Jump to content

Runtime errors during install


Recommended Posts

I'm working on a friend's laptop which has been infected with Antivirus 360. With what is looking to be minimal success, i've tried running scans with Webroot Spy Sweeper, PC Tool Spy Doctor, and Spybot S&D. It seems to be removing some files because each scan comes back a bit better. However, Spy Sweeper still blocking connections to known spyware sites. The list (which seems to be a long one) is moving alphabetically and is in the S's now. Not sure if any of this is useful information, but i'm trying to provide any details I can. Also, I tried to perform a system restore with no luck.

Also, when attempting to install Malwarebytes, I receive RTE's at several points during the installation. After the installation completes I get the same RTE's. Screenshots can be provided if necessary. Run-Time error 0 and Run-Time error 440 Automation Error

Here is my Hi-Jack This log...

Any help will be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 6:23:37 PM, on 3/6/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

C:\WINDOWS\system32\DVDRAMSV.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Spyware Doctor\pctsTray.exe

c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Viewpoint\Common\ViewpointService.exe

C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

C:\Program Files\Windows Media Player\WMPNetwk.exe

C:\WINDOWS\ehome\mcrdsvc.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe

C:\Program Files\Synaptics\SynTP\Toshiba.exe

C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\WINDOWS\System32\DLA\DLACTRLW.EXE

C:\WINDOWS\system32\igfxext.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Protector Suite QL\psqltray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe

C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\RAMASST.exe

C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe

C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

C:\Program Files\Webroot\WebrootSecurity\SSU.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ndscs.nodak.edu/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"

O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "CHDAudPropShortcut.exe"

O4 - HKLM\..\Run: [synTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"

O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en

O4 - HKLM\..\Run: [smoothView] "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe"

O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"

O4 - HKLM\..\Run: [igfxtray] "C:\WINDOWS\system32\igfxtray.exe"

O4 - HKLM\..\Run: [igfxhkcmd] "C:\WINDOWS\system32\hkcmd.exe"

O4 - HKLM\..\Run: [igfxpers] "C:\WINDOWS\system32\igfxpers.exe"

O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"

O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless

O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup

O4 - HKLM\..\Run: [KernelFaultCheck] "%systemroot%\system32\dumprep" 0 -k

O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray

O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"

O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"

O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe

O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\TOSHIBA Game Console\GameConsoleService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

O24 - Desktop Component 1: (no name) - http://gamercard.xbox.com/Chief%20Shake.card

--

End of file - 10406 bytes

Link to post
Share on other sites

  • Root Admin

STEP 01

Please visit this webpage for instructions for downloading ComboFix to your
DESKTOP
:
how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

NOTE!!:

You must save and run
ComboFix.exe
on your DESKTOP and not from any other folder.

Also,
DO NOT
click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:

Note:

The
Windows Recovery Console
will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click
    Yes
    to allow ComboFix to continue scanning for malware.

  • When the tool is finished, it will produce a report for you.

  • Please post the
    C:\ComboFix.txt
    along with a
    new HijackThis log
    so we may continue cleaning the system.

STEP 02

Download
DDS
and save it to your desktop

Disable any script blocker if your Anti-Virus/Anti-Malware has it.

Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.

Then double click
dds.scr
to run the tool.

When done, the
DDS.txt
will open.

Click Yes at the next prompt for Optional Scan.
    When done, DDS will open two (2) logs:

  1. DDS.txt
  2. Attach.txt

  • Save both reports to your desktop
  • Please include the following logs in your next reply:
    DDS.txt
    and
    Attach.txt

STEP 03

    Please create a BOOTLOG
  • Restart the computer and press F8 when Windows start booting. This will bring up the startup options.
  • Select "Enable Boot Logging" option and press enter.
  • Windows prompts you to select a Windows Installation (even if there is only one windows installation)
  • This boots windows normally and creates a boot log named ntbtlog.txt and saves it to C:\Windows
    If you're already running inside Windows you can enable it the following way.
  • Click on START - RUN and type in MSCONFIG go to the BOOT.INI tab and place a check mark by /BOOTLOG
  • Click on OK and you will be prompted to RESTART Windows. Please do restart now.
  • After Windows restarts open the file C:\Windows\ntbtlog.txt with Notepad
  • From the Edit menu choose Select All then Edit, COPY and post that back on your next reply.
Link to post
Share on other sites

  • Root Admin

Yep, no problem with the attachment on large logs. Just don't want them normally as it takes more time to review them.

