1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Got a window re "cmd.exe" (Solved)

Discussion in 'Malware Removal Help' started by Mara, Nov 15, 2009.

  1. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Re: Got a window re "cmd.exe"

    Hi Mara,

    Ok, thanks.
    I couldn't find any info on one file and got conflicting reviews on the second, that's why i wanted Jotti to scan them for us.

    i see what's happened.
    Let me explain.........
    There are 2 reports generated on the 1st run.
    As you are running OTL from this location:
    C:\Documents and Settings\Glen\My Documents\Downloads
    You will find the generated Extras.txt in that folder.

    Before we continue can you let me have an update as to how the system is running please.

    Many thanks.
     
  2. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Re: Got a window re "cmd.exe"

    I'm not too sure what happened but right after the MalwareBites scan - the one where text got copied and pasted into what to scan section - the problem with the semi-transparent windows quit and the computer seems to be running faster... so 'bug' gone or not, I thank you so very much for that alone, Starbuck!!

    And thanks so much for the easy explanation on where to find the 'Extras' from the OTL scan - I found it just where you said it would be :) ... here it is:

    OTL Extras logfile created on: 11/16/2009 10:34:58 AM - Run 1
    OTL by OldTimer - Version 3.1.5.0 Folder = C:\Documents and Settings\Glen\My Documents\Downloads
    Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.18702)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    1014.16 Mb Total Physical Memory | 191.32 Mb Available Physical Memory | 18.86% Memory free
    2.38 Gb Paging File | 1.78 Gb Available in Paging File | 74.51% Paging File free
    Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 225.88 Gb Total Space | 194.44 Gb Free Space | 86.08% Space Free | Partition Type: NTFS
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded
    G: Drive not present or media not loaded
    H: Drive not present or media not loaded
    I: Drive not present or media not loaded

    Computer Name: VALUED-FD36E9B8
    Current User Name: Glen
    Logged in as Administrator.

    Current Boot Mode: Normal
    Scan Mode: Current user
    Company Name Whitelist: Off
    Skip Microsoft Files: Off
    File Age = 30 Days
    Output = Minimal

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\FIREFOX 3.0.1, 16 August 2008\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %* File not found
    cmdfile [open] -- "%1" %* File not found
    comfile [open] -- "%1" %* File not found
    exefile [open] -- "%1" %* File not found
    htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
    piffile [open] -- "%1" %* File not found
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1" File not found
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
    scrfile [open] -- "%1" /S File not found
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "FirstRunDisabled" = 1
    "AntiVirusDisableNotify" = 0
    "FirewallDisableNotify" = 0
    "UpdatesDisableNotify" = 0
    "AntiVirusOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22008
    "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:mad:xpsp2res.dll,-22007
    "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
    "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Google\Google Talk\googletalk.exe" = C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk -- (Google)
    "%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
    "C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
    "C:\Program Files\Sony\Click to DVD 2\CtoDvd.exe" = C:\Program Files\Sony\Click to DVD 2\CtoDvd.exe:*:Disabled:Click to DVD -- (Sony Corporation)


