Jump to content

Malwarebytes crashing


Recommended Posts

Tried to run malwarebytes to detect malware. Program will open, begin scan and close. Followed instructions on "I'm infected - What do I do now" page. Logs follow:

DDS (Ver_09-12-01.01) - NTFSx86

Run by User1 at 23:58:34.61 on Thu 01/28/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.232 [GMT -5:00]

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

c:\program files\a-squared free\a2service.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\WINDOWS\System32\svchost.exe -k imgsvc

C:\WINDOWS\System32\wbem\wmiapsrv.exe

C:\Program Files\Apoint\Apoint.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\Apoint\HidFind.exe

C:\Program Files\Apoint\Apntex.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Program Files\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\User1\My Documents\Downloads\Defogger.exe

C:\Documents and Settings\User1\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.aol.com/

uInternet Settings,ProxyOverride = *.local

uURLSearchHooks: Conservative Talk Radio Toolbar: {717311b3-2725-4092-ad7a-d18e6c98fde0} - c:\program files\conservative_talk_radio\tbCons.dll

mURLSearchHooks: H - No File

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll

BHO: Conservative Talk Radio Toolbar: {717311b3-2725-4092-ad7a-d18e6c98fde0} - c:\program files\conservative_talk_radio\tbCons.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: ZoneAlarm Spy Blocker BHO: {f0d4b231-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL

TB: ZoneAlarm Spy Blocker: {f0d4b239-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL

TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File

TB: Conservative Talk Radio Toolbar: {717311b3-2725-4092-ad7a-d18e6c98fde0} - c:\program files\conservative_talk_radio\tbCons.dll

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

mRun: [Apoint] c:\program files\apoint\Apoint.exe

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

uPolicies-explorer: NoRecentDocsNetHood = 01000000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

Notify: AtiExtEvent - Ati2evxx.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2007-7-6 226424]

R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-1-28 38224]

S2 gupdate1c983bf5b254ed0;Google Update Service (gupdate1c983bf5b254ed0);c:\program files\google\update\GoogleUpdate.exe [2009-1-31 133104]

=============== Created Last 30 ================

2010-01-29 04:56:29 0 ----a-w- c:\documents and settings\user1\defogger_reenable

2010-01-29 04:43:21 0 d-----w- c:\docume~1\user1\applic~1\Malwarebytes

2010-01-29 04:43:16 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-01-29 04:43:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-01-29 04:43:14 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-01-29 04:43:14 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-01-29 03:40:22 0 d-sh--w- c:\documents and settings\user1\IECompatCache

2010-01-28 01:12:05 411368 ----a-w- c:\windows\system32\deploytk.dll

==================== Find3M ====================

2007-04-16 15:52:53 29184 -c--a-w- c:\program files\csvh.dat

============= FINISH: 23:59:27.04 ===============

ark.zip

Link to post
Share on other sites

Hello derrahlynn, and welcome to the forums here at Malwarebytes.org ;)

Please post your log here:

http://www.malwarebytes.org/forums/index.php?showforum=7

And someone will be happy to assist you when someone is available.

Thank you ;)

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.