| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
28-Sep-2009, 11:47 PM
#1 |
| Computer Boots, but Explorer Won't Start Hi! I am running Vista on a Dell Inspiron that I bought last October. Since I bought it, I have had issues with starting Explorer. My log-in screen loads and I'm able to sign in to my account; then, "My Documents" opens and nothing else happens. When I pull up Task Manager, the processes running are basic Dell and Windows processes, as well as McAfee and Ad-Aware. I have to go to "Start New Task" and type in "Explorer" to get my desktop to load. After that, everything works great. So far, I've spoken to Dell Online Support, and they told me I have a virus. I have ran McAfee, Ad-Aware, and Tune-Up Utilities scans, as well as Startup Repair and diagnostics from the startup screen. Here's my HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:45:07 PM, on 9/28/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18294) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Windows\explorer.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\Explorer.exe C:\Windows\system32\Rundll32.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myaccountinglab.mathxl.com/login_acct.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\csrss.exe O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 8505 bytes Thanks for your time! |
| |
|
30-Sep-2009, 04:00 AM
#2 |
| Hello emsiizilla, Please download Win32kDiag.exe to your Desktop. Double-click to run it. A log should appear when it is finished. Copy and paste back here. |
|
01-Oct-2009, 06:35 PM
#3 |
| Hey emeraldnzl, First of all, thanks for responding to my thread. Second, I ran the program and got an error message; the log read like this: Running from: C:\Users\emsii\Downloads\Win32kDiag(2).exe Log file at : C:\Users\emsii\Desktop\Win32kDiag.txt WARNING: Could not get backup privileges! Searching 'C:\Windows'... Cannot access: C:\Windows\CSC\v2.0.6\pq ERROR OCCURRED! ------------------------------ Windows Version: Windows Vista SP1 Exception Code: 0xc0000005 Exception Address: 0x00272415 Attempt to write to address: 0x00000000 |
|
01-Oct-2009, 07:04 PM
#4 |
| Hello emsiizilla, Moving on then Please download ExeHelper by Raktor
__________________ Manners are the basis of a civilised society and make everyone's lives just a little happier. They cost nothing but they are worth so much. |
|
01-Oct-2009, 10:30 PM
#5 |
| Here's the log: exeHelper by Raktor - 09 Build 20090925 Run at 20:28:27 on 10/01/09 Now searching... Checking for numerical processes... Checking for bad processes... Checking for bad files... Checking for bad registry entries... Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values... Resetting policies... --Finished-- Thanks! |
|
02-Oct-2009, 02:23 AM
#6 |
| Let's see if you can do this now then: Download Combofix from either of the links below. You must rename it before saving it. Save it to your desktop. Link 1 Link 2 ![]() ![]() -------------------------------------------------------------------- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Double click on Combo-Fix.exe & follow the prompts.
__________________ Manners are the basis of a civilised society and make everyone's lives just a little happier. They cost nothing but they are worth so much. |
|
02-Oct-2009, 09:28 PM
#7 |
| While running, Combo-Fix deleted my background and restarted my desktop. Then, when I tried to use anything on my computer it told me that the items I clicked on had been sorted for deletion. After restarting, Explorer started on its own; my background is still gone, but everything else is working again. I'm just telling you this, in case something was different than it should have been. Here's the log: ComboFix 09-10-01.05 - emsii 10/02/2009 18:26.1.1 - NTFSx86 Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2037.858 [GMT -5:00] Running from: c:\users\emsii\Desktop\Combo-Fix.exe SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-1188092344-3365634342-1950963333-500 c:\$recycle.bin\S-1-5-21-3261150311-2334348272-2852962061-500 c:\windows\system32\oem7.inf . ((((((((((((((((((((((((( Files Created from 2009-09-02 to 2009-10-02 ))))))))))))))))))))))))))))))) . 