Been having problems with internet running slow and hard drive being accessed continually.
Getting error at start up: dialogue box;
Delivery Manager Service has encountered a problem and needs to close.
Out of frustration ran Combofix. Log file below. Internet now seems to be running faster (back to normal) and hard drive access is normal but still getting the Delivery Manager Service error at start up.
Also been messing about with services in effort to get the computer to run faster. My first posting so apologies for omissions etc.
Name Status Startup Type Log On As
.NET Runtime Optimization Service v2.0.50727_X86 Manual Local System
Alerter Disabled Local Service
AOL Connectivity Service Disabled Local System
Application Layer Gateway Service Disabled Local Service
Application Management Manual Local System
ASP.NET State Service Manual Network Service
Automatic Updates Started Automatic Local System
AVG Free WatchDog Disabled Local System
Background Intelligent Transfer Service Manual Local System
Canon Camera Access Library 8 Disabled Local System
ClipBook Manual Local System
COM+ Event System Started Manual Local System
COM+ System Application Manual Local System
Computer Browser Disabled Local System
CryptSvc Started Automatic Local System
DCOM Server Process Launcher Started Automatic Local System
DHCP Client Started Automatic Local System
Distributed Link Tracking Client Disabled Local System
Distributed Transaction Coordinator Disabled Network Service
DNS Client Disabled Network Service
DSBrokerService Manual Local System
Error Reporting Service Started Automatic Local System
Event Log Started Automatic Local System
Extensible Authentication Protocol Service Manual Local System
Fast User Switching Compatibility Started Automatic Local System
Fax Disabled Local System
Google Update Service (gupdate) Disabled Local System
Health Key and Certificate Management Service Manual Local System
Help and Support Started Automatic Local System
HTTP SSL Started Automatic Local System
Human Interface Device Access Disabled Local System
IMAPI CD-Burning COM Service Manual Local System
Indexing Service Manual Local System
IPSEC Services Disabled Local System
KService Automatic Local System
LexBce Server Started Automatic Local System
Logical Disk Manager Manual Local System
Logical Disk Manager Administrative Service Manual Local System
McAfee Personal Firewall Service Disabled Local System
McAfee SecurityCenter Update Manager Disabled Local System
McAfee Task Scheduler Disabled Local System
McAfee WSC Integration Disabled Local System
Messenger Disabled Local System
MS Software Shadow Copy Provider Manual Local System
Net Logon Disabled Local System
Net.Tcp Port Sharing Service Manual Local Service
NetMeeting Remote Desktop Sharing Disabled Local System
Network Access Protection Agent Manual Local System
Network Connections Started Automatic Local System
Network DDE Disabled Local System
Network DDE DSDM Disabled Local System
Network Location Awareness (NLA) Disabled Local System
Network Provisioning Service Manual Local System
NI Service Locator Manual Local System
NILM License manager Manual Local System
NT LM Security Support Provider Manual Local System
Office Source Engine Automatic Local System
Performance Logs and Alerts Disabled Network Service
Plug and Play Started Automatic Local System
Portable Media Serial Number Service Manual Local System
Print Spooler Started Automatic Local System
Protected Storage Disabled Local System
QoS RSVP Manual Local System
Remote Access Auto Connection Manager Automatic Local System
Remote Access Connection Manager Manual Local System
Remote Desktop Help Session Manager Disabled Local System
Remote Procedure Call (RPC) Started Automatic Network Service
Remote Procedure Call (RPC) Locator Automatic Network Service
Removable Storage Manual Local System
Routing and Remote Access Disabled Local System
Secondary Logon Started Automatic Local System
Security Accounts Manager Disabled Local System
Security Center Started Automatic Local System
Server Disabled Local System
Shell Hardware Detection Started Automatic Local System
Smart Card Manual Local Service
SSDP Discovery Service Disabled Local Service
System Event Notification Started Automatic Local System
System Restore Service Started Automatic Local System
Task Scheduler Disabled Local System
TCP/IP NetBIOS Helper Started Automatic Local Service
Telephony Disabled Local System
Terminal Services Started Automatic Local System
Themes Disabled Local System
Uninterruptible Power Supply Manual Local Service
Universal Plug and Play Device Host Manual Local Service
Volume Shadow Copy Manual Local System
WebClient Disabled Local Service
Windows Audio Started Automatic Local System
Windows CardSpace Manual Local System
Windows Defender Started Automatic Local System
Windows Firewall/Internet Connection Sharing (ICS) Started Automatic Local System
Windows Image Acquisition (WIA) Started Manual Local System
Windows Installer Manual Local System
Windows Management Instrumentation Started Automatic Local System
Windows Presentation Foundation Font Cache 3.0.0.0 Manual Local Service
Windows Service Pack Installer update service Automatic Local System
Windows Time Disabled Local System
Windows User Mode Driver Framework Manual Local Service
Wired AutoConfig Manual Local System
Wireless Zero Configuration Disabled Local System
WMI Performance Adapter Manual Local System
Workstation Disabled Local System
ComboFix 09-11-18.04 - Clare Merryweather 17/11/2009 21:55.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.246.43 [GMT 0:00]
Running from: c:\documents and settings\Clare Merryweather\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\jestertb.dll
.
