Jump to content

Shell_NotifyIcon problem


Recommended Posts

I just started to receive an error notification [shell_NotifyIcon] Failed to perform desired action. Error Code: 0 when MBAM resident protection is enabled and the system has been running for 10-15 minutes then the resident protection closes down.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 10:20:21 AM, on 2/6/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\Program Files\USB Safely Remove\USBSRService.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe

C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE

C:\WINDOWS\system32\CTHELPER.EXE

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe

C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

C:\Program Files\BellCanada\McciTrayApp.exe

C:\Program Files\Brother\ControlCenter3\brccMCtl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Autorun Eater\oldmcdonald.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe

C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe

C:\Program Files\HostsMan\hostssrv.exe

C:\Program Files\HostsMan\hm.exe

C:\Program Files\LClock\lclock.exe

C:\Program Files\System Explorer\SystemExplorer.exe

C:\Program Files\USB Safely Remove\USBSafelyRemove.exe

C:\Program Files\MWSnap\MWSnap.exe

C:\WINDOWS\system32\sistray.exe

C:\Download\ClicKey.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\WINDOWS\system32\imapi.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\Autorun Eater\billy.exe

C:\Program Files\CDBurnerXP\NMSAccessU.exe

C:\Program Files\UPHClean\uphclean.exe

C:\Program Files\Windows Live\installer\WLSetupSvc.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe /r

O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [sBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

O4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe

O4 - HKLM\..\Run: [brMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

O4 - HKLM\..\Run: [setDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe

O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun

O4 - HKLM\..\Run: [bellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Autorun Eater] C:\Program Files\Autorun Eater\oldmcdonald.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min

O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB

O4 - HKCU\..\Run: [HostsServer] "C:\Program Files\HostsMan\hostssrv.exe" --start

O4 - HKCU\..\Run: [HostsMan] "C:\Program Files\HostsMan\hm.exe" -s

O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe

O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background

O4 - HKCU\..\Run: [systemExplorer] "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY

O4 - HKCU\..\Run: [uSB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe /startup

O4 - HKCU\..\Run: [MWSnap] "C:\Program Files\MWSnap\MWSnap.exe"

O4 - Startup: ClicKey.exe.lnk = C:\Download\ClicKey.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - Trusted Zone: http://forum.piriform.com

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1230849728890

O17 - HKLM\System\CCS\Services\Tcpip\..\{CFF32688-2D3D-4400-B4AE-A32BD466845B}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O23 - Service: McAfee Application Installer Cleanup (0233191230841888) (0233191230841888mcinstcleanup) - - (no file)

O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe

O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe

O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe

O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe

O23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Program Files\USB Safely Remove\USBSRService.exe

--

End of file - 9007 bytes

Link to post
Share on other sites

Here is the log:

Malwarebytes' Anti-Malware 1.33

Database version: 1733

Windows 5.1.2600 Service Pack 3

2/6/2009 7:37:08 AM

mbam-log-2009-02-06 (07-37-08).txt

Scan type: Quick Scan

Objects scanned: 46554

Time elapsed: 3 minute(s), 14 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

I don't know why the RESTRICTIONS are present.

There are no errors in the Application log but the System log reports a few DCOM errors but I think that is normal as this is a slow system.

Link to post
Share on other sites

  • Root Admin

Slow or not slow DCOM or any other errors are not normal. A normal system has NO errors.

Please run the following. Make sure you close ALL applications and disable your Anti-Virus first. Disconnect from the Internet when you disable your AV.

Please download the following scanning tool. GMER

  • Open the zip file and copy the file
    gmer.exe
    to your Desktop.
  • Double click on
    gmer.exe
    and run it.

  • It may take a minute to load and become available.

  • Do not make any changes. Click on the
    SCAN
    button and DO NOT use the computer while it's scanning.

  • Once the scan is done click on the
    SAVE
    button and browse to your Desktop and save the file as
    GMER.LOG

  • Zip up the
    GMER.LOG
    file and save it as
    gmerlog.zip
    and attach it to your reply post.

  • DO NOT
    directly post this log into a reply. You
    MUST
    attach it as a .ZIP file.

  • Click OK and quit the GMER program.

Link to post
Share on other sites

I do not know if I did this correctly?

I Created a New Compressed folder on the Desktop then I disabled the anti virus, disconnected from the Internet, closed all applications, ran gmer.exe from the Desktop and did a Scan and saved the output to the Desktop then copied it into the New Compressed folder that I have attached.

