Jump to content

Malwarebytes can enable protection module


Recommended Posts

when i try to enable protection module, it says: PROGRAM_ERROR_PROTECTION_MODULE (1086, 0,ProtectionEnable)

i think im infected

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_29

Run by MSI at 21:13:18 on 2012-05-24

Microsoft Windows 7 Ultimate 6.1.7600.0.1252.63.1033.18.7077.3817 [GMT 8:00]

.

SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

D:\Program Files\Sandboxie\SbieSvc.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\WLANExt.exe

C:\Windows\system32\conhost.exe

C:\Windows\System32\spoolsv.exe

C:\ProgramData\DatacardService\HWDeviceService64.exe

C:\Program Files (x86)\S-Bar\MSIService.exe

C:\Program Files (x86)\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

D:\Program Files (x86)\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe

D:\Program Files\Proxy Labs\ProxyCap\pcapsvc.exe

C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe

D:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

D:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe

D:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files\NVIDIA Corporation\Display\nvtray.exe

C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe

C:\Windows\system32\sppsvc.exe

C:\Windows\System32\svchost.exe -k secsvcs

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\SearchIndexer.exe

D:\Program Files\Proxy Labs\ProxyCap\pcapui.exe

C:\Program Files (x86)\S-Bar\S-Bar.exe

D:\Program Files (x86)\Internet Download Manager\IDMan.exe

C:\Program Files\Rainmeter\Rainmeter.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Windows\servicing\TrustedInstaller.exe

C:\Program Files (x86)\McAfee Security Scan\3.0.271\SSScheduler.exe

D:\Program Files (x86)\Mozilla Firefox\firefox.exe

D:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\AUDIODG.EXE

C:\Windows\system32\DllHost.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uInternet Settings,ProxyOverride = local;<local>

BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - D:\Program Files (x86)\Internet Download Manager\IDMIECC.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - D:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL

BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\MSI\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - D:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO: Microsoft Web Test Recorder 10.0 Helper: {dda57003-0068-4ed2-9d32-4d1ec707d94d} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll

uRun: [s-Bar] C:\Program Files (x86)\S-Bar\S-Bar.exe

uRun: [Akamai NetSession Interface] "C:\Users\MSI\AppData\Local\Akamai\netsession_win.exe"

uRun: [iDMan] D:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot

mRunOnce: [Malwarebytes Anti-Malware] D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

mRunOnce: [GrpConv] grpconv -o

mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.271\SSScheduler.exe

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\RAINME~1.LNK - C:\Program Files\Rainmeter\Rainmeter.exe

mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableLUA = 0 (0x0)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: PromptOnSecureDesktop = 0 (0x0)

IE: Download all by FlashGet3 - C:\Users\MSI\AppData\Roaming\FlashGetBHO\GetAllUrl.htm

IE: Download all links with IDM - D:\Program Files (x86)\Internet Download Manager\IEGetAll.htm

IE: Download by FlashGet3 - C:\Users\MSI\AppData\Roaming\FlashGetBHO\GetUrl.htm

IE: Download with IDM - D:\Program Files (x86)\Internet Download Manager\IEExt.htm

IE: E&xport to Microsoft Excel - D:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - D:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - D:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - D:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

LSP: pcapwsp.dll

Trusted Zone: kuaiche.com\software

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab

TCP: DhcpNameServer = 192.168.254.254 192.168.1.2

TCP: Interfaces\{59BFC928-3DF8-4F39-AF60-4A96536C71D7} : DhcpNameServer = 192.168.254.254

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746} : DhcpNameServer = 192.168.254.254 192.168.1.2

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746}\0525F4C496E4B4F58453030313E4F56313535623 : DhcpNameServer = 192.168.254.254

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746}\243424D616E63796F6E6 : DhcpNameServer = 192.168.254.254

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746}\265627E6162656 : DhcpNameServer = 192.168.254.254 192.168.1.2

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746}\3464350594352585 : DhcpNameServer = 124.106.6.2 124.106.5.2

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746}\45144545F4F4F5545383630323 : DhcpNameServer = 192.168.0.1 192.168.0.1

TCP: Interfaces\{5F3636B1-1FE8-4EDA-A1C3-A330AB341746}\54475627E6964797 : DhcpNameServer = 192.168.0.1 192.168.0.1

TCP: Interfaces\{75575E7F-3E90-4158-A0D0-93FE0034DDAD} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{888D9EEB-159D-47FC-932A-4C010824D17C} : DhcpNameServer = 192.168.1.1

