Page 2 of 2 FirstFirst 12
Results 11 to 16 of 16
  1. #11
    Member
    Join Date
    Mar 2010
    Posts
    8
    Points
    0

    Default Followup on John's instructions

    Hi John,

    Thanks for all your help. This is quite an involved process. I appreciate all your help.

    I had a problem with the first instructions. When I "Browsed" for a file to scan it opened a browser window and said 0 bytes uploaded. So I read the instructions and they gave a couple more options to scan files. One was to send and email with SCAN as the subject and to attach the file, so I did that with the two files you had highlighted. The site sent me an email response for each file, which I will paste in below.

    Then I downloaded and ran Combofix. Everything went smoothly, except I had to press OK a few times when my pc magazine utility Startup Cop Pro detected a change in the registry. The computer rebooted, I reactivated my McAfee virus protection and firewall, and I am using it to send this to you. I will paste in the report it generated below as well.

    I hope that you can make sense of all this information and that we are gaining ground. Thanks again for all your help. It is much appreciated.

    Regards,
    Art

    Complete scanning result of "lvuvc.hs", processed in VirusTotal at 03/14/2010 21:13:12 (CET).

    [ file data ]
    * name..: lvuvc.hs
    * size..: 0
    * md5...: d41d8cd98f00b204e9800998ecf8427e
    * sha1..: da39a3ee5e6b4b0d3255bfef95601890afd80709
    * peid..: -

    [ scan result ]
    a-squared 4.5.0.50/20100314 found nothing
    AhnLab-V3 5.0.0.2/20100314 found nothing
    AntiVir 8.2.1.180/20100312 found nothing
    Antiy-AVL 2.0.3.7/20100312 found nothing
    Authentium 5.2.0.5/20100314 found nothing
    Avast 4.8.1351.0/20100314 found nothing
    Avast5 5.0.332.0/20100314 found nothing
    AVG 9.0.0.787/20100314 found nothing
    BitDefender 7.2/20100314 found nothing
    CAT-QuickHeal 10.00/20100313 found nothing
    ClamAV 0.96.0.0-git/20100314 found nothing
    Comodo 4262/20100314 found nothing
    DrWeb 5.0.1.12222/20100314 found nothing
    eSafe 7.0.17.0/20100314 found nothing
    eTrust-Vet 35.2.7359/20100312 found nothing
    F-Prot 4.5.1.85/20100314 found nothing
    F-Secure 9.0.15370.0/20100314 found nothing
    Fortinet 4.0.14.0/20100313 found nothing
    GData 19/20100314 found nothing
    Ikarus T3.1.1.80.0/20100314 found nothing
    Jiangmin 13.0.900/20100314 found nothing
    K7AntiVirus 7.10.997/20100313 found nothing
    Kaspersky 7.0.0.125/20100314 found nothing
    McAfee 5920/20100314 found nothing
    McAfee+Artemis 5920/20100314 found nothing
    McAfee-GW-Edition 6.8.5/20100313 found nothing
    Microsoft 1.5502/20100312 found nothing
    NOD32 4944/20100314 found nothing
    Norman 6.04.08/20100314 found nothing
    nProtect 2009.1.8.0/20100313 found nothing
    Panda 10.0.2.2/20100314 found nothing
    PCTools 7.0.3.5/20100314 found nothing
    Prevx 3.0/20100314 found nothing
    Rising 22.38.04.03/20100312 found nothing
    Sophos 4.51.0/20100314 found nothing
    Sunbelt 5883/20100314 found nothing
    Symantec 20091.2.0.41/20100314 found nothing
    TheHacker 6.5.2.0.233/20100313 found nothing
    TrendMicro 9.120.0.1004/20100314 found nothing
    VBA32 3.12.12.2/20100314 found nothing
    ViRobot 2010.3.13.2226/20100313 found nothing
    VirusBuster 5.0.27.0/20100314 found nothing



    =================================================




    Complete scanning result of "logiflt.iad", processed in VirusTotal at 03/14/2010 21:19:42 (CET).