This system always had DCOM error ever since I got it way back in 2003 and if I remember I looked into it and as long as the DCOM service is active then it is OK.

This is what I see in the System Event log:

Type: Error

Date: 2/7/2009

Time: 6:00:09 AM

Event: 10005

Source: DCOM

Category: None

User: KSP4HOME\YoKenny

Computer: KSP4HOME

Description:

DCOM got error "%1055" attempting to start the service StiSvc with arguments ""

in order to run the server:

{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Type: Error

Date: 2/7/2009

Time: 6:00:09 AM

Event: 10005

Source: DCOM

Category: None

User: \SYSTEM

Computer: KSP4HOME

Description:

DCOM got error "%1055" attempting to start the service winmgmt with arguments ""

in order to run the server:

{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Link to post
Share on other sites

  • Root Admin

No rootkit detected. We'll work on the DCOM later on.

Please visit this webpage for instructions for downloading ComboFix to your
DESKTOP
:
how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

NOTE!!:

You must save and run
ComboFix.exe
on your DESKTOP and not from any other folder.

Also,
DO NOT
click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:

Note:

The
Windows Recovery Console
will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click
    Yes
    to allow ComboFix to continue scanning for malware.

  • When the tool is finished, it will produce a report for you.

  • Please post the
    C:\ComboFix.txt
    along with a
    new HijackThis log
    so we may continue cleaning the system.

Link to post
Share on other sites

Here is ComboFix.txt

ComboFix 09-02-06.04 - YoKenny 2009-02-07 20:49:17.1 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.214 [GMT -5:00]

Running from: c:\documents and settings\YoKenny\Desktop\ComboFix.exe

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)

* Created a new restore point

.

((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))

.

2009-02-07 11:04 . 2009-02-07 11:04 <DIR> d--hs---- c:\documents and settings\YoKenny\IECompatCache

2009-02-07 11:03 . 2009-02-07 11:03 <DIR> d--hs---- c:\documents and settings\YoKenny\PrivacIE

2009-02-07 11:02 . 2009-02-07 11:02 <DIR> d--hs---- c:\documents and settings\YoKenny\IETldCache

2009-02-07 10:14 . 2009-02-07 10:14 <DIR> d-------- c:\windows\ie8updates

2009-02-07 10:13 . 2009-02-07 10:13 1,355 --a------ c:\windows\imsins.BAK

2009-02-07 10:11 . 2009-02-07 10:13 <DIR> d--h-c--- c:\windows\ie8

2009-02-07 10:08 . 2009-01-11 00:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll

2009-02-07 07:01 . 2009-02-07 20:47 4,958,588 --a------ c:\windows\{00000000-00000000-0000000A-00001102-00000008-10011102}.BAK

2009-02-07 05:46 . 2009-02-07 06:12 250 --a------ c:\windows\gmer.ini

2009-02-06 10:41 . 2009-02-06 10:41 <DIR> dr------- c:\documents and settings\YoKenny\Application Data\Brother

2009-02-05 21:23 . 2009-02-05 21:23 <DIR> d-------- c:\documents and settings\YoKenny\Application Data\Avira

2009-02-05 15:34 . 2009-02-05 15:34 <DIR> d-------- c:\program files\Avira

2009-02-05 15:34 . 2009-02-05 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira

2009-02-05 13:27 . 2009-02-05 13:27 230,776 --a------ C:\aswclear.exe

2009-02-04 09:57 . 2009-02-04 09:57 <DIR> d-------- c:\program files\FLVPlayer4Free

2009-02-04 09:57 . 2009-02-04 09:58 <DIR> d-------- c:\documents and settings\YoKenny\Application Data\FLVPlayer4Free

2009-02-03 17:33 . 2009-02-07 20:28 <DIR> d-------- c:\program files\Autorun Eater

2009-02-03 08:28 . 2009-02-03 08:27 73,728 --a------ c:\windows\system32\javacpl.cpl

2009-01-31 13:42 . 2009-01-31 13:40 93,362 --a------ c:\windows\VGAsetup.ini

2009-01-31 13:41 . 2009-01-31 13:41 <DIR> d-------- c:\windows\SIS

2009-01-31 13:41 . 2009-01-31 13:41 <DIR> d-------- c:\program files\sisagp

2009-01-31 13:41 . 2009-01-31 13:42 <DIR> d-------- c:\program files\SiS VGA Utilities V3.85