    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}" = SonicStage Mastering Studio Audio Filter Custom Preset
    "{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library
    "{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
    "{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
    "{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
    "{1BEF9285-5530-426B-A5F1-5836B95C7EB1}" = VAIO Original Screen Saver
    "{1EB317D8-8945-4FD6-B37F-DF470317C6AB}" = VAIO Media 4.0
    "{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0
    "{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
    "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 16
    "{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter
    "{29999594-B540-4C88-A8D3-C99CA43809FC}" = Image Converter 2
    "{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
    "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
    "{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
    "{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
    "{40D1BC4F-56CB-458E-BE8C-35A025CC52FB}" = Sony TV Tuner Library 1.0
    "{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
    "{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2
    "{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central
    "{639BB4D3-AA30-4A7B-8CB5-6DE681AD6659}" = VAIO Light Flo Wallpaper
    "{685BCC47-B8EC-45EC-BBCE-77DF2451502C}" = DVgate Plus
    "{71249EFF-EFAB-48A0-B967-630F4E70BBC3}" = VAIO Original Screen Saver VAIO Scene SD Normal Contents
    "{7128C69B-8F7E-4336-8698-3FD3CDD955EC}" = VAIO Media Redistribution 4.0
    "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{777AD08E-B32A-4456-AFE1-094DBECEB268}" = Intel(R) Network Connections 13.5.32.0
    "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
    "{7A79D11B-FD82-4A5E-834F-20173515DD14}" = VAIO Media Integrated Server 4.2
    "{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
    "{80EE18E6-F16C-11D4-8BE8-006097C9A3ED}" = ISScript
    "{82081533-F045-469E-BD53-F16839E445C3}" = VAIO Support Central
    "{849ABF1A-6AE3-45E1-B260-D5447B2F29F5}" = OpenMG Secure Module 4.2.00
    "{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
    "{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
    "{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}" = InterVideo WinDVD for VAIO
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
    "{9B953606-000E-491C-B74D-78ECFDD520A0}" = OpenMG Metadata Extractor for Windows Media Player
    "{9E407618-D9CD-4F39-9490-9ED45294073D}" = Click to DVD 2.0.03 Menu Data
    "{A0EB195B-5876-48E6-879D-33D4B2102610}" = SonicStage 3.2
    "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
    "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
    "{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
    "{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
    "{A4870F16-380A-47D5-B30F-45A99FED3403}" = Click to DVD 2.4.12
    "{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
    "{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}" = VAIO Media Registration Tool 4.0
    "{BA41ADD4-6FE6-406E-8C4F-42A207B57F39}" = PhotoRite FX
    "{BBFFB027-7D53-4E1B-95BC-35A2216D1D60}" = VAIO Long Battery Life Wallpaper
    "{BC5E5F8F-0BA2-480A-94C4-0E65D4FA8238}" = Click to DVD 2.4.12
    "{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}" = Sony Video Shared Library
    "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
    "{C7340571-7773-4A8C-9EBC-4E4243B38C76}" = Microsoft XML Parser
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{D0448678-1203-4158-A58F-B3D0B616BF9E}" = Sony Certificate PCH
    "{D917FD82-6CE5-489A-AAF8-C701AAC85C4D}" = VAIO Entertainment Platform
    "{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (VAIO_VEDB)
    "{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
    "{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
    "{E809063C-51A3-4269-8984-D1EB742F2151}" = Click to DVD 2.4.12
    "{E86E5246-AA7E-11D4-88C9-00105ADBE398}" = O&O Defrag 2000 Freeware Edition
    "{F34D9A5F-484A-4E31-A9D3-908CB265B289}" = Sygate Personal Firewall
    "{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
    "{FA11D5B5-7D0A-43E8-88C4-960F97B194DE}" = VAIO Survey Standalone
    "Action Replay Code Manager_is1" = Action Replay Code Manager
    "ActiveScan 2.0" = Panda ActiveScan 2.0
    "Adaptec UDF Reader" = Adaptec UDF Reader
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe Photoshop CS4_is1" = Adobe Photoshop CS4
    "Adobe Shockwave Player" = Adobe Shockwave Player 11
    "Advanced SystemCare 3_is1" = Advanced SystemCare 3
    "Agere Systems Soft Modem" = Agere Systems PCI Soft Modem
    "All ATI Software" = ATI - Software Uninstall Utility
    "a-squared Free_is1" = a-squared Free 4.5
    "ATI Display Driver" = ATI Display Driver
    "avast!" = avast! Antivirus
    "Belarc Advisor" = Belarc Advisor 8.1
    "CamStudio" = CamStudio
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "Corel Uninstaller" = Corel Uninstaller
    "Digital Camera Enhancer 1.3_is1" = Digital Camera Enhancer 1.3
    "DriverAgent.exe" = DriverAgent by eSupport.com
    "EsetOnlineScanner" = ESET Online Scanner
    "Everything" = Everything 1.2.1.371
    "HDMI" = Intel(R) Graphics Media Accelerator Driver
    "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
    "ie7" = Windows Internet Explorer 7
    "ie8" = Windows Internet Explorer 8
    "ImageSkill Magic Enhancer Lite 1" = ImageSkill Magic Enhancer Lite 1 (Remove only)
    "InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration
    "InstallShield_{849ABF1A-6AE3-45E1-B260-D5447B2F29F5}" = OpenMG Secure Module 4.2.00
    "InstallShield_{FA11D5B5-7D0A-43E8-88C4-960F97B194DE}" = VAIO Survey Standalone
    "LMS" = C-Dilla Licence Management System
    "Logon Loader" = Logon Loader 3.0
    "MAGIX Xtreme Photo Designer 6 US" = MAGIX Xtreme Photo Designer 6 6.0.19.0 (US)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Mozilla Firefox (3.5.3)" = Mozilla Firefox (3.5.3)
    "Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
    "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
    "Netscape Online Setup" = Netscape Internet Service Setup
    "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
    "PhotoFiltre" = PhotoFiltre
    "Photomania Deluxe" = Photomania Deluxe
    "PhotoScape" = PhotoScape
    "PhotoToolkit_is1" = Photo! Editor 1.1
    "Portrait Professional 6_is1" = Portrait Professional 6.5
    "Recuva" = Recuva (remove only)
    "Revo Uninstaller" = Revo Uninstaller 1.83
    "SiteHoundFirefox" = SiteHound for FireFox 2.0.0
    "Soulseek2" = SoulSeek 157 NS 13c
    "SystemRequirementsLab" = System Requirements Lab
    "tintii" = indii.org/tintii
    "UnityWebPlayer" = Unity Web Player
    "Windows Media Format Runtime" = Windows Media Format 11 runtime
    "Windows Media Player" = Windows Media Player 11
    "Windows XP Service Pack" = Windows XP Service Pack 3
    "WinPatrol" = WinPatrol 2009
    "WMFDist11" = Windows Media Format 11 runtime
    "wmp11" = Windows Media Player 11
    "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
    "Zipeg" = Zipeg