You need to uninstall and remove the followowing P2P file sharing software if you want us to continue to assist you in cleaning your system.

Often P2P is how users get infected and its a losing situation trying to help you with this software installed.

File sharing involves using technology that allows internet users to share files that are housed on their individual computers. Peer-to-peer (P2P) applications, such as those used to share music files, are some of the most common forms of file-sharing technology. However, P2P applications introduce security risks that may put your information or your computer in jeopardy.

Risks of File-Sharing Technology

BitComet 0.70

LimeWire 5.0.11

The following software is OLD and has exploited code and needs to be removed and then updated to the latest versions.

A lot of Malware takes advantage of the exploits in the code to get on your system.

J2SE Development Kit 5.0 Update 7

J2SE Runtime Environment 5.0 Update 10

J2SE Runtime Environment 5.0 Update 7

Java DB 10.3.1.4

Java™ 6 Update 11

Java™ 6 Update 3

Java™ 6 Update 5

Java™ 6 Update 7

Java™ SE Development Kit 6

Java™ SE Development Kit 6 Update 7

Java™ SE Runtime Environment 6

Java™ SE Runtime Environment 6 Update 1

This software is also old and exploited and needs to be updated

Update available for vulnerability in versions 8.1 and earlier of Adobe Reader and Acrobat

Adobe Reader 7.1.0

Adobe now own this Company for a long time now - just remove this and use the current Adobe version

Macromedia Flash Player 8

This is not Malware. It is called Foistware because it is often installed without the users knowledge.

Its up to you if you want to remove it or not, I would myself but you do not have to.

Viewpoint Media Player

Please download Lop S&D

Double-click on Lop S&D.exe

Choose the language, then choose Option 1 (Search)

Wait till the end of the scan

Post the log which is created: (%SystemDrive%\lopR.txt), typcially C:\lopR.txt

Please let me know when the above is done and ready and we can proceed.

Link to post
Share on other sites

Ok, Java SDK's are gone as well as the other items.

Here is the log...

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2

X86-based PC ( Multiprocessor Free : Genuine Intel® CPU T2300 @ 1.66GHz )

BIOS : PhoenixBIOS 4.0 Release 6.1

USER : Noel ( Administrator )

BOOT : Normal boot

C:\ (Local Disk) - NTFS - Total:111 Go (Free:54 Go)

D:\ (CD or DVD)

E:\ (USB) - FAT32 - Total:1907 Mo (Free:1 Go)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )

Option : [1] ( Sat 03/07/2009|21:34 )

--------------------\\ Listing folders in APPLIC~1

[05/11/2006|12:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe

[07/13/2006|04:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> AOL

[03/02/2006|03:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities

[07/12/2006|11:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Intel

[03/03/2006|12:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InterVideo

[03/02/2006|05:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Intuit

[03/02/2006|03:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft

[03/02/2006|06:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> toshiba

[03/02/2006|06:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> You've Got Pictures Screensaver

[11/30/2008|08:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}

[12/01/2008|02:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> acccore

[02/29/2008|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL

[12/01/2008|02:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL Downloads

[02/13/2008|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL OCP

[07/07/2007|10:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple

[10/14/2006|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer

[03/02/2006|05:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DIGStream

[07/12/2006|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel

[03/02/2006|05:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intuit

[04/02/2009|04:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes

[07/12/2006|11:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com

[09/09/2008|04:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft

[09/29/2008|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help

[08/23/2006|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Otto

[04/02/2009|05:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC Tools

[03/02/2006|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pure Networks

[03/02/2006|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime

[03/06/2009|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy

[03/07/2009|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP

[05/06/2008|01:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TuneUp Software

[03/07/2009|09:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint

[04/02/2009|01:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Webroot

[07/12/2006|07:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WildTangent

[07/13/2006|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage

[02/05/2007|10:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Live Toolbar

[03/06/2008|01:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WLInstaller

[05/11/2006|12:56] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe

[07/13/2006|04:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> AOL

[03/02/2006|03:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities

[07/12/2006|11:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Intel

[03/03/2006|12:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InterVideo

[03/02/2006|05:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Intuit

[03/02/2006|03:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft

[03/02/2006|06:29] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> toshiba

[03/02/2006|06:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> You've Got Pictures Screensaver

