#1
Posted 02 September 2009 - 06:36 PM
#2
Posted 02 September 2009 - 07:36 PM
Welcome.
Please save this file to your desktop. Double-click on it to run a scan. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.

Unanswered threads for move than five (5) days, will be removed from my subscriptions.
No help throughout a Private Message will be provided.
Please do not post on someone else's thread. it will be removed immediately
If I have helped you, consider making a donation to help me continue the fight against Malware! 
#3
Posted 02 September 2009 - 07:47 PM
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00147\MCE00147
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00148\MCE00148
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00149\MCE00149
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0014a\MCE0014a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0014b\MCE0014b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0014c\MCE0014c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0014d\MCE0014d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0014e\MCE0014e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0014f\MCE0014f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00150\MCE00150
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00151\MCE00151
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00152\MCE00152
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00153\MCE00153
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00154\MCE00154
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00155\MCE00155
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00156\MCE00156
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00157\MCE00157
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00158\MCE00158
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00159\MCE00159
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0015a\MCE0015a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0015b\MCE0015b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0015c\MCE0015c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0015d\MCE0015d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0015e\MCE0015e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0015f\MCE0015f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00160\MCE00160
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00161\MCE00161
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00162\MCE00162
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00163\MCE00163
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00164\MCE00164
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00165\MCE00165
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00166\MCE00166
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00167\MCE00167
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00168\MCE00168
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00169\MCE00169
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0016a\MCE0016a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0016b\MCE0016b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0016c\MCE0016c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0016d\MCE0016d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0016e\MCE0016e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0016f\MCE0016f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00170\MCE00170
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00171\MCE00171
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00172\MCE00172
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00173\MCE00173
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00174\MCE00174
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00175\MCE00175
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00176\MCE00176
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00177\MCE00177
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00178\MCE00178
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00179\MCE00179
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0017a\MCE0017a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0017b\MCE0017b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0017c\MCE0017c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0017d\MCE0017d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0017e\MCE0017e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0017f\MCE0017f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00180\MCE00180
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00181\MCE00181
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00182\MCE00182
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00183\MCE00183
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00184\MCE00184
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00185\MCE00185
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00186\MCE00186
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00187\MCE00187
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00188\MCE00188
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00189\MCE00189
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0018a\MCE0018a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0018b\MCE0018b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0018c\MCE0018c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0018d\MCE0018d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0018e\MCE0018e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0018f\MCE0018f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00190\MCE00190
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00191\MCE00191
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00192\MCE00192
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00193\MCE00193
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00194\MCE00194
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00195\MCE00195
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00196\MCE00196
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00197\MCE00197
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00198\MCE00198
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE00199\MCE00199
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0019a\MCE0019a
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0019b\MCE0019b
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0019c\MCE0019c
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0019d\MCE0019d
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0019e\MCE0019e
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE0019f\MCE0019f
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a0\MCE001a0
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a1\MCE001a1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a2\MCE001a2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a3\MCE001a3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a4\MCE001a4
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a5\MCE001a5
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a6\MCE001a6
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a7\MCE001a7
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a8\MCE001a8
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001a9\MCE001a9
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001aa\MCE001aa
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ab\MCE001ab
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ac\MCE001ac
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ad\MCE001ad
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ae\MCE001ae
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001af\MCE001af
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b0\MCE001b0
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b1\MCE001b1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b2\MCE001b2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b3\MCE001b3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b4\MCE001b4
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b5\MCE001b5
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b6\MCE001b6
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b7\MCE001b7
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b8\MCE001b8
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001b9\MCE001b9
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ba\MCE001ba
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001bb\MCE001bb
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001bc\MCE001bc
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001bd\MCE001bd
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001be\MCE001be
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001bf\MCE001bf
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c0\MCE001c0
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c1\MCE001c1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c2\MCE001c2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c3\MCE001c3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c4\MCE001c4
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c5\MCE001c5
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c6\MCE001c6
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c7\MCE001c7
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c8\MCE001c8
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001c9\MCE001c9
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ca\MCE001ca
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001cb\MCE001cb
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001cc\MCE001cc
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001cd\MCE001cd
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001ce\MCE001ce
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001cf\MCE001cf
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d0\MCE001d0
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d1\MCE001d1
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d2\MCE001d2
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d3\MCE001d3
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d4\MCE001d4
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d5\MCE001d5
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d6\MCE001d6
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d7\MCE001d7
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\MCE001d8\MCE001d8
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\Temp\SiteAdvisor\SiteAdvisor
Mount point destination : \Device\__max++>\^
Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp
Mount point destination : \Device\__max++>\^
Finished! Press any key to exit...
#4
Posted 02 September 2009 - 10:31 PM
Click on Start->Run, then Copy and Paste the following command (including the quotation marks) into the "Run" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.
"%userprofile%\desktop\win32kdiag.exe" -f -r

Unanswered threads for move than five (5) days, will be removed from my subscriptions.
No help throughout a Private Message will be provided.
Please do not post on someone else's thread. it will be removed immediately
If I have helped you, consider making a donation to help me continue the fight against Malware! 
#5
Posted 03 September 2009 - 02:14 PM
Thanks again
#6
Posted 03 September 2009 - 05:49 PM
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
- Tools->Options->Main tab
- During the download, rename Combofix to Combo-Fix as follows:


- It is important you rename Combofix during the download, but not after.
- Please do not rename Combofix to other names, but only to the one indicated.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-----------------------------------------------------------
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
-----------------------------------------------------------
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
-----------------------------------------------------------
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Double click on combo-Fix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\Combo-Fix.txt" .
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
Please do not install any new programs or update anything unless told to do so while we are fixing your problem.

Unanswered threads for move than five (5) days, will be removed from my subscriptions.
No help throughout a Private Message will be provided.
Please do not post on someone else's thread. it will be removed immediately
If I have helped you, consider making a donation to help me continue the fight against Malware! 
#7
Posted 03 September 2009 - 08:19 PM

Unanswered threads for move than five (5) days, will be removed from my subscriptions.
No help throughout a Private Message will be provided.
Please do not post on someone else's thread. it will be removed immediately
If I have helped you, consider making a donation to help me continue the fight against Malware! 
#8
Posted 03 September 2009 - 08:24 PM
JSntgRvr, on Sep 3 2009, 09:19 PM, said:
- Please download Junction.zip and save it.
- Unzip it and put junction.exe in the Windows directory (C:\Windows).
- Go to Start => Run... => Copy and paste the following command in the run box and click OK:
[indent]cmd /c junction -s c:\ >log.txt&log.txt& del log.txt[/indent]A command window opens starting to scan the system. Wait until a log file opens. Copy and paste or attach the content of it.
JSntgRvr
Was this for me or sbattista? I think my machine is good now but i'd love to double check and make sure we are in the clear. Let me know which of the two i should run to verify it? ComboFix or the Junction?
#9
Posted 03 September 2009 - 08:43 PM

Unanswered threads for move than five (5) days, will be removed from my subscriptions.
No help throughout a Private Message will be provided.
Please do not post on someone else's thread. it will be removed immediately
If I have helped you, consider making a donation to help me continue the fight against Malware! 
#10
Posted 03 September 2009 - 08:47 PM

Unanswered threads for move than five (5) days, will be removed from my subscriptions.
No help throughout a Private Message will be provided.
Please do not post on someone else's thread. it will be removed immediately
If I have helped you, consider making a donation to help me continue the fight against Malware! 
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top









