It is currently Tue Sep 01, 2026 4:31 pm


System restarts

All versions of Windows 7, 2008 and Vista including 32 bit and 64 bit

Moderator: icecube

System restarts

Postby HIBB » Sun Feb 08, 2009 7:51 pm

My pc keeps restarting about every15 mins. or anytime i try to do a virus scan.
From System Event Log:
The following boot-start or system-start driver(s) failed to load:
fqumnmfo
Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher 9 service to connect.
The MCSTRM service failed to start due to the following error:
The system cannot find the file specified.
Error code 10000050, parameter1 e41a1000, parameter2 00000000, parameter3 ba94d8d6, parameter4 00000001.
Error code 10000050, parameter1 e5213000, parameter2 00000000, parameter3 ba94d8d6, parameter4 00000001.
Error code 10000050, parameter1 e4207000, parameter2 00000000, parameter3 ba94d8d6, parameter4 00000001.
Error code 10000050, parameter1 e3e3a000, parameter2 00000000, parameter3 ba94d8d6, parameter4 00000001.
Error code 10000050, parameter1 e34c4000, parameter2 00000000, parameter3 ba94d8d6, parameter4 00000001.
Error code 10000050, parameter1 e43b8000, parameter2 00000000, parameter3 ba94d8d6, parameter4 00000001.

Also System restore points are erased.
Upon restart I get "System has recovered from a Serious Error"

Any Help would be greatly appreciated.
User avatar
HIBB
Geek
Geek
 
Posts: 50
Joined: Mon Jan 30, 2006 1:00 am

Thanks given:0
Thanks received:0
Top

Re: System restarts

Postby liljim » Mon Feb 09, 2009 12:29 am

MCSTRM is a part of Rhapsody. Reinstalling or uninstalling rhapsody and real player should help that one.

For the roxio error, you can disable the service to see if it helps.

Click start>run> type services.msc >click ok
scroll down until you see Roxio Hard Drive Watcher 9 and double click it.
Set startup type to disabled from the dropdown box then apply and ok.

reboot, see what happens and we go from there.


side note, what AV are you using?
Vista, XP?
can you get a scan in at ?
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Re: System restarts

Postby HIBB » Mon Feb 09, 2009 4:31 pm

I've disabled roxio.
I'm using AVG 8.0 for XP
There's no program to uninstall for rhapsody or real player when I open add/remove programs in control panel.

I am still unable to complete a scan( virus, malware, adware, spyware).
My computer reboots midway through.
User avatar
HIBB
Geek
Geek
 
Posts: 50
Joined: Mon Jan 30, 2006 1:00 am

Thanks given:0
Thanks received:0
Top

Re: System restarts

Postby liljim » Mon Feb 09, 2009 5:51 pm

can you get a hijack this log without crashing?
User avatar
liljim
Moderator
Moderator
 
Posts: 3017
Joined: Mon Mar 03, 2003 1:00 am
Location: Louisiana
Operating System:

Thanks given:0
Thanks received:12
Top

Re: System restarts

Postby Axelation » Tue Feb 10, 2009 1:51 am

Can you run it in safe mode? If so, then run msconfig and remove all start up entries that are not absolutely neccesary. Then reboot back into safe mode and perform your spyware,virus,malware scans. However,the fact that your system is getting critical errors concerns me a little though. You may want to run a PC-Check diagnostics from Eurosoft. That will let you know if you have some underlying hardware issue. Typically it is the hard drive or memory that will cause system shut downs. Your event log did seem to indicate a driver issue, but the fact that your restore points are missing, may indicate drive, registry or filesystem corruption. Now for the advice...ready?

