Jump to content

Malwarebytes

Runtime errors during install

- - - - -

18 replies to this topic

#1
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
I'm working on a friend's laptop which has been infected with Antivirus 360. With what is looking to be minimal success, i've tried running scans with Webroot Spy Sweeper, PC Tool Spy Doctor, and Spybot S&D. It seems to be removing some files because each scan comes back a bit better. However, Spy Sweeper still blocking connections to known spyware sites. The list (which seems to be a long one) is moving alphabetically and is in the S's now. Not sure if any of this is useful information, but i'm trying to provide any details I can. Also, I tried to perform a system restore with no luck.

Also, when attempting to install Malwarebytes, I receive RTE's at several points during the installation. After the installation completes I get the same RTE's. Screenshots can be provided if necessary. Run-Time error 0 and Run-Time error 440 Automation Error

Here is my Hi-Jack This log...

Any help will be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:37 PM, on 3/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ndscs.nodak.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SE...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ehTray] "C:\WINDOWS\ehome\ehtray.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "CHDAudPropShortcut.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [SmoothView] "C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [igfxtray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [igfxhkcmd] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [igfxpers] "C:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [KernelFaultCheck] "%systemroot%\system32\dumprep" 0 -k
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [TOSCDSPD] "C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\TOSHIBA Game Console\GameConsoleService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O24 - Desktop Component 1: (no name) - http://gamercard.xbo...ef%20Shake.card

--
End of file - 10406 bytes

#2
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
STEP 01
[indent]Please visit this webpage for instructions for downloading ComboFix to your DESKTOP : how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
NOTE!!: You must save and run ComboFix.exe on your DESKTOP and not from any other folder.
Also, DO NOT click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:
ComboFix.exe
ComboFix.exe
ComboFix.exe


Note: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.
  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system.
[/indent]

STEP 02
[indent]Download DDS and save it to your desktop
http://download.bleepingcomputer.com/sUBs/dds.scr

Disable any script blocker if your Anti-Virus/Anti-Malware has it.
Once downloaded you can disconnect from the Internet and disable your Ant-Virus temporarily if needed.
Then double click dds.scr to run the tool.
When done, the DDS.txt will open.
Click Yes at the next prompt for Optional Scan.
    When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop
  • Please include the following logs in your next reply: DDS.txt and Attach.txt
[/indent]

STEP 03
    Please create a BOOTLOG
  • Restart the computer and press F8 when Windows start booting. This will bring up the startup options.
  • Select "Enable Boot Logging" option and press enter.
  • Windows prompts you to select a Windows Installation (even if there is only one windows installation)
  • This boots windows normally and creates a boot log named ntbtlog.txt and saves it to C:\Windows

    If you're already running inside Windows you can enable it the following way.

  • Click on START - RUN and type in MSCONFIG go to the BOOT.INI tab and place a check mark by /BOOTLOG
  • Click on OK and you will be prompted to RESTART Windows. Please do restart now.
  • After Windows restarts open the file C:\Windows\ntbtlog.txt with Notepad
  • From the Edit menu choose Select All then Edit, COPY and post that back on your next reply.

Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#3
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
My original reply with all the logs pasted was too long, so I attached a zip file with all the log files inside.

I apologize if this is not was I was supposed to do.

Thanks,

Taylor

Attached Files



#4
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Yep, no problem with the attachment on large logs. Just don't want them normally as it takes more time to review them.


You need to uninstall and remove the followowing P2P file sharing software if you want us to continue to assist you in cleaning your system.
Often P2P is how users get infected and its a losing situation trying to help you with this software installed.
File sharing involves using technology that allows internet users to share files that are housed on their individual computers. Peer-to-peer (P2P) applications, such as those used to share music files, are some of the most common forms of file-sharing technology. However, P2P applications introduce security risks that may put your information or your computer in jeopardy.
Risks of File-Sharing Technology
BitComet 0.70
LimeWire 5.0.11