((((((((((((((((((((((((( Files Created from 2009-10-17 to 2009-11-17 )))))))))))))))))))))))))))))))
.
2009-11-17 21:55 . 2001-08-17 13:52 13952 ----a-w- c:\windows\system32\drivers\cbidf2k.sys
2009-11-17 21:55 . 2001-08-17 13:52 13952 ----a-w- c:\windows\system32\dllcache\cbidf2k.sys
2009-11-17 21:55 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-17 21:55 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-17 20:08 . 2009-11-17 20:08 -------- d-----w- c:\documents and settings\HelpAssistant\PrivacIE
2009-11-17 19:54 . 2009-11-17 19:54 -------- d-sh--w- c:\documents and settings\HelpAssistant\IETldCache
2009-11-17 19:26 . 2009-11-17 19:33 -------- d-----w- c:\windows\ie8updates
2009-11-17 19:20 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-11-17 19:20 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-17 19:12 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-11-17 18:51 . 2009-11-17 18:51 -------- d-sh--w- c:\documents and settings\Clare Merryweather\PrivacIE
2009-11-17 18:47 . 2009-11-17 18:47 -------- d-sh--w- c:\documents and settings\Clare Merryweather\IETldCache
2009-11-17 18:38 . 2009-11-17 18:41 -------- dc-h--w- c:\windows\ie8
2009-11-10 18:00 . 2009-11-05 20:42 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-11-10 17:57 . 2009-11-05 20:42 610072 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-11-10 17:57 . 2009-11-05 20:42 1657112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-05 21:00 . 2009-10-16 12:12 1119488 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-11-05 20:44 . 2009-11-05 20:53 -------- d-----w- C:\$AVG
2009-11-05 20:43 . 2009-11-07 13:04 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-05 20:42 . 2009-11-05 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-11-04 10:31 . 2009-11-17 20:52 -------- d-----w- c:\documents and settings\HelpAssistant
2009-11-03 20:22 . 2009-11-03 20:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Temp
2009-11-02 20:47 . 2009-11-02 20:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 14:22 . 2009-11-01 14:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-11-01 14:01 . 2009-11-01 14:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2009-10-24 07:13 . 2009-10-24 07:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-17 20:48 . 2008-02-29 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2009-11-17 20:47 . 2008-02-29 19:47 -------- d-----w- c:\program files\Kontiki
2009-11-10 18:00 . 2009-05-25 12:57 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-05 20:43 . 2009-05-25 12:57 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-05 20:43 . 2009-05-25 12:56 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-05 20:42 . 2009-05-25 12:56 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-05 20:42 . 2009-05-25 12:55 -------- d-----w- c:\program files\AVG
2009-11-04 10:47 . 2009-11-04 10:47 64000 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2009-11-04 10:47 . 2009-11-04 10:47 52288 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2009-11-04 10:47 . 2009-11-04 10:47 50688 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2009-11-04 10:47 . 2009-11-04 10:47 114688 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2009-11-04 10:45 . 2008-04-18 18:53 488968 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\setup.exe
2009-11-02 18:47 . 2007-01-11 11:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-02 18:43 . 2007-01-11 11:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-24 07:21 . 2005-07-30 20:59 -------- d-----w- c:\program files\Google
2009-10-08 19:42 . 2009-10-08 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SpellForce Demo
2009-10-08 19:41 . 2009-10-08 19:41 -------- d-----w- c:\program files\SpellingFORCE Demo
2009-09-22 18:17 . 2008-02-12 19:38 -------- d-----w- c:\documents and settings\Clare Merryweather\Application Data\ZoomBrowser EX
2009-09-11 14:18 . 2004-08-04 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 05:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-24 10:21 . 2009-05-25 13:02 36744 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-23 06:54 . 2008-12-09 18:19 36744 ----a-w- c:\documents and settings\Martin Merryweather\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-11-04 22:13 . 2004-11-04 22:13 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 12:12 1119488 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-05 20:43 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Clare Merryweather\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Clare Merryweather\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [25/05/2009 12:56 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [25/05/2009 12:57 360584]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder
2009-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ca5cc3fc01ef26.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-24 07:12]
2009-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2912826986-2473095810-878126563-1007Core.job
- c:\documents and settings\Clare Merryweather\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 17:36]
2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2912826986-2473095810-878126563-1007UA.job
- c:\documents and settings\Clare Merryweather\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 17:36]
2009-11-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-05-25 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-05-25 17:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.esinet.norfolk.gov.uk/Personnel/vacancies/new%20website/
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=pdf
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - hxxp://www.cig.canon-europe.com/ph/en_GB/st/download/ddup/CNIMGUP_01_210102E.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-kdx - c:\program files\KHost.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-17 22:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0xFF591B00]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf9652f28
\Driver\ACPI -> ACPI.sys @ 0xf9545cb8
\Driver\atapi -> 0xff591b00
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> 0xff5ce200
PacketIndicateHandler -> NDIS.sys @ 0xf93b6a21
SendHandler -> NDIS.sys @ 0xf939487b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x094FE9BD
malicious code @ sector 0x094FE9C0 !
PE file found in sector at 0x094FE9D6 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2912826986-2473095810-878126563-1007\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
Completion time: 2009-11-17 22:43
ComboFix-quarantined-files.txt 2009-11-17 22:42
Pre-Run: 50,199,158,784 bytes free
Post-Run: 50,869,444,608 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 2BEA351D9C2E142AA159DC43D8AAF2BD
Getting error at start up: dialogue box;
Delivery Manager Service has encountered a problem and needs to close.
Out of frustration ran Combofix. Log file below. Internet now seems to be running faster (back to normal) and hard drive access is normal but still getting the Delivery Manager Service error at start up.
Also been messing about with services in effort to get the computer to run faster. My first posting so apologies for omissions etc.
Name Status Startup Type Log On As
.NET Runtime Optimization Service v2.0.50727_X86 Manual Local System
Alerter Disabled Local Service
AOL Connectivity Service Disabled Local System
Application Layer Gateway Service Disabled Local Service
Application Management Manual Local System
ASP.NET State Service Manual Network Service
Automatic Updates Started Automatic Local System
AVG Free WatchDog Disabled Local System
Background Intelligent Transfer Service Manual Local System
Canon Camera Access Library 8 Disabled Local System
ClipBook Manual Local System
COM+ Event System Started Manual Local System
COM+ System Application Manual Local System
Computer Browser Disabled Local System
CryptSvc Started Automatic Local System
DCOM Server Process Launcher Started Automatic Local System
DHCP Client Started Automatic Local System
Distributed Link Tracking Client Disabled Local System
Distributed Transaction Coordinator Disabled Network Service
DNS Client Disabled Network Service
DSBrokerService Manual Local System
Error Reporting Service Started Automatic Local System
Event Log Started Automatic Local System
Extensible Authentication Protocol Service Manual Local System
Fast User Switching Compatibility Started Automatic Local System
Fax Disabled Local System
Google Update Service (gupdate) Disabled Local System
Health Key and Certificate Management Service Manual Local System
Help and Support Started Automatic Local System
HTTP SSL Started Automatic Local System
Human Interface Device Access Disabled Local System
IMAPI CD-Burning COM Service Manual Local System
Indexing Service Manual Local System
IPSEC Services Disabled Local System
KService Automatic Local System
LexBce Server Started Automatic Local System
Logical Disk Manager Manual Local System
Logical Disk Manager Administrative Service Manual Local System
McAfee Personal Firewall Service Disabled Local System
McAfee SecurityCenter Update Manager Disabled Local System
McAfee Task Scheduler Disabled Local System
McAfee WSC Integration Disabled Local System
Messenger Disabled Local System
MS Software Shadow Copy Provider Manual Local System
Net Logon Disabled Local System
Net.Tcp Port Sharing Service Manual Local Service
NetMeeting Remote Desktop Sharing Disabled Local System
Network Access Protection Agent Manual Local System
Network Connections Started Automatic Local System
Network DDE Disabled Local System
Network DDE DSDM Disabled Local System
Network Location Awareness (NLA) Disabled Local System
