I'm running XP Pro on a machine a friend built for me.
While browsing today Firefox suddenly disappeared and one of the fake anti-malware programs showed up and started running. Couldn't run Malwarebytes, RogueKiller, or DSSKiller. Rebooted into safe mode with networking, and tried various programs to see what worked and what came up in task manager. An unknown program (mvs.exe) kept popping up, so I stopped it via task manager. I searched for this and found it newly installed in Program Files, so shredded it with Window Washer. Couldn't shred the prefetch version, so deleted that and then shredded it in the recycle bin.
Now the rogue program no longer comes up when I try to start anything, but most programs won't run, at least from start. Each time I try, I get an error message stating it can't find firefox.exe, etc. This also happens when I try to run the program's executable from within Program Files. Oddly enough, some personal language and study programs are totally unaffected, also Thunderbird WILL run directly from Start menu. However, if I bring up a document/picture and click on it, it will open and bring up WordPerfect, Word, Excel, Foxit Reader, Photoshop, etc. (but this does not work with audio/video files and WMPlayer). Even firefox will come up if I click on a link embedded in a document/email, but again, I can't access it directly.
Tried downloading firefox from the computer I'm typing on, also mbam, and transferring each to the affected computer. When i try to install either, I get the "can't find .exe" message. Even tried renaming mbam install, but same issue (except it keeps stating that it is "mbam.exe.exe." (that's right, exe.exe, not a typo). Also can't right-click on Properties in My Computer, instead get an error message Windows cannot find 'rundll32.exe'
Should also mention that System Restore isn't functioning, nor is Checkdisk. Also, I don't have an XP CD to use, although I do have a copy of the UNINSTALLED program (XP Pro SP3) on a hard drive, which could be written to a disk with ActiveISOBurner, If I can figure out how to accomplish this (or if someone will instruct me), in order to use it to restore missing DLLs, etc.
Per your instructions, I downloaded Defogger, but it would not run (it’s an .exe file, which is mainly disabled, see above).
Next, I downloaded and successfully ran DDS. DDS log follows, and ATTACH file is attached.
Then, I downloaded GMER but was unable to run it (again, it's an .exe file).
Here's the DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 6.0.2800.1106 BrowserJavaVersion: 1.6.0_22
Run by Owner at 17:05:09 on 2011-12-03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1918.1574 [GMT -6:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Watchtower\Watchtower Library 2010\E\WTLibrary.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\WordPerfect Office 12\Programs\wpwin12.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll
BHO: iFinger plugin / Browser helper object: {a114d52b-870c-4f15-8021-b6d7f91a054b} - c:\progra~1\ifinger\plugins\IE.ifp
BHO: Foxit PDF Creator Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Foxit PDF Creator Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
EB: iFinger: {0cbd5120-990b-11d3-8abd-00c04fa95ee0} - c:\windows\system32\SHDOCVW.DLL
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DesktopobjARM] rundll32.exe "c:\documents and settings\owner\local settings\application data\rasglmgmt\DesktopobjARM.dll",SystemobjRpl olePadServ
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [RTHDCPL] RTHDCPL.EXE
dRun: [EapMapUsb] rundll32.exe "c:\documents and settings\localservice\local settings\application data\quickuserserv\EapMapUsb.dll",SystemobjIde CvtMapInterval
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\watcht~1.lnk - c:\program files\watchtower\watchtower library 2010\e\WTLibrary.exe
uPolicies-explorer: NoFileAssociate = 0 (0x0)
mPolicies-explorer: NoFileAssociate = 0 (0x0)
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {936E5D60-596C-11D3-BB96-00600816DF55} - {0CBD5120-990B-11D3-8ABD-00C04FA95EE0} - c:\windows\system32\SHDOCVW.DLL
LSP: mswsock.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1307050131000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\pboz0262.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20111027&q=
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\nitro pdf\reader\npdf.dll
FF - plugin: c:\program files\nitro pdf\reader\npnitromozilla.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
S0 kpioc;kpioc;c:\windows\system32\drivers\siqjxd.sys --> c:\windows\system32\drivers\siqjxd.sys [?]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-8-20 51984]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-8-20 59664]
S0 wfrurqy;wfrurqy;c:\windows\system32\drivers\agjthtvu.sys --> c:\windows\system32\drivers\agjthtvu.sys [?]
S1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2011-6-2 13696]
S2 srvB9C;srvB9C;c:\windows\system32\svchost.exe -k netsvcs [2011-6-2 12800]
S2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service --> c:\program files\threatfire\TFService.exe service [?]
S2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2011-6-6 598856]
S3 LP;LP;c:\docume~1\owner\locals~1\temp\lp.exe --> c:\docume~1\owner\locals~1\temp\LP.exe [?]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-8-20 33552]
S4 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\nitro pdf\reader\NitroPDFReaderDriverService2.exe [2011-6-21 196912]
.
=============== File Associations ===============
.
.exe=ah
.
=============== Created Last 30 ================
.
2011-11-22 23:31:09 -------- d-----w- c:\documents and settings\owner\application data\Mozal
2011-11-22 23:31:09 -------- d-----w- c:\documents and settings\owner\application data\Ecasgeo
2011-11-21 16:25:29 1409 ----a-w- c:\windows\QTFont.for
2011-11-19 20:06:44 -------- d-----w- c:\documents and settings\all users\application data\CAT
2011-11-19 20:06:12 -------- d-----w- c:\windows\system32\CatRoot2
2011-11-18 21:46:41 33280 ----a-w- c:\windows\system32\esccm.dll
2011-11-18 21:46:41 32256 ----a-w- c:\windows\system32\escwiab.dll
2011-11-18 21:46:41 27648 ----a-w- c:\windows\system32\escimg.dll
2011-11-18 21:13:28 -------- d-----w- C:\EPSONREG
2011-11-14 20:23:08 -------- d-----w- c:\program files\common files\EzTools
2011-11-13 00:28:34 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2011-11-13 00:28:26 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-13 00:28:23 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-13 00:28:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-12 19:11:16 -------- d-----w- c:\documents and settings\owner\application data\The Word
2011-11-12 19:11:16 -------- d-----w- c:\documents and settings\all users\application data\The Word
.
==================== Find3M ====================
.
2011-12-03 18:48:49 157056 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-12-01 03:37:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-29 15:03:22 131968 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-23 03:01:43 407552 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-12 17:16:52 62464 ----a-w- c:\windows\system32\drivers\serial.sys
2011-10-20 15:16:21 0 ----a-w- c:\windows\system32\svcgost.exe
2011-10-06 23:54:34 0 ----a-w- c:\windows\.exe
2011-10-03 20:27:54 295810 ----a-w- c:\windows\system32\shimg.dll
2011-09-05 05:07:54 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-06-06 06:14:32 37044224 ----a-w- c:\program files\e-Sword.msi
.
============= FINISH: 17:05:27.81 ===============
Attached File(s)
-
attach.txt (7.92K)
Number of downloads: 1

Help
This topic is locked

Back to top