The following software is OLD and has exploited code and needs to be removed and then updated to the latest versions.
A lot of Malware takes advantage of the exploits in the code to get on your system.
J2SE Development Kit 5.0 Update 7
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 7
Java DB 10.3.1.4
Java™ 6 Update 11
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
Java™ SE Development Kit 6
Java™ SE Development Kit 6 Update 7
Java™ SE Runtime Environment 6
Java™ SE Runtime Environment 6 Update 1


This software is also old and exploited and needs to be updated
Update available for vulnerability in versions 8.1 and earlier of Adobe Reader and Acrobat
Adobe Reader 7.1.0

Adobe now own this Company for a long time now - just remove this and use the current Adobe version
Macromedia Flash Player 8

This is not Malware. It is called Foistware because it is often installed without the users knowledge.
Its up to you if you want to remove it or not, I would myself but you do not have to.
Viewpoint Media Player


Please download Lop S&D
Double-click on Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt), typcially C:\lopR.txt


Please let me know when the above is done and ready and we can proceed.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#5
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Ok, Java SDK's are gone as well as the other items.

Here is the log...


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Genuine Intel® CPU T2300 @ 1.66GHz )
BIOS : PhoenixBIOS 4.0 Release 6.1
USER : Noel ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:111 Go (Free:54 Go)
D:\ (CD or DVD)
E:\ (USB) - FAT32 - Total:1907 Mo (Free:1 Go)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Sat 03/07/2009|21:34 )

--------------------\\ Listing folders in APPLIC~1

[05/11/2006|12:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
[07/13/2006|04:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> AOL
[03/02/2006|03:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
[07/12/2006|11:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Intel
[03/03/2006|12:22] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InterVideo
[03/02/2006|05:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Intuit
[03/02/2006|03:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
[03/02/2006|06:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> toshiba
[03/02/2006|06:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> You've Got Pictures Screensaver

[11/30/2008|08:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[12/01/2008|02:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> acccore
[02/29/2008|12:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[12/01/2008|02:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL Downloads
[02/13/2008|03:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL OCP
[07/07/2007|10:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[10/14/2006|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[03/02/2006|05:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DIGStream
[07/12/2006|11:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intel
[03/02/2006|05:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Intuit
[04/02/2009|04:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[07/12/2006|11:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee.com
[09/09/2008|04:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[09/29/2008|07:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft Help
[08/23/2006|12:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Otto
[04/02/2009|05:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC Tools
[03/02/2006|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Pure Networks
[03/02/2006|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> QuickTime
[03/06/2009|06:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[03/07/2009|09:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[05/06/2008|01:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TuneUp Software
[03/07/2009|09:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint
[04/02/2009|01:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Webroot
[07/12/2006|07:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WildTangent
[07/13/2006|12:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[02/05/2007|10:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Live Toolbar
[03/06/2008|01:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WLInstaller

[05/11/2006|12:56] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Adobe
[07/13/2006|04:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> AOL
[03/02/2006|03:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Identities
[07/12/2006|11:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Intel
[03/03/2006|12:22] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> InterVideo
[03/02/2006|05:54] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Intuit
[03/02/2006|03:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[03/02/2006|06:29] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> toshiba
[03/02/2006|06:03] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> You've Got Pictures Screensaver