2009-01-31 13:41 . 2008-06-27 14:54 262,144 --a------ c:\windows\system32\sistray.exe

2009-01-31 13:41 . 2009-01-31 13:40 208,896 --a------ c:\windows\Progress.exe

2009-01-31 13:41 . 2009-01-31 13:40 135,168 --------- c:\windows\system32\SiSApCom.dll

2009-01-31 13:41 . 2009-01-31 13:40 110,592 --------- c:\windows\system32\TVMode.dll

2009-01-31 13:41 . 2009-01-31 13:40 65,536 --------- c:\windows\system32\SiSHook.dll

2009-01-31 13:41 . 2009-01-31 13:40 53,248 --a------ c:\windows\system32\SiSPower.dll

2009-01-31 13:40 . 2009-01-31 13:42 79,872 --a------ c:\windows\system32\VGAunistlog.ini

2009-01-29 17:46 . 2009-01-29 17:46 <DIR> d-------- c:\documents and settings\YoKenny\Application Data\Ashampoo

2009-01-29 17:41 . 2009-01-29 17:41 <DIR> d-------- c:\program files\Ashampoo

2009-01-29 11:11 . 2009-01-29 11:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\ashampoo

2009-01-29 09:12 . 2009-01-29 09:12 <DIR> d-------- c:\program files\MWSnap

2009-01-26 10:44 . 2009-01-26 10:44 <DIR> d-------- c:\program files\CDBurnerXP

2009-01-26 10:44 . 2009-01-26 10:44 <DIR> d-------- c:\documents and settings\YoKenny\Application Data\Canneverbe_Limited

2009-01-26 10:38 . 2009-01-26 11:10 <DIR> d-------- c:\program files\NCH Software

2009-01-26 10:38 . 2009-01-26 10:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\NCH Swift Sound

2009-01-26 10:38 . 2009-01-26 10:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\NCH Software

2009-01-24 02:03 . 2009-01-24 02:03 <DIR> d-------- c:\program files\USB Safely Remove

2009-01-24 02:03 . 2009-01-24 02:03 <DIR> d-------- c:\documents and settings\YoKenny\Application Data\USBSafelyRemove

2009-01-24 02:03 . 2009-01-24 02:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\USBSRService

2009-01-22 04:18 . 2009-01-22 04:18 <DIR> d-------- c:\program files\Microsoft USB Flash Drive Manager

2009-01-19 09:15 . 2009-01-19 09:15 <DIR> d-------- c:\program files\Windows Update Remover

2009-01-19 09:15 . 2007-05-09 01:10 237,552 --a------ c:\windows\system32\tpuninst.exe

2009-01-16 16:58 . 2009-01-16 16:58 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-01-16 16:58 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-01-16 16:58 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-01-15 02:22 . 2009-01-15 02:22 49,152 --------- c:\windows\system32\msrating.dll.mui

2009-01-15 02:21 . 2009-01-15 02:21 2,560 --------- c:\windows\system32\mshta.exe.mui

2009-01-15 02:19 . 2009-01-15 02:19 81,920 --------- c:\windows\system32\iedkcs32.dll.mui

2009-01-15 02:19 . 2009-01-15 02:19 4,096 --------- c:\windows\system32\ie4uinit.exe.mui

2009-01-13 04:43 . 2009-01-13 04:44 <DIR> d-------- c:\windows\system32\NtmsData

2009-01-09 06:34 . 2009-01-31 13:15 <DIR> d-------- c:\documents and settings\YoKenny\Tracing

2009-01-09 06:31 . 2009-01-09 08:59 <DIR> d-------- c:\windows\SxsCaPendDel

2009-01-09 06:31 . 2009-01-09 06:31 <DIR> d-------- c:\program files\Microsoft

2009-01-09 06:30 . 2009-01-09 06:30 <DIR> d-------- c:\program files\Windows Live SkyDrive

2009-01-09 06:25 . 2009-01-09 06:25 <DIR> d-------- c:\program files\Common Files\Windows Live

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-07 16:11 --------- d-----w c:\program files\IEPro

2009-02-06 12:30 --------- d-----w c:\documents and settings\NetworkService\Application Data\SACore