    ========== Last 10 Event Log Errors ==========

    [ Antivirus Events ]
    Error - 2/17/2009 1:28:22 AM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    http://beta.mytelus.com/ScriptResou...Hx2I9beraCDDESF0st23wbt0&t=633518004010894565
    failed, 0000A413.

    Error - 8/24/2009 5:10:21 PM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\DOCUMENTS AND SETTINGS\GLEN\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5HAGCR85.DEFAULT\PREFS.JS
    failed, 00000005.

    Error - 8/24/2009 5:10:59 PM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL$VAIO_VEDB\BINN\SQLSERVR.EXE failed,
    00000005.

    Error - 8/24/2009 5:11:00 PM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL$VAIO_VEDB\BINN\SQLAGENT.EXE failed,
    00000005.

    Error - 11/6/2009 3:30:06 AM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    http://clients1.google.ca/complete/...R LANDING CONSTRUCTION&q=DECK STAIRS l&cp=13
    failed, 0000A413.

    Error - 11/6/2009 5:18:46 AM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    http://clients1.google.ca/complete/search?hl=en&ds=i&pq=2X6&q=2X6 DECK STAI&cp=13
    failed, 0000A413.

    Error - 11/7/2009 4:24:58 AM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    http://clients1.google.ca/complete/...sing heavy wood&q=stringers set 40 inch&cp=21
    failed, 0000A413.

    Error - 11/7/2009 2:25:29 PM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    C:\Documents and Settings\Glen\Application Data\Mozilla\Firefox\Profiles\5hagcr85.default\sessionstore.js
    failed, 0000A413.

    Error - 11/8/2009 7:22:58 PM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    http://clients1.google.ca/complete/...natomy joists boards&q=deck constructio&cp=16
    failed, 0000A413.