[03/02/2006|03:32] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

[03/02/2006|03:32] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

[02/13/2008|03:18] C:\DOCUME~1\Noel\APPLIC~1\<DIR> acccore
[08/31/2006|10:33] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Adobe
[07/11/2008|05:55] C:\DOCUME~1\Noel\APPLIC~1\<DIR> AdobeUM
[02/18/2008|06:54] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Aim
[07/13/2006|04:57] C:\DOCUME~1\Noel\APPLIC~1\<DIR> AOL
[07/12/2008|11:27] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Apple Computer
[08/18/2006|07:16] C:\DOCUME~1\Noel\APPLIC~1\<DIR> CiscoCAA
[03/29/2009|11:30] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Deusty
[08/03/2008|11:11] C:\DOCUME~1\Noel\APPLIC~1\<DIR> DivX
[03/31/2009|09:55] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Hamachi
[08/09/2007|07:03] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Help
[03/02/2006|03:28] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Identities
[07/12/2006|11:27] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Intel
[03/03/2006|12:22] C:\DOCUME~1\Noel\APPLIC~1\<DIR> InterVideo
[03/02/2006|05:54] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Intuit
[07/12/2006|08:13] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Macromedia
[08/25/2008|07:02] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Microsoft
[06/23/2008|06:01] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Mozilla
[07/12/2006|05:01] C:\DOCUME~1\Noel\APPLIC~1\<DIR> MSNInstaller
[07/12/2006|04:18] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Opera
[08/23/2006|12:56] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Otto
[04/02/2009|05:31] C:\DOCUME~1\Noel\APPLIC~1\<DIR> PC Tools
[07/13/2006|12:47] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Protector Suite
[12/25/2008|04:30] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Simple Sudoku
[12/26/2007|11:22] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Sony Corporation
[09/22/2008|08:34] C:\DOCUME~1\Noel\APPLIC~1\<DIR> SpeedSim
[09/21/2006|10:11] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Sun
[10/11/2006|09:10] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Template
[04/02/2007|11:43] C:\DOCUME~1\Noel\APPLIC~1\<DIR> TextPad
[07/13/2006|02:00] C:\DOCUME~1\Noel\APPLIC~1\<DIR> toshiba
[09/03/2006|01:49] C:\DOCUME~1\Noel\APPLIC~1\<DIR> TuneUp Software
[03/05/2007|07:52] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Ventrilo
[04/02/2009|01:31] C:\DOCUME~1\Noel\APPLIC~1\<DIR> Webroot
[07/12/2006|07:39] C:\DOCUME~1\Noel\APPLIC~1\<DIR> WildTangent
[03/02/2006|06:03] C:\DOCUME~1\Noel\APPLIC~1\<DIR> You've Got Pictures Screensaver

