| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
10-Jan-2009, 07:48 PM
#61 | |||||
| Please remove the version of ComboFix you have by dragging it from your desktop to the recycle bin and then grab the latest version, do a new scan and post the resulting log please. Please visit Combofix Guide & Instructions for instructions for downloading and running ComboFix. The only thing different from the instructions there is that when downloading and saving the ComboFix.exe I would like you to rename it to Combo-Fix.exe please. Post the log from ComboFix when you've accomplished that along with a new HijackThis log.
__________________ Microsoft MVP - Consumer Security |
| |
|
10-Jan-2009, 08:42 PM
#62 |
| combofix problem I am following your instructions from above. combofix has completed stage 50. in the blue box, i have the following message: '"C:\WINDOWS\system32\"' is not recognized as an internal or external command, operable program or batch file. ----------------------------------- OK, an hour went by and I got antsy. I hit the enter key, and the machine rebooted. My desktop returned, I did recieve this error microsoft visual c++ runtime library Roxwatchtray.exe Runtime error - asked to terminate in an unusual way Then I had to say ''ok'' to a selective startup, and then got THE ERROR. Here is the combofix log: ComboFix 09-01-10.01 - Helene 2009-01-10 19:15:33.5 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.257 [GMT -5:00] Running from: c:\documents and settings\Helene\Desktop\ComboFix\Combo-Fix.exe Command switches used :: c:\documents and settings\Helene\Desktop\ComboFix\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) FW: AOL Firewall *enabled* FW: McAfee Personal Firewall *disabled* . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\java2.sys c:\windows\system32\snjava.dll c:\windows\system32\mfcans32.DLL c:\windows\system32\mfcuia32.dll c:\windows\system32\msexcl35.dll c:\windows\system32\msltus35.dll c:\windows\system32\mspdox35.dll c:\windows\system32\msrdo20.dll c:\windows\system32\mstext35.dll c:\windows\system32\msxbse35.dll c:\windows\system32\rdocurs.dll . ((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 ))))))))))))))))))))))))))))))) . 2009-01-10 07:55 . 2009-01-10 07:55 <DIR> d-------- c:\documents and settings\Robbie\Application Data\Malwarebytes 2009-01-10 07:34 . 2009-01-10 07:34 <DIR> d-------- c:\documents and settings\Joanie\Application Data\Malwarebytes 2009-01-10 00:10 . 2009-01-10 00:10 <DIR> d-------- c:\documents and settings\Becca\Application Data\Malwarebytes 2009-01-08 01:51 . 2009-01-08 01:51 <DIR> d-------- c:\documents and settings\Robbie\Application Data\Viewpoint 2009-01-08 01:47 . 2009-01-08 01:47 <DIR> d-------- c:\documents and settings\Robbie\Application Data\McAfee 2009-01-08 01:41 . 2009-01-08 01:41 <DIR> d-------- c:\documents and settings\Joanie\Application Data\McAfee 2009-01-08 01:32 . 2009-01-08 01:32 <DIR> d-------- c:\documents and settings\Becca\Application Data\McAfee 2009-01-04 20:12 . 2009-01-04 20:12 <DIR> d-------- c:\program files\Viewpoint 2009-01-04 17:31 . 2009-01-04 17:30 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll 2009-01-04 17:31 . 2009-01-04 17:30 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl 2009-01-04 16:55 . 2009-01-04 16:55 <DIR> d-------- c:\program files\Windows Installer Clean Up 2009-01-04 16:55 . 2009-01-04 16:55 <DIR> d-------- c:\program files\MSECACHE 2009-01-01 11:09 . 2009-01-01 11:09 <DIR> d-------- c:\program files\McAfee DesktopDoctor 2008-12-28 22:36 . 2008-12-28 22:36 <DIR> d-------- c:\documents and settings\LocalService\Application Data\McAfee 2008-12-28 21:53 . 2008-12-28 21:54 <DIR> d-------- c:\program files\ATFCleaner 2008-12-28 21:50 . 2008-12-29 07:47 <DIR> d-------- c:\program files\Trend Micro 2008-12-28 12:38 . 2009-01-10 00:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware 2008-12-28 12:38 . 2008-12-28 12:38 <DIR> d-------- c:\documents and settings\Helene\Application Data\Malwarebytes 2008-12-28 12:38 . 2008-12-28 12:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2008-12-28 12:38 . 2009-01-04 18:38 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys 2008-12-28 12:38 . 