComboFix.exe & follow the prompts.
    • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
    • When finished, it shall produce a log for you. Post that log in your next reply

      Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

      ---------------------------------------------------------------------------------------------
    • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
      ---------------------------------------------------------------------------------------------

    NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

    =========================

    In your next post please provide the following:

    • Rkill report
    • ComboFix.txt
    OCD
    ----------
    Graduate of WTT Classroom
    Member of UNITE

    Threads will be closed if no response after 5 days

  9. #9
    Member
    Join Date
    Nov 2008
    Posts
    36

    Default

    Combofix:

    ComboFix 13-07-25.02 - Home 07/26/2013 18:54:28.1.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6135.4441 [GMT -5:00]
    Running from: c:\users\Home\Desktop\ComboFix.exe
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\Install.exe
    c:\users\Public\Documents\~WRL1558.tmp
    c:\windows\Downloaded Program Files\x64
    c:\windows\Downloaded Program Files\x64\racodec.ax
    c:\windows\Downloaded Program Files\x86
    c:\windows\Downloaded Program Files\x86\racodec.ax
    c:\windows\security\Database\tmp.edb
    .
    .
    ((((((((((((((((((((((((( Files Created from 2013-06-26 to 2013-07-26 )))))))))))))))))))))))))))))))
    .
    .
    2013-07-26 23:58 . 2013-07-26 23:58 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
    2013-07-26 23:58 . 2013-07-26 23:58 -------- d-----w- c:\users\Default\AppData\Local\temp
    2013-07-20 13:25 . 2013-07-20 13:25 -------- d-----w- c:\program files (x86)\ERUNT
    2013-07-19 07:18 . 2013-07-19 07:18 -------- d-----w- c:\windows\9E23819E8AF44D25A7FE7756C9E3DBB9.TMP
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-06-24 08:26 . 2010-01-30 23:11 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
    2013-06-24 08:26 . 2010-05-19 20:22 2876528 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
    2013-06-24 08:25 . 2010-05-19 20:19 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
    2013-06-24 08:25 . 2010-02-27 20:28 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2013-06-12 16:50 . 2012-04-15 13:25 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2013-06-12 16:50 . 2011-05-14 02:58 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2013-06-12 16:50 . 2013-06-12 16:50 9089416 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
    2013-06-08 02:21 . 2012-02-25 15:29 107368 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
    2013-06-08 02:21 . 2012-02-25 15:29 35656 ----a-w- c:\windows\system32\LMIport.dll
    2013-06-08 02:21 . 2012-02-25 15:29 100680 ----a-w- c:\windows\system32\LMIinit.dll
    2013-06-01 02:21 . 2012-02-25 15:29 107368 ----a-w- c:\windows\system32\LMIRfsClientNP.dll.001.bak
    2013-05-16 00:13 . 2010-01-30 21:55 75016696 ----a-w- c:\windows\system32\MRT.exe
    2013-05-05 21:36 . 2013-05-29 02:31 17818624 ----a-w- c:\windows\system32\mshtml.dll
    2013-05-05 21:16 . 2013-05-29 02:31 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2013-05-05 19:12 . 2013-05-29 02:31 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2012-07-02 2736128]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Monitor"="c:\program files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe" [2011-06-06 251744]
    "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-27 336384]
    "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2011-03-30 87336]
    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-03-13 1532992]
    "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-02 190808]
    "LGODDFU"="c:\program files (x86)\lg_fwupdate\lgfw.exe" [2012-07-20 27760]
    "KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2011-07-12 1764352]
    "CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2009-12-15 103720]
    "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-09-28 75048]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    R2 CLKMSVC10_38F51D56;CyberLink Product - 2012/07/15 19:54;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [x]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys [x]
    R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
    R3 LVUVC64;Logitech Webcam Pro 9000(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys;c:\windows\SYSNATIVE\drivers\mferkdet.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys [x]
    S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSr64.exe;c:\windows\SYSNATIVE\AERTSr64.exe [x]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
    S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]
    S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [x]
    S2 LVPrcS64;Process Monitor;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe [x]
    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe [x]
    S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
    S3 AE3000;Linksys AE3000 Driver;c:\windows\system32\DRIVERS\AE3000w764.sys;c:\windows\SYSNATIVE\DRIVERS\AE3000w764.sys [x]
    S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
    S3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service;c:\windows\system32\DRIVERS\AVerBDA716x_x64.sys;c:\windows\SYSNATIVE\DRIVERS\AVerBDA716x_x64.sys [x]
    S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
    S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - CLKMDRV10_38F51D56
    *Deregistered* - mfeavfk01
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2012-07-02 21:40 453736 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-07-13 04:30 1173456 ----a-w- c:\program files (x86)\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2013-07-26 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 16:50]
    .
    2013-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-13 00:59]
    .
    2013-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-11-13 00:59]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="RAVCpl64.exe" [2008-09-02 6475808]
    "LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2011-09-16 57928]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = about:blank
    mLocal Page = c:\windows\SysWOW64\blank.htm
    TCP: DhcpNameServer = 208.67.222.123 208.67.220.123 68.94.156.1
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-Skytel - Skytel.exe
    AddRemove-{F46BF5EA-0B4E-4A41-8C4B-3B127346E30F} - c:\users\Home\AppData\Local\{2853BFD5-3865-45EB-A4E3-967D4A9B969A}\NBCDirectInstaller.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_224_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_224.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2013-07-26 19:00:19
    ComboFix-quarantined-files.txt 2013-07-27 00:00
    .
    Pre-Run: 259,635,040,256 bytes free
    Post-Run: 261,951,897,600 bytes free
    .
    - - End Of File - - 39AEEA51254692B081360685AF83BC1C
    A36C5E4F47E84449FF07ED3517B43A31