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[04/03/2009 05:59 AM][--a------] C:\WINDOWS\tasks\wrSpySweeper_L540A79C9BBCA46128C9F6AB7C009C481.job
[03/18/2009 08:32 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[04/03/2009 04:17 PM][--a------] C:\WINDOWS\tasks\1-Click Maintenance.job
[07/12/2006 11:27 PM][--a------] C:\WINDOWS\tasks\Registration reminder 2.job
[03/07/2009 10:24 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 06:00 AM][-r-h-c---] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[03/02/2006|05:36] C:\Program Files\<DIR> Adobe
[02/18/2008|06:54] C:\Program Files\<DIR> AIM
[03/30/2009|12:01] C:\Program Files\<DIR> AIM Toolbar
[12/01/2008|02:34] C:\Program Files\<DIR> AIM6
[01/02/2008|01:02] C:\Program Files\<DIR> AOD
[08/11/2008|07:05] C:\Program Files\<DIR> Apple Software Update
[03/02/2006|05:40] C:\Program Files\<DIR> ArcSoft
[07/12/2006|11:28] C:\Program Files\<DIR> AVerMedia
[07/04/2007|07:38] C:\Program Files\<DIR> AWS
[03/07/2009|09:08] C:\Program Files\<DIR> BitComet
[03/18/2009|10:35] C:\Program Files\<DIR> Bonjour
[03/07/2009|09:29] C:\Program Files\<DIR> Common Files
[03/02/2006|03:24] C:\Program Files\<DIR> ComPlus Applications
[03/02/2006|04:23] C:\Program Files\<DIR> CONEXANT
[07/30/2008|07:00] C:\Program Files\<DIR> Diablo II
[04/02/2009|08:39] C:\Program Files\<DIR> DIGStream
[03/02/2006|04:23] C:\Program Files\<DIR> DVD-RAM
[08/04/2008|06:50] C:\Program Files\<DIR> DVDVideoSoft
[09/06/2006|11:12] C:\Program Files\<DIR> ElcomSoft
[07/18/2008|03:21] C:\Program Files\<DIR> EnglishOtto
[07/18/2008|03:21] C:\Program Files\<DIR> ESPNMotion
[08/25/2008|10:14] C:\Program Files\<DIR> Frets on Fire
[07/18/2008|03:21] C:\Program Files\<DIR> GemMaster
[07/13/2006|12:30] C:\Program Files\<DIR> Google
[03/02/2006|06:04] C:\Program Files\<DIR> illiminable
[09/09/2008|05:03] C:\Program Files\<DIR> InstallShield Installation Information
[07/12/2006|11:27] C:\Program Files\<DIR> Intel
[08/14/2008|02:03] C:\Program Files\<DIR> Internet Explorer
[03/02/2006|05:50] C:\Program Files\<DIR> InterVideo
[11/30/2008|08:27] C:\Program Files\<DIR> iPod
[11/30/2008|08:27] C:\Program Files\<DIR> iTunes
[03/07/2009|09:27] C:\Program Files\<DIR> Java
[03/07/2009|09:08] C:\Program Files\<DIR> LimeWire
[03/06/2009|06:39] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[03/02/2006|05:50] C:\Program Files\<DIR> McAfee.com
[08/14/2008|02:06] C:\Program Files\<DIR> Messenger
[03/02/2006|05:03] C:\Program Files\<DIR> Metamail Inc
[03/02/2006|03:42] C:\Program Files\<DIR> Microsoft ActiveSync
[03/02/2006|03:29] C:\Program Files\<DIR> microsoft frontpage
[08/25/2008|06:52] C:\Program Files\<DIR> Microsoft Office
[09/07/2008|08:46] C:\Program Files\<DIR> Microsoft Silverlight
[08/25/2008|06:52] C:\Program Files\<DIR> Microsoft Works
[03/02/2006|03:41] C:\Program Files\<DIR> Microsoft.NET
[03/02/2006|03:26] C:\Program Files\<DIR> Movie Maker
[03/07/2009|03:42] C:\Program Files\<DIR> Mozilla Firefox
[07/12/2006|04:52] C:\Program Files\<DIR> MSN
[03/02/2006|03:23] C:\Program Files\<DIR> MSN Gaming Zone
[04/02/2009|01:31] C:\Program Files\<DIR> MSSOAP
[11/18/2006|03:01] C:\Program Files\<DIR> MSXML 4.0
[08/24/2007|10:11] C:\Program Files\<DIR> netbeans-5.0
[03/02/2006|03:26] C:\Program Files\<DIR> NetMeeting
[03/02/2006|03:26] C:\Program Files\<DIR> Online Services
[12/01/2008|04:00] C:\Program Files\<DIR> Opera
[06/12/2007|11:53] C:\Program Files\<DIR> Outlook Express
[05/20/2008|08:25] C:\Program Files\<DIR> PokerStars
[07/18/2008|03:21] C:\Program Files\<DIR> Protector Suite QL
[07/13/2006|05:03] C:\Program Files\<DIR> Pure Networks
[07/18/2008|03:21] C:\Program Files\<DIR> Quicken
[11/30/2008|08:25] C:\Program Files\<DIR> QuickTime
[02/05/2007|10:04] C:\Program Files\<DIR> Real
[11/19/2008|07:37] C:\Program Files\<DIR> Research In Motion
[07/18/2008|03:21] C:\Program Files\<DIR> RGB
[08/09/2007|07:03] C:\Program Files\<DIR> Simple Sudoku
[03/02/2006|05:56] C:\Program Files\<DIR> Sonic
[12/26/2007|11:13] C:\Program Files\<DIR> Sony
[11/28/2008|04:38] C:\Program Files\<DIR> SpeedSim
[03/06/2009|06:02] C:\Program Files\<DIR> Spybot - Search & Destroy
[03/06/2009|06:02] C:\Program Files\<DIR> Spyware Doctor
[11/08/2008|10:19] C:\Program Files\<DIR> Stardock
[09/14/2008|05:50] C:\Program Files\<DIR> Sun
[03/02/2006|04:29] C:\Program Files\<DIR> Synaptics
[08/28/2006|11:52] C:\Program Files\<DIR> TextPad 4
[09/14/2008|05:32] C:\Program Files\<DIR> TextPad 5
[07/12/2006|07:37] C:\Program Files\<DIR> Toshiba
[03/11/2008|12:30] C:\Program Files\<DIR> Toshiba Games
[03/06/2009|06:23] C:\Program Files\<DIR> Trend Micro
[12/25/2008|10:19] C:\Program Files\<DIR> TuneUp Utilities 2008
[03/02/2006|03:33] C:\Program Files\<DIR> Uninstall Information
[11/21/2007|12:37] C:\Program Files\<DIR> VentSrv
[04/14/2007|10:22] C:\Program Files\<DIR> Warcraft III
[04/02/2009|01:31] C:\Program Files\<DIR> Webroot
[03/02/2006|04:54] C:\Program Files\<DIR> WildTangent
[03/06/2008|01:52] C:\Program Files\<DIR> Windows Live
[02/05/2007|10:06] C:\Program Files\<DIR> Windows Live Toolbar
[07/18/2008|03:21] C:\Program Files\<DIR> Windows Media Connect 2
[04/22/2008|01:01] C:\Program Files\<DIR> Windows Media Player
[03/02/2006|03:23] C:\Program Files\<DIR> Windows NT
[03/02/2006|03:24] C:\Program Files\<DIR> Windows Plus
[03/02/2006|03:26] C:\Program Files\<DIR> WindowsUpdate
[03/02/2006|03:29] C:\Program Files\<DIR> xerox
[03/02/2006|06:04] C:\Program Files\<DIR> Yahoo!