2009-01-04 18:38 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys 2008-12-22 21:09 . 2008-12-22 21:09 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy) 2008-12-22 21:09 . 2008-12-22 21:09 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy) 2008-12-22 19:57 . 2008-12-22 19:57 <DIR> d-------- c:\documents and settings\Helene\Application Data\McAfee . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-01-11 01:00 --------- d-----w c:\documents and settings\Helene\Application Data\Skype 2009-01-10 21:00 --------- d-----w c:\documents and settings\Helene\Application Data\skypePM 2009-01-10 13:35 --------- d-----w c:\program files\Greetings Workshop 2009-01-10 12:52 --------- d--h--w c:\documents and settings\Robbie\Application Data\GTek 2009-01-10 12:26 --------- d--h--w c:\documents and settings\Joanie\Application Data\Gtek 2009-01-05 13:36 --------- d-----w c:\program files\Canon 2009-01-05 13:15 --------- d-----w c:\documents and settings\Helene\Application Data\MSN6 2009-01-05 02:09 --------- d-----w c:\documents and settings\All Users\Application Data\AOL 2009-01-05 01:31 --------- d-----w c:\program files\Common Files\AOL 2009-01-04 22:30 --------- d-----w c:\program files\Java 2009-01-02 21:58 --------- d-----w c:\program files\Upromise_RemindU 2009-01-01 15:41 --------- d-----w c:\program files\iTunes 2009-01-01 15:17 --------- d-----w c:\program files\ICopyDVDs2 2008-12-29 19:57 195,168 ----a-w c:\documents and settings\Helene\Application Data\GDIPFONTCACHEV1.DAT 2008-12-29 15:43 --------- d-----w c:\program files\Dell Computer 2008-12-29 03:37 --------- d-----w c:\program files\Spybot - Search & Destroy 2008-12-29 03:04 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2008-12-23 20:28 --------- d-----w c:\documents and settings\Helene\Application Data\Nero 2008-12-23 00:56 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee 2008-12-05 22:20 --------- d--h--w c:\documents and settings\Helene\Application Data\Move Networks 2008-11-18 00:48 --------- d-----w c:\documents and settings\Helene\Application Data\LimeWire 2008-08-26 17:04 56,912 ----a-w c:\documents and settings\Helene\g2mdlhlpx.exe 2008-03-14 01:38 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat 2008-02-25 04:18 61,480 ----a-w c:\documents and settings\Helene\GoToAssistDownloadHelper.exe 2006-01-23 13:50 134,944 ----a-w c:\documents and settings\Robbie\Application Data\GDIPFONTCACHEV1.DAT 2003-11-02 09:50 130,832 ------w c:\documents and settings\Becca\Application Data\GDIPFONTCACHEV1.DAT 2003-08-21 21:00 130,832 ------w c:\documents and settings\Joanie\Application Data\GDIPFONTCACHEV1.DAT 2000-12-12 15:17 100,432 ------w c:\program files\Win2000PPAHotfix.exe 2008-12-20 20:08 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll 2008-12-20 20:08 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll 2008-12-20 20:08 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll 2008-12-20 20:08 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll 2008-12-20 20:08 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((( snapshot@2008-12-29_20.43.19.37 ))))))))))))))))))))))))))))))))))))))))) . + 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE - 2006-05-19 15:52:16 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\ARPPRODUCTICON.exe + 2009-01-10 12:17:13 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\ARPPRODUCTICON.exe - 2006-05-19 15:52:12 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\Contribute.exe + 2009-01-10 12:17:13 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\Contribute.exe - 2006-05-19 15:52:12 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.exe + 2009-01-10 12:17:13 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.exe - 2006-05-19 15:52:17 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_B673A475445E47568AB1AE72FDC5B639.exe + 2009-01-10 12:17:14 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut1_B673A475445E47568AB1AE72FDC5B639.exe - 2006-05-19 15:52:17 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut11_2388ED126A5243258E7B1A229914C1AE.exe + 2009-01-10 12:17:14 65,536 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut11_2388ED126A5243258E7B1A229914C1AE.exe - 2006-05-19 