[03/02/2006|03:32] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

[03/02/2006|03:32] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

[02/13/2008|03:18] C:\DOCUME~1\Noel\APPLIC~1\<DIR> acccore

[08/31/2006|10:33] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Adobe

[07/11/2008|05:55] C:\DOCUME~1\Noel\APPLIC~1\<DIR> AdobeUM

[02/18/2008|06:54] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Aim

[07/13/2006|04:57] C:\DOCUME~1\Noel\APPLIC~1\<DIR> AOL

[07/12/2008|11:27] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Apple Computer

[08/18/2006|07:16] C:\DOCUME~1\Noel\APPLIC~1\<DIR> CiscoCAA

[03/29/2009|11:30] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Deusty

[08/03/2008|11:11] C:\DOCUME~1\Noel\APPLIC~1\<DIR> DivX

[03/31/2009|09:55] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Hamachi

[08/09/2007|07:03] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Help

[03/02/2006|03:28] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Identities

[07/12/2006|11:27] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Intel

[03/03/2006|12:22] C:\DOCUME~1\Noel\APPLIC~1\<DIR> InterVideo

[03/02/2006|05:54] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Intuit

[07/12/2006|08:13] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Macromedia

[08/25/2008|07:02] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Microsoft

[06/23/2008|06:01] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Mozilla

[07/12/2006|05:01] C:\DOCUME~1\Noel\APPLIC~1\<DIR> MSNInstaller

[07/12/2006|04:18] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Opera

[08/23/2006|12:56] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Otto

[04/02/2009|05:31] C:\DOCUME~1\Noel\APPLIC~1\<DIR> PC Tools

[07/13/2006|12:47] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Protector Suite

[12/25/2008|04:30] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Simple Sudoku

[12/26/2007|11:22] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Sony Corporation

[09/22/2008|08:34] C:\DOCUME~1\Noel\APPLIC~1\<DIR> SpeedSim

[09/21/2006|10:11] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Sun

[10/11/2006|09:10] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Template

[04/02/2007|11:43] C:\DOCUME~1\Noel\APPLIC~1\<DIR> TextPad

[07/13/2006|02:00] C:\DOCUME~1\Noel\APPLIC~1\<DIR> toshiba

[09/03/2006|01:49] C:\DOCUME~1\Noel\APPLIC~1\<DIR> TuneUp Software

[03/05/2007|07:52] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Ventrilo

[04/02/2009|01:31] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Webroot

[07/12/2006|07:39] C:\DOCUME~1\Noel\APPLIC~1\<DIR> WildTangent

[03/02/2006|06:03] C:\DOCUME~1\Noel\APPLIC~1\<DIR> You've Got Pictures Screensaver

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[04/03/2009 05:59 AM][--a------] C:\WINDOWS\tasks\wrSpySweeper_L540A79C9BBCA46128C9F6AB7C009C481.job

[03/18/2009 08:32 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job

[04/03/2009 04:17 PM][--a------] C:\WINDOWS\tasks\1-Click Maintenance.job

[07/12/2006 11:27 PM][--a------] C:\WINDOWS\tasks\Registration reminder 2.job

[03/07/2009 10:24 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT

[08/10/2004 06:00 AM][-r-h-c---] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[03/02/2006|05:36] C:\Program Files\<DIR> Adobe