--------------------\\ Listing Folders in C:\Program Files\Common Files

[02/14/2008|12:03] C:\Program Files\Common Files\<DIR> AOL
[11/30/2008|08:27] C:\Program Files\Common Files\<DIR> Apple
[03/12/2008|10:22] C:\Program Files\Common Files\<DIR> Blizzard Entertainment
[03/02/2006|03:41] C:\Program Files\Common Files\<DIR> DESIGNER
[08/04/2008|06:45] C:\Program Files\Common Files\<DIR> DVDVideoSoft
[09/22/2006|12:18] C:\Program Files\Common Files\<DIR> InstallShield
[03/02/2006|05:50] C:\Program Files\Common Files\<DIR> InterVideo
[03/02/2006|05:54] C:\Program Files\Common Files\<DIR> Intuit
[08/25/2008|06:55] C:\Program Files\Common Files\<DIR> Microsoft Shared
[03/02/2006|03:26] C:\Program Files\Common Files\<DIR> MSSoap
[03/02/2006|06:03] C:\Program Files\Common Files\<DIR> Nullsoft
[03/02/2006|07:19] C:\Program Files\Common Files\<DIR> ODBC
[03/02/2006|05:54] C:\Program Files\Common Files\<DIR> Palo Alto Software
[04/02/2009|05:34] C:\Program Files\Common Files\<DIR> PC Tools
[07/12/2006|11:29] C:\Program Files\Common Files\<DIR> Protector Suite QL
[08/30/2006|09:45] C:\Program Files\Common Files\<DIR> Real
[03/02/2006|03:26] C:\Program Files\Common Files\<DIR> Services
[03/02/2006|07:19] C:\Program Files\Common Files\<DIR> SpeechEngines
[11/08/2008|10:19] C:\Program Files\Common Files\<DIR> Stardock
[04/02/2009|10:59] C:\Program Files\Common Files\<DIR> Symantec Shared
[03/07/2009|09:45] C:\Program Files\Common Files\<DIR> System
[03/06/2008|01:50] C:\Program Files\Common Files\<DIR> WindowsLiveInstaller
[07/06/2008|09:48] C:\Program Files\Common Files\<DIR> Wise Installation Wizard

--------------------\\ Process

( 56 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-07 21:36:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\Noel\Application Data\Opera\Opera\profile\images\www.crack.ms.ico
C:\DOCUME~1\Noel\Application Data\Opera\Opera\profile\images\www.crackpassword.com.ico


[F:28][D:5]-> C:\DOCUME~1\Noel\LOCALS~1\Temp
[F:15][D:0]-> C:\DOCUME~1\Noel\Cookies
[F:72][D:7]-> C:\DOCUME~1\Noel\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sat 03/07/2009|21:38 - Option : [1]

--------------------\\ Scan completed at 21:38:07

#6
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
You appear to have had the BOOTLOG running for a while. Please delete the file C:\Windows\ntbtlog.txt , reboot the computer again and attach the newly created file.