Network Provisioning Service Manual Local System
NI Service Locator Manual Local System
NILM License manager Manual Local System
NT LM Security Support Provider Manual Local System
Office Source Engine Automatic Local System
Performance Logs and Alerts Disabled Network Service
Plug and Play Started Automatic Local System
Portable Media Serial Number Service Manual Local System
Print Spooler Started Automatic Local System
Protected Storage Disabled Local System
QoS RSVP Manual Local System
Remote Access Auto Connection Manager Automatic Local System
Remote Access Connection Manager Manual Local System
Remote Desktop Help Session Manager Disabled Local System
Remote Procedure Call (RPC) Started Automatic Network Service
Remote Procedure Call (RPC) Locator Automatic Network Service
Removable Storage Manual Local System
Routing and Remote Access Disabled Local System
Secondary Logon Started Automatic Local System
Security Accounts Manager Disabled Local System
Security Center Started Automatic Local System
Server Disabled Local System
Shell Hardware Detection Started Automatic Local System
Smart Card Manual Local Service
SSDP Discovery Service Disabled Local Service
System Event Notification Started Automatic Local System
System Restore Service Started Automatic Local System
Task Scheduler Disabled Local System
TCP/IP NetBIOS Helper Started Automatic Local Service
Telephony Disabled Local System
Terminal Services Started Automatic Local System
Themes Disabled Local System
Uninterruptible Power Supply Manual Local Service
Universal Plug and Play Device Host Manual Local Service
Volume Shadow Copy Manual Local System
WebClient Disabled Local Service
Windows Audio Started Automatic Local System
Windows CardSpace Manual Local System
Windows Defender Started Automatic Local System
Windows Firewall/Internet Connection Sharing (ICS) Started Automatic Local System
Windows Image Acquisition (WIA) Started Manual Local System
Windows Installer Manual Local System
Windows Management Instrumentation Started Automatic Local System
Windows Presentation Foundation Font Cache 3.0.0.0 Manual Local Service
Windows Service Pack Installer update service Automatic Local System
Windows Time Disabled Local System
Windows User Mode Driver Framework Manual Local Service
Wired AutoConfig Manual Local System
Wireless Zero Configuration Disabled Local System
WMI Performance Adapter Manual Local System
Workstation Disabled Local System
ComboFix 09-11-18.04 - Clare Merryweather 17/11/2009 21:55.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.246.43 [GMT 0:00]
Running from: c:\documents and settings\Clare Merryweather\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\jestertb.dll
.
((((((((((((((((((((((((( Files Created from 2009-10-17 to 2009-11-17 )))))))))))))))))))))))))))))))
.
2009-11-17 21:55 . 2001-08-17 13:52 13952 ----a-w- c:\windows\system32\drivers\cbidf2k.sys
2009-11-17 21:55 . 2001-08-17 13:52 13952 ----a-w- c:\windows\system32\dllcache\cbidf2k.sys
2009-11-17 21:55 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-17 21:55 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\dllcache\atapi.sys
2009-11-17 20:08 . 2009-11-17 20:08 -------- d-----w- c:\documents and settings\HelpAssistant\PrivacIE
2009-11-17 19:54 . 2009-11-17 19:54 -------- d-sh--w- c:\documents and settings\HelpAssistant\IETldCache
2009-11-17 19:26 . 2009-11-17 19:33 -------- d-----w- c:\windows\ie8updates
2009-11-17 19:20 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-11-17 19:20 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-17 19:12 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-11-17 18:51 . 2009-11-17 18:51 -------- d-sh--w- c:\documents and settings\Clare Merryweather\PrivacIE
2009-11-17 18:47 . 2009-11-17 18:47 -------- d-sh--w- c:\documents and settings\Clare Merryweather\IETldCache
2009-11-17 18:38 . 2009-11-17 18:41 -------- dc-h--w- c:\windows\ie8
2009-11-10 18:00 . 2009-11-05 20:42 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-11-10 17:57 . 2009-11-05 20:42 610072 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-11-10 17:57 . 2009-11-05 20:42 1657112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-05 21:00 . 2009-10-16 12:12 1119488 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-11-05 20:44 . 2009-11-05 20:53 -------- d-----w- C:\$AVG
2009-11-05 20:43 . 2009-11-07 13:04 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-05 20:42 . 2009-11-05 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-11-04 10:31 . 2009-11-17 20:52 -------- d-----w- c:\documents and settings\HelpAssistant
2009-11-03 20:22 . 2009-11-03 20:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Temp
