1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active Can't download any antivirus program

Discussion in 'Malware and Virus Removal Archive' started by maha, 2009/04/09.

  1. 2009/04/09
    maha

    maha Inactive Thread Starter

    Joined:
    2009/04/09
    Messages:
    2
    Likes Received:
    0
    [Active] Can't download any antivirus program

    Dear Aaflac I have the same problem, I downloaded combofix as u said to dseawright and attaching the log:
    ComboFix 09-04-04.01 - maha 2009-04-10 1:38:44.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.292 [GMT -7:00]
    Running from: c:\documents and settings\maha\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    D:\WinRAR.exe

    .
    ((((((((((((((((((((((((( Files Created from 2009-03-10 to 2009-04-10 )))))))))))))))))))))))))))))))
    .

    2009-04-10 00:50 . 2004-11-08 14:10 127,744 --a------ c:\windows\system32\drivers\aeaudio.sys
    2009-04-10 00:49 . 2009-04-10 00:49 <DIR> d-------- c:\program files\Analog Devices
    2009-04-10 00:49 . 2001-09-11 14:20 1,285,632 --a------ c:\windows\system32\SMMedia.dll
    2009-04-10 00:49 . 2004-10-13 14:25 259,840 --a------ c:\windows\system32\drivers\smwdm.sys
    2009-04-10 00:49 . 2002-04-17 14:05 122,880 --a------ c:\windows\system32\CleanUp.exe
    2009-04-10 00:49 . 2003-06-16 07:32 118,784 --a------ c:\windows\system32\DSndUp.exe
    2009-04-10 00:49 . 2001-09-11 14:20 30,208 --a------ c:\windows\system32\wdmioctl.dll
    2009-04-10 00:30 . 2009-04-10 00:30 130,424 --a------ c:\windows\system32\drivers\PCTCore.sys
    2009-04-10 00:30 . 2009-04-10 00:30 73,840 --a------ c:\windows\system32\drivers\PCTAppEvent.sys
    2009-04-10 00:30 . 2009-04-10 00:30 28,560 --a------ c:\windows\system32\drivers\AVHook.sys
    2009-04-10 00:30 . 2009-04-10 00:30 21,904 --a------ c:\windows\system32\drivers\AVRec.sys
    2009-04-10 00:30 . 2009-04-10 00:30 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
    2009-04-10 00:25 . 2009-04-10 00:58 <DIR> d-------- c:\program files\Common Files\PC Tools
    2009-04-10 00:22 . 2009-04-10 00:58 <DIR> d-------- c:\program files\PC Tools AntiVirus
    2009-04-10 00:02 . 2009-04-10 01:32 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
    2009-04-09 23:52 . 2009-04-09 23:52 <DIR> d-------- c:\program files\Real
    2009-04-09 23:52 . 2009-04-09 23:52 <DIR> d-------- c:\program files\Common Files\xing shared
    2009-04-09 23:52 . 2009-04-09 23:52 <DIR> d-------- c:\program files\Common Files\Real
    2009-04-09 23:52 . 2009-04-09 23:52 499,712 --a------ c:\windows\system32\msvcp71.dll
    2009-04-09 23:52 . 2009-04-09 23:52 348,160 --a------ c:\windows\system32\msvcr71.dll
    2009-04-09 23:32 . 2009-04-09 23:32 546,328 --a------ C:\RealPlayer11GOLD.exe
    2009-04-09 22:35 . 2009-04-09 22:35 <DIR> d-------- c:\documents and settings\maha\Application Data\InterVideo
    2009-04-09 22:28 . 2004-08-03 23:15 145,792 --a------ c:\windows\system32\drivers\portcls.sys
    2009-04-09 22:21 . 2009-04-09 22:21 <DIR> d-------- c:\documents and settings\maha\Bluetooth Software
    2009-04-09 22:17 . 2009-04-09 22:17 <DIR> d-------- c:\program files\WIDCOMM
    2009-04-09 21:29 . 2009-04-09 21:29 <DIR> d-------- c:\documents and settings\Administrator
    2009-04-09 20:43 . 2009-04-09 21:04 <DIR> d-------- c:\program files\Windows Live Safety Center
    2009-04-09 20:16 . 2009-04-10 00:58 <DIR> d-------- c:\documents and settings\maha\Tracing
    2009-04-09 20:14 . 2009-04-09 20:14 <DIR> d-------- c:\program files\Windows Live SkyDrive
    2009-04-09 20:14 . 2009-04-09 20:14 <DIR> d-------- c:\program files\Microsoft
    2009-04-09 20:13 . 2009-04-09 20:14 <DIR> d-------- c:\program files\Windows Live
    2009-04-09 19:54 . 2009-04-09 19:54 <DIR> d-------- c:\program files\Google
    2009-04-09 19:54 . 2009-04-09 19:54 1,679,792 --a------ c:\program files\googletalk-setup.exe
    2009-04-09 19:51 . 2009-04-09 19:51 <DIR> d-------- c:\program files\Common Files\Windows Live
    2009-04-09 19:50 . 2009-04-09 19:50 1,221,960 --a------ c:\program files\windows live messenger.exe
    2009-04-09 19:40 . 2009-04-09 19:40 <DIR> d-------- c:\windows\Downloaded Installations
    2009-04-09 19:40 . 2009-04-09 19:40 <DIR> d-------- c:\program files\Broadcom
    2009-04-09 19:32 . 2009-04-09 19:32 <DIR> d---s---- c:\documents and settings\maha\UserData
    2009-04-09 19:08 . 2007-06-19 16:26 139,264 --a------ c:\windows\system32\igfxres.dll
    2009-04-09 19:06 . 2009-04-09 19:06 <DIR> d----c--- c:\windows\system32\DRVSTORE
    2009-04-09 19:06 . 2009-04-09 19:06 <DIR> d-------- c:\program files\Texas Instruments Inc
    2009-04-09 19:05 . 2009-04-09 19:05 <DIR> d-------- c:\program files\HPQ
    2009-04-09 19:05 . 2005-12-07 10:35 47,104 --a------ c:\windows\system32\WACntlPnl.cpl
    2009-04-09 19:04 . 2009-04-09 19:04 <DIR> d-------- c:\windows\Options
    2009-04-09 19:04 . 2002-11-21 10:57 204,800 --a------ c:\windows\system32\IVIresizeW7.dll
    2009-04-09 19:04 . 2002-11-21 10:57 200,704 --a------ c:\windows\system32\IVIresizeA6.dll
    2009-04-09 19:04 . 2002-11-21 10:57 192,512 --a------ c:\windows\system32\IVIresizeP6.dll
    2009-04-09 19:04 . 2002-11-21 10:57 192,512 --a------ c:\windows\system32\IVIresizeM6.dll
    2009-04-09 19:04 . 2002-11-21 10:57 188,416 --a------ c:\windows\system32\IVIresizePX.dll
    2009-04-09 19:04 . 2002-11-21 10:57 20,480 --a------ c:\windows\system32\IVIresize.dll
    2009-04-09 19:03 . 2009-04-09 19:03 <DIR> d-------- c:\program files\SP31763
    2009-04-09 19:03 . 2009-04-09 19:04 <DIR> d-------- c:\program files\InterVideo
    2009-04-09 19:01 . 2009-04-10 00:49 <DIR> d--h----- c:\program files\InstallShield Installation Information
    2009-04-09 19:00 . 2009-04-10 00:49 <DIR> d-------- C:\SWSetup
    2009-04-09 19:00 . 2009-04-09 19:00 <DIR> d-------- c:\program files\GCC4243N_fw
    2009-04-09 19:00 . 2009-04-09 19:05 <DIR> d-------- c:\program files\Common Files\InstallShield
    2009-04-09 19:00 . 2005-09-28 16:00 376,320 --------- c:\windows\system32\drivers\BCMWL5.SYS
    2009-04-09 19:00 . 2005-09-28 16:00 176,128 --------- c:\windows\system32\bcmwlu00.EXE
    2009-04-09 19:00 . 2005-09-28 16:00 69,632 --------- c:\windows\system32\bcmwlD2K.EXE