[02/18/2008|06:54] C:\Program Files\<DIR> AIM

[03/30/2009|12:01] C:\Program Files\<DIR> AIM Toolbar

[12/01/2008|02:34] C:\Program Files\<DIR> AIM6

[01/02/2008|01:02] C:\Program Files\<DIR> AOD

[08/11/2008|07:05] C:\Program Files\<DIR> Apple Software Update

[03/02/2006|05:40] C:\Program Files\<DIR> ArcSoft

[07/12/2006|11:28] C:\Program Files\<DIR> AVerMedia

[07/04/2007|07:38] C:\Program Files\<DIR> AWS

[03/07/2009|09:08] C:\Program Files\<DIR> BitComet

[03/18/2009|10:35] C:\Program Files\<DIR> Bonjour

[03/07/2009|09:29] C:\Program Files\<DIR> Common Files

[03/02/2006|03:24] C:\Program Files\<DIR> ComPlus Applications

[03/02/2006|04:23] C:\Program Files\<DIR> CONEXANT

[07/30/2008|07:00] C:\Program Files\<DIR> Diablo II

[04/02/2009|08:39] C:\Program Files\<DIR> DIGStream

[03/02/2006|04:23] C:\Program Files\<DIR> DVD-RAM

[08/04/2008|06:50] C:\Program Files\<DIR> DVDVideoSoft

[09/06/2006|11:12] C:\Program Files\<DIR> ElcomSoft

[07/18/2008|03:21] C:\Program Files\<DIR> EnglishOtto

[07/18/2008|03:21] C:\Program Files\<DIR> ESPNMotion

[08/25/2008|10:14] C:\Program Files\<DIR> Frets on Fire

[07/18/2008|03:21] C:\Program Files\<DIR> GemMaster

[07/13/2006|12:30] C:\Program Files\<DIR> Google

[03/02/2006|06:04] C:\Program Files\<DIR> illiminable

[09/09/2008|05:03] C:\Program Files\<DIR> InstallShield Installation Information

[07/12/2006|11:27] C:\Program Files\<DIR> Intel

[08/14/2008|02:03] C:\Program Files\<DIR> Internet Explorer

[03/02/2006|05:50] C:\Program Files\<DIR> InterVideo

[11/30/2008|08:27] C:\Program Files\<DIR> iPod

[11/30/2008|08:27] C:\Program Files\<DIR> iTunes

[03/07/2009|09:27] C:\Program Files\<DIR> Java

[03/07/2009|09:08] C:\Program Files\<DIR> LimeWire

[03/06/2009|06:39] C:\Program Files\<DIR> Malwarebytes' Anti-Malware

[03/02/2006|05:50] C:\Program Files\<DIR> McAfee.com

[08/14/2008|02:06] C:\Program Files\<DIR> Messenger

[03/02/2006|05:03] C:\Program Files\<DIR> Metamail Inc

[03/02/2006|03:42] C:\Program Files\<DIR> Microsoft ActiveSync

[03/02/2006|03:29] C:\Program Files\<DIR> microsoft frontpage

[08/25/2008|06:52] C:\Program Files\<DIR> Microsoft Office

[09/07/2008|08:46] C:\Program Files\<DIR> Microsoft Silverlight

[08/25/2008|06:52] C:\Program Files\<DIR> Microsoft Works

[03/02/2006|03:41] C:\Program Files\<DIR> Microsoft.NET

[03/02/2006|03:26] C:\Program Files\<DIR> Movie Maker

[03/07/2009|03:42] C:\Program Files\<DIR> Mozilla Firefox

[07/12/2006|04:52] C:\Program Files\<DIR> MSN

[03/02/2006|03:23] C:\Program Files\<DIR> MSN Gaming Zone

[04/02/2009|01:31] C:\Program Files\<DIR> MSSOAP

[11/18/2006|03:01] C:\Program Files\<DIR> MSXML 4.0

[08/24/2007|10:11] C:\Program Files\<DIR> netbeans-5.0

[03/02/2006|03:26] C:\Program Files\<DIR> NetMeeting

[03/02/2006|03:26] C:\Program Files\<DIR> Online Services

[12/01/2008|04:00] C:\Program Files\<DIR> Opera

[06/12/2007|11:53] C:\Program Files\<DIR> Outlook Express

[05/20/2008|08:25] C:\Program Files\<DIR> PokerStars

[07/18/2008|03:21] C:\Program Files\<DIR> Protector Suite QL

[07/13/2006|05:03] C:\Program Files\<DIR> Pure Networks

[07/18/2008|03:21] C:\Program Files\<DIR> Quicken

[11/30/2008|08:25] C:\Program Files\<DIR> QuickTime

[02/05/2007|10:04] C:\Program Files\<DIR> Real

[11/19/2008|07:37] C:\Program Files\<DIR> Research In Motion

[07/18/2008|03:21] C:\Program Files\<DIR> RGB

[08/09/2007|07:03] C:\Program Files\<DIR> Simple Sudoku

[03/02/2006|05:56] C:\Program Files\<DIR> Sonic

[12/26/2007|11:13] C:\Program Files\<DIR> Sony

[11/28/2008|04:38] C:\Program Files\<DIR> SpeedSim