15:52:15 4,133,376 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut2_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.bat + 2009-01-10 12:17:13 4,133,376 ----a-r c:\windows\Installer\{4B9535BF-CC90-4158-AF32-CAF57A8820CA}\NewShortcut2_1.D404042C_B1B4_413E_B1C0_526D0BBE80E3.bat - 2008-12-29 22:58:23 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT + 2009-01-10 21:16:31 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT - 2008-12-29 22:58:23 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT + 2009-01-10 21:16:31 32,768 ----a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT - 2006-04-01 15:36:47 172,704 ----a-w c:\windows\SYSTEM32\GDIPFONTCACHEV1.DAT + 2009-01-08 06:48:17 195,104 ----a-w c:\windows\SYSTEM32\GDIPFONTCACHEV1.DAT - 2008-06-10 05:21:01 135,168 ----a-w c:\windows\SYSTEM32\java.exe + 2009-01-04 22:30:50 144,792 ----a-w c:\windows\SYSTEM32\java.exe - 2008-06-10 05:21:04 135,168 ----a-w c:\windows\SYSTEM32\javaw.exe + 2009-01-04 22:30:51 144,792 ----a-w c:\windows\SYSTEM32\javaw.exe - 2008-06-10 06:32:34 139,264 ----a-w c:\windows\SYSTEM32\javaws.exe + 2009-01-04 22:30:51 148,888 ----a-w c:\windows\SYSTEM32\javaws.exe + 2009-01-11 01:22:24 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_210.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-09-24 290816] "tgcmd"="c:\program files\support.com\bin\tgcmd.exe" [2002-04-24 1544192] "Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 28738] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe" [2005-11-22 163840] "RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe" [2005-11-21 1687552] "AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992] "MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480] "MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2005-09-26 169984] "ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\SYSTEM32\Ati2mdxx.exe] c:\documents and settings\Robbie\Start Menu\Programs\Startup\ Greetings Workshop Reminders.lnk - c:\program files\Greetings Workshop\GWREMIND.EXE [1996-06-25 40448] Quicken Scheduled Updates.lnk - c:\documents and settings\All Users\Documents\2448\bagent.exe [2004-07-16 57344] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-16 113664] D-Link AirPlus G Wireless Utility.lnk - c:\program files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe [2005-12-15 774220] D-Link REG Utility.lnk - c:\program files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe [2005-12-15 24576] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664] HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360] MySoftware InterCom.lnk - c:\program files\Common Files\MySoftware\InterCom.exe [2003-02-28 260608] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry] -ra------ 2002-08-14 19:22 28672 c:\windows\SYSTEM32\DSentry.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] --a------ 2005-01-16 11:44 26112 c:\program files\Real\RealPlayer\realplay.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2009-01-04 17:30 136600 c:\program files\Java\jre6\bin\jusched.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" -quiet [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Documents and Settings\\All Users\\Documents\\2448\\qw.exe"= "c:\\Program Files\\PowerDVD\\CLDMA.EXE"= "c:\\Program Files\\HP\\Digital Imaging\\Diagnostics\\HPSysDig.exe"= "c:\\TAX98\\32BIT\\TTXMPC98.EXE"= "c:\\Program Files\\FTP Explorer\\ftpx.exe"= "c:\\WINDOWS\\SYSTEM32\\ntvdm.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"= "c:\\Program Files\\support.com\\bin\\tgcmd.exe"= "c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"= "c:\\Program Files\\America Online 9.0c\\waol.exe"= "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"= "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"= "c:\\Program Files\\Common Files\\AOL\\1132598226\\ee\\AOLServiceHost.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"= "c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"= "c:\\Program Files\\Roxio\\Easy Media Creator 8\\Audio Master\\MusicDiscCreator.exe"= "c:\\Program Files\\Common Files\\Roxio Shared\\SharedCom\\RoxUpnpRenderer.exe"= "c:\\Program Files\\Common Files\\AOL\\1132598226\\ee\\aolsoftware.exe"= "c:\\Program Files\\AIM95\\aim.