Jump to content

Infected and can't run Malwarebytes


Recommended Posts

Hello

I booted up my desktop today and found that I just got a series of error messages everytime I tried to run any program eg "McAfee services has encountered a problem and needs to close". Disabling the startup items with the system configuration utility at least helped me to get into My Computer. I can't access the internet and could not boot into Windows Safemode either via F8 or with system configuration utility.I came across Malwarebytes after some searching and downloaded / installed the Anti-malware program. However I can't get it to run, even after renaming it.

I have attached the logs as suggested on one of the postings along with a typical screen dump showing the error reports.

Any help would be gratefully received.

Thanks LynnJ

DDS (Ver_09-12-01.01) - NTFSx86

Run by Owner at 11:33:27.78 on 23/01/2010

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.704 [GMT 0:00]

============== Running Processes ===============

J:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

J:\WINDOWS\System32\svchost.exe -k netsvcs

J:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

svchost.exe

J:\WINDOWS\system32\spoolsv.exe

J:\WINDOWS\Explorer.EXE

svchost.exe

J:\Program Files\Creative\Shared Files\CTDevSrv.exe

J:\Program Files\Java\jre6\bin\jqs.exe

J:\Program Files\McAfee\SiteAdvisor\McSACore.exe

J:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

J:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

J:\Program Files\McAfee\MPF\MPFSrv.exe

J:\WINDOWS\System32\svchost.exe -k imgsvc

J:\WINDOWS\system32\wpabaln.exe

J:\WINDOWS\system32\wuauclt.exe

J:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

J:\Documents and Settings\Owner\Desktop\dds.scr

j:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

J:\WINDOWS\system32\dwwin.exe

============== Pseudo HJT Report ===============

uLocal Page = j:\windows\pchealth\helpctr\system\panels\blank.htm

uStart Page = hxxp://www.google.co.uk/

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

uDefault_Search_URL = hxxp://www.google.com/ie

mLocal Page = j:\windows\pchealth\helpctr\system\panels\blank.htm

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - j:\progra~1\mcafee\sitead~1\mcieplg.dll

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - j:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - j:\program files\mcafee\virusscan\scriptsn.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - j:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - j:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll

BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - j:\progra~1\mcafee\sitead~1\mcieplg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - j:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - j:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - j:\progra~1\mcafee\sitead~1\mcieplg.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - j:\program files\google\google toolbar\GoogleToolbar_32.dll

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

mRun: [MSConfig] j:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto

dRun: [CTFMON.EXE] j:\windows\system32\CTFMON.EXE

IE: Add to Google Photos Screensa&ver - j:\windows\system32\GPhotos.scr/200

IE: Google Sidewiki... - j:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - j:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - j:\progra~1\micros~2\office11\REFIEBAR.DLL

Trusted Zone: ebay.co.uk\pages

Trusted Zone: ebay.co.uk\www

Trusted Zone: live.com\login

Trusted Zone: microsoft.com\*.update

Trusted Zone: microsoft.com\update

Trusted Zone: windowsupdate.com\download

DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204

DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab

DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1242766955046

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242761258656

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1242763156343

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab

DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\progra~1\mcafee\sitead~1\McIEPlg.dll

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - j:\progra~1\mcafee\sitead~1\McIEPlg.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - j:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;j:\windows\system32\drivers\Si3112r.sys [2009-5-18 84529]

R1 mfehidk;McAfee Inc. mfehidk;j:\windows\system32\drivers\mfehidk.sys [2009-3-25 214664]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;j:\program files\mcafee\siteadvisor\McSACore.exe [2009-5-24 93320]

R2 McShield;McAfee Real-time Scanner;j:\progra~1\mcafee\viruss~1\mcshield.exe [2009-5-24 144704]

R3 McSysmon;McAfee SystemGuards;j:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-5-24 606736]