[03/06/2009|06:02] C:\Program Files\<DIR> Spybot - Search & Destroy

[03/06/2009|06:02] C:\Program Files\<DIR> Spyware Doctor

[11/08/2008|10:19] C:\Program Files\<DIR> Stardock

[09/14/2008|05:50] C:\Program Files\<DIR> Sun

[03/02/2006|04:29] C:\Program Files\<DIR> Synaptics

[08/28/2006|11:52] C:\Program Files\<DIR> TextPad 4

[09/14/2008|05:32] C:\Program Files\<DIR> TextPad 5

[07/12/2006|07:37] C:\Program Files\<DIR> Toshiba

[03/11/2008|12:30] C:\Program Files\<DIR> Toshiba Games

[03/06/2009|06:23] C:\Program Files\<DIR> Trend Micro

[12/25/2008|10:19] C:\Program Files\<DIR> TuneUp Utilities 2008

[03/02/2006|03:33] C:\Program Files\<DIR> Uninstall Information

[11/21/2007|12:37] C:\Program Files\<DIR> VentSrv

[04/14/2007|10:22] C:\Program Files\<DIR> Warcraft III

[04/02/2009|01:31] C:\Program Files\<DIR> Webroot

[03/02/2006|04:54] C:\Program Files\<DIR> WildTangent

[03/06/2008|01:52] C:\Program Files\<DIR> Windows Live

[02/05/2007|10:06] C:\Program Files\<DIR> Windows Live Toolbar

[07/18/2008|03:21] C:\Program Files\<DIR> Windows Media Connect 2

[04/22/2008|01:01] C:\Program Files\<DIR> Windows Media Player

[03/02/2006|03:23] C:\Program Files\<DIR> Windows NT

[03/02/2006|03:24] C:\Program Files\<DIR> Windows Plus

[03/02/2006|03:26] C:\Program Files\<DIR> WindowsUpdate

[03/02/2006|03:29] C:\Program Files\<DIR> xerox

[03/02/2006|06:04] C:\Program Files\<DIR> Yahoo!

--------------------\\ Listing Folders in C:\Program Files\Common Files

[02/14/2008|12:03] C:\Program Files\Common Files\<DIR> AOL

[11/30/2008|08:27] C:\Program Files\Common Files\<DIR> Apple

[03/12/2008|10:22] C:\Program Files\Common Files\<DIR> Blizzard Entertainment

[03/02/2006|03:41] C:\Program Files\Common Files\<DIR> DESIGNER

[08/04/2008|06:45] C:\Program Files\Common Files\<DIR> DVDVideoSoft

[09/22/2006|12:18] C:\Program Files\Common Files\<DIR> InstallShield

[03/02/2006|05:50] C:\Program Files\Common Files\<DIR> InterVideo

[03/02/2006|05:54] C:\Program Files\Common Files\<DIR> Intuit

[08/25/2008|06:55] C:\Program Files\Common Files\<DIR> Microsoft Shared

[03/02/2006|03:26] C:\Program Files\Common Files\<DIR> MSSoap

[03/02/2006|06:03] C:\Program Files\Common Files\<DIR> Nullsoft

[03/02/2006|07:19] C:\Program Files\Common Files\<DIR> ODBC

[03/02/2006|05:54] C:\Program Files\Common Files\<DIR> Palo Alto Software

[04/02/2009|05:34] C:\Program Files\Common Files\<DIR> PC Tools

[07/12/2006|11:29] C:\Program Files\Common Files\<DIR> Protector Suite QL

[08/30/2006|09:45] C:\Program Files\Common Files\<DIR> Real

[03/02/2006|03:26] C:\Program Files\Common Files\<DIR> Services

[03/02/2006|07:19] C:\Program Files\Common Files\<DIR> SpeechEngines

[11/08/2008|10:19] C:\Program Files\Common Files\<DIR> Stardock

[04/02/2009|10:59] C:\Program Files\Common Files\<DIR> Symantec Shared

[03/07/2009|09:45] C:\Program Files\Common Files\<DIR> System

[03/06/2008|01:50] C:\Program Files\Common Files\<DIR> WindowsLiveInstaller

[07/06/2008|09:48] C:\Program Files\Common Files\<DIR> Wise Installation Wizard

--------------------\\ Process

( 56 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN

--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-07 21:36:07

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden files ...

scan completed successfully

hidden processes: 0

hidden files: 0

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\Noel\Application Data\Opera\Opera\profile\images\www.crack.ms.ico

C:\DOCUME~1\Noel\Application Data\Opera\Opera\profile\images\www.crackpassword.com.ico