    [ file data ]
    * name..: logiflt.iad
    * size..: 0
    * md5...: d41d8cd98f00b204e9800998ecf8427e
    * sha1..: da39a3ee5e6b4b0d3255bfef95601890afd80709
    * peid..: -

    [ scan result ]
    a-squared 4.5.0.50/20100314 found nothing
    AhnLab-V3 5.0.0.2/20100314 found nothing
    AntiVir 8.2.1.180/20100312 found nothing
    Antiy-AVL 2.0.3.7/20100312 found nothing
    Authentium 5.2.0.5/20100314 found nothing
    Avast 4.8.1351.0/20100314 found nothing
    Avast5 5.0.332.0/20100314 found nothing
    AVG 9.0.0.787/20100314 found nothing
    BitDefender 7.2/20100314 found nothing
    CAT-QuickHeal 10.00/20100313 found nothing
    ClamAV 0.96.0.0-git/20100314 found nothing
    Comodo 4262/20100314 found nothing
    DrWeb 5.0.1.12222/20100314 found nothing
    eSafe 7.0.17.0/20100314 found nothing
    eTrust-Vet 35.2.7359/20100312 found nothing
    F-Prot 4.5.1.85/20100314 found nothing
    F-Secure 9.0.15370.0/20100314 found nothing
    Fortinet 4.0.14.0/20100313 found nothing
    GData 19/20100314 found nothing
    Ikarus T3.1.1.80.0/20100314 found nothing
    Jiangmin 13.0.900/20100314 found nothing
    K7AntiVirus 7.10.997/20100313 found nothing
    Kaspersky 7.0.0.125/20100314 found nothing
    McAfee 5920/20100314 found nothing
    McAfee+Artemis 5920/20100314 found nothing
    McAfee-GW-Edition 6.8.5/20100313 found nothing
    Microsoft 1.5502/20100312 found nothing
    NOD32 4944/20100314 found nothing
    Norman 6.04.08/20100314 found nothing
    nProtect 2009.1.8.0/20100313 found nothing
    Panda 10.0.2.2/20100314 found nothing
    PCTools 7.0.3.5/20100314 found nothing
    Prevx 3.0/20100314 found nothing
    Rising 22.38.04.03/20100312 found nothing
    Sophos 4.51.0/20100314 found nothing
    Sunbelt 5883/20100314 found nothing
    Symantec 20091.2.0.41/20100314 found nothing
    TheHacker 6.5.2.0.233/20100313 found nothing
    TrendMicro 9.120.0.1004/20100314 found nothing
    VBA32 3.12.12.2/20100314 found nothing
    ViRobot 2010.3.13.2226/20100313 found nothing
    VirusBuster 5.0.27.0/20100314 found nothing

    ===============================================

    ComboFix 10-03-14.03 - Art 03/14/2010 15:48:27.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1305 [GMT -5:00]
    Running from: c:\documents and settings\Art\Desktop\ComboFix.exe
    AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\eSellerateEngine.dll
    c:\windows\system32\ndisapi.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_NDISRD
    -------\Service_NDISRD


    ((((((((((((((((((((((((( Files Created from 2010-02-14 to 2010-03-14 )))))))))))))))))))))))))))))))
    .