2009-10-02 23:46 . 2009-10-02 23:47 -------- d-----w- c:\users\emsii\AppData\Local\temp 2009-10-02 23:46 . 2009-10-02 23:46 -------- d-----w- c:\users\Default\AppData\Local\temp 2009-09-29 02:41 . 2009-09-29 02:41 -------- d-----w- c:\program files\Trend Micro 2009-09-17 20:41 . 2009-09-17 20:41 -------- d-----w- c:\programdata\Last.fm 2009-09-17 20:31 . 2009-09-17 20:32 -------- d-----w- c:\program files\Last.fm 2009-09-09 21:57 . 2009-08-14 17:07 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys 2009-09-09 21:57 . 2009-08-14 16:29 104960 ----a-w- c:\windows\system32\netiohlp.dll 2009-09-09 21:57 . 2009-08-14 14:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE 2009-09-09 21:57 . 2009-08-14 14:16 19968 ----a-w- c:\windows\system32\ARP.EXE 2009-09-09 21:57 . 2009-08-14 14:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE 2009-09-09 21:57 . 2009-08-14 14:16 10240 ----a-w- c:\windows\system32\finger.exe 2009-09-09 21:57 . 2009-08-14 14:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE 2009-09-09 21:57 . 2009-08-14 14:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE 2009-09-09 21:57 . 2009-08-14 14:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE 2009-09-09 21:57 . 2009-08-14 16:29 17920 ----a-w- c:\windows\system32\netevent.dll 2009-09-09 21:55 . 2009-07-11 19:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll 2009-09-09 21:55 . 2009-07-11 19:32 302592 ----a-w- c:\windows\system32\wlansec.dll 2009-09-09 21:55 . 2009-07-11 19:29 127488 ----a-w- c:\windows\system32\L2SecHC.dll 2009-09-09 21:55 . 2009-07-11 19:32 513024 ----a-w- c:\windows\system32\wlansvc.dll 2009-09-09 21:55 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll 2009-09-05 14:40 . 2009-09-30 03:16 -------- d-----w- c:\users\emsii\AppData\Roaming\vlc 2009-09-05 14:10 . 2009-09-05 14:10 -------- d-----w- c:\windows\system32\Adobe 2009-09-04 02:45 . 2009-09-19 04:04 -------- d-----w- C:\OutputFolder 2009-09-02 23:51 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2009-09-02 23:51 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-01 21:38 . 2009-07-14 14:51 -------- d-----w- c:\users\emsii\AppData\Roaming\uTorrent 2009-09-25 18:51 . 2008-10-19 14:41 4252 ----a-w- c:\users\emsii\AppData\Roaming\wklnhst.dat 2009-09-20 12:39 . 2008-10-14 06:05 680 ----a-w- c:\users\emsii\AppData\Local\d3d9caps.dat 2009-09-17 20:41 . 2008-10-11 01:24 -------- d-----w- c:\program files\iTunes 2009-09-14 00:18 . 2008-11-02 16:55 -------- d-----w- c:\programdata\Electronic Arts 2009-09-10 08:26 . 2009-04-12 17:22 -------- d-----w- c:\program files\Microsoft Silverlight 2009-09-10 08:09 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-09-10 08:07 . 2008-10-23 01:37 -------- d-----w- c:\programdata\Microsoft Help 2009-09-02 02:19 . 2009-05-19 20:35 -------- d-----w- c:\program files\Common Files\AVSMedia 2009-08-30 14:57 . 2008-10-05 17:58 -------- d-----w- c:\program files\Java 2009-08-30 14:32 . 2009-08-30 14:32 -------- d-----w- c:\program files\iPod 2009-08-30 14:32 . 2008-10-11 01:19 -------- d-----w- c:\program files\Common Files\Apple 2009-08-30 14:29 . 2008-10-11 01:23 -------- d-----w- c:\program files\Bonjour 2009-08-30 14:20 . 2008-10-11 01:25 -------- d-----w- c:\users\emsii\AppData\Roaming\Apple Computer 2009-08-22 03:05 . 2009-08-22 03:05 -------- d-----w- c:\program files\VideoLAN 2009-08-16 18:42 . 2009-08-16 18:42 999801 ----a-w- c:\windows\XOU Clock.exe 2009-08-16 18:42 . 2009-08-16 18:42 18192 ----a-w- c:\windows\XOU Clock.dat 2009-08-16 18:42 . 2009-08-16 18:42 400512 ----a-w- c:\windows\XOU Clock.scr 2009-08-16 18:42 . 2009-08-16 18:42 40960 ----a-w- c:\windows\XOU Clock.dll 2009-08-16 16:13 . 2008-10-09 17:32 -------- d-----w- c:\program files\McAfee 2009-08-14 03:05 . 2008-10-31 04:33 -------- d-----w- c:\users\emsii\AppData\Roaming\XnView 2009-07-25 10:23 . 2009-06-01 04:09 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-07-18 16:06 . 