If you can't scan it in safemode, and if your hardware checks out, do a repair install of Windows. That should fix any registry, or filesystem errors you may have. Then you should be able to scan it for viruses etc.
"You don't know it yet, but.......You are sharing your secrets....One packet at a time."
User avatar
Axelation
Senior Geek
Senior Geek
 
Posts: 133
Joined: Fri Aug 06, 2004 1:00 am
Location: Texas

Thanks given:0
Thanks received:0
Top

Re: System restarts

Postby PcTestCard.com » Wed Feb 11, 2009 4:27 am

try disable the Startup apps and see if the PC still auto reboot.

from the RUN command, type "msconfig" and hit enter, select "startup" tab and disable all option, ok to reboot.
If this works, go back to the same startup option and enable app one by one, reboot everytime for each app enabled.
Just do not enable the app(s) that you find that causing the auto reboot.

Hope this helps!
Bill
PcTestCard.com
Geek
Geek
 
Posts: 75
Joined: Tue Oct 07, 2008 9:57 am

Thanks given:2
Thanks received:0
Top

Re: System restarts

Postby HIBB » Wed Feb 11, 2009 5:58 am

Here's the hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:04 PM, on 2/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEA.EXE
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {AFF760A6-C156-4CE1-BC75-47671685E357} - C:\WINDOWS\system32\pmnlljGX.dll (file missing)
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus CX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEA.EXE /FU "C:\WINDOWS\TEMP\E_SE0.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [jusotujama] Rundll32.exe "C:\WINDOWS\system32\kuhirelu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [jusotujama] Rundll32.exe "C:\WINDOWS\system32\kuhirelu.dll",s (User 'NETWORK SERVICE')
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - G:\Program Files\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - G:\Program Files\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/ ... 586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll C:\WINDOWS\system32\kewevuro.dll omqdxj.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

--
End of file - 9951 bytes
User avatar
HIBB
Geek
Geek
 
Posts: 50
Joined: Mon Jan 30, 2006 1:00 am

Thanks given:0
Thanks received:0
Top

Re: System restarts

Postby Gecko » Wed Feb 11, 2009 12:46 pm

HIBB,

I can see that you have at least two Trojans running on your system.
This may or may not be the cause of the system restarts, we won't know until we clean your system.


Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: System restarts

Postby HIBB » Sat Feb 21, 2009 5:22 am

HAd a little trouble uninstalling AVG. I went to the avg website and downloaded the remover to uninstall but still when i ran combofix it warned me that avg was still running.
Here's the log:
ComboFix 09-02-19.01 - hibb 2009-02-20 21:09:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1790 [GMT -7:00]
Running from: c:\documents and settings\hibb\Desktop\repair.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\hibb\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\hibb\LOCALS~1\Temp\tmp2.tmp
c:\windows\system32\ceme25.dll
c:\windows\system32\exljssgo.ini
c:\windows\system32\msvcsv60.dll
c:\windows\system32\pmnlljGX.dll.vir
c:\windows\system32\tarpjkel.ini
c:\windows\system32\XGjllnmp.ini
c:\windows\system32\XGjllnmp.ini2
J:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-01-21 to 2009-02-21 )))))))))))))))))))))))))))))))
.