    2010-03-07 19:39 . 2010-03-07 19:39 -------- d-----w- c:\documents and settings\Art\Application Data\Malwarebytes
    2010-03-07 19:39 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-03-07 19:39 . 2010-03-07 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-03-07 19:39 . 2010-03-07 19:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-03-07 19:39 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-03-07 05:53 . 2010-03-07 05:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2010-03-07 05:50 . 2010-03-07 05:51 -------- d-----w- c:\program files\SUPERAntiSpyware
    2010-03-07 05:50 . 2010-03-07 05:50 -------- d-----w- c:\documents and settings\Art\Application Data\SUPERAntiSpyware.com
    2010-03-07 05:49 . 2010-03-07 05:49 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2010-03-07 05:03 . 2010-03-07 05:03 -------- d-----w- c:\program files\Trend Micro
    2010-03-04 05:17 . 2004-08-10 11:00 7168 ----a-w- c:\windows\system32\dllcache\wamregps.dll
    2010-03-04 05:17 . 2001-08-17 20:56 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
    2010-03-04 05:16 . 2004-08-10 11:00 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll
    2010-03-04 05:16 . 2004-08-10 11:00 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe
    2010-03-04 05:16 . 2004-08-10 11:00 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll
    2010-03-04 05:16 . 2004-08-10 11:00 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll
    2010-03-04 05:16 . 2004-08-10 11:00 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe
    2010-03-04 05:16 . 2004-08-10 11:00 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll
    2010-03-04 04:02 . 2009-07-16 18:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
    2010-03-04 04:02 . 2010-03-04 04:03 -------- d-----w- c:\program files\Common Files\McAfee
    2010-03-04 04:02 . 2010-03-04 04:02 -------- d-----w- c:\program files\McAfee.com
    2010-02-28 16:21 . 2010-02-28 16:21 -------- d-----w- c:\documents and settings\Art\Local Settings\Application Data\Iceni
    2010-02-28 16:21 . 2010-02-28 16:21 -------- d-----w- c:\documents and settings\Art\Application Data\Aspell
    2010-02-28 15:18 . 2010-02-28 15:18 -------- d-----w- c:\documents and settings\Art\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2010-02-20 08:30 . 2010-02-20 08:30 -------- d-----w- c:\program files\Common Files\Panasonic
    2010-02-20 08:28 . 2010-02-20 08:28 -------- d-----w- c:\program files\Panasonic
    2010-02-20 08:27 . 2010-02-20 08:27 -------- d-----w- c:\program files\Microsoft Synchronization Services
    2010-02-20 08:27 . 2010-02-20 08:27 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-03-10 03:09 . 2009-09-14 04:17 72096 -c-ha-w- c:\windows\system32\mlfcache.dat
    2010-03-07 19:14 . 2009-12-27 22:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-03-07 05:54 . 2010-03-07 05:54 52224 ----a-w- c:\documents and settings\Art\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
    2010-03-07 05:54 . 2010-03-07 05:54 117760 ----a-w- c:\documents and settings\Art\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-03-06 18:46 . 2009-03-25 20:31 -------- d-----w- c:\program files\McAfee
    2010-03-06 15:37 . 2009-03-25 18:43 93448 -c--a-w- c:\documents and settings\Art\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-03-06 07:11 . 2009-06-16 01:36 25214 ----a-r- c:\documents and settings\Art\Application Data\Microsoft\Installer\{38EE230F-F631-451F-8800-E29F5E5C9E7D}\_6459EB3CC1021F99697573.exe
    2010-03-06 07:11 . 2009-06-16 01:36 25214 ----a-r- c:\documents and settings\Art\Application Data\Microsoft\Installer\{38EE230F-F631-451F-8800-E29F5E5C9E7D}\_4D456665B6A1916105928F.exe
    2010-03-06 07:11 . 2009-06-16 01:36 31702 ----a-r- c:\documents and settings\Art\Application Data\Microsoft\Installer\{38EE230F-F631-451F-8800-E29F5E5C9E7D}\_2964C3DE7E291AF3F2353D.exe
    2010-03-06 07:11 . 2009-06-16 01:36 31702 ----a-r- c:\documents and settings\Art\Application Data\Microsoft\Installer\{38EE230F-F631-451F-8800-E29F5E5C9E7D}\_21F3885A18D238E15AAE81.exe
    2010-03-06 07:11 . 2009-06-16 01:36 1078 ----a-r- c:\documents and settings\Art\Application Data\Microsoft\Installer\{38EE230F-F631-451F-8800-E29F5E5C9E7D}\_0044238C9C33EE6AE43EBB.exe
    2010-03-06 07:11 . 2009-06-16 01:36 31702 ----a-r- c:\documents and settings\Art\Application Data\Microsoft\Installer\{38EE230F-F631-451F-8800-E29F5E5C9E7D}\_6FEFF9B68218417F98F549.exe
    2010-03-06 07:11 . 2009-06-16 01:36 -------- d-----w- c:\program files\iTunes Library Updater
    2010-03-06 06:54 . 2009-03-26 15:41 -------- d-----w- c:\program files\Common Files\Adobe
    2010-03-04 04:32 . 2009-03-25 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2010-03-03 05:50 . 2009-03-29 02:16 0 -c--a-w- c:\windows\system32\drivers\lvuvc.hs
    2010-03-03 05:50 . 2009-03-30 22:39 0 -c--a-w- c:\windows\system32\drivers\logiflt.iad
    2010-03-03 05:48 . 2009-03-29 02:30 -------- d-----w- c:\documents and settings\Art\Application Data\Skype
    2010-03-01 02:15 . 2009-03-29 02:50 -------- d-----w- c:\documents and settings\Art\Application Data\skypePM
    2010-02-28 17:21 . 2009-03-26 18:51 -------- d-----w- c:\program files\CCleaner
    2010-02-24 15:16 . 2010-01-14 04:39 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-02-20 22:19 . 2009-03-25 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
    2010-02-20 08:28 . 2009-03-25 03:02 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-02-12 02:35 . 2010-02-12 02:35 -------- d-----w- c:\program files\MSECache
    2010-02-02 00:16 . 2010-02-02 00:15 -------- d-----w- c:\program files\iTunes
    2010-02-02 00:15 . 2010-02-02 00:15 -------- d-----w- c:\program files\iPod
    2010-02-02 00:15 . 2009-03-26 01:08 -------- d-----w- c:\program files\Common Files\Apple
    2010-02-02 00:12 . 2009-09-11 16:03 -------- d-----w- c:\program files\QuickTime
    2010-02-02 00:06 . 2010-02-02 00:06 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
    2010-01-31 19:15 . 2009-03-29 02:29 -------- d-----r- c:\program files\Skype
    2010-01-31 19:15 . 2010-01-31 19:15 -------- d-----w- c:\program files\Common Files\Skype
    2010-01-31 19:15 . 2009-03-29 02:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
    2010-01-23 19:51 . 2009-03-25 04:17 -------- d-----w- c:\program files\Windows Desktop Search
    2010-01-22 19:17 . 2009-03-25 04:33 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-01-21 06:00 . 2009-09-28 05:44 -------- d-----w- c:\documents and settings\Art\Application Data\Binary Boy
    2010-01-06 00:04 . 2010-01-06 00:04 385536 ----a-w- c:\windows\system32\drivers\mfehidk.sys
    2010-01-05 03:26 . 2010-01-05 03:26 184584 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
    2009-12-31 16:50 . 2005-08-16 10:18 353792 ------w- c:\windows\system32\drivers\srv.sys
    2009-12-26 03:13 . 2009-10-21 20:06 6725632 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181625-18178.dll
    2009-12-21 19:14 . 2005-08-16 10:18 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-12-16 18:43 . 2005-08-16 10:37 343040 ------w- c:\windows\system32\mspaint.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Startup Cop Pro Startup Launcher"="c:\program files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" [2009-12-16 4064256]
    "Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
    "PhotoshopElements8SyncAgent"="c:\program files\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe" [2009-09-06 1893728]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-7-30 217195]
    Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
    backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PHOTOfunSTUDIO 4.0.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PHOTOfunSTUDIO 4.0.lnk
    backup=c:\windows\pss\PHOTOfunSTUDIO 4.0.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2009-12-22 07:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
    2007-02-20 17:29 1191936 ----a-w- c:\program files\Dell\QuickSet\quickset.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
    2006-10-18 23:04 802816 ----a-w- c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
    2009-09-11 19:36 128232 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
    2008-05-14 15:31 244208 ----a-w- c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "WZCSVC"=2 (0x2)
    "RoxWatch10"=2 (0x2)
    "RoxMediaDB10"=3 (0x3)
    "RoxLiveShare10"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\WINDOWS\\system32\\spoolsv.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
    "c:\\Program Files\\Adobe\\Elements Organizer 8.0\\AdobePhotoshopElementsMediaServer.exe"=
    "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0
    "1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1
    "1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2
    "1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3
    "1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4
    "1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5
    "1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6
    "1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7
    "1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8
    "1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9
    "1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
    "1647:TCP"= 1647:TCP:MioNet Storage Device Configuration
    "5432:UDP"= 5432:UDP:MioNet Storage Device Discovery
    "9100:TCP"= 9100:TCP:HPscan 9100
    "427:UDP"= 427:UDP:HPscan 427 UDP
    "427:TCP"= 427:TCP:HPscan 427 TCP
    "161:UDP"= 161:UDP:HPscan 151 UDP
    "139:UDP"= 139:UDP:HPscan 139 UDP
    "9220:TCP"= 9220:TCP:HPscan 9220 TCP
    "9290:TCP"= 9290:TCP:HPscan 9290 TCP
    "9500:TCP"= 9500:TCP:HPscan 9500 TCP