2009-07-28 22:24 827904 ----a-w- c:\windows\system32\wininet.dll 2009-07-18 16:01 . 2009-07-28 22:24 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-07-18 09:46 . 2009-07-28 22:24 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-07-17 14:35 . 2009-08-12 22:40 71680 ----a-w- c:\windows\system32\atl.dll 2009-07-14 13:00 . 2009-08-12 22:39 313344 ----a-w- c:\windows\system32\wmpdxm.dll 2009-07-14 12:59 . 2009-08-12 22:39 4096 ----a-w- c:\windows\system32\dxmasf.dll 2009-07-14 12:58 . 2009-08-12 22:39 7680 ----a-w- c:\windows\system32\spwmp.dll 2009-07-14 10:59 . 2009-08-12 22:39 8147456 ----a-w- c:\windows\system32\wmploc.DLL 2009-07-09 17:16 . 2009-07-09 17:16 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2009-07-09 17:16 . 2009-07-09 17:16 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll 2008-10-05 20:28 . 2008-10-05 20:26 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-07-03 3563520] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320] "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\syste m] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] SetupExecute REG_MULTI_SZ \0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavaso ft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscs vc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf010 00.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDef end] @="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{EF6D7C14-D70A-4A72-9B60-1D5C8F9DFBD1}"= c:\program files\Dell\MediaDirect\MediaDirect.exe ell MediaDirect"{C227FF74-5686-447D-8DCB-41A501895921}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{148EB713-246A-42FF-81AD-4761522B24BF}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine "{1B6EA708-CA4E-4BD6-ADDC-4F5D872D2C18}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server "{2DEAD4AA-3454-4D01-9581-CC9378D595DE}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent "{EEABB986-056D-411C-A240-3E412CBF478D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{73FB6D2D-68B9-474B-BCAF-23852067E9F1}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{6688C3E2-311D-4A87-8611-36DDBABC209E}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{D7358334-57B6-406B-8A33-817468D0AB82}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{9E6F02CB-C339-479F-9F43-666A532BCCE9}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove "{8556A53C-40C9-450D-85BC-E612CDCC101A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{4529419D-885C-4BA2-9C5A-002F722EB8F9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{B5AA52D0-4127-432B-B3E8-15DACE78C719}"= Disabled:UDP:e:\setup\HPZNUI01.EXE:hpznui01.exe "{10258008-28AB-4449-98F6-4336BA8A6113}"= Disabled:TCP:e:\setup\HPZNUI01.EXE:hpznui01.exe "{9CB96F23-7AF8-4F3C-B339-CC71F08DE291}"= Disabled:UDP:e:\setup\HPONICIFS01.EXE:hponicifs01.exe "{526EA44A-A905-4988-99FD-8F77D766CBF8}"= Disabled:TCP:e:\setup\HPONICIFS01.EXE:hponicifs01.exe "{E19978BB-0D34-4386-9119-48CF01F865EE}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe "{C63166C8-AA6F-474C-A7D3-51F4537CB5B5}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe "{D8E8B01A-1206-49E8-B417-E499DABD8874}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe "{D91A46EA-BAA0-4D1D-8469-B86AF319603F}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe "{5CC02A0D-EF3B-490F-AA66-89E72806BD55}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{12624B50-CE0C-4781-8866-D32CC6E17B1C}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes "{6F2191D2-D8D0-4048-9818-6412BA36A0C2}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe "{50FF11FE-A716-4E7F-AB7D-155A3F9FE46F}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqscnvw.exe:hpqscnvw.exe "{8A42F8C8-522C-4B46-B89C-3FCAE12D16AA}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe "{28031554-DDEA-4647-905A-69A6FD71C0F2}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe "TCP Query User{1412E1A0-79C1-4AF4-AACE-ECA483162F64}c:\\program files\\trillian\\trillian.exe"= UDP:c:\program files\trillian\trillian.exe:Trillian "UDP Query User{E844A2AD-220A-4425-8362-3879C11ED645}c:\\program