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-04-10 07:35 167,936 ----a-w c:\windows\system32\igfxtray.exe
    2009-04-10 01:53 --------- d-----w c:\program files\microsoft frontpage
    2009-02-07 01:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr "= "c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3955040]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpWirelessAssistant "= "c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
    "googletalk "= "c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
    "SoundMAXPnP "= "c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-02-27 581693]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr "= 1 (0x1)
    "DisableRegistryTools "= 1 (0x1)

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DVD Check.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DVD Check.lnk
    backup=c:\windows\pss\DVD Check.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
    --a------ 2007-06-19 16:26 158488 c:\windows\system32\hkcmd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
    --a------ 2007-06-19 16:26 297752 c:\windows\system32\igfxpers.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
    --a------ 2009-04-10 00:35 167936 c:\windows\system32\igfxtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    --a------ 2009-04-09 23:52 267792 c:\program files\Common Files\Real\Update_OB\realsched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
    --a------ 2005-11-16 14:12 161937 c:\windows\AGRSMMSG.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify "=dword:00000001
    "AntiVirusOverride "=dword:00000001
    "FirewallOverride "=dword:00000001
    "UacDisableNotify "=dword:00000001
    "AntiVirusDisableNotify "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusOverride "=dword:00000001
    "AntiVirusDisableNotify "=dword:00000001
    "FirewallDisableNotify "=dword:00000001
    "FirewallOverride "=dword:00000001
    "UpdatesDisableNotify "=dword:00000001
    "UacDisableNotify "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "d:\\hp drivers\\sp29361.exe "=
    "c:\\Program Files\\HPQ\\HP wireless Assistant\\HPQWA_UI.EXE "=
    "c:\\WINDOWS\\system32\\userinit.exe "=
    "c:\\Program Files\\Google\\Google Talk\\googletalk.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe "=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe "=
    "c:\\Program Files\\WIDCOMM\\Bluetooth Software\\BTTray.exe "=
    "c:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe "=
    "c:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe "=

    R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\klllon.sys --> c:\windows\system32\drivers\klllon.sys [?]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - mchInjDrv
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    .

    **************************************************************************

    catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-04-10 01:39:37
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2009-04-10 1:40:34
    ComboFix-quarantined-files.txt 2009-04-10 08:40:32

    Pre-Run: 16,945,356,800 bytes free
    Post-Run: 17,499,840,512 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT= "Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS= "Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    164


    Kindly instruct me on what to do next
     
    maha,
    #1
  2. 2009/04/09
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    I moved your post.

    http://www.windowsbbs.com/malware-virus-removal/announcements.html

     

  3. to hide this advert.

  4. 2009/04/09
    maha

    maha Inactive Thread Starter

    Joined:
    2009/04/09
    Messages:
    2
    Likes Received:
    0
    appreciating ur help, thnx in advance
     
    maha,
    #3
  5. 2009/04/19
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Welcome to WindowsBBS maha :)

    Are you still in need of assistance? If so, please read this topic and post fresh DDS logs.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.