2009-02-10 21:46 . 2009-02-10 21:46 <DIR> d-------- c:\program files\Trend Micro
2009-02-08 13:44 . 2009-02-08 13:44 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-08 13:44 . 2009-02-08 13:44 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-08 13:43 . 2009-02-09 05:26 <DIR> d-------- c:\windows\SxsCaPendDel
2009-02-08 13:43 . 2009-02-08 13:44 <DIR> d-------- C:\9f5ef5b98e170336ad109ef68f8f6077
2009-02-08 13:43 . 2008-07-06 05:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-08 13:43 . 2008-07-06 05:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-08 13:43 . 2008-07-06 03:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-08 13:43 . 2008-07-06 05:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-08 13:43 . 2008-07-06 05:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-08 13:43 . 2008-07-06 05:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-08 13:43 . 2008-07-06 05:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-02-08 13:27 . 2009-02-08 13:27 <DIR> d-------- C:\efa58e411ac82778b10065dab89deee5
2009-02-08 13:27 . 2009-02-08 13:27 <DIR> d-------- C:\73e1ce2e2077e84b21d82a79
2009-02-08 11:08 . 2009-02-08 11:02 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-02-08 11:02 . 2009-02-08 11:28 <DIR> d-------- c:\documents and settings\hibb\.housecall6.6
2009-02-05 22:15 . 2009-02-05 22:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\QuickTime
2009-02-05 22:13 . 2009-02-05 22:13 <DIR> d-------- c:\program files\Common Files\SWF Studio
2009-01-29 00:03 . 2009-01-29 00:03 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Roxio
2009-01-29 00:03 . 2009-01-29 00:07 <DIR> d-------- c:\documents and settings\hibb\Application Data\Roxio
2009-01-28 23:26 . 2009-01-28 23:26 <DIR> d-------- c:\documents and settings\hibb\Application Data\Research In Motion
2009-01-28 23:26 . 2009-02-11 15:07 256 --a------ c:\windows\system32\pool.bin
2009-01-28 23:24 . 2009-01-28 23:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sonic
2009-01-28 23:24 . 2009-01-28 23:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2009-01-28 23:22 . 2009-01-28 23:22 <DIR> d-------- c:\program files\Roxio
2009-01-28 23:22 . 2009-01-28 23:22 <DIR> d-------- c:\program files\Common Files\Sonic Shared
2009-01-28 23:22 . 2009-01-28 23:22 <DIR> d-------- c:\program files\Common Files\Roxio Shared
2009-01-28 23:22 . 2009-01-29 00:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Roxio
2009-01-28 23:18 . 2009-01-28 23:18 <DIR> d-------- c:\program files\Research In Motion
2009-01-28 23:18 . 2009-01-28 23:18 <DIR> d-------- c:\program files\Common Files\Research In Motion
2009-01-28 23:18 . 2007-01-18 10:24 26,496 -ra------ c:\windows\system32\drivers\RimSerial.sys
2009-01-28 23:15 . 2009-01-28 23:15 <DIR> d--hs---- c:\windows\ftpcache
2009-01-23 18:03 . 2009-01-23 18:04 <DIR> d-------- c:\program files\DivX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-21 03:52 --------- d-----w c:\documents and settings\hibb\Application Data\AVGTOOLBAR
2009-02-21 03:11 --------- d-----w c:\program files\Arturia
2009-02-20 04:39 --------- d-----w c:\documents and settings\hibb\Application Data\uTorrent
2009-02-18 05:00 --------- d-----w c:\documents and settings\hibb\Application Data\LimeWire
2009-02-17 20:13 --------- d-----w c:\program files\PeerGuardian2
2009-02-08 04:01 --------- d-----w c:\program files\Edirol
2009-02-08 03:36 --------- d-----w c:\program files\Native Instruments
2009-02-06 05:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-30 19:10 --------- d-----w c:\documents and settings\hibb\Application Data\Digidesign
2009-01-29 06:22 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-05 12:39 --------- d-----w c:\program files\Java
2009-01-04 08:19 --------- d-----w c:\documents and settings\hibb\Application Data\Move Networks
2008-12-31 20:50 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-31 20:50 --------- d-----w c:\documents and settings\hibb\Application Data\Malwarebytes
2008-12-31 20:50 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-30 18:47 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-30 18:46 --------- d-----w c:\program files\MSBuild
2008-12-30 18:46 --------- d-----w c:\program files\Microsoft Works
2008-12-30 18:45 --------- d-----w c:\program files\Microsoft.NET
2008-12-30 18:43 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-11-29 21:39 3,532 ----a-w C:\drmHeader.bin
2008-06-26 19:23 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008061620080623\index.dat
2008-06-26 19:23 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008062620080627\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"DigidesignMMERefresh"="c:\program files\Digidesign\Drivers\MMERefresh.exe" [2006-02-15 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-05 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-01-30 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"MIDI1"= diomidi.dll
"wave1"= Digi32.dll
"midi2"= usbmn2x2.dll
"midi4"= usbmn2x2.dll