    R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [4/30/2009 6:18 PM 284416]
    R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [12/27/2009 11:19 PM 136744]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 11:15 AM 66632]
    R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\VCdRom.sys [6/14/2009 1:00 PM 8576]
    R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [9/6/2009 7:06 AM 169312]
    R2 M4iPodWPDService;M4iPodWPDService;c:\program files\Common Files\Mediafour\iPod\M4iPodWPDService.exe [11/13/2009 2:59 PM 216064]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3/3/2010 11:05 PM 93320]
    R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\WD\WD Anywhere Backup\MemeoBackgroundService.exe [4/17/2009 12:51 PM 25824]
    R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [7/24/2008 3:22 PM 102400]
    R3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [3/29/2009 9:06 PM 513152]
    R3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [3/29/2009 9:06 PM 2688]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 11:15 AM 12872]
    S2 HidCom;USB-HID -> COM Driver Service;c:\windows\system32\drivers\HidCom.sys [3/29/2009 9:36 PM 21016]
    S3 AngelUsb;Angel USB MPEG Device;c:\windows\system32\drivers\AngelUsb.sys [3/20/2009 8:08 AM 386560]
    S3 SoundMovieServer;SoundMovieServer;c:\windows\system32\snmvtsvc.exe [3/29/2009 9:06 PM 184320]
    S4 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [5/14/2008 10:32 AM 309744]
    S4 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [5/14/2008 10:31 AM 1120752]
    S4 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [5/14/2008 10:32 AM 166384]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