2009-02-05 19:41 92,672 ----a-w c:\windows\system32\wlnotify.dll

2009-02-05 11:51 --------- d-----w c:\program files\Defraggler

2009-02-03 13:27 410,984 ----a-w c:\windows\system32\deploytk.dll

2009-02-01 11:42 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP

2009-02-01 11:42 --------- d-----w c:\program files\SpywareBlaster

2009-01-31 18:56 --------- d-----w c:\program files\SpeedFan

2009-01-31 18:42 --------- d--h--w c:\program files\InstallShield Installation Information

2009-01-21 15:49 --------- d-----w c:\program files\AutoMz

2009-01-16 21:58 --------- d-----w c:\documents and settings\YoKenny\Application Data\Malwarebytes

2009-01-16 21:58 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes

2009-01-15 07:05 911,872 ----a-w c:\windows\system32\wininet.dll

2009-01-15 07:05 43,008 ----a-w c:\windows\system32\licmgr10.dll

2009-01-15 07:04 18,944 ----a-w c:\windows\system32\corpol.dll

2009-01-15 07:03 72,704 ----a-w c:\windows\system32\admparse.dll

2009-01-15 07:03 71,680 ----a-w c:\windows\system32\iesetup.dll

2009-01-15 07:03 420,352 ----a-w c:\windows\system32\vbscript.dll

2009-01-15 07:01 34,304 ----a-w c:\windows\system32\imgutil.dll

2009-01-15 07:00 48,128 ----a-w c:\windows\system32\mshtmler.dll

2009-01-15 07:00 45,568 ----a-w c:\windows\system32\mshta.exe

2009-01-15 06:50 156,160 ----a-w c:\windows\system32\msls31.dll

2009-01-14 11:51 --------- d-----w c:\program files\BellCanada

2009-01-14 11:51 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller

2009-01-13 10:31 25,992 ----a-w c:\windows\system32\pgdfgsvc.exe

2009-01-13 09:49 --------- d-----w c:\program files\LClock

2009-01-11 12:52 --------- d-----w c:\program files\Windows Desktop Search

2009-01-09 14:01 --------- d-----w c:\program files\McAfee

2009-01-09 13:57 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee

2009-01-09 11:30 --------- d-----w c:\program files\Windows Live

2009-01-07 20:05 --------- d-----w c:\documents and settings\All Users\Application Data\Motive

2009-01-07 03:22 --------- d-----w c:\program files\Resource Kit

2009-01-07 00:31 --------- d-----w c:\documents and settings\YoKenny\Application Data\Motive

2009-01-06 20:46 --------- d-----w c:\program files\Common Files\Motive

2009-01-06 11:13 --------- d-----w c:\documents and settings\YoKenny\Application Data\Foxit

2009-01-06 11:12 --------- d-----w c:\program files\Foxit Software

2009-01-05 20:55 --------- d-----w c:\documents and settings\YoKenny\Application Data\ScanSoft

2009-01-05 20:34 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore

2009-01-05 12:35 --------- d-----w c:\program files\OE-QuoteFix

2009-01-04 20:03 --------- d-----w c:\documents and settings\All Users\Application Data\SystemExplorer

2009-01-04 19:25 --------- d-----w c:\program files\System Explorer

2009-01-04 18:45 --------- d-----w c:\program files\TweakNow WinSecret

2009-01-04 18:45 --------- d-----w c:\documents and settings\YoKenny\Application Data\TweakNow WinSecret

2009-01-04 18:37 --------- d-----w c:\program files\xp-AntiSpy

2009-01-04 01:46 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller

2009-01-04 01:42 --------- d-----w c:\program files\filehippo.com

2009-01-04 01:30 --------- d-----w c:\program files\Java

2009-01-03 19:27 --------- d-----w c:\documents and settings\YoKenny\Application Data\IEPro

2009-01-03 17:21 --------- d-----w c:\program files\Common Files\InstallShield

2009-01-03 17:21 --------- d-----w c:\program files\Brother

2009-01-03 17:16 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield

2009-01-03 17:15 --------- d-----w c:\program files\ScanSoft

2009-01-03 17:15 --------- d-----w c:\program files\Common Files\ScanSoft Shared

2009-01-03 17:15 --------- d-----w c:\documents and settings\All Users\Application Data\ScanSoft

2009-01-03 17:13 --------- d-----w c:\documents and settings\All Users\Application Data\Brother