    Error - 11/9/2009 4:36:25 PM | Computer Name = VALUED-FD36E9B8 | Source = avast! | ID = 33554522
    Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
    http://suggestqueries.google.com/co...fox&client=firefox&hl=en-US&q=memorial+statue
    failed, 0000A413.

    [ Application Events ]
    Error - 10/15/2009 11:53:01 PM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
    dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

    Error - 10/18/2009 12:13:49 AM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application photohse.exe, version 3.199.0.0, faulting module
    sh33w32.dll, version 3.3.1.0, fault address 0x000024ad.

    Error - 10/18/2009 12:14:06 AM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application photohse.exe, version 3.199.0.0, faulting module
    sh33w32.dll, version 3.3.1.0, fault address 0x000024ad.

    Error - 10/18/2009 12:14:56 AM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application photohse.exe, version 3.199.0.0, faulting module
    sh33w32.dll, version 3.3.1.0, fault address 0x000024ad.

    Error - 10/22/2009 6:56:37 AM | Computer Name = VALUED-FD36E9B8 | Source = VzCdbSvc | ID = 7
    Description = Failed to load the plug-in module. (GUID = {F508055A-CDBF-4D4D-BC8F-4D8E0D9B9E81})(Error
    code = 0x80004005)

    Error - 10/23/2009 8:49:00 PM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x02930a18.

    Error - 11/1/2009 7:57:54 PM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application photohse.exe, version 3.199.0.0, faulting module
    ntdll.dll, version 5.1.2600.5755, fault address 0x00028c0b.

    Error - 11/9/2009 5:02:18 AM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x05cc0a18.

    Error - 11/9/2009 6:29:36 PM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x020f0a18.

    Error - 11/10/2009 10:04:24 PM | Computer Name = VALUED-FD36E9B8 | Source = Application Error | ID = 1000
    Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
    module unknown, version 0.0.0.0, fault address 0x01ec0a18.

    [ System Events ]
    Error - 11/10/2009 10:27:11 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Windows Media Player Network Sharing Service service depends on
    the Universal Plug and Play Device Host service which failed to start because of
    the following error: %%1068

    Error - 11/10/2009 10:27:18 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Universal Plug and Play Device Host service depends on the SSDP
    Discovery Service service which failed to start because of the following error:
    %%1058

    Error - 11/10/2009 10:27:18 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Windows Media Player Network Sharing Service service depends on
    the Universal Plug and Play Device Host service which failed to start because of
    the following error: %%1068

    Error - 11/13/2009 4:37:55 AM | Computer Name = VALUED-FD36E9B8 | Source = DCOM | ID = 10005
    Description = DCOM got error "%1068" attempting to start the service upnphost with
    arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

    Error - 11/13/2009 4:37:56 AM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Universal Plug and Play Device Host service depends on the SSDP
    Discovery Service service which failed to start because of the following error:
    %%1058

    Error - 11/15/2009 9:54:27 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Media Center Extender Service service depends on the SSDP Discovery
    Service service which failed to start because of the following error: %%1058

    Error - 11/15/2009 9:54:27 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Universal Plug and Play Device Host service depends on the SSDP
    Discovery Service service which failed to start because of the following error:
    %%1058

    Error - 11/15/2009 9:54:27 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Windows Media Player Network Sharing Service service depends on
    the Universal Plug and Play Device Host service which failed to start because of
    the following error: %%1068

    Error - 11/15/2009 9:54:34 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Universal Plug and Play Device Host service depends on the SSDP
    Discovery Service service which failed to start because of the following error:
    %%1058

    Error - 11/15/2009 9:54:34 PM | Computer Name = VALUED-FD36E9B8 | Source = Service Control Manager | ID = 7001
    Description = The Windows Media Player Network Sharing Service service depends on
    the Universal Plug and Play Device Host service which failed to start because of
    the following error: %%1068


    < End of report >
     
  3. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Re: Got a window re "cmd.exe"

    Hi Mara,

    I'm glad things are running a bit better now.
    and glad you found the Extras.txt, it helps to have the full picture.

    Things are looking good now, but let's spare no expense ( the site can afford it :) )
    Let's check if anything is trying to hide from us ( let's get the big hammer out)

    Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.
    Please note, it must be the 'Desktop'.

    Link 1
    Link 2

    [​IMG]


    [​IMG]

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with the running of ComboFix.
      For more information read:
      How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

      Then:

      Double click on Combo-Fix.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
      If running Vista, you may not see this screen
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [​IMG]

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [​IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


    Note:
    Do not mouseclick combofix's window while it's running. That may cause it to stall


    Many thanks.
     
  4. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Re: Got a window re "cmd.exe"

    Glad you're "sparing no expense", starbuck - huge happy smile!!!

    Here's the scan results from COMBO (and who knows, maybe it'll even tell us why the computer won't restart when shut off, rather than it being a hardware issue! :)).

    Truly appreciate your help with all this - how very kind of you!!

    ComboFix 09-11-18.04 - Glen 11/17/2009 15:55.1.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.348 [GMT -8:00]
    Running from: c:\documents and settings\Glen\My Documents\Downloads\Combo-Fix.exe
    AV: avast! antivirus 4.8.1356 [VPS 091117-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Sygate Personal Firewall *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\Glen\Application Data\.#
    c:\recycler\S-1-5-21-1507342847-483047397-1139445416-500
    c:\recycler\S-1-5-21-1691757890-1773251546-1096039709-500
    c:\windows\kb913800.exe
    c:\windows\setup.exe

    .
    ((((((((((((((((((((((((( Files Created from 2009-10-18 to 2009-11-18 )))))))))))))))))))))))))))))))
    .

    2009-11-17 23:13 . 2004-08-10 12:00 7168 -c--a-w- c:\windows\system32\dllcache\wamregps.dll
    2009-11-17 23:13 . 2001-08-17 22:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
    2009-11-17 23:12 . 2009-11-17 23:12 -------- d-----w- c:\windows\LastGood
    2009-11-17 23:12 . 2004-08-10 12:00 7680 -c--a-w- c:\windows\system32\dllcache\inetmgr.exe
    2009-11-17 23:12 . 2004-08-10 12:00 19968 -c--a-w- c:\windows\system32\dllcache\inetsloc.dll
    2009-11-17 23:12 . 2004-08-10 12:00 169984 -c--a-w- c:\windows\system32\dllcache\iisui.dll
    2009-11-17 23:12 . 2004-08-10 12:00 5632 -c--a-w- c:\windows\system32\dllcache\iisrstap.dll
    2009-11-17 23:12 . 2004-08-10 12:00 14336 -c--a-w- c:\windows\system32\dllcache\iisreset.exe
    2009-11-17 23:12 . 2004-08-10 12:00 6144 -c--a-w- c:\windows\system32\dllcache\ftpsapi2.dll
    2009-11-17 07:32 . 2009-11-17 07:32 -------- d-----w- c:\program files\JRE
    2009-11-17 07:32 . 2009-11-17 07:32 -------- d-----w- c:\program files\OpenOffice.org 3
    2009-11-17 03:16 . 2009-11-17 03:16 -------- d-----w- C:\_OTL
    2009-11-10 19:55 . 2009-09-05 01:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
    2009-11-10 19:55 . 2009-09-05 01:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
    2009-11-10 19:55 . 2009-09-05 01:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
    2009-11-10 19:55 . 2009-09-05 01:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
    2009-11-10 19:55 . 2009-09-05 01:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
    2009-11-10 19:55 . 2009-09-05 01:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
    2009-11-10 19:55 . 2009-09-05 01:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
    2009-11-10 19:55 . 2009-03-09 23:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
    2009-11-10 19:55 . 2009-03-09 23:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
    2009-11-10 19:55 . 2009-03-09 23:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
    2009-11-10 19:49 . 2009-11-10 19:49 -------- d-----w- c:\windows\Logs
    2009-10-22 21:41 . 2009-10-22 21:41 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
    2009-10-22 21:41 . 2009-10-22 21:41 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-18 00:02 . 2009-08-31 02:51 723060768 --sha-w- c:\windows\system32\drivers\fidbox.dat
    2009-11-17 23:48 . 2005-08-19 22:19 104872 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-11-17 23:41 . 2008-08-17 05:40 -------- d-----w- c:\program files\FIREFOX 3.0.1, 16 August 2008
    2009-11-17 23:38 . 2008-08-17 05:41 -------- d-----w- c:\program files\THUNDERBIRD Email
    2009-11-17 10:51 . 2009-08-31 02:51 8444900 --sha-w- c:\windows\system32\drivers\fidbox.idx
    2009-11-17 08:37 . 2008-12-23 00:28 1 ----a-w- c:\documents and settings\Glen\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2009-11-17 02:48 . 2009-08-29 03:49 117760 ----a-w- c:\documents and settings\Glen\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2009-11-12 07:50 . 2009-01-13 19:13 -------- d-----w- c:\documents and settings\Glen\Application Data\PhotoCleaner
    2009-11-10 19:57 . 2009-11-10 19:57 2311 ----a-w- c:\documents and settings\All Users\Application Data\xml358.tmp
    2009-11-10 19:57 . 2009-11-10 19:57 13382 ----a-w- c:\documents and settings\All Users\Application Data\xml357.tmp
    2009-11-10 19:57 . 2009-11-10 19:57 8757 ----a-w- c:\documents and settings\All Users\Application Data\xml356.tmp
    2009-11-09 22:16 . 2009-09-25 02:16 -------- d-----w- c:\documents and settings\Glen\Application Data\Zipeg
    2009-10-21 18:28 . 2009-01-20 04:33 -------- d-----w- c:\program files\Common Files\Adobe
    2009-10-14 06:54 . 2009-09-04 01:49 -------- d-----w- c:\program files\Belarc
    2009-09-26 22:42 . 2009-09-26 22:42 -------- d-----w- c:\program files\Panda Security
    2009-09-25 02:20 . 2009-09-23 03:01 152576 ----a-w- c:\documents and settings\Glen\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
    2009-09-25 02:16 . 2008-08-17 22:26 -------- d-----w- c:\program files\Zipeg
    2009-09-25 02:15 . 2008-08-17 22:27 -------- d-----w- c:\documents and settings\Glen\Application Data\com.zipeg
    2009-09-23 03:02 . 2005-08-19 19:04 -------- d-----w- c:\program files\Java
    2009-09-20 06:35 . 2009-09-20 06:35 -------- d-----w- c:\program files\Photo!
    2009-09-19 05:00 . 2009-08-30 00:18 -------- d-----w- c:\documents and settings\Glen\Application Data\CBS Interactive
    2009-09-19 04:36 . 2009-09-19 04:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
    2009-09-19 04:34 . 2009-09-10 01:46 -------- d-----w- c:\program files\QuickTime
    2009-09-15 10:59 . 2008-08-17 05:12 1279968 ----a-w- c:\windows\system32\aswBoot.exe
    2009-09-15 10:56 . 2008-08-17 05:12 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2009-09-15 10:56 . 2008-08-17 05:12 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2009-09-15 10:55 . 2008-08-17 05:12 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2009-09-15 10:55 . 2008-08-17 05:12 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2009-09-15 10:54 . 2008-08-17 05:12 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2009-09-15 10:54 . 2008-08-17 05:12 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2009-09-15 10:53 . 2008-08-17 05:12 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2009-09-15 10:53 . 2008-08-17 05:12 97480 ----a-w- c:\windows\system32\AvastSS.scr
    2009-09-11 14:18 . 2005-08-18 20:20 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-11 06:16 . 2008-08-19 17:09 4045528 -c--a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
    2009-09-10 22:54 . 2008-08-19 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-10 22:53 . 2008-08-19 17:09 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-09-09 03:01 . 2009-01-09 05:17 20520 ----a-w- c:\program files\init.dat
    2009-09-05 01:44 . 2009-11-10 19:54 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
    2009-09-04 21:03 . 2005-08-18 20:20 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 08:08 . 2005-08-18 20:20 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-08-29 02:45 . 2009-08-29 02:45 1014 ----a-w- c:\windows\system32\Dswfx.dll
    2009-08-26 08:00 . 2005-08-18 20:21 247326 ----a-w- c:\windows\system32\strmdll.dll
    2008-08-26 20:51 . 2008-08-26 20:51 1487 ----a-w- c:\program files\Windows Explorer.lnk
    2007-09-27 19:03 . 2008-08-17 06:07 318904 ----a-w- c:\program files\wmpfirefoxplugin WindowsMediaPlay PLUG IN for FIREFOX.exe
    2009-01-09 07:14 . 2009-01-09 07:13 80 --sh--r- c:\windows\system32\EE25177F65.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinPatrol"="c:\program files - security\WIN PATROL" [X]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-23 339968]
    "VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
    "VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-01-14 151552]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
    "PartSeal"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
    "avast!"="c:\progra~2\AVAST4~1\ashDisp.exe" [2009-09-15 81000]
    "SmcService"="c:\progra~2\SYGATE~1.6FI\smc.exe" [2004-10-16 2577632]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
    "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-10-08 88363]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files - security\SUPERAntiSpyWare - Anti Spyware program\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 19:05 356352 ----a-w- c:\program files - security\SUPERAntiSpyWare - Anti Spyware program\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Sony\\Click to DVD 2\\CtoDvd.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest"= 1 (0x1)