    2010-03-04 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2010-03-04 18:22]

    2010-03-04 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2010-03-04 18:22]

    2010-03-14 c:\windows\Tasks\User_Feed_Synchronization-{52F6011B-667A-4808-9D25-4A96FCBD5801}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 10:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    Trusted Zone: amazon.com\www
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2010-03-14 15:56
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(912)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    c:\windows\system32\WININET.dll
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(6416)
    c:\windows\system32\WININET.dll
    c:\windows\TEMP\logishrd\LVPrcInj01.dll
    c:\progra~1\WINDOW~3\wmpband.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\Mediafour\XPlay 3\XPCopyHook.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Intel\Wireless\Bin\WLKeeper.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\eHome\ehRecvr.exe
    c:\windows\eHome\ehSched.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\progra~1\mcafee.com\agent\mcagent.exe
    c:\program files\McAfee\MPF\MPFSrv.exe
    c:\program files\McAfee\MSK\MskSrver.exe
    c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    c:\windows\system32\HPZipm12.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\windows\ehome\mcrdsvc.exe
    c:\windows\system32\dllhost.exe
    c:\windows\eHome\ehmsas.exe
    .
    **************************************************************************
    .
    Completion time: 2010-03-14 16:00:47 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-03-14 21:00

    Pre-Run: 9,572,933,632 bytes free
    Post-Run: 9,442,127,872 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptOut

    - - End Of File - - 0F7BA9CBF36AAA7F85C31F4FFB2EBD64

  2. #12
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    Hi,

    Everything is looking fine so let's see if everything really is.

    Step 1: Run CCleaner
    CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!

    • Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
    • Then select the items you wish to clean up.