[HKLM\~\startupfolder\C:^Documents and Settings^hibb^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\hibb\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX8400 Series]
--a------ 2007-02-15 06:00 179200 c:\windows\system32\spool\drivers\w32x86\3\E_FATICEA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
-ra------ 2001-07-09 02:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 2007-06-02 15:52 1457152 c:\program files\PeerGuardian2\pg2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2008-06-26 12:22 236016 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"RoxMediaDB9"=3 (0x3)
"RoxLiveShare9"=2 (0x2)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"LexBceS"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"f:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"g:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Digidesign\\Pro Tools\\digiSPTIService.exe"=
"c:\\Program Files\\Western Digital\\WD Drive Manager\\WDBtnMgrSvc.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [2008-06-30 16384]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2008-01-30 106496]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2008-06-30 107008]
R3 USBMN2X2;M-Audio USB MidiSport 2x2;c:\windows\system32\drivers\usbmn2x2.sys [2008-06-30 22304]
S0 fqumnmfo;fqumnmfo;c:\windows\system32\drivers\xpaflifa.sys []
S0 xtrrl;xtrrl;c:\windows\system32\drivers\saec.sys --> c:\windows\system32\drivers\saec.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2008-12-31 38496]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2008-06-22 32840]
S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;c:\windows\system32\drivers\usb22ldr.sys [2008-06-30 14272]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-12-18 11520]
.
- - - - ORPHANS REMOVED - - - -

BHO-{AFF760A6-C156-4CE1-BC75-47671685E357} - c:\windows\system32\pmnlljGX.dll
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-Lexmark 4200 Series - c:\program files\Lexmark 4200 Series\lxbmbmgr.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/def ... earch.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\hibb\Application Data\Mozilla\Firefox\Profiles\p4e64eg2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-20 21:12:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\drivers\xpaflifa.sys 25088 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
.
**************************************************************************
.
Completion time: 2009-02-20 21:14:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-21 04:14:40

Pre-Run: 430,490,648,576 bytes free
Post-Run: 431,450,415,104 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

207 --- E O F --- 2009-02-12 01:23:10
User avatar
HIBB
Geek
Geek
 
Posts: 50
Joined: Mon Jan 30, 2006 1:00 am

Thanks given:0
Thanks received:0
Top

Re: System restarts

Postby Gecko » Sat Feb 21, 2009 1:44 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: System restarts

Postby HIBB » Mon Feb 23, 2009 3:46 am

combofix log:

ComboFix 09-02-19.01 - hibb 2009-02-22 19:42:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1680 [GMT -7:00]
Running from: c:\documents and settings\hibb\Desktop\repair.exe
Command switches used :: c:\documents and settings\hibb\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090221-0] *On-access scanning disabled* (Updated)
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
* Created a new restore point

FILE ::
c:\windows\system32\drivers\xpaflifa.sys
.

((((((((((((((((((((((((( Files Created from 2009-01-23 to 2009-02-23 )))))))))))))))))))))))))))))))
.