files\\trillian\\trillian.exe"= TCP:c:\program files\trillian\trillian.exe:Trillian "TCP Query User{40A65A2B-C619-4D58-B53D-66F49EC7FD86}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "UDP Query User{78DD6A13-E015-4CA4-AA5A-18447FCAF033}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "TCP Query User{478419BB-21D0-4654-B006-6203B143CA4F}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "UDP Query User{27AF31C9-56E4-4ABF-910D-AD6C5E243958}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager "TCP Query User{8FCCEFD7-F9DD-4F29-9CDE-FDC04FDAC2ED}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "UDP Query User{0B59C3A8-FB69-444B-90D4-0E3820D5BEA4}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer "{0923C735-070D-423C-A202-F8007C0E11BB}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{F00EF840-CEAC-420C-8716-6F11C9C9F000}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{49C42394-0EDF-4C4A-A7B5-39A0D9CBC77E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{DD2A4401-0C6F-4171-B480-B33B293BED6A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{70649FF7-4580-4AFE-A1E3-CC38626A4137}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes "{439F7FBC-70FC-4ADB-889C-1AA302954616}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [7/10/2009 6:00 PM 64160] R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [10/5/2008 7:43 AM 73728] R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [5/2/2008 2:09 PM 161048] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [10/9/2008 12:36 PM 210216] R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [10/5/2008 3:37 PM 111616] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1028432] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 . Contents of the 'Scheduled Tasks' folder 2009-10-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 23:00] 2009-08-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-26 16:53] 2009-10-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-02-26 16:53] . . ------- Supplementary Scan ------- . uStart Page = hxxp://myaccountinglab.mathxl.com/login_acct.htm uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\emsii\AppData\Roaming\Mozilla\Firefox\Profiles\jw34tkke.default\ FF - prefs.js: browser.startup.homepage - hxxp://kol.coldfront.net/thekolwiki/index.php/Main_Page FF - plugin: c:\users\emsii\AppData\Roaming\Mozilla\Firefox\Profiles\jw34tkke.default\ex tensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . - - - - ORPHANS REMOVED - - - - AddRemove-Ultra MP4 Video Converter_is1 - h:\program files\Ultra MP4 Video Converter\unins000.exe AddRemove-Win AVI HelixSDK_is1 - h:\program files\WinAVI Video Converter\HelixSDK\unins000.exe AddRemove-WinAVI Video Converter_is1 - h:\program files\WinAVI Video Converter\unins000.exe AddRemove-XnView_is1 - h:\program files\XnView\unins000.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-02 18:46 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3261150311-2334348272-2852962061-1000\Software\SecuROM\License information*] "datasecu"=hex:61,b3,b0,af,ea,e8,74,47,c0,a9,c8,e4,37,84,2d,63,0b,00,f9,0a, 7a, d9,b3,b5,e8,b7,ba,c5,4a,57,59,38,e1,1b,2d,5e,cc,35,4e,87,47,99,b7,5c,fd,a4, \ "rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2009-10-02 18:51 ComboFix-quarantined-files.txt 2009-10-02 23:51 Pre-Run: 72,336,392,192 bytes free Post-Run: 75,154,206,720 bytes free 226 --- E O F --- 2009-09-28 22:34 Thanks so much, emsiizilla |
|
02-Oct-2009, 11:45 PM
#8 |
| Hello emsiizilla, You may have used Malwarebytes before. If you still have it on your machine please update and run. Post the scan report back here. If you do not have Malwarebytes please download from Here Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Next Kaspersky on line scanner is very thorough. It can take a long time and for periods may seem not to be working. Just be patient and let it do its job. Kaspersky works with Internet Explorer and Firefox 3. Go to Kaspersky website and perform an online antivirus scan. Note: you will need to turn off your security programs to allow Kaspersky to do its job.