2009-01-03 14:15 --------- d-----w c:\program files\BillP Studios

2009-01-03 14:15 --------- d-----w c:\documents and settings\YoKenny\Application Data\WinPatrol

2009-01-02 10:58 --------- d-----w c:\program files\RogueRemover FREE

2009-01-01 23:08 --------- d-----w c:\program files\Trend Micro

2009-01-01 22:57 --------- d-----w c:\documents and settings\YoKenny\Application Data\Windows Search

2009-01-01 22:55 --------- d-----w c:\program files\Microsoft Silverlight

2009-01-01 22:53 --------- d-----w c:\program files\Windows Media Connect 2

2009-01-01 20:37 --------- d-----w c:\program files\Belarc

2009-01-01 20:32 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor

2009-01-01 20:31 --------- d-----w c:\program files\Common Files\McAfee

2009-01-01 19:46 --------- d-----w c:\program files\CCleaner

2009-01-01 19:00 --------- d-----w c:\program files\Event Log Explorer

2009-01-01 18:44 --------- d-----w c:\program files\Windows Defender

2009-01-01 18:39 --------- d-----w c:\program files\NT Registry Optimizer

2009-01-01 18:05 --------- d-----w c:\documents and settings\YoKenny\Application Data\abelhadigital.com

2009-01-01 18:03 --------- d-----w c:\program files\HostsMan

2009-01-01 18:03 --------- d-----w c:\documents and settings\All Users\Application Data\abelhadigital.com

2009-01-01 17:49 --------- d-----w c:\program files\UPHClean

2009-01-01 16:49 --------- d-----w c:\documents and settings\YoKenny\Application Data\Creative

2009-01-01 16:47 --------- d-----w c:\program files\Creative

2009-01-01 16:02 --------- d-----w c:\program files\microsoft frontpage

2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys

2008-12-03 03:37 49,480 ----a-w c:\windows\system32\sirenacm.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Creative MediaSource Go"="c:\program files\Creative\MediaSource\Go\CTCMSGo.exe" [2003-08-12 131072]

"HostsServer"="c:\program files\HostsMan\hostssrv.exe" [2008-10-28 1830400]

"HostsMan"="c:\program files\HostsMan\hm.exe" [2008-10-28 2913280]

"LClock"="c:\program files\LClock\lclock.exe" [2004-09-19 65536]

"filehippo.com"="c:\program files\filehippo.com\UpdateChecker.exe" [2008-12-31 146432]

"SystemExplorer"="c:\program files\System Explorer\SystemExplorer.exe" [2008-08-25 1833472]

"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2008-12-15 1100048]

"MWSnap"="c:\program files\MWSnap\MWSnap.exe" [2002-07-06 427008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]

"CTDVDDET"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2003-06-18 45056]

"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]

"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-02-01 337216]

"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]

"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]

"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]

"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 622592]

"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]

"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 61440]

"BellCanada_McciTrayApp"="c:\program files\BellCanada\McciTrayApp.exe" [2008-12-07 1471488]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-01-14 399504]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 148888]

"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [2008-11-27 501768]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]

"CTHelper"="CTHELPER.EXE" [2007-04-09 c:\windows\system32\CtHelper.exe]

"SiSPower"="SiSPower.dll" [2009-01-31 c:\windows\system32\SiSPower.dll]

c:\documents and settings\YoKenny\Start Menu\Programs\Startup\

ClicKey.exe.lnk - c:\download\ClicKey.exe [2009-01-02 42560]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-01-31 262144]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NoRecentDocsNetHood"= 01000000

"MaxRecentDocs"= 7 (0x7)

"NoTaskGrouping"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\IEPro\\MiniDM.exe"=

R2 AntiVirMailService;Avira AntiVir Premium MailGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe [2009-02-05 164097]

R2 antivirwebservice;Avira AntiVir Premium WebGuard;c:\program files\Avira\AntiVir PersonalEdition Premium\avwebgrd.exe [2009-02-05 258305]

R2 AVEService;Avira AntiVir Premium MailGuard helper service;c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe [2009-02-05 41217]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-16 170640]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-01-01 206096]

R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [2009-01-24 208144]

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-01-16 15504]

S2 0233191230841888mcinstcleanup;McAfee Application Installer Cleanup (0233191230841888); [x]

--- Other Services/Drivers In Memory ---

*Deregistered* - uphcleanhlp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd10cca3-eac3-11dd-b3ee-0013d4081b60}]

\Shell\AutoRun\command - F:\winpatrolflash.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]

"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

.

