1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Only able to run in safe mode-scans

Discussion in 'Malware and Virus Removal Archive' started by Inb4Jordan, 2012/10/01.

Thread Status:
Not open for further replies.
  1. 2012/10/01
    Inb4Jordan

    Inb4Jordan Inactive Thread Starter

    Joined:
    2012/10/01
    Messages:
    3
    Likes Received:
    0
    [Inactive] Only able to run in safe mode-scans

    dds.txt--
    .
    DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
    Internet Explorer: 7.0.5730.13
    Run by Jordan at 15:46:58 on 2012-10-01
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\Explorer.EXE
    C:\Documents and Settings\Jordan.LAPTOP1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jordan.LAPTOP1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Documents and Settings\Jordan.LAPTOP1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jordan.LAPTOP1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
    C:\Documents and Settings\Jordan.LAPTOP1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jordan.LAPTOP1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Jordan.LAPTOP1\My Documents\Downloads\dds.com
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.ca/
    uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {90222687-F593-4738-B738-FBEE9C7B26DF} - No File
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
    TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Google Update] "c:\documents and settings\jordan.laptop1\local settings\application data\google\update\GoogleUpdate.exe" /c
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe "
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe "
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Boot] c:\acer\empowering technology\epower\Boot.exe
    mRun: [AzMixerSel] c:\program files\realtek\installshield\AzMixerSel.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe "
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [Acer ePresentation HPD] c:\acer\empowering technology\epresentation\ePresentation.exe
    mRun: [ePower_DMC] c:\acer\empowering technology\epower\ePower_DMC.exe
    mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    mRun: [COMODO] c:\program files\comodo\comodo geekbuddy\CLPSLA.exe
    mRun: [CPA] c:\program files\comodo\comodo geekbuddy\VALA.exe
    mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    LSP: mswsock.dll
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
    DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager/plugin/IEGetPlugin.cab
    DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1349115084312
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab
    TCP: DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{784241E9-0165-4ED0-9C37-9B4FA19A8792} : DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{FDFD018C-2D58-41A2-933C-256665BAB532} : DhcpNameServer = 192.168.0.1
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R? getPlus(R) Installer;getPlus(R) Installer
    R? syshost32;syshost32
    S? CLPSLS;COMODO livePCsupport Service
    .
    =============== Created Last 30 ================
    .
    2012-10-01 20:17:54 -------- d-----w- c:\documents and settings\all users\application data\Comodo
    2012-10-01 20:17:46 -------- d-----w- c:\program files\COMODO
    2012-10-01 20:17:44 1700352 ----a-w- c:\windows\system32\gdiplus.dll
    2012-10-01 20:16:29 54016 ----a-w- c:\windows\system32\drivers\gbsl.sys
    2012-10-01 19:54:37 -------- d-----w- c:\documents and settings\jordan.laptop1\application data\Malwarebytes
    2012-10-01 19:53:38 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-10-01 19:53:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2012-10-01 00:51:01 -------- d-----w- c:\documents and settings\jordan.laptop1\jagexcache
    2012-09-30 22:23:01 -------- d-----w- c:\documents and settings\jordan.laptop1\local settings\application data\Google
    2012-09-30 22:21:46 -------- d-----w- c:\documents and settings\jordan.laptop1\local settings\application data\Deployment
    2012-09-30 21:14:54 -------- d-----w- c:\program files\VideoLAN
    2012-09-30 20:37:05 -------- d-----w- c:\program files\TeamViewer
    2012-09-29 04:32:17 -------- d-----w- c:\windows\setup.pss
    2012-09-29 03:21:26 -------- d-----w- c:\program files\EASEUS
    2012-09-29 03:18:02 -------- d-----w- c:\documents and settings\jordan.laptop1\application data\TeamViewer
    2012-09-28 20:45:39 70528 ----a-w- c:\windows\system32\drivers\16105c64707131bd.sys
    2012-09-28 20:44:48 3993600 ----a-w- c:\program files\GUTC6.tmp
    2012-09-28 20:36:55 -------- d-----w- c:\windows\system32\CatRoot_bak
    2012-09-28 02:45:05 666492 ----a-w- c:\windows\system32\PerfStringBackup.TMP
    2012-09-28 02:05:42 -------- d-----w- c:\program files\Support Tools
    2012-09-28 01:21:28 119808 ---ha-w- c:\windows\system32\Copy of winmine.exe
    .
    ==================== Find3M ====================
    .
    .
    ============= FINISH: 15:52:42.39 ===============

    attach.txt--
    .
    ==== Installed Programs ======================
    .
    Acer eDataSecurity Management
    Acer eDataSecurity Management 2.0.4088
    Acer eLock Management
    Acer Empowering Technology
    Acer ePower Management
    Acer ePresentation Management
    Acer eSettings Management
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.2.0
    Adobe Shockwave Player
    Broadcom Gigabit Integrated Controller
    CCleaner
    COMODO GeekBuddy
    getPlus(R) for Corel
    Google Chrome
    HDAUDIO Soft Data Fax Modem with SmartCP
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB954550-v5)
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) Matrix Storage Manager
    Java(TM) 6 Update 14
    Java(TM) 6 Update 4
    LightScribe 1.4.142.1
    Malwarebytes Anti-Malware version 1.65.0.1400
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2656353)
    Microsoft .NET Framework 1.1 Security Update (KB2656370)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2003 Web Components
    Microsoft Office File Validation Add-In
    Microsoft Office Professional Edition 2003
    Microsoft Office Small Business Connectivity Components
    Microsoft Silverlight
    Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    Mirar
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB954459)
    NTI Backup NOW! 4.7
    NTI CD & DVD-Maker
    NTI Shadow
    PowerDVD
    QuickTime
    Realtek High Definition Audio Driver
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
    Security Update for Windows XP (KB923789)
    Synaptics Pointing Device Driver
    TeamViewer 7
    Texas Instruments PCIxx21/x515/xx12 drivers.
    TIPCI
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Installer 3.1 (KB893803)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Support Tools
    .
    ==== End Of File ===========================
     
  2. 2012/10/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, complete all steps listed HERE

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.