Jump to content

Error code 2 no mbam.exe file available


Recommended Posts

Here is the logs that I was asked to run and have someone look at....please help with me with getting this off my infected computer....THANK YOU so much!!

DDS (Ver_10-03-17.01) - NTFSx86

Run by HP_Administrator at 22:04:12.04 on Thu 07/22/2010

Internet Explorer: 6.0.2900.5512

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.501 [GMT -5:00]

AV: AV Security Suite *On-access scanning enabled* (Updated) {AE716D16-40FE-4cb9-8FD2-2975088F55B2}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

C:\WINDOWS\arservice.exe

C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

svchost.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\ARPWRMSG.EXE

C:\Program Files\DISC\DISCover.exe

C:\Program Files\DISC\DiscUpdateMgr.exe

C:\Program Files\HP\HP Software Update\HPwuSchd2.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE

C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe

C:\Documents and Settings\HP_Administrator\Application Data\FDCE7A7D0972FE534A5EB0596586084D\070700Setup.exe

C:\Program Files\DISC\DiscGui.exe

C:\WINDOWS\system32\rundll32.exe

C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\y7gkls6u.exe

C:\WINDOWS\system32\rundll32.exe

C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\drweb.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Ocucom\PreCast\tmon.exe

C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe

C:\Documents and Settings\HP_Administrator\Application Data\Dropbox\bin\Dropbox.exe

C:\Program Files\TrueAssistant\TrueAssistant.exe

C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe

C:\Program Files\DISC\DiscStreamHub.exe

C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\HP\KBD\KBD.EXE

C:\WINDOWS\explorer.exe

C:\WINDOWS\ALCXMNTR.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

c:\windows\system\hpsysdrv.exe

C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

G:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/

uSearch Page = hxxp://www.google.com

uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop

uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop

uSearch Bar = hxxp://www.google.com/ie

mDefault_Search_URL = hxxp://www.google.com/ie

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop

mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop

uInternet Settings,ProxyOverride = <local>

uInternet Settings,ProxyServer = http=127.0.0.1:5577

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://www.google.com/ie

BHO: c:\windows\system32\wr7a2ig92.dll: {c3ba40a2-75f1-52bd-f413-04b15a2c8953} - c:\windows\system32\wr7a2ig92.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe

uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0

uRun: [070700Setup.exe] c:\documents and settings\hp_administrator\application data\fdce7a7d0972fe534a5eb0596586084d\070700Setup.exe

uRun: [Oqanukuwupomuki] rundll32.exe "c:\windows\tholgt.dll",Startup

uRun: [JDK5SWFMZY] c:\docume~1\hp_adm~1\locals~1\temp\Vcl.exe

uRun: [lxpbrpee] c:\documents and settings\hp_administrator\local settings\application data\gagcpfptv\gofkwcmtssd.exe

uRun: [hsef87ehf3jishfs87fhuishfsgggfdgs4g] c:\docume~1\hp_adm~1\locals~1\temp\y7gkls6u.exe

uRun: [mcexecwin] rundll32.exe c:\docume~1\hp_adm~1\locals~1\temp\r7vptlut.dll, RestoreWindows

uRun: [hsehf98u34i9tjioaugy987iuegdsg] c:\docume~1\hp_adm~1\locals~1\temp\drweb.exe

mRun: [ehTray] c:\windows\ehome\ehtray.exe

mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE

mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe

mRun: [DISCover] c:\program files\disc\DISCover.exe

mRun: [DiscUpdateManager] c:\program files\disc\DiscUpdateMgr.exe

mRun: [<NO NAME>]

mRun: [PCDrProfiler]

mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run

mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe

mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [EPSON Stylus CX5400] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"

mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [net] "c:\windows\system32\net.net"

mRun: [lxpbrpee] c:\documents and settings\hp_administrator\local settings\application data\gagcpfptv\gofkwcmtssd.exe

mRun: [Pyunikazubija] rundll32.exe "c:\windows\equzuzeqijiw.dll",Startup

mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent

StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\hp_administrator\application data\dropbox\bin\Dropbox.exe