[F:28][D:5]-> C:\DOCUME~1\Noel\LOCALS~1\Temp

[F:15][D:0]-> C:\DOCUME~1\Noel\Cookies

[F:72][D:7]-> C:\DOCUME~1\Noel\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sat 03/07/2009|21:38 - Option : [1]

--------------------\\ Scan completed at 21:38:07

Link to post
Share on other sites

Service Pack 2 3 7 2009 22:50:33.359

Loaded driver \WINDOWS\system32\ntoskrnl.exe

Loaded driver \WINDOWS\system32\hal.dll

Loaded driver \WINDOWS\system32\KDCOM.DLL

Loaded driver \WINDOWS\system32\BOOTVID.dll

Loaded driver ACPI.sys

Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS

Loaded driver pci.sys

Loaded driver isapnp.sys

Loaded driver ohci1394.sys

Loaded driver \WINDOWS\system32\DRIVERS\1394BUS.SYS

Loaded driver sshrmd.sys

Loaded driver ssfs0bbc.sys

Loaded driver ssidrv.sys

Loaded driver \WINDOWS\system32\DRIVERS\NDIS.SYS

Loaded driver \WINDOWS\system32\DRIVERS\TDI.SYS

Loaded driver compbatt.sys

Loaded driver \WINDOWS\system32\DRIVERS\BATTC.SYS

Loaded driver pciide.sys

Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS

Loaded driver pcmcia.sys

Loaded driver MountMgr.sys

Loaded driver ftdisk.sys

Loaded driver dmload.sys

Loaded driver dmio.sys

Loaded driver ACPIEC.sys

Loaded driver \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS

Loaded driver PartMgr.sys

Loaded driver VolSnap.sys

Loaded driver atapi.sys

Loaded driver disk.sys

Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS

Loaded driver fltMgr.sys

Loaded driver sr.sys

Loaded driver PCTCore.sys

Loaded driver DRVMCDB.SYS

Loaded driver PxHelp20.sys

Loaded driver KSecDD.sys

Loaded driver Ntfs.sys

Loaded driver Mup.sys

Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys

Loaded driver \SystemRoot\system32\DRIVERS\ialmnt5.sys

Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys

Loaded driver \SystemRoot\system32\DRIVERS\w39n51.sys

Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys

Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys

Loaded driver \SystemRoot\system32\drivers\tifm21.sys

Loaded driver \SystemRoot\system32\DRIVERS\sdbus.sys

Loaded driver \SystemRoot\system32\DRIVERS\e100b325.sys

Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys

Loaded driver \SystemRoot\System32\Drivers\sskbfd.sys

Loaded driver \SystemRoot\system32\drivers\qkbfiltr.sys

Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys

Loaded driver \SystemRoot\system32\drivers\qmofiltr.sys

Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys

Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys

Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys

Loaded driver \SystemRoot\system32\drivers\iviaspi.sys

Loaded driver \SystemRoot\system32\drivers\pfc.sys

Loaded driver \SystemRoot\System32\Drivers\DLACDBHM.SYS

Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys

Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys

Loaded driver \SystemRoot\System32\Drivers\GEARAspiWDM.sys

Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys

Loaded driver \SystemRoot\system32\DRIVERS\wmiacpi.sys

Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys

Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys

Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys

Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys

Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys

Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys

Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys

Loaded driver \SystemRoot\system32\DRIVERS\psched.sys

Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys

Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys

Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys

Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys

Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys

Loaded driver \SystemRoot\system32\DRIVERS\update.sys

Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys

Loaded driver \SystemRoot\system32\drivers\BoiHwSetup.sys

Loaded driver \SystemRoot\system32\DRIVERS\tbiosdrv.sys

Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS

Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS

Loaded driver \SystemRoot\system32\drivers\CHDAud.sys

Loaded driver \SystemRoot\system32\DRIVERS\HSFHWAZL.sys

Loaded driver \SystemRoot\system32\DRIVERS\HSF_DPV.sys

Loaded driver \SystemRoot\system32\DRIVERS\HSF_CNXT.sys

Loaded driver \SystemRoot\System32\Drivers\Modem.SYS

Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys

Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS

Did not load driver \SystemRoot\System32\Drivers\Fdc.SYS

Did not load driver \SystemRoot\System32\Drivers\Flpydisk.SYS

Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS

Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS

Did not load driver \SystemRoot\System32\Drivers\Changer.SYS

Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS

Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS

Loaded driver \SystemRoot\System32\Drivers\Null.SYS

Loaded driver \SystemRoot\System32\Drivers\Beep.SYS

Loaded driver \SystemRoot\System32\Drivers\DLARTL_N.SYS

Did not load driver \SystemRoot\system32\DRIVERS\kbdhid.sys

Loaded driver \SystemRoot\System32\drivers\vga.sys

Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS

Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys

Loaded driver \SystemRoot\System32\Drivers\Udfs.SYS

Loaded driver \SystemRoot\System32\Drivers\meiudf.sys

Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS

Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS

Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys

Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys

Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys

Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys

Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys

Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys

Loaded driver \SystemRoot\System32\drivers\afd.sys

Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys

Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS

Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys

Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys

Loaded driver \SystemRoot\System32\Drivers\Fips.SYS

Loaded driver \SystemRoot\System32\Drivers\tcusb.sys

Loaded driver \??\C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys

Loaded driver \??\C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys

Loaded driver \SystemRoot\System32\Drivers\DRVNDDM.SYS

Loaded driver \SystemRoot\System32\DLA\DLADResN.SYS

Loaded driver \SystemRoot\System32\DLA\DLAIFS_M.SYS

Loaded driver \SystemRoot\System32\DLA\DLAOPIOM.SYS

Loaded driver \SystemRoot\System32\DLA\DLAPoolM.SYS

Loaded driver \??\C:\Program Files\Protector Suite QL\smihlp.sys

Loaded driver \SystemRoot\System32\DLA\DLABOIOM.SYS

Loaded driver \SystemRoot\System32\DLA\DLAUDFAM.SYS

Loaded driver \SystemRoot\System32\DLA\DLAUDF_M.SYS

Loaded driver \SystemRoot\system32\DRIVERS\AegisP.sys

Loaded driver \SystemRoot\system32\DRIVERS\s24trans.sys

Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys

Loaded driver \SystemRoot\system32\DRIVERS\netdevio.sys

Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys

Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys

Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys

Did not load driver \SystemRoot\System32\Drivers\Serial.SYS

Loaded driver \SystemRoot\System32\Drivers\HTTP.sys

Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys

Loaded driver \SystemRoot\system32\DRIVERS\srv.sys

Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys

Loaded driver \SystemRoot\system32\drivers\wdmaud.sys

Loaded driver \SystemRoot\system32\drivers\sysaudio.sys

Loaded driver \SystemRoot\system32\drivers\splitter.sys

Loaded driver \SystemRoot\system32\drivers\aec.sys

Loaded driver \SystemRoot\system32\drivers\swmidi.sys

Loaded driver \SystemRoot\system32\drivers\DMusic.sys

Loaded driver \SystemRoot\system32\drivers\kmixer.sys

Loaded driver \SystemRoot\system32\drivers\drmkaud.sys

Loaded driver \SystemRoot\system32\DRIVERS\USBSTOR.SYS

Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS

Link to post
Share on other sites

  • Root Admin

Well current logs don't show anything obvious.

Please try the following and let me know if you have trouble with it, otherwise post back it's log.

Update and Scan with Malwarebytes' Anti-Malware

  • Start MalwareBytes AntiMalware (Vista users must Right click and choose RunAs Admin)
  • Please DO NOT run MBAM in Safe Mode unless requested to, you MUST run it in normal Windows mode.
    • Update Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Update

    [*]When the update is complete, select the Scanner tab

    [*]Select Perform quick scan, then click Scan.

    [*]When the scan is complete, click OK, then Show Results to view the results.

    [*]Be sure that everything is checked, and click Remove Selected.

    [*]When completed, a log will open in Notepad. please copy and paste the log into your next reply

    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Then post back the MBAM log and a new Hijackthis log.

Link to post
Share on other sites

  • Root Admin

Okay just another update that the code is now functional and probably at about 98% completion for an Alternate installer for MBAM.

I still need to clean up some debug code and polish it up a bit for normal users to use it and then I'll post you a link for it to try out.

NOTES:

1. This is NOT for use by everyone and should ONLY be used by users that appear to have a CLEAN system but are still having issues installing MBAM.

2. It will only run on English Windows XP 32 Bit.

3. If it does work and you can now scan with the program you should update and do a scan, then remove it and do an install with the normal PUBLISHED program from Malwarebytes.

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.