2009-02-20 21:37 . 2009-02-20 21:37 <DIR> d-------- c:\program files\Alwil Software
2009-02-10 21:46 . 2009-02-10 21:46 <DIR> d-------- c:\program files\Trend Micro
2009-02-08 13:44 . 2009-02-08 13:44 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-08 13:44 . 2009-02-08 13:44 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-08 13:43 . 2009-02-09 05:26 <DIR> d-------- c:\windows\SxsCaPendDel
2009-02-08 13:43 . 2009-02-08 13:44 <DIR> d-------- C:\9f5ef5b98e170336ad109ef68f8f6077
2009-02-08 13:43 . 2008-07-06 05:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-08 13:43 . 2008-07-06 05:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-08 13:43 . 2008-07-06 03:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-08 13:43 . 2008-07-06 05:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-08 13:43 . 2008-07-06 05:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-08 13:43 . 2008-07-06 05:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-08 13:43 . 2008-07-06 05:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-02-08 13:27 . 2009-02-08 13:27 <DIR> d-------- C:\efa58e411ac82778b10065dab89deee5
2009-02-08 13:27 . 2009-02-08 13:27 <DIR> d-------- C:\73e1ce2e2077e84b21d82a79
2009-02-08 11:08 . 2009-02-08 11:02 102,664 --a------ c:\windows\system32\drivers\tmcomm.sys
2009-02-08 11:02 . 2009-02-08 11:28 <DIR> d-------- c:\documents and settings\hibb\.housecall6.6
2009-02-05 22:15 . 2009-02-05 22:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\QuickTime
2009-02-05 22:13 . 2009-02-05 22:13 <DIR> d-------- c:\program files\Common Files\SWF Studio
2009-01-29 00:03 . 2009-01-29 00:03 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Roxio
2009-01-29 00:03 . 2009-01-29 00:07 <DIR> d-------- c:\documents and settings\hibb\Application Data\Roxio
2009-01-28 23:26 . 2009-01-28 23:26 <DIR> d-------- c:\documents and settings\hibb\Application Data\Research In Motion
2009-01-28 23:26 . 2009-02-11 15:07 256 --a------ c:\windows\system32\pool.bin
2009-01-28 23:24 . 2009-01-28 23:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sonic
2009-01-28 23:24 . 2009-01-28 23:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2009-01-28 23:22 . 2009-01-28 23:22 <DIR> d-------- c:\program files\Roxio
2009-01-28 23:22 . 2009-01-28 23:22 <DIR> d-------- c:\program files\Common Files\Sonic Shared
2009-01-28 23:22 . 2009-01-28 23:22 <DIR> d-------- c:\program files\Common Files\Roxio Shared
2009-01-28 23:22 . 2009-01-29 00:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Roxio
2009-01-28 23:18 . 2009-01-28 23:18 <DIR> d-------- c:\program files\Research In Motion
2009-01-28 23:18 . 2009-01-28 23:18 <DIR> d-------- c:\program files\Common Files\Research In Motion
2009-01-28 23:18 . 2007-01-18 10:24 26,496 -ra------ c:\windows\system32\drivers\RimSerial.sys
2009-01-28 23:15 . 2009-01-28 23:15 <DIR> d--hs---- c:\windows\ftpcache
2009-01-23 18:03 . 2009-01-23 18:04 <DIR> d-------- c:\program files\DivX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-21 03:11 --------- d-----w c:\program files\Arturia
2009-02-20 04:39 --------- d-----w c:\documents and settings\hibb\Application Data\uTorrent
2009-02-18 05:00 --------- d-----w c:\documents and settings\hibb\Application Data\LimeWire
2009-02-17 20:13 --------- d-----w c:\program files\PeerGuardian2
2009-02-08 04:01 --------- d-----w c:\program files\Edirol
2009-02-08 03:36 --------- d-----w c:\program files\Native Instruments
2009-02-06 05:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-30 19:10 --------- d-----w c:\documents and settings\hibb\Application Data\Digidesign
2009-01-29 06:22 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-05 12:39 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-05 12:39 --------- d-----w c:\program files\Java
2009-01-04 08:19 --------- d-----w c:\documents and settings\hibb\Application Data\Move Networks
2008-12-31 20:50 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-31 20:50 --------- d-----w c:\documents and settings\hibb\Application Data\Malwarebytes
2008-12-31 20:50 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-30 18:47 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-30 18:46 --------- d-----w c:\program files\MSBuild
2008-12-30 18:46 --------- d-----w c:\program files\Microsoft Works
2008-12-30 18:45 --------- d-----w c:\program files\Microsoft.NET
2008-12-30 18:43 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-11-29 21:39 3,532 ----a-w C:\drmHeader.bin
2008-06-26 19:23 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008061620080623\index.dat
2008-06-26 19:23 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008062620080627\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-02-20_21.14.12.92 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-05 21:11:35 1,256,296 ----a-w c:\windows\system32\aswBoot.exe
+ 2009-02-05 21:04:45 97,480 ----a-w c:\windows\system32\AvastSS.scr
+ 2009-02-05 21:05:11 26,944 ----a-w c:\windows\system32\drivers\aavmker4.sys
+ 2009-02-05 21:07:12 20,560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2009-02-05 21:08:19 93,296 ----a-w c:\windows\system32\drivers\aswmon.sys
+ 2009-02-05 21:08:10 94,032 ----a-w c:\windows\system32\drivers\aswmon2.sys
+ 2009-02-05 21:06:10 23,152 ----a-w c:\windows\system32\drivers\aswRdr.sys
+ 2009-02-05 21:07:23 114,768 ----a-w c:\windows\system32\drivers\aswSP.sys
+ 2009-02-05 21:06:20 51,376 ----a-w c:\windows\system32\drivers\aswTdi.sys
+ 2009-02-21 08:08:53 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_658.dat
+ 2009-02-23 02:25:29 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_794.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"DigidesignMMERefresh"="c:\program files\Digidesign\Drivers\MMERefresh.exe" [2006-02-15 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-05 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-01-30 438272]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"MIDI1"= diomidi.dll
"wave1"= Digi32.dll
"midi2"= usbmn2x2.dll
"midi4"= usbmn2x2.dll