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List] "1700:TCP"= 1700:TCP:MioNet Remote Drive Access "1641:TCP"= 1641:TCP:MioNet Remote Drive Verification R4 ColdFusion MX 7 ODBC Agent;ColdFusion MX 7 ODBC Agent;c:\cfusionmx7\db\slserver54\bin\swagent.exe "ColdFusion MX 7 ODBC Agent" --> c:\cfusionmx7\db\slserver54\bin\swagent.exe ColdFusion MX 7 ODBC Agent [?] R4 ColdFusion MX 7 ODBC Server;ColdFusion MX 7 ODBC Server;c:\cfusionmx7\db\slserver54\bin\swstrtr.exe "ColdFusion MX 7 ODBC Server" --> c:\cfusionmx7\db\slserver54\bin\swstrtr.exe ColdFusion MX 7 ODBC Server [?] S3 hpusbwdm;HP DVD Movie Writer dc3000/dc4000;c:\windows\SYSTEM32\DRIVERS\hpusbwdm.sys [2003-12-30 1080832] S3 Wdm1;USB Bridge Cable Driver;c:\windows\SYSTEM32\DRIVERS\usbbc.sys [2003-02-27 15576] S4 ColdFusion MX 7 Application Server;ColdFusion MX 7 Application Server;c:\cfusionmx7\runtime\bin\jrunsvc.exe [2006-04-15 61440] . Contents of the 'Scheduled Tasks' folder 2009-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57] 2003-07-03 c:\windows\Tasks\ISP signup reminder 1.job - c:\windows\System32\OOBE\OOBEBALN.EXE [2004-08-04 02:56] 2009-01-11 c:\windows\Tasks\jselxtca.job - c:\windows\system32\rundll32.exe [2004-08-04 02:56] 2008-02-25 c:\windows\Tasks\McAfee Cleanup.job - c:\docume~1\Helene\LOCALS~1\Temp\MCPR.tmp\mccleanup.exe [] 2008-12-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32] 2008-12-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32] 2003-06-28 c:\windows\Tasks\Symantec NetDetect.job - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 09:04] . . ------- Supplementary Scan ------- . uStart Page = hxxp://registration.aol.com/mail?s_url=http%3a%2f%2fwebmail.aol.com%2f_cqr%2fLoginSuccess.aspx%3fsitedo main%3dsns.webmail.aol.com%26siteState%3dver%253a1%25252c0%2526ld%253awebma il.aol.com%2526pv%253aAOL%2526lc%253aen-us%2526ud%253aaol.com%2526br%253aWebSuite-CurrentProd mWindow Title = Microsoft Internet Explorer provided by Comcast uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000 IE: RemindU - file://c:\program files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm Trusted Zone: *.internet Trusted Zone: *.mcafee.com O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd O16 -: {FFFFFFFF-CAFE-BABE-BABE-01AA0055595A} - hxxp://www.truesuite.com/trueclean/TrueCleanInstall.exe FF - ProfilePath - c:\documents and settings\Helene\Application Data\Mozilla\Firefox\Profiles\e3w25nyj.default\ FF - prefs.js: browser.startup.homepage - hxxps://my.screenname.aol.com/_cqr/login/login.psp?mcState=initialized&seamless=novl&sitedomain=sns.webmail.aol.com& lang=en&locale=us&authLev=2&siteState=ver%3a2%7cac%3aWS%7cat%3aSNS%7cld%3aw ebmail.aol.com%7cuv%3aAOL%7clc%3aen-us FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll ---- FIREFOX POLICIES ---- FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-01-10 20:27:17 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-2257554901-1753557314-821268821-1007\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . ------------------------ Other Running Processes ------------------------ . c:\windows\SYSTEM32\acs.exe c:\program files\Common Files\AOL\ACS\AOLacsd.exe c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\SYSTEM32\ati2evxx.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe c:\windows\SYSTEM32\DRIVERS\CDAC11BA.EXE c:\cfusionmx7\db\slserver54\bin\swagent.exe c:\cfusionmx7\db\slserver54\bin\swstrtr.exe c:\cfusionmx7\db\slserver54\bin\swsoc.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\McAfee\MBK\MBackMonitor.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe c:\program files\Photodex\ProShowProducer\scsiaccess.exe c:\progra~1\McAfee.com\Agent\mcagent.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\windows\wanmpsvc.exe c:\program files\Common Files\AOL\1132598226\ee\aolsoftware.exe c:\program files\HP\Digital Imaging\bin\hpqgalry.exe c:\program files\iPod\bin\iPodService.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\program files\McAfee\MPF\MpfSrv.exe c:\program files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe c:\progra~1\McAfee\MSC\mcuimgr.exe . ************************************************************************** . Completion time: 2009-01-10 20:37:49 - machine was rebooted ComboFix-quarantined-files.txt 2009-01-11 01:36:53 ComboFix2.txt 2009-01-01 00:10:48 ComboFix3.txt 2008-12-31 04:02:22 ComboFix4.txt 2008-12-31 01:37:41 ComboFix5.txt 2009-01-11 00:13:35 Pre-Run: 31,840,944,128 bytes free Post-Run: 31,926,620,160 bytes free 306 --- E O F --- 2009-01-05 18:17:20 Last edited by heleneh; 10-Jan-2009 at 09:50 PM.. |
