hallnoates Posted April 17, 2011 ID:417184 Share Posted April 17, 2011 I have something jacking windows up for me. Can't run Anti-Malware, runtime error 372 (vbalGrid... yadda yadda yadda).Ark.txt, attach.txt zipped and attached.Attach.zipcontents of DDS.txt below:.DDS (Ver_11-03-05.01) - NTFSx86 Run by Jason at 18:34:05.96 on Sat 04/16/2011Internet Explorer: 8.0.6001.18702.============== Running Processes ===============.C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Symantec AntiVirus\DefWatch.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Motorola\MotoConnectService\MotoConnectService.exeC:\Program Files\Motorola\MotoConnectService\MotoConnect.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\OpenOffice.org 3\program\soffice.binC:\WINDOWS\explorer.exeC:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\Application\chrome.exeC:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\Application\chrome.exeC:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\Application\chrome.exeC:\Documents and Settings\Jason\Local Settings\Application Data\Google\Chrome\Application\chrome.exeC:\Program Files\Windows NT\Accessories\wordpad.exeC:\Documents and Settings\Jason\My Documents\Downloads\Defogger.exeC:\Documents and Settings\Jason\My Documents\Downloads\dds.scrC:\WINDOWS\System32\svchost.exe -k netsvcsC:\WINDOWS\system32\svchost.exe -k WudfServiceGroupC:\WINDOWS\system32\svchost.exe -k NetworkServiceC:\WINDOWS\system32\svchost.exe -k LocalServiceC:\WINDOWS\System32\svchost.exe -k HPZ12C:\WINDOWS\System32\svchost.exe -k HPZ12.============== Pseudo HJT Report ===============.uSearch Page = uStart Page = hxxp://start.pogo.iplay.com/?o=shpuSearch Bar = uInternet Settings,ProxyOverride = *.localmSearchAssistant = mWinlogon: Userinit=c:\windows\system32\userinit.exeBHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No FileBHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dllBHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dllBHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dllBHO: GamesBarBHO Class: {cb0d163c-e9f4-4236-9496-0597e24b23a5} - c:\program files\gamesbar\2.0.1.81\oberontb.dllBHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1303.0\msneshellx.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dllBHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllTB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dllTB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1303.0\msneshellx.dllTB: GamesBar: {6f282b65-56bf-4bd1-a8b2-a4449a05863d} - c:\program files\gamesbar\2.0.1.81\oberontb.dllTB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No FileTB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File{555d4d79-4bd2-4094-a395-cfc534424a05}uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exeuRun: [Google Update] "c:\documents and settings\jason\local settings\application data\google\update\GoogleUpdate.exe" /cuRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /backgrounduRun: [searchEngineProtection] c:\program files\gamesbar\SearchEngineProtection.exeuRunOnce: [shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.candystand.com/play/ping-pong-3d"mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"mRun: [vptray] c:\progra~1\symant~1\VPTray.exemRun: [igfxtray] c:\windows\system32\igfxtray.exemRun: [igfxpers] c:\windows\system32\igfxpers.exemRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exemRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kmRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottimemRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exeIE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exeIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exeIE: {1A93C934-025B-4c3a-B38E-9654A7003239} - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - c:\program files\gamesbar\2.0.1.81\oberontb.dllDPF: {000F1EA4-5E08-4564-A29B-29076F63A37A} - hxxp://launch.soe.com/plugin/web/SOEWebInstaller.cabDPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cabDPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cabDPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cabDPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cabDPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - hxxp://gamerival.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cabDPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cabDPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://my.markelcorp.com/dana-cached/setup/JuniperSetupSP1.cabDPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://my.markelcorp.com/dana-cached/sc/JuniperSetupClient.cabNotify: igfxcui - igfxdev.dllNotify: NavLogon - c:\windows\system32\NavLogon.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll.============= SERVICES / DRIVERS ===============.R? ccEvtMgr;Symantec Event ManagerR? ccSetMgr;Symantec Settings ManagerR? SavRoam;SavRoamR? Symantec AntiVirus;Symantec AntiVirusS? EraserUtilRebootDrv;EraserUtilRebootDrvS? MotoConnect Service;MotoConnect ServiceS? NAVENG;NAVENGS? NAVEX15;NAVEX15S? SAVRT;SAVRTS? SAVRTPEL;SAVRTPEL.=============== Created Last 30 ================.2011-04-16 19:44:31 -------- d-----w- C:\MGtools2011-04-16 19:38:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2011-04-16 19:38:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys2011-04-16 19:38:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware2011-03-30 01:06:56 -------- d-----w- c:\program files\iPod2011-03-30 01:06:51 -------- d-----w- c:\program files\iTunes2011-03-30 00:59:56 -------- d-----w- c:\program files\Bonjour.==================== Find3M ====================.2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll2011-02-03 01:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll2011-02-02 23:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll.============= FINISH: 18:34:28.89 =============== Link to post Share on other sites More sharing options...
Staff screen317 Posted April 18, 2011 Staff ID:417848 Share Posted April 18, 2011 Hi,I have something jacking windows up for me.Could you be more specific regarding what issues you are experiencing and why you think they are malware related?Please do the following:Download and run mbam-clean.exe from here It will ask to restart your computer, please allow it to do so very importantAfter the computer restarts, temporarily disable your Anti-Virus and install the latest version of Malwarebytes' Anti-Malware from hereNote: You will need to reactivate the program using the license you were sent via email if using the Pro versionLaunch the program and set the Protection and Registration. Then go to the UPDATE tab if not done during installation and check for updates.Restart the computer again and verify that MBAM is in the task tray if using the Pro version. Now setup any file exclusions as may be required in your Anti-Virus/Internet-Security/Firewall applications and restart your Anti-Virus/Internet-Security applications. You may use the guides posted in the FAQ's here or ask and we'll explain how to do it.Does MBAM run now? Link to post Share on other sites More sharing options...
hallnoates Posted April 19, 2011 Author ID:418007 Share Posted April 19, 2011 I ran the cleaner and reinstalled. Anti-Malware will not launch. see attached error message. As far as windows being jacked up, I cannot drag/drop or copy/paste files. I cannot launch Windows system restore. While trying to uninstall applications, I get an error that says "The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. What makes me believe it's malware or a virus is that one of my children told me they were browsing the internet and "a page popped up that said we have a virus, and I clicked yes, I want to get rid of it." Link to post Share on other sites More sharing options...
Staff screen317 Posted April 21, 2011 Staff ID:418979 Share Posted April 21, 2011 Download and install this:http://support.microsoft.com/kb/290887Restart your computer and see if the MBAM error persists. Link to post Share on other sites More sharing options...
hallnoates Posted April 29, 2011 Author ID:422929 Share Posted April 29, 2011 I tried, but the installation seems to die after launching. Link to post Share on other sites More sharing options...
Staff screen317 Posted May 3, 2011 Staff ID:424281 Share Posted May 3, 2011 What do you mean? The download may have been corrupted. Try downloading it again and seeing if it will install now. Link to post Share on other sites More sharing options...
Recommended Posts