So when you return please post
__________________ Manners are the basis of a civilised society and make everyone's lives just a little happier. They cost nothing but they are worth so much. |
|
08-Oct-2009, 08:59 PM
#9 |
| Sorry I haven't responded yet; I have had a few research papers to work on lately. I will get back to you by the end of the weekend. Thanks for your help, emsiizilla |
|
08-Oct-2009, 09:41 PM
#10 |
| Okie dokie. |
|
19-Oct-2009, 09:15 PM
#11 |
| I'm really sorry about how long it took me to get back to you. Here's the Malwarebytes log: Malwarebytes' Anti-Malware 1.41 Database version: 2902 Windows 6.0.6001 Service Pack 1 10/18/2009 8:19:00 PM mbam-log-2009-10-18 (20-19-00).txt Scan type: Quick Scan Objects scanned: 91322 Time elapsed: 34 minute(s), 44 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) And here's the Kaspersky log: KASPERSKY ONLINE SCANNER 7.0: scan report Monday, October 19, 2009 Operating system: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, October 19, 2009 03:35:24 Records in database: 3030996 Scan settings scan using the following database extended Scan archives yes Scan e-mail databases yes Scan area My Computer C:\ D:\ E:\ Scan statistics Objects scanned 156847 Threats found 0 Infected objects found 0 Suspicious objects found 0 Scan duration 05:20:00 No threats found. Scanned area is clean. Selected area has been scanned. Also, my computer has been working great since you had me install and run Combo-Fix. Explorer starts right up without my having to "start new task". Thanks, emsiizilla |
|
19-Oct-2009, 11:59 PM
#12 | |
| Hello again emsiizilla, Quote:
Now I think your computer is clean of malware. We have a couple of last steps to perform and then you're all set. Follow these steps to uninstall Combofix and some tools used in the removal of malware. This will also clean out and reset your Restore Points
Run this program to remove the remaining tools we have been using. You will be asked to reboot the machine to finish the Cleanup process choose Yes. MBAM can be uninstalled via control panel add/remove but it may be a useful tool to keep. The Win32KDiag and ExeHelper folders/files can be deleted. Next, we need to clean your restore points and set a new one: Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
------------------------------------------------------------------------------------------------------------------- A reminder: Remember to turn back on any anti-malware programs you may have turned off during the cleaning process. ------------------------------------------------------------------------------------------------------------------- Now that your machine is clean here are some things that I think are worth having a look at if you don't already know a bout them: --------------------------------------------------------------------------------------------------------------------- Be sure and give the Temp folders a cleaning out now and then. This helps with security and your computer will run more efficiently. I clean mine once a week. For ease of use, you might consider the following free program:-------------------------------------------------------------------------------------------------------------------- Make Internet Explorer more secure
* Consider using an alternate browser. Mozilla's Firefox browser is excellant; it is more secure than Internet Explorer. Firefox is my default browser but I retain Internet Explorer as well so that I can access the very few sites that require it. Firefox may be downloaded from Here NoScripts is a good Add-on for Firefox that prevents execution of malicious scripts. ----------------------------------------------------------------------------------------------------------------------- Startuplite is a tool to help you stop some programs not needed when you start your computer from loading. They will begin automatically only when needed. ----------------------------------------------------------------------------------------------------------------------- To help protect your computer in the future here are some free programs you can look at: If your Microsoft Update is not working automatically. Keep your operating system up to date by visitingmonthly. It is recommended that you do set Windows to check, download and install your updates automatically.
Have a safe and happy computing day!
__________________ Manners are the basis of a civilised society and make everyone's lives just a little happier. They cost nothing but they are worth so much. |
| Tags |
| dell 1525, explorer, virus, vista |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 02:18 AM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