Contents of the 'Scheduled Tasks' folder

2009-02-08 c:\windows\Tasks\MP Scheduled Scan.job

- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.ca/

IE: {{000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\IEPro\iepro.dll

LSP: avsda.dll

Trusted Zone: piriform.com\forum

TCP: {CFF32688-2D3D-4400-B4AE-A32BD466845B} = 208.67.222.222,208.67.220.220

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-07 20:50:32

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(584)

c:\windows\system32\avsda.dll

.

Completion time: 2009-02-07 20:51:47

ComboFix-quarantined-files.txt 2009-02-08 01:51:44

Pre-Run: 73,312,907,264 bytes free

Post-Run: 73,300,918,272 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

248 --- E O F --- 2009-02-03 13:24:26

Here is HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:08:08 PM, on 2/7/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18372)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\Program Files\USB Safely Remove\USBSRService.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe

C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE

C:\WINDOWS\system32\CTHELPER.EXE

C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe

C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

C:\Program Files\BellCanada\McciTrayApp.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Brother\ControlCenter3\brccMCtl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Autorun Eater\oldmcdonald.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe

C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe

C:\Program Files\HostsMan\hostssrv.exe

C:\Program Files\HostsMan\hm.exe

C:\Program Files\LClock\lclock.exe

C:\Program Files\System Explorer\SystemExplorer.exe

C:\Program Files\USB Safely Remove\USBSafelyRemove.exe

C:\Program Files\MWSnap\MWSnap.exe

C:\WINDOWS\system32\sistray.exe

C:\Download\ClicKey.exe

C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\WINDOWS\system32\imapi.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Autorun Eater\billy.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\CDBurnerXP\NMSAccessU.exe

C:\Program Files\UPHClean\uphclean.exe

C:\Program Files\Windows Live\installer\WLSetupSvc.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe /r

O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [sBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

O4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe

O4 - HKLM\..\Run: [brMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

O4 - HKLM\..\Run: [setDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe

O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun

O4 - HKLM\..\Run: [bellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Autorun Eater] C:\Program Files\Autorun Eater\oldmcdonald.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min

O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB

O4 - HKCU\..\Run: [HostsServer] "C:\Program Files\HostsMan\hostssrv.exe" --start

O4 - HKCU\..\Run: [HostsMan] "C:\Program Files\HostsMan\hm.exe" -s

O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe

O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background

O4 - HKCU\..\Run: [systemExplorer] "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY

O4 - HKCU\..\Run: [uSB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe /startup

O4 - HKCU\..\Run: [MWSnap] "C:\Program Files\MWSnap\MWSnap.exe"

O4 - Startup: ClicKey.exe.lnk = C:\Download\ClicKey.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - Trusted Zone: http://forum.piriform.com

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1230849728890

O17 - HKLM\System\CCS\Services\Tcpip\..\{CFF32688-2D3D-4400-B4AE-A32BD466845B}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O23 - Service: McAfee Application Installer Cleanup (0233191230841888) (0233191230841888mcinstcleanup) - - (no file)

O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe

O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe

O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe

O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe

O23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Program Files\USB Safely Remove\USBSRService.exe

--

End of file - 9368 bytes

Link to post
Share on other sites

  • Root Admin

Please download this, then disable your current AV and run it. You can disconnect from the Internet while it's running.

Download to the desktop: Dr.Web CureIt

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan"-tab, remove the mark at "Heuristic analysis".
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
    check.gif
    If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    move.gif
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply with a new hijackthis log.
Link to post
Share on other sites

o After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list

o Save the report to your desktop. The report will be called DrWeb.csv

I do not get that option so it is stored in the default location so I went there and started to copy-n-paste the log but it caused IE to hang while replying here so I will do the logs in two posts.