      • In the Windows Tab:

        • Clean all entries in the Internet Explorer section except Cookies
        • Clean all the entries in the Windows Explorer section
        • Clean all entries in the System section
        • Clean all entries in the Advanced section
        • Clean any others that you choose
      • In the Applications Tab:

        • Clean all except cookies in the Firefox/Mozilla section if you use it
        • Clean all in the Opera section if you use it
        • Clean Sun Java in the Internet Section
        • Clean any others that you choose
    • Click the Run Cleaner button.
    • A pop up box will appear advising this process will permanently delete files from your system.
    • Click OK and it will scan and clean your system.
    • Click exit when done.
    • If it asks you to reboot at the end, click NO

    CCleaner should be run with the above settings for each User Account!

    Step 2: Run Malwarebytes' Anti-Malware
    Please start Malwarebytes' Anti-Malware by clicking the icon on your desktop or launching it from the start menu.

    • Go to the Update tab and click Check for Updates
    • If an update is found, it will download and install the latest version.
    • Once the program has updated, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. Close the Notepad file.
    • The log file is saved here and will be named like this: C:\Documents and Settings\<your username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt


    Step 3: Use Adobe Reader
    You're using an outdated version of Adobe Acrobat Elements, which will undoubtedly contain security leaks.

    I am not going to force you to update because it costs quite some money to do so, however I insist that you use an updated version for viewing online PDF files. For that please use Adobe Reader which you do already have installed. Adobe Acrobat Elements is fine for editing and creating PDFs yourself as that does not bring security risks.

    Step 4: Update Java
    Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
    First remove the older versions:

    • Click Start
    • Go to Control Panel
    • Go to Add/Remove Programs
    • Find and click Remove for each version of Java that is present
    • Download JavaRa and unzip it to your desktop.
    • Double-click on JavaRa.exe to start the program.
    • From the drop-down menu, choose English and click on Select.
    • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
    • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
    • A logfile will pop up. Please save it to a convenient location.

    Now let's download and install the newest version:

    • Go to the website of Java: Java SE Downloads - Sun Developer Network (SDN)
    • Under JDK 6 Update 18 click the red box called Download JRE.
    • As Platform select your operating system, agree to the License Agreement and click Continue.
    • Now click on the link under Windows Offline Installation and download the installer to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Then from your desktop double-click on the download to install the newest version.
    • Reboot your computer.


    Step 5: Run Kaspersky Online Scan
    Please go to Kaspersky website to perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:

      • Spyware, Adware, Dialers, and other potentially dangerous programs
      • Archives
      • Mail databases
    • Click on My Computer under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As....
    • Save this report to your desktop by changing the Files of type to Text file (.txt) before clicking on the Save button.
    • Now close the window.


    Step 6: Post logs
    Please post the following in a reply to this topic:

    • Let me know how your computer is running and tell me about any problems you still have
    • New HijackThis log
    • Kaspersky log
    • MBAM log


    Regards,
    John.

  3. #13
    Member
    Join Date
    Mar 2010
    Posts
    8
    Points
    0

    Default Shutdown and performance problems

    Sorry to be the bearer of bad news John, but I spent most of yesterday running Ccleaner for each user account, Malwarebytes anti-malware software, updating Java by cleaning out older versions and installing the latest version, and running Kaspersky. I'm pasting in the logs, but don't think there will be much useful information in them.

    I realize that my copy of Adobe Acrobat Elements is OLD, but just kept it so I would have the capability of creating PDF files. I use the latest version of Adobe Acrobat Reader to view and print PDF files. That should be okay.

    Should I uninstall WinRar. I think it is only good for 30 days or so and then they want you to purchase a license.

    I rebooted a number of times, and I am still getting an error message that there is an unresponsive program, with a name that is always different and is only 3 characters long (usually a combination of alpha and numeric characters). I try to let Windows close it but it can't, so I press "End Now" (it says I will lose any unsaved information) and the reboot shutdown continues ok.

    When the system comes back up, everything looks normal except for one minor thing. My little icon for the Intel/Wireless adapter in the system tray is white and it should be green. I checked it out and it says another wireless utility is communicating with the Intel Pro/Wireless adapter. To avoid conflicts, Intel's profile management features have been temporarily disabled. I checked for Internet connectivity by opening my browser and I was online, so just left it.