[HKLM\~\startupfolder\C:^Documents and Settings^hibb^Start Menu^Programs^Startup^DING!.lnk]
path=c:\documents and settings\hibb\Start Menu\Programs\Startup\DING!.lnk
backup=c:\windows\pss\DING!.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX8400 Series]
--a------ 2007-02-15 06:00 179200 c:\windows\system32\spool\drivers\w32x86\3\E_FATICEA.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
-ra------ 2001-07-09 02:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 2007-06-02 15:52 1457152 c:\program files\PeerGuardian2\pg2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2008-06-26 12:22 236016 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"RoxMediaDB9"=3 (0x3)
"RoxLiveShare9"=2 (0x2)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"LexBceS"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"f:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"g:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Digidesign\\Pro Tools\\digiSPTIService.exe"=
"c:\\Program Files\\Western Digital\\WD Drive Manager\\WDBtnMgrSvc.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [2008-06-30 16384]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-20 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-20 20560]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2008-01-30 106496]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2008-06-30 107008]
R3 USBMN2X2;M-Audio USB MidiSport 2x2;c:\windows\system32\drivers\usbmn2x2.sys [2008-06-30 22304]
S0 xtrrl;xtrrl;c:\windows\system32\drivers\saec.sys --> c:\windows\system32\drivers\saec.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2008-12-31 38496]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2008-06-22 32840]
S3 USB22LDR;M-Audio USB MidiSport 2x2 Loader;c:\windows\system32\drivers\usb22ldr.sys [2008-06-30 14272]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-12-18 11520]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/def ... earch.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\hibb\Application Data\Mozilla\Firefox\Profiles\p4e64eg2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-22 19:44:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-22 19:45:03
ComboFix-quarantined-files.txt 2009-02-23 02:45:01
ComboFix2.txt 2009-02-21 04:14:43

Pre-Run: 431,352,991,744 bytes free
Post-Run: 431,389,458,432 bytes free

198 --- E O F --- 2009-02-12 01:23:10

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:11 PM, on 2/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/def ... earch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - G:\Program Files\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - G:\Program Files\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/ ... 586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

--
End of file - 7492 bytes
User avatar
HIBB
Geek
Geek
 
Posts: 50
Joined: Mon Jan 30, 2006 1:00 am

Thanks given:0
Thanks received:0
Top

Re: System restarts

Postby Gecko » Mon Feb 23, 2009 12:23 pm

HIBB,

Your logs are clean, how's it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Windows 7, 2008 and Vista

Who is online

Users browsing this forum: No registered users and 1 guest

cron