Running Windows XP Pro with SP3.
IE Explorer is the main web application.
Hard Drive is only about 50% full.
I've run MBAM and SuperAntiSpyware a couple of times to clean recurring malware.
Constantly has the following problem at Startup:
WINLOGON.EXE - Application Error
The instruction at 0x00182581 referenced memory at 0x012f0000. The memory could not be "read"
If I ignore the warning, the computer works with limited functionality. If I click OK or Cancel, it goes into BSOD.
Computer is finishing another MBAM scan right now.....as soon at that completes, I'll run and post:
1) BlueScreenView logs
2) DDS logs
3) GMER logs
for one of you fine folks to analyze and give me some help to get her back in decent health.
Here are the BlueScreenView logs:
==================================================
Dump File : Mini070210-01.dmp
Crash Time : 7/2/2010 9:02:14 PM
Bug Check String : KERNEL_MODE_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000008e
Parameter 1 : 0xc0000017
Parameter 2 : 0x8056d666
Parameter 3 : 0xa9301654
Parameter 4 : 0x00000000
Caused By Driver : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+96666
File Description : NT Kernel & System
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5938 (xpsp_sp3_gdr.100216-1514)
Processor : 32-bit
Computer Name :
Full Path : C:WINDOWSMinidumpMini070210-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================
==================================================
Dump File : Mini072208-01.dmp
Crash Time : 7/22/2008 8:53:35 AM
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x00000000
Parameter 3 : 0xf88cca98
Parameter 4 : 0xf88cc794
Caused By Driver : usbhub.sys
Caused By Address : usbhub.sys+46ff
File Description : Default Hub Driver for USB
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Computer Name :
Full Path : C:WINDOWSMinidumpMini072208-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================
==================================================
Dump File : Mini071107-01.dmp
Crash Time : 7/11/2007 8:37:25 AM
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x00000000
Parameter 3 : 0xf88c8a98
Parameter 4 : 0xf88c8794
Caused By Driver : usbhub.sys
Caused By Address : usbhub.sys+46ff
File Description : Default Hub Driver for USB
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Computer Name :
Full Path : C:WINDOWSMinidumpMini071107-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================
==================================================
Dump File : Mini061807-01.dmp
Crash Time : 6/18/2007 10:25:46 AM
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x00000000
Parameter 3 : 0xf88c0a98
Parameter 4 : 0xf88c0794
Caused By Driver : usbhub.sys
Caused By Address : usbhub.sys+46ff
File Description : Default Hub Driver for USB
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Computer Name :
Full Path : C:WINDOWSMinidumpMini061807-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================
==================================================
Dump File : Mini061307-01.dmp
Crash Time : 6/13/2007 5:22:35 PM
Bug Check String : SYSTEM_THREAD_EXCEPTION_NOT_HANDLED
Bug Check Code : 0x1000007e
Parameter 1 : 0xc0000005
Parameter 2 : 0x00000000
Parameter 3 : 0xf88d4a98
Parameter 4 : 0xf88d4794
Caused By Driver : usbhub.sys
Caused By Address : usbhub.sys+46ff
File Description : Default Hub Driver for USB
Product Name : Microsoft® Windows® Operating System
Company : Microsoft Corporation
File Version : 5.1.2600.5512 (xpsp.080413-2108)
Processor : 32-bit
Computer Name :
Full Path : C:WINDOWSMinidumpMini061307-01.dmp
Processors Count : 2
Major Version : 15
Minor Version : 2600
==================================================
Here's the DDS log and the Attach.txt (attached):
DDS (Ver_10-03-17.01) - NTFSx86
Run by tammy at 16:19:50.94 on Mon 08/09/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.173 [GMT -4:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:PROGRA~1ENIGMA~1SPYHUN~1SH4SER~1.EXE
C:WINDOWSsystem32svchost -k DcomLaunch
svchost.exe
C:WINDOWSSystem32svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:WINDOWSsystem32spoolsv.exe
svchost.exe
C:Program FilesDigitalPersonaBinDpHost.exe
C:Program FilesJavajre6binjqs.exe
C:Program FilesGoogleUpdate1.2.183.29GoogleCrashHandler.exe
C:Program FilesLogMeInx86RaMaint.exe
C:Program FilesLogMeInx86LogMeIn.exe
C:Program FilesLogMeInx86LMIGuardian.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:PAYCLOCKBTENG32M.EXE
C:PAYCLOCKTOUCHS~1BTENG32M.EXE
C:Program FilesCommon FilesArtisoftTeleVantageTvWksSvc.exe
C:Program FilesRealVNCVNC4WinVNC4.exe
C:WINDOWSExplorer.EXE
C:Program FilesLogMeInx86LogMeInSystray.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:Program FilesLogMeInx86LMIGuardian.exe
C:Program FilesEmailsAgentEmailsAgentEmailsAgent.exe
C:Documents and SettingstammyDesktopdds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://crowecounter.moraware.net/crowecounter/default.asp?wp=16&customerid=3
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:program filesadobeacrobat 7.0activexAcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:program filesgooglegoogletoolbarnotifier5.5.5126.1836swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:windowssystem32Shdocvw.dll
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:progra~1micros~4office11REFIEBAR.DLL
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [swg] "c:program filesgooglegoogletoolbarnotifierGoogleToolbarNotifier.exe"
mRun: [LogMeIn GUI] "c:program fileslogmeinx86LogMeInSystray.exe"
mRun: [SunJavaUpdateSched] c:program filesjavajre6binjusched.exe
dRun: [iqtpdvti] c:documents and settingsnetworkservicelocal settingsapplication dataevueeooukmcyvdiftssd.exe
dRun: [iujmybur] c:documents and settingsnetworkservicelocal settingsapplication dataeksdeadhfmsxwpqgtssd.exe
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupemails~1.lnk - c:program filesemailsagentemailsagentEmailsAgent.exe
uPolicies-explorer: NoActiveDesktop = 2 (0x2)
uPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
uPolicies-system: Wallpaper =
uPolicies-system: EnableProfileQuota = 1 (0x1)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
IE: E&xport to Microsoft Excel - c:progra~1micros~4office11EXCEL.EXE/3000
IE: Google Sidewiki... - c:program filesgooglegoogle toolbarcomponentGoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~4office11REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:windowssystem32Shdocvw.dll
Trusted Zone: isqft.comwww
Trusted Zone: isqft.comwww
Trusted Zone: musicmatch.comonline
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} - hxxp://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_6.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178737890861
DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} - hxxps://mail.crowecounter.com/Remote/msrdp.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {BD41251E-4B03-4898-97B7-74595F808687} = 192.168.1.1
Notify: !SASWinLogon - c:program filessuperantispywareSASWINLO.DLL
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:program filessuperantispywareSASSEH.DLL
LSA: Authentication Packages = msv1_0 c:windowssystem32rQhIxyyw
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:program filessuperantispywaresasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:program filessuperantispywareSASKUTIL.SYS [2010-5-10 67656]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:program fileslogmeinx86rainfo.sys [2008-7-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:windowssystem32driversLMIRfsDriver.sys [2009-2-10 47640]
R2 PayClockServer;PayClock Database Service;c:payclockBteng32m.exe [2007-5-3 200763]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:progra~1enigma~1spyhun~1SH4SER~1.EXE [2010-5-18 327064]
R2 TouchStationServer;PayClock TouchStation Service;c:payclocktouchs~1BTENG32M.EXE [2007-5-3 200763]
R2 TvWksSvc;TeleVantage Workstation Service;c:program filescommon filesartisofttelevantageTvWksSvc.exe [2006-7-11 102400]
R3 dpK00701;U.are.U Fingerprint Reader Upper Driver;c:windowssystem32driversdpK00701.sys [2004-10-12 41856]
R3 TOUCHDSP;TouchStation LCD/LED USB driver;c:windowssystem32driversTOUCHDSP.sys [2007-5-3 48128]
R3 UsbdpFP;U.are.U Fingerprint Reader Class Driver;c:windowssystem32driversUsbdpFP.sys [2004-10-12 45056]
S2 gupdate1c9edbab4cbc1f7;Google Update Service (gupdate1c9edbab4cbc1f7);c:program filesgoogleupdateGoogleUpdate.exe [2009-6-15 133104]
S2 tgeiigy;tgeiigy;??c:windowssystem32driversonzmsqfmqtw.sys --> c:windowssystem32driversonzmsqfmqtw.sys [?]
S3 TOUCHSTA;TOUCHSTA;c:windowssystem32driversTouchSta.SYS [2007-5-9 20736]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
============== File Associations ===============
regfile=regedit.exe "%1" %*
scrfile="%1" %*
=============== Created Last 30 ================
2010-08-09 13:43:45 0 ----a-w- C:__tmp_rar_sfx_access_check_167796
2010-08-06 19:59:44 0 d-----w- C:VundoFix Backups
2010-07-15 16:38:34 0 d-----w- c:docume~1tammyapplic~1SUPERAntiSpyware.com
2010-07-12 12:29:33 0 d-sh--w- c:documents and settingstammyPrivacIE
==================== Find3M ====================
2010-06-09 21:54:36 83360 ----a-w- c:windowssystem32LMIRfsClientNP.dll
2010-06-09 21:54:35 29568 ----a-w- c:windowssystem32LMIport.dll
2010-06-09 21:54:34 87424 ----a-w- c:windowssystem32LMIinit.dll
2009-08-13 19:07:04 17594 -c--a-w- c:program filescommon filespucugo._sy
2009-08-13 19:07:04 14592 -c--a-w- c:program filescommon fileskewycezag.exe
2009-08-13 19:07:04 13545 -c--a-w- c:program filescommon fileseripuwe.inf
2009-08-09 19:28:31 17573 -c--a-w- c:program filescommon filespexubyrym.inf
2009-08-09 19:28:31 15185 ----a-w- c:program filescommon filesjupojofi.dll
2009-08-09 19:28:30 16910 -c--a-w- c:program filescommon fileswibiroguma.bin
2009-08-09 19:28:30 10108 -c--a-w- c:program filescommon filesulyjyxuty.dl
2009-08-06 14:18:01 10941 -c--a-w- c:program filescommon filesiqes.dll
2009-08-06 14:18:00 11198 -c--a-w- c:program filescommon filesybivo.reg
2009-07-13 15:15:08 56 -csh--r- c:windowssystem32A892EC4C7E.sys
2008-03-12 07:13:00 203917 -csha-w- c:windowssystem32cccdd.ini2
2009-07-13 15:15:09 3766 -csha-w- c:windowssystem32KGyGaAvL.sys
2010-01-19 14:13:05 245760 --sha-w- c:windowssystem32configsystemprofileietldcacheindex.dat
============= FINISH: 16:21:21.47 ===============
EDIT: Posts merged ~BP
Oops! Thanks for merging, BP! I remembered on my way home that mods look for unanswered posts.
Edit 9/10 - Added GMER Scan ARK.TXT log file. ~MM


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