    I haven't had time to use a number of other programs much, so am not sure how well they are working. I was having a few problems with Excel hanging before we got into all this, so tried working on a file in Excel to test it. The program loaded quick. However, while working in the file a few times I ran into sluggish performance. Once I copied a couple cells and it took about 15 seconds to write the information to the clipboard. The copy worked fine. Then I went to "save as" and it took about 30 seconds for the directory to come up. The save worked fine. Another time, I edited a cell, pressed enter and it took about 5 seconds before my cursor came back and I could do anything else. The spreadsheet doesn't contain anything complicated and is only 67kb in size, so I would have to say the performance in Excel is sluggish, but at least it works.

    I had to use my browser a few times to access web sites (including this one) and everything worked fine. I used Word a few times and it seemed to work fine.

    I used Adobe Photoshop Elements to download some photos from my camera, and that worked fine. It is sluggish at the best of times. I played around with some of the settings in Elements and think I got my backup/synchronization agent working to backup my entire photo catalogue of 33,000 photos, so experienced some very degraded performance after that. I’ve been struggling to get it working, so will have to wait a day or two and check to see if that worked or not. I set it to just backup when the system is idle.

    My biggest problem is handling email, as that is probably the program I use most often. I use Outlook 2003. I was replying to an email and did spell check, everything working fine until I told it to ignore a word and then it hung. After waiting awhile I used Windows Task Manager to end the program. Windows detected the event and I sent them an error report. I reloaded Outlook and of course got the message it wasn’t closed properly. It took a minute to check my files and then came back. I had copied my wife on the email I was working on, and checked her machine and she received it. I tried a few more things in Outlook, like forwarding or replying to messages, deleting a few and every second or third one, the program would hang – I would close it in task manager and reload it until I got through my emails. Very frustrating.

    I don’t know if you noticed but I have a PC Magazine Utility Startup Cop Pro loaded. I exported the configuration to an csv file format and will also try send that to you. It is probably easiest read by importing the data into a spreadsheet and adjusting the column widths to accomodate the data.

    I’ll post in the logs below: (Hope I got everything you asked for.)

    Regards,
    Art

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Tuesday, March 16, 2010
    Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Monday, March 15, 2010 22:45:36
    Records in database: 3808822
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\
    G:\
    X:\
    Y:\

    Scan statistics:
    Objects scanned: 689905
    Threats found: 0
    Infected objects found: 0
    Suspicious objects found: 0
    Scan duration: 08:52:47

    No threats found. Scanned area is clean.

    Selected area has been scanned.
    JavaRa 1.15 Removal Log.
    Report follows after line.
    ------------------------------------
    The JavaRa removal process was started on Mon Mar 15 20:32:31 2010

    Found and removed: C:\Documents and Settings\Art\Application Data\Sun\Java\jre1.6.0_14
    Found and removed: C:\Documents and Settings\Art\Application Data\Sun\Java\jre1.6.0_15
    Found and removed: Software\Classes\JavaPlugin.160_05
    Found and removed: Software\JavaSoft\Java2D\1.6.0_02
    ------------------------------------
    Finished reporting.
    ==============================================================

    Malwarebytes' Anti-Malware 1.44
    Database version: 3871
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    3/15/2010 8:20:15 PM
    mbam-log-2010-03-15 (20-20-15).txt

    Scan type: Full Scan (C:\|E:\|G:\|)
    Objects scanned: 602084
    Time elapsed: 4 hour(s), 14 minute(s), 34 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:24:29 AM, on 3/16/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\McAfee\MSK\MskSrver.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe
    C:\Program Files\Microsoft Location Finder\LocationFinder.exe
    C:\Program Files\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [Startup Cop Pro Startup Launcher] "C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" /startup /Embedding
    O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
    O4 - HKCU\..\Run: [PhotoshopElements8SyncAgent] C:\Program Files\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.5.0.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - https://wimpro.cce.hp.com/ChatEntry/...ds/sysinfo.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase8942.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1237949628225
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1237949726015
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: M4iPodWPDService - Mediafour Corporation - C:\Program Files\Common Files\Mediafour\iPod\M4iPodWPDService.exe
    O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 12276 bytes
    Attached Files

  4. #14
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    Hi Art,

    As you may have noticed the scanners did not find anything bad so this is my normal post for when you are clear - which you now are - or seem to be.