|
10-Jan-2009, 09:51 PM
#63 |
| and here is the hijackthis log HIjackthis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:47:50 PM, on 1/10/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\acs.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\System32\Ati2evxx.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\CFusionMX7\db\slserver54\bin\swagent.exe C:\CFusionMX7\db\slserver54\bin\swstrtr.exe C:\CFusionMX7\db\slserver54\bin\swsoc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\McAfee\MBK\MBackMonitor.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\support.com\bin\tgcmd.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe C:\Program Files\Common Files\AOL\1132598226\ee\aolsoftware.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\MySoftware\InterCom.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe c:\PROGRA~1\mcafee\msc\mcuimgr.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://registration.aol.com/mail?s_u...te-CurrentProd R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe" O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe" O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ? O4 - Global Startup: D-Link REG Utility.lnk = ? O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: MySoftware InterCom.lnk = C:\Program Files\Common Files\MySoftware\InterCom.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: RemindU - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing) O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing) O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.mcafee.com O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol.com/help/acp2/en...ach_core_1.cab O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/...oUploader3.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/...ploader4_5.cab O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://trueswitch.com/TrueInstall.exe O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-01AA0055595A} - http://www.truesuite.com/trueclean/TrueCleanInstall.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: ColdFusion MX 7 Application Server - Macromedia Inc. - C:\CFusionMX7\runtime\bin\jrunsvc.exe O23 - Service: ColdFusion MX 7 ODBC Agent - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swagent.exe O23 - Service: ColdFusion MX 7 ODBC Server - Unknown owner - C:\CFusionMX7\db\slserver54\bin\swstrtr.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe -- End of file - 13140 bytes thanks Helene |
12-Jan-2009, 04:51 PM
#64 | |||||
| Go to Control Panel - Add/Remove programs and remove any of these you see there: Viewpoint Viewpoint Manager Viewpoint Media Player Then delete these folders: c:\documents and settings\Robbie\Application Data\Viewpoint c:\program files\Viewpoint What can you tell me about this program? It may be known as WebSniffer, possibly belonging to McAfee: c:\program files\Common Files\MySoftware\InterCom.exe Do you have MioNet which is used for remote access? This is a scheduled task. Can you tell me what it does? c:\windows\Tasks\jselxtca.job You have McAfee but there is a scheduled task to run LiveUpdate for Symantec. Did you remove Symantec in favour of McAfee? If so, please delete this Scheduled Task: c:\windows\Tasks\Symantec NetDetect.job See if LiveUpdate (Symantec) is listing in the Add/Remove programs and if so remove it from there. Then if you no longer have any Symantec products, delete this folder: - c:\program files\Symantec Now please do this: Download GMER from: http://gmer.net/index.php Save it on your desktop and unzip it. Double click the gmer.exe to run it and select the rootkit tab and press scan. When the scan is done, click Copy. This will copy the report to the clipboard. Paste it into Notepad and save it and also paste the log report back here please.