    rkill:

    Rkill 2.5.7 by Lawrence Abrams (Grinler)
    http://www.bleepingcomputer.com/
    Copyright 2008-2013 BleepingComputer.com
    More Information about Rkill can be found at this link:
    http://www.bleepingcomputer.com/forums/topic308364.html

    Program started at: 07/26/2013 06:49:20 PM in x64 mode.
    Windows Version: Windows 7 Home Premium Service Pack 1

    Checking for Windows services to stop:

    * No malware services found to stop.

    Checking for processes to terminate:

    * No malware processes found to kill.

    Checking Registry for malware related settings:

    * No issues found in the Registry.

    Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

    Performing miscellaneous checks:

    * Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware" = dword:00000001

    Checking Windows Service Integrity:

    * Windows Defender (WinDefend) is not Running.
    Startup Type set to: Manual

    Searching for Missing Digital Signatures:

    * No issues found.

    Checking HOSTS File:

    * No issues found.

    Program finished at: 07/26/2013 06:50:53 PM
    Execution time: 0 hours(s), 1 minute(s), and 33 seconds(s)

    Thanks!

  10. #10
    Malware Team-Emeritus
    Join Date
    Sep 2012
    Location
    Florida, USA
    Posts
    1,161

    Default

    Hi grhull,

    Any improvement in the performance of the computer?

    =========================

    1. Windows Automatic Updates
    • Open Windows Update by clicking the Start button , clicking All Programs, and then clicking Windows Update.
    • In the left pane, click Change settings.
    • Choose the option that you want.
    • Under Recommended updates, select the Include recommended updates when downloading, installing, or notifying me about updates check box, and then click OK. Administrator permission required If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

    =========================

    2. Windows Update
    • Open Windows Update by clicking the Start button . In the search box, type Update, and then, in the list of results, click Windows Update.
    • In the left pane, click Check for updates, and then wait while Windows looks for the latest updates for your computer.
    • If you see a message telling you that important updates are available, or telling you to review important updates, click the message to view and select the important updates to install.
    • In the list, click the important updates for more information. Select the check boxes for any updates that you want to install, and then click OK.
    • Click Install updates.
    • Read and accept the license terms, and then click Finish if the update requires it. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.

    =========================

    3. Reboot

    =========================

    4. Delete the copy of OTL you previously downloaded

    =========================

    5. Farbar Recovery Scan Tool

    Download Farbar Recovery Scan Tool and save it to your desktop.

    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply

    =========================

    In your next post please provide the following:

    • FRST.txt
    • Addition.txt
    OCD
    ----------
    Graduate of WTT Classroom
    Member of UNITE

    Threads will be closed if no response after 5 days

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •