I have been suffering from bsod from "eaglextn.sys" "DRIVER_UNLOADED_WITHOUT_CANCELLING_PENDING_OPERATIONS"
which I googled and said it was a a part of maple story anlab hack shield
I wasnt too sure of it but I removed it since it seemed to be the cause of the stop errors
and more info at my previous forum posting below.
Was not specified exactly if something was wrong but I was referred here, thanx for help in advance.
http://www.bleepingcomputer.com/forums/topic410437.html
also I installed the program audacity, which just caused me more issues, it froze after recording and got a few errors
and then some mp3 files i downloaded wouldnt play on windows media player saying the file was not found
but I know for fact I didnt delete it.
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by elyse at 23:14:46 on 2011-07-20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.84 [GMT -5:00]
.
AV: Norton Security Suite *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\Acer\Acer VCM\RS_Service.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Carbonite\CarbonitePreinstaller.exe
C:\DOCUME~1\elyse\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Constant Guard Protection Suite\IDVaultSvc.exe
C:\Program Files\Constant Guard Protection Suite\IDVault.exe
C:\Documents and Settings\elyse\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\elyse\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\elyse\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\elyse\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\elyse\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0711&m=aspire_one
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0711&m=aspire_one
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\5.1.0.29\ips\IPSBHO.DLL
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - c:\documents and settings\all users\application data\partner\partner.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Constant Guard Protection Suite (COM): {b84cdbe7-1b46-494b-a188-01d4c52deb61} - c:\program files\constant guard protection suite\NativeBHO.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\5.1.0.29\coIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\documents and settings\elyse\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [AzMixerSel] c:\program files\realtek\audio\drivers\AzMixerSel.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [snp2uvc] rundll32.exe c:\windows\system32\csnp2uvc.dll,ResetCIDS
mRun: [NotificationCenterLauncher] c:\program files\acer\acer erecovery management\NotificationLauncher.exe
mRun: [GIDDesktop] c:\program files\sft\guardedid\gidd.exe /s
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\acer\acer vcm\Skype4COM.dll
Notify: GIDLogonXP - GIDLogonXP.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
mASetup: {9191979D-821C-4EA8-B021-2DA1D859A7C5}-3Reg - c:\program files\sft\guardedid\gidi.exe /v
.
============= SERVICES / DRIVERS ===============
.
R? EagleXNt;EagleXNt
R? GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? Partner Service;Partner Service
R? RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader
R? Rts516xIR;Realtek IR Driver
S? BHDrvx86;BHDrvx86
S? EraserUtilRebootDrv;EraserUtilRebootDrv
S? GIDv2;GIDv2
S? IDSxpx86;IDSxpx86
S? IDVaultSvc;CGPS Service
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? N360;Norton Security Suite
S? NAVENG;NAVENG
S? NAVEX15;NAVEX15
S? RS_Service;Raw Socket Service
S? SymDS;Symantec Data Store
S? SymEFA;Symantec Extended File Attributes
S? SymIRON;Symantec Iron Driver
.
=============== Created Last 30 ================
.
2011-07-21 01:30:42 -------- d-----w- c:\documents and settings\elyse\application data\Malwarebytes
2011-07-21 01:30:33 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-21 01:30:31 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-07-21 01:30:27 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-21 01:30:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-19 12:38:57 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-07-19 12:38:57 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-18 23:19:14 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-07-18 05:30:58 -------- d-----w- c:\documents and settings\elyse\local settings\application data\Identities
2011-07-18 04:50:25 -------- d-----w- c:\documents and settings\elyse\application data\TeamViewer
2011-07-18 00:50:13 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-18 00:50:12 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-18 00:50:12 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2011-07-17 23:43:43 -------- d-----w- c:\documents and settings\elyse\local settings\application data\WMTools Downloaded Files
2011-07-17 23:06:14 -------- d-----w- c:\program files\PhotoScape
2011-07-17 20:46:38 -------- d-----w- C:\Nexon
2011-07-17 20:46:28 -------- d-----w- c:\documents and settings\all users\application data\NexonUS
2011-07-17 20:02:46 -------- d-----w- c:\program files\Pando Networks
2011-07-17 09:27:07 -------- d-sh--w- c:\documents and settings\elyse\IECompatCache
2011-07-17 09:00:39 744568 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\symefa.sys
2011-07-17 09:00:39 50168 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\srtspx.sys