    The problems that you still have all seem to be related to non-malware topics or not enough maintanance. Later on in this post I will give some recommendations on maintanance and for the problems that you still have I recommend that you start a new topic in the Computer Help subforum:
    Computer Help - Help2Go
    The helpers there may be able to find out what is wrong with the help of event logs and other data which I am not specialized in.

    WinRAR will keep working after the 30-day trial and almost everybody uses that expired version. The only difference between than and now is that after the 30 days you will get a popup when starting WinRAR that the trial has expired and it kindly asks you to buy the product. You can close that window and just use WinRAR then. So I recommend that you keep it installed as it important for extracting archives.

    Now that you are clean, I got some tips & tricks for you to keep your computer clean and secure. The first few (like removing dangerous tools and Windows Update) have to be done, the others are optional (beginning with SpywareBlaster).

    It may seem like your system will be too much protected with all these things installed, but a lot of programs aren't running always on the background so don't slow down your computer. Please take a look at the following things:

    • Uninstall tools - The following will not only uninstall ComboFix but also clean up some other dangerous tools and backups, clean up the System Restore points and hide the system files.

      • Go to Start
      • Click on Run
      • Type ComboFix /Uninstall (Note: This command is case sensitive.)

      After doing that with ComboFix, do this with OTCleanIt to remove the tools not removed by ComboFix.

      • Download OTC from here to your desktop.
      • Click the OTC icon on your desktop.
      • Click the CleanUp button.
      • If you get any pop ups asking if it is OK let the program proceed.
      • At the end the program will ask to let it reboot the computer. Let it do so.

      You may delete any logs and other tools left on the desktop.
    • Make your Internet Explorer more secure - This can be done by following these simple instructions:

      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.

        • Change the Download signed ActiveX controls to Prompt
        • Change the Download unsigned ActiveX controls to Disable
        • Change the Initialise and script ActiveX controls not marked as safe to Disable
        • Change the Installation of desktop items to Prompt
        • Change the Launching programs and files in an IFRAME to Prompt
        • Change the Navigate sub-frames across different domains to Prompt
        • When all these settings have been made, click on the OK button.
        • If it prompts you as to whether or not you want to save the settings, press the Yes button.

      • Next press the Apply button and then the OK to exit the Internet Properties page.

    • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
    • Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. You can download it here:
      SpywareBlaster
    • Install MVPS HOSTS - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
      For information on how to download and install, please read this tutorial here:
      WinHelp2002
      Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
    • Use an alternative Internet Browser - Many of the exploits are directed to users of Internet Explorer. Try using a different browser instead:
      Firefox << Most used, I use this one myself.
      Opera
    • Bookmark general cleanup link - It could be that your computer is becoming slower and slower. This is not always the cause of malware. Most of the times it's malware when you're computer is suddenly getting slow or doing strange. When the slowdown increases slowly, check (so now bookmark) this link for tips & tricks:
      What to do if your Computer's running slowly
    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.


    Follow this list and your potential for being infected again will reduce dramatically.

    Stand Up and Be Counted!
    Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints called Malware Complaints. Please register there first! Then follow the instructions here:
    Malware that you were infected with -- malwarecomplaints.info

    >> Here << you can see how you can help us.

    Happy surfing!

    John.

  5. #15
    Member
    Join Date
    Mar 2010
    Posts
    8
    Points
    0

    Default Computer shutdown and performance problems

    Thanks for all your help John. My computer is behaving much better than before. I'm not exactly sure which remedies helped, but am just glad it isn't hanging on me all the time.

    If I continue to have shutdown problems I will do a post on the other forum as you suggested.

    Regards,
    Art

  6. #16
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    As your problems appear to have been resolved I have now closed this topic.

    We are pleased to have been some help in getting you clean.

    If you have been helped and wish to donate to help with the costs of this volunteer site, please read:
    Donate to Help2Go

Page 2 of 2 FirstFirst 12