R3 mfeavfk;McAfee Inc. mfeavfk;j:\windows\system32\drivers\mfeavfk.sys [2009-5-24 79816]

R3 mfebopk;McAfee Inc. mfebopk;j:\windows\system32\drivers\mfebopk.sys [2009-5-24 35272]

R3 mfesmfk;McAfee Inc. mfesmfk;j:\windows\system32\drivers\mfesmfk.sys [2009-5-24 40552]

S2 McProxy;McAfee Proxy Service;j:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-5-24 359952]

S3 CTUPnPSv;Creative Centrale Media Server;j:\program files\creative\creative centrale\CTUPnPSv.exe [2008-5-21 64000]

S3 mferkdk;McAfee Inc. mferkdk;j:\windows\system32\drivers\mferkdk.sys [2009-5-24 34248]

=============== Created Last 30 ================

2010-01-23 11:18:44 0 ----a-w- j:\documents and settings\owner\defogger_reenable

2010-01-23 10:48:33 38224 ----a-w- j:\windows\system32\drivers\mbamswissarmy.sys

2010-01-23 10:48:31 0 d-----w- j:\docume~1\alluse~1\applic~1\Malwarebytes

2010-01-23 10:48:30 19160 ----a-w- j:\windows\system32\drivers\mbam.sys

2010-01-23 10:48:30 0 d-----w- j:\program files\Malwarebytes' Anti-Malware

2010-01-23 08:55:59 0 d-----w- j:\windows\pss

2010-01-22 23:14:01 0 d-----w- j:\program files\Amazon

2010-01-15 20:13:12 0 d--h--w- j:\docume~1\alluse~1\applic~1\{26D901A1-2540-4430-81DC-0317F01BD7BE}

2010-01-15 20:12:04 0 d--h--w- j:\docume~1\alluse~1\applic~1\{BF1E655E-0210-4F9E-BE22-94A9069BF84B}

2010-01-13 15:08:16 471552 -c----w- j:\windows\system32\dllcache\aclayers.dll

2010-01-02 16:23:04 0 d-----w- j:\program files\eBay

2010-01-02 16:23:04 0 d-----w- j:\documents and settings\all users\eBay

2010-01-01 18:45:18 0 d-----w- j:\program files\MSECache

2009-12-25 18:48:42 647872 ------w- j:\windows\system32\Mscomct2.ocx

2009-12-25 18:48:41 53248 ------w- j:\windows\Ctregrun.exe

2009-12-25 18:48:10 755320 ----a-w- j:\windows\system32\awrdscdc.ax

2009-12-25 18:48:01 24576 ------w- j:\windows\system32\msxml3a.dll

2009-12-25 18:48:01 1060864 ------w- j:\windows\system32\mfc71.dll

2009-12-25 18:47:28 0 d-----w- j:\program files\Audible

2009-12-25 18:46:19 0 d--h--w- j:\docume~1\alluse~1\applic~1\{12DD4DFD-49D5-4382-9533-B21955C1FD4C}

2009-12-25 18:44:45 0 d-----w- j:\program files\Creative

==================== Find3M ====================

2009-12-21 19:14:05 916480 ----a-w- j:\windows\system32\wininet.dll

2009-12-14 19:15:14 2146304 ----a-w- j:\windows\system32\GPhotos.scr

2009-11-13 22:57:16 922112 ------w- j:\windows\system32\imapi2fs.dll

2009-11-13 22:57:16 426496 ------w- j:\windows\system32\imapi2.dll

2009-11-13 14:31:40 49152 ----a-r- j:\windows\system32\inetwh32.dll

2009-11-13 14:31:40 1044480 ----a-r- j:\windows\system32\roboex32.dll

2009-10-15 05:22:14 245760 --sha-w- j:\windows\system32\config\systemprofile\ietldcache\index.dat

============= FINISH: 11:34:08.23 ===============

Attach.zip

ark.zip

screen_print.doc

Link to post
Share on other sites

 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.