TCP: Interfaces\{C7C45D09-2B02-4585-AC69-A2A4A0896819} : DhcpNameServer = 10.26.24.1

TCP: Interfaces\{F2CC4522-FFFD-420A-89A4-F1E75E02520D} : DhcpNameServer = 192.168.0.1 192.168.0.1

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL

AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - D:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files (x86)\Internet Download Manager\IDMIECC.dll

BHO-X64: IDM Helper - No File

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL

BHO-X64: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\MSI\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll

BHO-X64: FlashGetBHO - No File

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

BHO-X64: Microsoft Web Test Recorder 10.0 Helper: {DDA57003-0068-4ed2-9D32-4D1EC707D94D} - C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll

mRunOnce-x64: [Malwarebytes Anti-Malware] D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

mRunOnce-x64: [GrpConv] grpconv -o

mRunOnce-x64: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript

AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll

SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\MSI\AppData\Roaming\Mozilla\Firefox\Profiles\kkb5mnmg.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/

FF - prefs.js: network.proxy.ftp - proxy.pointwest.com.ph

FF - prefs.js: network.proxy.ftp_port - 80

FF - prefs.js: network.proxy.http - proxy.pointwest.com.ph

FF - prefs.js: network.proxy.http_port - 80

FF - prefs.js: network.proxy.socks - proxy.pointwest.com.ph

FF - prefs.js: network.proxy.socks_port - 80

FF - prefs.js: network.proxy.ssl - proxy.pointwest.com.ph

FF - prefs.js: network.proxy.ssl_port - 80

FF - prefs.js: network.proxy.type - 0

FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrlui.dll

FF - plugin: C:\Users\MSI\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll

FF - plugin: D:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: D:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin2.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin3.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin4.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin5.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin6.dll

FF - plugin: D:\Program Files (x86)\QuickTime\Plugins\npqtplugin7.dll

.

---- FIREFOX POLICIES ----

FF - user.js: network.http.max-persistent-connections-per-server - 4

FF - user.js: nglayout.initialpaint.delay - 600

FF - user.js: content.notify.interval - 600000

FF - user.js: content.max.tokenizing.time - 1800000

FF - user.js: content.switch.threshold - 600000

.

============= SERVICES / DRIVERS ===============

.

R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]

R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]

R2 HWDeviceService64.exe;HWDeviceService64.exe;C:\ProgramData\DatacardService\HWDeviceService64.exe [2011-3-14 346976]

R2 IDMWFP;IDMWFP;C:\Windows\system32\DRIVERS\idmwfp.sys --> C:\Windows\system32\DRIVERS\idmwfp.sys [?]

R2 Micro Star SCM;Micro Star SCM;C:\Program Files (x86)\S-Bar\MSIService.exe [2011-3-4 160768]

R2 MsDtsServer;SQL Server Integration Services;C:\Program Files (x86)\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [2005-10-14 199384]

R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-12 2348352]

R2 pcapsvc;ProxyCap Service;D:\Program Files\Proxy Labs\ProxyCap\pcapsvc.exe [2012-4-8 2195456]

R2 StarWindServiceAE;StarWind AE Service;D:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-24 370688]

R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;D:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2011-10-20 2072896]

R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]

R3 huawei_enumerator;huawei_enumerator;C:\Windows\system32\DRIVERS\ew_jubusenum.sys --> C:\Windows\system32\DRIVERS\ew_jubusenum.sys [?]

R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]

R3 MBfilt;MBfilt;C:\Windows\system32\drivers\MBfilt64.sys --> C:\Windows\system32\drivers\MBfilt64.sys [?]

R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]

R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]

R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]

R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

R3 SbieDrv;SbieDrv;D:\Program Files\Sandboxie\SbieDrv.sys [2012-4-10 164528]

R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;D:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [2011-10-20 11856]

R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]

S1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 Globe Tattoo Broadband. RunOuc;Globe Tattoo Broadband. OUC;D:\Program Files (x86)\Globe Tattoo Broadband\UpdateDog\ouc.exe [2012-5-2 655712]

S2 MBAMService;MBAMService;D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-24 654408]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-12 257696]

S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;C:\Windows\system32\DRIVERS\ew_hwusbdev.sys --> C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [?]

S3 ew_usbenumfilter;huawei_CompositeFilter;C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys --> C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys [?]

S3 huawei_cdcacm;huawei_cdcacm;C:\Windows\system32\DRIVERS\ew_jucdcacm.sys --> C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [?]