Thanks.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#7
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Run the Lop S&D after the restart?

Thanks,

Taylor

#8
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
No, we're done with LOP for now. Just upload the NEW C:\Windows\ntbtlog.txt which is updated every time you reboot until you turn it off.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#9
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Gotcha. I'll have it in a minute here.

Taylor

#10
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Service Pack 2 3 7 2009 22:50:33.359
Loaded driver \WINDOWS\system32\ntoskrnl.exe
Loaded driver \WINDOWS\system32\hal.dll
Loaded driver \WINDOWS\system32\KDCOM.DLL
Loaded driver \WINDOWS\system32\BOOTVID.dll
Loaded driver ACPI.sys
Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver ohci1394.sys
Loaded driver \WINDOWS\system32\DRIVERS\1394BUS.SYS
Loaded driver sshrmd.sys
Loaded driver ssfs0bbc.sys
Loaded driver ssidrv.sys
Loaded driver \WINDOWS\system32\DRIVERS\NDIS.SYS
Loaded driver \WINDOWS\system32\DRIVERS\TDI.SYS
Loaded driver compbatt.sys
Loaded driver \WINDOWS\system32\DRIVERS\BATTC.SYS
Loaded driver pciide.sys
Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Loaded driver pcmcia.sys
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver dmload.sys
Loaded driver dmio.sys
Loaded driver ACPIEC.sys
Loaded driver \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
Loaded driver PartMgr.sys
Loaded driver VolSnap.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Loaded driver fltMgr.sys
Loaded driver sr.sys
Loaded driver PCTCore.sys
Loaded driver DRVMCDB.SYS
Loaded driver PxHelp20.sys
Loaded driver KSecDD.sys
Loaded driver Ntfs.sys
Loaded driver Mup.sys
Loaded driver \SystemRoot\system32\DRIVERS\intelppm.sys
Loaded driver \SystemRoot\system32\DRIVERS\ialmnt5.sys
Loaded driver \SystemRoot\system32\DRIVERS\HDAudBus.sys
Loaded driver \SystemRoot\system32\DRIVERS\w39n51.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbuhci.sys
Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
Loaded driver \SystemRoot\system32\drivers\tifm21.sys
Loaded driver \SystemRoot\system32\DRIVERS\sdbus.sys
Loaded driver \SystemRoot\system32\DRIVERS\e100b325.sys
Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\Drivers\sskbfd.sys
Loaded driver \SystemRoot\system32\drivers\qkbfiltr.sys
Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\system32\drivers\qmofiltr.sys
Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys
Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
Loaded driver \SystemRoot\system32\drivers\iviaspi.sys
Loaded driver \SystemRoot\system32\drivers\pfc.sys
Loaded driver \SystemRoot\System32\Drivers\DLACDBHM.SYS
Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
Loaded driver \SystemRoot\System32\Drivers\GEARAspiWDM.sys
Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
Loaded driver \SystemRoot\system32\DRIVERS\wmiacpi.sys
Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
Loaded driver \SystemRoot\system32\DRIVERS\rdpdr.sys
Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\system32\DRIVERS\update.sys
Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
Loaded driver \SystemRoot\system32\drivers\BoiHwSetup.sys
Loaded driver \SystemRoot\system32\DRIVERS\tbiosdrv.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\system32\drivers\CHDAud.sys
Loaded driver \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
Loaded driver \SystemRoot\system32\DRIVERS\HSF_DPV.sys
Loaded driver \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Fdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Flpydisk.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Did not load driver \SystemRoot\System32\Drivers\i2omgmt.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Loaded driver \SystemRoot\System32\Drivers\DLARTL_N.SYS
Did not load driver \SystemRoot\system32\DRIVERS\kbdhid.sys
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\System32\Drivers\Udfs.SYS
Loaded driver \SystemRoot\System32\Drivers\meiudf.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
Loaded driver \SystemRoot\System32\drivers\afd.sys
Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
Loaded driver \SystemRoot\System32\Drivers\tcusb.sys
Loaded driver \??\C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys
Loaded driver \??\C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys
Loaded driver \SystemRoot\System32\Drivers\DRVNDDM.SYS
Loaded driver \SystemRoot\System32\DLA\DLADResN.SYS
Loaded driver \SystemRoot\System32\DLA\DLAIFS_M.SYS
Loaded driver \SystemRoot\System32\DLA\DLAOPIOM.SYS
Loaded driver \SystemRoot\System32\DLA\DLAPoolM.SYS
Loaded driver \??\C:\Program Files\Protector Suite QL\smihlp.sys
Loaded driver \SystemRoot\System32\DLA\DLABOIOM.SYS
Loaded driver \SystemRoot\System32\DLA\DLAUDFAM.SYS
Loaded driver \SystemRoot\System32\DLA\DLAUDF_M.SYS
Loaded driver \SystemRoot\system32\DRIVERS\AegisP.sys
Loaded driver \SystemRoot\system32\DRIVERS\s24trans.sys
Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
Loaded driver \SystemRoot\system32\DRIVERS\netdevio.sys
Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
Did not load driver \SystemRoot\System32\Drivers\Serial.SYS
Loaded driver \SystemRoot\System32\Drivers\HTTP.sys
Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys
Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys
Loaded driver \SystemRoot\system32\drivers\aec.sys
Loaded driver \SystemRoot\system32\drivers\swmidi.sys
Loaded driver \SystemRoot\system32\drivers\DMusic.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
Loaded driver \SystemRoot\system32\DRIVERS\USBSTOR.SYS
Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS

#11
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Well current logs don't show anything obvious.

Please try the following and let me know if you have trouble with it, otherwise post back it's log.

Update and Scan with Malwarebytes' Anti-Malware
  • Start MalwareBytes AntiMalware (Vista users must Right click and choose RunAs Admin)
  • Please DO NOT run MBAM in Safe Mode unless requested to, you MUST run it in normal Windows mode.
    • Update Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Update
  • When the update is complete, select the Scanner tab
  • Select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Then post back the MBAM log and a new Hijackthis log.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#12
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Still getting the vbAccelerator RT errors when trying to install

Thanks,

Taylor

#13
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
But you can access security sites okay? Aside from errors installing MBAM does everything else seem okay?

Please look in your C:\WINDOWS\SYSTEM32 folder for a file named REGSVR32.EXE and make sure there is one.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#14
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Yeah, everything else seems under control. I was able to download and install Spybot, Spy Sweeper and Spy Doctor just fine on the local machine.

Just MBAM that's giving me troubles.

Thanks,

Taylor

#15
taylorhempel

    New Member

  • Members
  • Pip
  • 9 posts
Sorry, yes regsvr32.exe is present.

#16
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Okay just another update that the code is now functional and probably at about 98% completion for an Alternate installer for MBAM.

I still need to clean up some debug code and polish it up a bit for normal users to use it and then I'll post you a link for it to try out.

NOTES:
1. This is NOT for use by everyone and should ONLY be used by users that appear to have a CLEAN system but are still having issues installing MBAM.
2. It will only run on English Windows XP 32 Bit.
3. If it does work and you can now scan with the program you should update and do a scan, then remove it and do an install with the normal PUBLISHED program from Malwarebytes.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#17
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Please download and run this alternative installer. Make sure you close all other applications as it will restart the computer when it's finished.

Download here: fixmbam.exe

Let me know how it works out please.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#18
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Please post a status update on this
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#19
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us