__________________ Microsoft MVP - Consumer Security |
|
12-Jan-2009, 07:38 PM
#65 |
| 1) Go to Control Panel - Add/Remove programs and remove any of these you see there: Viewpoint Viewpoint Manager Viewpoint Media Player - removed 2) Then delete these folders: c:\documents and settings\Robbie\Application Data\Viewpoint -deleted c:\program files\Viewpoint -not found 3) What can you tell me about this program? It may be known as WebSniffer, possibly belonging to McAfee: c:\program files\Common Files\MySoftware\InterCom.exe This was bundled with a label printing software - I have always been suspicious of it, what I learned from googling it is that it it is used to check for updates to the software - totally unnecessary 4) Do you have MioNet which is used for remote access? no, not that I am aware 5) This is a scheduled task. Can you tell me what it does? c:\windows\Tasks\jselxtca.job (I have never noticed it running) From the properties tab: Run exe "C:\WINDOWS\system32\khfEWPGw.dll",ShellPath Run as : DBZGB421\Helene 6) You have McAfee but there is a scheduled task to run LiveUpdate for Symantec. Did you remove Symantec in favour of McAfee? probably, long ago. If so, please delete this Scheduled Task: c:\windows\Tasks\Symantec NetDetect.job - deleted See if LiveUpdate (Symantec) is listing in the Add/Remove programs and if so remove it from there. - not found Then if you no longer have any Symantec products, delete this folder: - c:\program files\Symantec -deleted 7) gmer log attached thanks again Helene |
12-Jan-2009, 08:46 PM
#66 | |||||
| Delete both of these files: c:\windows\Tasks\jselxtca.job C:\WINDOWS\system32\khfEWPGw.dll MioNet appears to be legit and would be likely from Western Digital for backups. How are things now? |
|
12-Jan-2009, 09:01 PM
#67 |
| Delete both of these files: c:\windows\Tasks\jselxtca.job deleted C:\WINDOWS\system32\khfEWPGw.dll not found MioNet appears to be legit and would be likely from Western Digital for backups. I went to the mionet website, and if it is related to the module you are seeing (i see no reference to it, didn't even know I had it), I'd just as soon get rid of it How are things now? i ran msconfig in the ''general tab'', selective start up is selected I went to the startup tab i unchecked 2 items i hit ''apply'' i am still getting the access denied error! I did a little poking around on the internet, and the hp software seems to be implicated in the access denied error, as you mentioned days ago. do you think that is worth chasing down? thanks again Helene |
|
13-Jan-2009, 03:07 PM
#69 |
| I did not see your post above, I saw the following email: Yes, is it possible any of your HP hardware updated itself or drivers recently? Lets try this: Go to *Start *– *Run *- type *msconfig* – click OK and click on the *startup tab*. Uncheck everything there except for your anti-virus program. Then reboot Let me know if the problem persists after doing that. Well, there are definitley fewer processes running than normal! And I run msconfig, and everything is still unchecked. So, it may be working! So am I running in selective mode from now on, not normal? Will this startup definition apply to all accounts? Next, I'd like to identify the services that don't have to run unless specifically invoked by user. the machine is running much faster! thank Helene |
|
13-Jan-2009, 08:28 PM
#71 |
| Sorry, I was not clear. Per your instructions in post #69, i ran msconfig in the ''general tab'', selective start up is selected I went to the startup tab i unchecked all but mcafee stuff i hit ''apply'' i got the access denied error i hit ''ok'' i got the access denied error Then I rebooted All of the items are still unchecked in the startup tab and there are many fewer processes running. so it appears to be working, and that the error is not a true error? Helene |
14-Jan-2009, 06:37 PM
#72 | |||||
| This sounds more like the HP problem as those users were able to uncheck items in msconfig even though they got that error. I'm posting a link with instructions to change the startup of one of the HP services. Let me know if you understand it and think you can make the changes in the registry. You can back up your registry first in case you make a mistake by doing the following: Please go to Start - Run and copy and paste the following and then click OK: regedit /e c:\registrybackup2.reg It won't appear to be doing anything and that's normal. Your mouse pointer may turn to an hour glass for a minute. When it no longer has the hour glass, check in your C drive to be sure you have a file called registrybackup2.reg before continuing. If you do not see that file, please let me know before doing anything else. http://www.ehow.com/how_4531999_fix-...ror-using.html
__________________ Microsoft MVP - Consumer Security |
|
14-Jan-2009, 08:26 PM
#73 |
| Per your instructions, I backed up the registry. I changed the key according to instructions - the only difference being that the value in the key was '4', and I changed it to '3' (the instructions assumed the key value would be changed from '2' to '3') I rebooted I ran msconfig, checked an item in the startup tab, clicked ''apply'', and unfortunately, am still getting the access denied error. But, man, does it boot fast now! Helene |
|
18-Jan-2009, 08:48 PM
#75 |
| CookieGal, I am unable to find the printer software to re-install the software, and working with HP is a long arduous process. Since I was able, for now, to update msconfig/startup, I'm going to set that problem aside for now. At this point, I would love help with a couple of things: 1) reducing the number of services running, including AOL that I thought I had removed 2) Getting rid of McAfee in favor of something less resource intensive - I see that in other posts, AVAST, COMODO FIrewall, and Malwarebytes are recommended. Would you concur with that? 3) Any other recommendations you might have Again, thanks for everything Helene |
| Tags |
| malware, trojan |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 10:20 PM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