S3 huawei_ext_ctrl;huawei_ext_ctrl;C:\Windows\system32\DRIVERS\ew_juextctrl.sys --> C:\Windows\system32\DRIVERS\ew_juextctrl.sys [?]

S3 huawei_wwanecm;huawei_wwanecm;C:\Windows\system32\DRIVERS\ew_juwwanecm.sys --> C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [?]

S3 massfilter;Mass Storage Filter Driver;C:\Windows\system32\drivers\massfilter.sys --> C:\Windows\system32\drivers\massfilter.sys [?]

S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.271\McCHSvc.exe [2012-3-14 237272]

S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-24 129976]

S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]

S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-1-5 340240]

S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]

S3 NisSrv;NisSrv;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]

S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUVStor.sys --> C:\Windows\system32\Drivers\RtsUVStor.sys [?]

S3 tap0801;TAP-Win32 Adapter V8;C:\Windows\system32\DRIVERS\tap0801.sys --> C:\Windows\system32\DRIVERS\tap0801.sys [?]

S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]

S3 VSPerfDrv100;Performance Tools Driver 10.0;C:\Program Files (x86)\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\x64\VSPerfDrv100.sys [2010-3-17 68440]

S3 ZTEusbnet;ZTE USB-NDIS miniport;C:\Windows\system32\DRIVERS\ZTEusbnet.sys --> C:\Windows\system32\DRIVERS\ZTEusbnet.sys [?]

S4 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-9-3 13336]

S4 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;D:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208]

S4 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-9-3 2656280]

SUnknown 5091624drv;5091624drv; [x]

.

=============== File Associations ===============

.

inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1

VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*

VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*

.

=============== Created Last 30 ================

.

2012-05-24 04:51:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys

2012-05-24 04:47:45 -------- d-----w- C:\ProgramData\McAfee Security Scan

2012-05-24 04:47:37 -------- d-----w- C:\Program Files (x86)\McAfee Security Scan

2012-05-24 04:28:09 98816 ----a-w- C:\Windows\sed.exe

2012-05-24 04:28:09 518144 ----a-w- C:\Windows\SWREG.exe

2012-05-24 04:28:09 256000 ----a-w- C:\Windows\PEV.exe

2012-05-24 04:28:09 208896 ----a-w- C:\Windows\MBR.exe

2012-05-24 04:28:05 -------- d-----w- C:\ComboFix

2012-05-24 03:31:08 -------- d-----w- C:\Program Files\ESET

2012-05-24 02:54:06 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service

2012-05-22 10:39:08 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F83FBE56-C2EB-40A1-B7E2-65EFB351E429}\mpengine.dll

2012-05-15 13:52:04 -------- d-----w- C:\Users\MSI\AppData\Local\ODUI

2012-05-15 13:47:47 -------- d-----w- C:\Users\MSI\AppData\Roaming\Stardock

2012-05-15 13:45:26 -------- d-----w- C:\Users\MSI\AppData\Local\Stardock

2012-05-13 12:54:24 -------- d-----w- C:\Users\MSI\AppData\Local\Vidalia

2012-05-13 12:54:24 -------- d-----w- C:\Users\MSI\AppData\Local\Tor

2012-05-12 16:04:29 -------- d-----w- C:\ProgramData\EPS

2012-05-12 13:55:39 -------- d-----w- C:\ProgramData\Trymedia

2012-05-12 13:55:35 -------- d-----w- C:\Users\MSI\AppData\Roaming\Wildfire

2012-05-12 13:53:27 -------- d-----w- C:\Program Files (x86)\RealArcade

2012-05-12 10:11:32 -------- d-----w- C:\Users\MSI\AppData\Roaming\XWindows Dock

2012-05-12 03:11:17 -------- d-----w- C:\Users\MSI\AppData\Roaming\Rainmeter

2012-05-12 03:10:25 -------- d-----w- C:\Program Files\Rainmeter

2012-05-11 18:39:09 -------- d-----w- C:\Users\MSI\AppData\Roaming\tor

2012-05-02 07:18:39 98304 ----a-w- C:\Windows\System32\drivers\ew_jucdcacm.sys

2012-05-02 07:18:39 87040 ----a-w- C:\Windows\System32\drivers\ew_jubusenum.sys

2012-05-02 07:18:39 72192 ----a-w- C:\Windows\System32\drivers\ew_jucdcecm.sys

2012-05-02 07:18:39 421888 ----a-w- C:\Windows\System32\drivers\ewusbwwan.sys

2012-05-02 07:18:39 32768 ----a-w- C:\Windows\System32\drivers\ewdcsc.sys

2012-05-02 07:18:39 28672 ----a-w- C:\Windows\System32\drivers\ew_juextctrl.sys

2012-05-02 07:18:39 223744 ----a-w- C:\Windows\System32\drivers\ew_juwwanecm.sys

2012-05-02 07:18:39 223232 ----a-w- C:\Windows\System32\drivers\ewusbmdm.sys

2012-05-02 07:18:39 22016 ----a-w- C:\Windows\System32\drivers\ew_hwupgrade.sys

2012-05-02 07:18:39 13952 ----a-w- C:\Windows\System32\drivers\ew_usbenumfilter.sys