StartupFolder: c:\docume~1\hp_adm~1\startm~1\programs\startup\trueas~1.lnk - c:\program files\trueassistant\TrueAssistant.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\at&tse~1.lnk - c:\program files\sbc self support tool\bin\matcli.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\precas~1.lnk - c:\program files\ocucom\precast\tmon.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\9972322\program\Updates from HP.exe

uPolicies-explorer: NoFolderOptions = 1 (0x1)

uPolicies-system: DisableRegistryTools = 1 (0x1)

mPolicies-system: EnableLUA = 0 (0x0)

IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html

IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_05\bin\npjpi150_05.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL

Trusted Zone: ncponline.com\www

Trusted Zone: trymedia.com

DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}

DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab

DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab

DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab

DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

TCP: NameServer = 93.188.162.224,93.188.166.204

TCP: {16233298-2793-4155-A3D0-5F3280E2075A} = 93.188.162.224,93.188.166.204

Notify: AtiExtEvent - Ati2evxx.dll

SSODL: MDmXzsQF - {7425B19C-DE8F-1B36-1FB6-E9F883A8DBA0} - c:\windows\system32\nrsq.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

STS: c:\windows\system32\wr7a2ig92.dll: {c3ba40a2-75f1-52bd-f413-04b15a2c8953} - c:\windows\system32\wr7a2ig92.dll

============= SERVICES / DRIVERS ===============

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

S0 mvlkof;mvlkof;c:\windows\system32\drivers\mvlkof.sys [2010-7-9 0]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664]

============== File Associations ===============

regfile=regedit.exe "%1" %*

scrfile="%1" %*

=============== Created Last 30 ================

2010-07-23 03:03:07 0 ----a-w- c:\documents and settings\hp_administrator\defogger_reenable

2010-07-23 02:57:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-07-23 02:57:28 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-07-23 01:27:39 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-07-14 01:37:26 1587 ----a-w- c:\windows\lsrslt.ini

2010-07-14 01:35:12 0 d--h--w- c:\windows\system32\GroupPolicy

2010-07-13 00:50:52 3255 ----a-w- c:\windows\system32\wbem\Outlook_01cb222571b0831e.mof

2010-07-10 00:50:19 552 ----a-w- c:\windows\system32\d3d8caps.dat

2010-07-10 00:50:12 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-07-09 17:09:10 0 d-----w- c:\program files\AV Security Suite Basic

2010-07-09 16:35:09 2716 ----a-w- c:\windows\ucoceweweciqusol.dll

2010-07-09 16:27:26 2716 ----a-w- c:\windows\oyositefesuf.dll

2010-07-09 16:16:55 2716 ----a-w- c:\windows\icujuqumof.dll

2010-07-09 16:01:23 30000 ----a-w- c:\windows\system32\wr7a2ig92.dll

2010-07-09 16:01:02 0 ----a-w- c:\windows\Yjehu.dat

2010-07-09 15:59:16 206336 ----a-w- c:\windows\Vtixea.exe

2010-07-09 15:59:05 0 ----a-w- c:\windows\system32\drivers\mvlkof.sys

2010-07-09 15:57:13 0 d-----w- c:\docume~1\hp_adm~1\applic~1\FDCE7A7D0972FE534A5EB0596586084D

2010-07-09 15:57:04 36819 ----a-w- c:\windows\system32\net.net

==================== Find3M ====================

2010-05-02 05:22:50 1851264 ----a-w- c:\windows\system32\win32k.sys

2010-05-02 05:22:50 1851264 ------w- c:\windows\system32\dllcache\win32k.sys

============= FINISH: 22:05:09.46 ===============

ark.zip

Attach.zip

Link to post
Share on other sites

Hello STEPHNDOUG1! Welcome to Malwarebytes' Anti-Malware Forums!

My name is Borislav and I will be glad to help you solve your problems with malware. Before we begin, please note the following:

  • The process of cleaning your system may take some time, so please be patient.
  • Follow my instructions step by step if there is a problem somewhere, stop and tell me.
  • Stay with the thread until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • If you don't know or can't understand something please ask.
  • Do not install or uninstall any software or hardware, while work on.
  • Keep me informed about any changes.

Please follow these instructions:

http://forums.malwarebytes.org/index.php?showtopic=29028

Next:

  • Launch Malwarebytes' Anti-Malware
  • Go to "Update" tab and select "Check for Updates". If an update is found, it will download and install the latest version.
  • Go to "Scanner" tab and select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.