2011-07-17 09:00:39 369784 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\symtdi.sys
2011-07-17 09:00:39 340088 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\symds.sys
2011-07-17 09:00:39 331384 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys
2011-07-17 09:00:39 296568 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\symnets.sys
2011-07-17 09:00:38 516216 ----a-w- c:\windows\system32\drivers\n360\0501000.01d\srtsp.sys
2011-07-17 09:00:38 136312 ----a-r- c:\windows\system32\drivers\n360\0501000.01d\ironx86.sys
2011-07-17 09:00:11 -------- d-----w- c:\windows\system32\drivers\n360\0501000.01D
2011-07-17 08:29:56 -------- d-----w- C:\0fde0505caf4a510381b8e11eee60b06
2011-07-17 08:17:07 -------- d-sh--w- c:\documents and settings\elyse\IETldCache
2011-07-17 08:13:57 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-07-17 08:13:40 -------- d-----w- c:\windows\ie8updates
2011-07-17 08:13:25 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-07-17 08:13:23 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-07-17 08:13:23 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-07-17 08:12:09 -------- dc-h--w- c:\windows\ie8
2011-07-17 07:50:09 -------- d-----w- c:\windows\ServicePackFiles
2011-07-17 07:34:42 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-07-17 07:34:39 60872 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-07-17 07:34:39 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-17 07:34:39 -------- d-----w- c:\program files\Symantec
2011-07-17 07:34:39 -------- d-----w- c:\program files\common files\Symantec Shared
2011-07-17 07:34:24 106928 ----a-w- c:\windows\system32\GEARAspi.dll
2011-07-17 07:34:09 -------- d-----w- c:\windows\system32\drivers\N360
2011-07-17 07:34:06 -------- d-----w- c:\program files\Norton Security Suite
2011-07-17 07:34:00 -------- d-----w- c:\documents and settings\elyse\local settings\application data\Temp
2011-07-17 07:33:49 -------- d-----w- c:\program files\NortonInstaller
2011-07-17 07:33:49 -------- d-----w- c:\documents and settings\all users\application data\NortonInstaller
2011-07-17 07:32:00 -------- d-----w- c:\documents and settings\all users\application data\Norton
2011-07-17 07:29:54 -------- d-----w- c:\documents and settings\all users\application data\IsolatedStorage
2011-07-17 07:29:47 -------- d-----w- c:\documents and settings\elyse\local settings\application data\ID Vault
2011-07-17 07:29:06 -------- d-----w- c:\documents and settings\elyse\application data\ID Vault
2011-07-17 07:28:57 25232 ------w- c:\windows\system32\drivers\gidv2.sys
2011-07-17 07:28:53 -------- d-----w- c:\documents and settings\all users\GID
2011-07-17 07:28:51 -------- d-----w- c:\program files\SFT
2011-07-17 07:28:41 -------- d-----w- c:\program files\Constant Guard Protection Suite
2011-07-17 07:20:05 -------- d-----w- c:\windows\system32\XPSViewer
2011-07-17 07:19:06 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-07-17 07:18:55 14048 ------w- c:\windows\system32\spmsg2.dll
2011-07-17 07:16:54 -------- d-----w- c:\documents and settings\all users\application data\White Sky, Inc
2011-07-17 07:14:50 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-07-17 07:08:29 -------- d-----w- c:\windows\system32\PreInstall
2011-07-17 07:04:10 -------- d-----w- c:\windows\system32\SoftwareDistribution
2011-07-17 06:57:20 -------- d-----w- c:\documents and settings\all users\application data\Partner
2011-07-17 06:53:59 -------- d---a-w- c:\windows\BTW
2011-07-17 06:51:43 94208 ----a-w- c:\windows\PLFSetL.exe
2011-07-17 06:51:43 286720 ----a-w- c:\windows\system32\vsnp2uvc.dll
2011-07-17 06:51:43 28160 ----a-w- c:\windows\system32\drivers\sncduvc.sys
2011-07-17 06:51:43 196608 ----a-w- c:\windows\system32\csnp2uvc.dll
2011-07-17 06:51:43 1769984 ----a-w- c:\windows\system32\drivers\snp2uvc.sys
2011-07-17 06:51:39 172032 ----a-w- c:\windows\system32\rsnp2uvc.dll
2011-07-17 06:51:38 -------- d-----w- c:\windows\SUYIN NB Cam
2011-07-17 06:51:38 -------- d-----w- c:\program files\common files\SNP2UVC
2011-07-17 06:51:14 -------- d---a-w- c:\windows\Dev1
2011-07-17 06:51:10 -------- d-----w- c:\windows\3G
2011-07-05 15:25:38 66328 ----a-w- c:\windows\system32\SysEventMenu.dll
2011-07-05 15:25:12 53528 ----a-w- c:\windows\system32\GIDLogonXP.dll
2011-07-05 15:24:42 380696 ----a-w- c:\windows\system32\GIDHookLogon.dll
2011-07-05 15:24:32 398608 ----a-w- c:\windows\system32\GIDHook.dll
2011-07-05 15:23:48 102160 ----a-w- c:\windows\system32\GIDBIN3.dll
2011-07-05 15:23:30 173840 ----a-w- c:\windows\system32\GIDBIN1.dll
.
==================== Find3M ====================
.
2011-07-17 06:54:01 2422 ----a-w- c:\windows\CLEANUP.CMD
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07:50 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ------w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ------w- c:\windows\system32\html.iec
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
.
Disk trace:
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV DI, 0x5; XOR AX, AX; MOV DL, 0x80; INT 0x13; JAE 0x2d; DEC DI; }
user != kernel MBR !!!
.
============= FINISH: 23:22:16.06 ===============
Attached File(s)
-
IMG00601-20110717-2301.jpg (140.81K)
Number of downloads: 5
This post has been edited by elybeit09: 21 July 2011 - 08:40 AM

Help
This topic is locked


Back to top