2012-05-02 07:18:39 117248 ----a-w- C:\Windows\System32\drivers\ew_hwusbdev.sys

2012-05-02 07:18:39 1001472 ----a-w- C:\Windows\System32\drivers\mod7700.sys

2012-04-28 11:58:15 -------- d-----r- C:\Sandbox

2012-04-28 11:19:05 -------- d-----w- C:\ProgramData\Insight Software Solutions

2012-04-28 11:18:53 -------- d-----w- C:\Program Files (x86)\Common Files\Insight Software Solutions

2012-04-28 11:18:42 -------- d-----w- C:\Program Files (x86)\Macro Express3

.

==================== Find3M ====================

.

2012-05-05 07:22:14 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-05-05 07:22:14 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-05-05 07:21:58 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2012-05-02 07:18:08 1490656 ----a-w- C:\Windows\System32\WdfCoInstaller01007.dll

2012-05-02 07:18:08 1490656 ----a-w- C:\Windows\System32\drivers\WdfCoInstaller01007.dll

2012-04-07 17:28:50 653824 ----a-w- C:\Windows\System32\pcapwsp.dll

2012-04-07 17:28:40 536576 ----a-w- C:\Windows\SysWow64\pcapwsp.dll

2012-04-07 17:26:42 315392 ----a-w- C:\Windows\SysWow64\sbcrreag.dll

2012-04-07 17:25:48 356352 ----a-w- C:\Windows\System32\sbcrreag.dll

2012-03-11 17:34:29 43520 ----a-w- C:\Windows\SysWow64\CmdLineExt03.dll

2011-10-30 13:38:27 2169856 --sha-w- C:\Windows\System32\hale.exe

.

============= FINISH: 21:13:31.75 ===============

Link to post
Share on other sites

:welcome:

Please do the following to see if it resolves the issue: Post back and let us know please


  • Download and run mbam-clean.exe from here
  • It will ask to restart your computer, please allow it to do so very important
  • After the computer restarts, temporarily disable your Anti-Virus and install the latest version of Malwarebytes' Anti-Malware from here

    • Note: You will need to reactivate the program using the license you were sent via email if using the Pro version
    • Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
      Restart the computer again and verify that MBAM is in the task tray if using the Pro version. Now setup any file exclusions as may be required in your Anti-Virus/Internet-Security/Firewall applications and restart your Anti-Virus/Internet-Security applications. You may use the guides posted in the FAQ's here or ask and we'll explain how to do it.

Link to post
Share on other sites

:welcome:

Please do the following to see if it resolves the issue: Post back and let us know please

  • Download and run mbam-clean.exe from here
  • It will ask to restart your computer, please allow it to do so very important
  • After the computer restarts, temporarily disable your Anti-Virus and install the latest version of Malwarebytes' Anti-Malware from here
    • Note: You will need to reactivate the program using the license you were sent via email if using the Pro version
    • Launch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.
      Restart the computer again and verify that MBAM is in the task tray if using the Pro version. Now setup any file exclusions as may be required in your Anti-Virus/Internet-Security/Firewall applications and restart your Anti-Virus/Internet-Security applications. You may use the guides posted in the FAQ's here or ask and we'll explain how to do it.

i did all your instructions but i still have the same error, PROGRAM_ERROR_PROTECTION_MODULE (1086, 0,ProtectionEnable)

Link to post
Share on other sites

MBAM isn't a anti-virus program, it's a anti-malware program.

It isn't made to replace a anti-virus.

Only run one Anti-Virus at a time.

Use an AntiVirus Software - Choose only one - More than one will conflict. It is very important that your computer has anti-virus software running to protect against viruses. Update Antivirus prior to manual scans as necessary or as used. Please only choose one, having more than one can cause problems, such as crashes and your computer to slow down.

Run a full scan and let us know what it finds

Also please describe how your computer behaves at the moment

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.