I don't know why I have to keep sending a HijackThis log as I do not change the applications loaded:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 6:34:51 AM, on 2/8/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18372)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\Program Files\USB Safely Remove\USBSRService.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe

C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE

C:\WINDOWS\system32\CTHELPER.EXE

C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe

C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe

C:\Program Files\BellCanada\McciTrayApp.exe

C:\Program Files\Brother\ControlCenter3\brccMCtl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Autorun Eater\oldmcdonald.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe

C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe

C:\Program Files\HostsMan\hostssrv.exe

C:\Program Files\HostsMan\hm.exe

C:\Program Files\LClock\lclock.exe

C:\Program Files\System Explorer\SystemExplorer.exe

C:\Program Files\USB Safely Remove\USBSafelyRemove.exe

C:\Program Files\MWSnap\MWSnap.exe

C:\WINDOWS\system32\sistray.exe

C:\Download\ClicKey.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe

C:\WINDOWS\system32\CTsvcCDA.exe

C:\WINDOWS\system32\imapi.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\CDBurnerXP\NMSAccessU.exe

C:\Program Files\Autorun Eater\billy.exe

C:\Program Files\UPHClean\uphclean.exe

C:\Program Files\Windows Live\installer\WLSetupSvc.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe

C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

C:\Program Files\Windows Defender\MsMpEng.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe /r

O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [sBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r

O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe

O4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe

O4 - HKLM\..\Run: [brMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

O4 - HKLM\..\Run: [setDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe

O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun

O4 - HKLM\..\Run: [bellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Autorun Eater] C:\Program Files\Autorun Eater\oldmcdonald.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min

O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe /SCB

O4 - HKCU\..\Run: [HostsServer] "C:\Program Files\HostsMan\hostssrv.exe" --start

O4 - HKCU\..\Run: [HostsMan] "C:\Program Files\HostsMan\hm.exe" -s

O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe

O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background

O4 - HKCU\..\Run: [systemExplorer] "C:\Program Files\System Explorer\SystemExplorer.exe" /TRAY

O4 - HKCU\..\Run: [uSB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe /startup

O4 - HKCU\..\Run: [MWSnap] "C:\Program Files\MWSnap\MWSnap.exe"

O4 - Startup: ClicKey.exe.lnk = C:\Download\ClicKey.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - C:\Program Files\IEPro\iepro.dll

O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll

O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O15 - Trusted Zone: http://forum.piriform.com

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1230849728890

O17 - HKLM\System\CCS\Services\Tcpip\..\{CFF32688-2D3D-4400-B4AE-A32BD466845B}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll

O23 - Service: McAfee Application Installer Cleanup (0233191230841888) (0233191230841888mcinstcleanup) - - (no file)

O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe

O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe

O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe

O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE

O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe

O23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Program Files\USB Safely Remove\USBSRService.exe

--

End of file - 9197 bytes

Link to post
Share on other sites

I can't post the DrWeb log as it says the post is too long so I'll post the last little bit that indicates that there was no detected problem:

-----------------------------------------------------------------------------

Scan statistics

-----------------------------------------------------------------------------

Scanned: 1257

Infected: 0

Modifications: 0

Suspicious: 0

Adware: 0

Dialers: 0

Jokes: 0

Riskware: 0

Hacktools: 0

Cured: 0

Deleted: 0

Renamed: 0

Moved: 0

Ignored: 0

Scan speed: 2378 Kb/s

Scan time: 00:01:36

-----------------------------------------------------------------------------

=============================================================================

Total session statistics

=============================================================================

Scanned: 1257

Infected: 0

Modifications: 0

Suspicious: 0

Adware: 0

Dialers: 0

Jokes: 0

Riskware: 0

Hacktools: 0

Cured: 0

Deleted: 0

Renamed: 0

Moved: 0

Ignored: 0

Scan speed: 851 Kb/s

Scan time: 00:04:28

=============================================================================

Link to post
Share on other sites

  • Root Admin

Okay, please uninstall MBAM and then run the Dial-a-fix program. Select all features and have it run.

Please download and run this program: Dial-a-fix

When that is done then download a new copy of MBAM and re-install it and put your code in if needed and try it out and let us know if you continue to have this problem or not.

Thanks.

Link to post
Share on other sites

I always download Dial-a-fix and run it right away and I have un-installed MBAM then re-installed it and it seems that the failure is unpredictable and sometimes won't happen all the time the system is booted up.

I don't know if this has anything to do with what I am seeing but sometimes the Taskbar develops an unusual transparency and the Desktop can be seen around the right end of the active tasks and when I go to start then Turn Off Computer the window with the 3 choices does not show up so I have to Ctrl+Alt+Del to bring up Task Manager and chose Shut Down Restart.

It is no big deal and I can live with it as I am going to replace it with a Vista system at the end of this month.

Thanks for your time and patience.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.