2009-11-02 20:47 . 2009-11-02 20:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 14:22 . 2009-11-01 14:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-11-01 14:01 . 2009-11-01 14:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2009-10-24 07:13 . 2009-10-24 07:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-17 20:48 . 2008-02-29 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2009-11-17 20:47 . 2008-02-29 19:47 -------- d-----w- c:\program files\Kontiki
2009-11-10 18:00 . 2009-05-25 12:57 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-05 20:43 . 2009-05-25 12:57 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-05 20:43 . 2009-05-25 12:56 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-05 20:42 . 2009-05-25 12:56 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-05 20:42 . 2009-05-25 12:55 -------- d-----w- c:\program files\AVG
2009-11-04 10:47 . 2009-11-04 10:47 64000 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2009-11-04 10:47 . 2009-11-04 10:47 52288 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2009-11-04 10:47 . 2009-11-04 10:47 50688 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2009-11-04 10:47 . 2009-11-04 10:47 114688 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2009-11-04 10:45 . 2008-04-18 18:53 488968 ----a-w- c:\documents and settings\Clare Merryweather\Application Data\Real\Update\setup\setup.exe
2009-11-02 18:47 . 2007-01-11 11:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-02 18:43 . 2007-01-11 11:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-24 07:21 . 2005-07-30 20:59 -------- d-----w- c:\program files\Google
2009-10-08 19:42 . 2009-10-08 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SpellForce Demo
2009-10-08 19:41 . 2009-10-08 19:41 -------- d-----w- c:\program files\SpellingFORCE Demo
2009-09-22 18:17 . 2008-02-12 19:38 -------- d-----w- c:\documents and settings\Clare Merryweather\Application Data\ZoomBrowser EX
2009-09-11 14:18 . 2004-08-04 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 05:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-24 10:21 . 2009-05-25 13:02 36744 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-23 06:54 . 2008-12-09 18:19 36744 ----a-w- c:\documents and settings\Martin Merryweather\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2004-11-04 22:13 . 2004-11-04 22:13 114688 ----a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-16 12:12 1119488 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-05 20:43 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\Clare Merryweather\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Clare Merryweather\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [25/05/2009 12:56 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [25/05/2009 12:57 360584]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder
2009-11-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ca5cc3fc01ef26.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-24 07:12]
2009-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2912826986-2473095810-878126563-1007Core.job
- c:\documents and settings\Clare Merryweather\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 17:36]
2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2912826986-2473095810-878126563-1007UA.job
- c:\documents and settings\Clare Merryweather\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 17:36]
2009-11-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-05-25 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-05-25 17:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.esinet.norfolk.gov.uk/Personnel/vacancies/new%20website/
uInternet Connection Wizard,ShellNext = hxxp://shell.windows.com/fileassoc/0409/xml/redir.asp?Ext=pdf
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - hxxp://www.cig.canon-europe.com/ph/en_GB/st/download/ddup/CNIMGUP_01_210102E.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-kdx - c:\program files\KHost.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-17 22:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0xFF591B00]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf9652f28
\Driver\ACPI -> ACPI.sys @ 0xf9545cb8
\Driver\atapi -> 0xff591b00
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> 0xff5ce200
PacketIndicateHandler -> NDIS.sys @ 0xf93b6a21
SendHandler -> NDIS.sys @ 0xf939487b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x094FE9BD
malicious code @ sector 0x094FE9C0 !
PE file found in sector at 0x094FE9D6 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2912826986-2473095810-878126563-1007\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
Completion time: 2009-11-17 22:43
ComboFix-quarantined-files.txt 2009-11-17 22:42
Pre-Run: 50,199,158,784 bytes free
Post-Run: 50,869,444,608 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 2BEA351D9C2E142AA159DC43D8AAF2BD

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top