    R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [9/26/2009 2:42 PM 28544]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/16/2008 9:12 PM 114768]
    R1 is-004FIdrv;is-004FIdrv;c:\windows\system32\drivers\65599369.sys [9/10/2009 10:40 PM 148496]
    R1 is-EE9LBdrv;is-EE9LBdrv;c:\windows\system32\drivers\54389780.sys [8/30/2009 6:51 PM 148496]
    R1 SASDIFSV;SASDIFSV;c:\program files - security\SUPERAntiSpyWare - Anti Spyware program\sasdifsv.sys [8/5/2009 3:06 PM 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files - security\SUPERAntiSpyWare - Anti Spyware program\SASKUTIL.SYS [8/5/2009 3:06 PM 74480]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/16/2008 9:12 PM 20560]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/14/2009 12:36 AM 210216]
    R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
    S3 SASENUM;SASENUM;c:\program files - security\SUPERAntiSpyWare - Anti Spyware program\SASENUM.SYS [8/5/2009 3:06 PM 7408]
    S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - MBR
    *NewlyCreated* - PROCEXP113
    *Deregistered* - mbr
    *Deregistered* - PROCEXP113
    .
    Contents of the 'Scheduled Tasks' folder

    2009-11-16 c:\windows\Tasks\SmartDefrag.job
    - c:\program files - security\ADVANCED System Care - Smart Defrag\IObit SmartDefrag\IObit SmartDefrag.exe [2009-05-04 01:15]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.sony.com/vaiopeople
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
    IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
    IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
    IE: Transfer by Image Converter 2 - c:\program files\Sony\Image Converter 2\menu.htm
    IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
    FF - ProfilePath - c:\documents and settings\Glen\Application Data\Mozilla\Firefox\Profiles\5hagcr85.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.mytelus.com ew_homepage/
    FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - plugin: c:\program files\FIREFOX 3.0.1, 16 August 2008\plugins\NPFxViewer.dll
    FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    FF - user.js: browser.cache.memory.capacity - 16000
    FF - user.js: browser.chrome.favicons - fales
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.urlbar.autofill - true
    FF - user.js: content.max.tokenizing.time - 3000000
    FF - user.js: content.maxtextrun - 4095
    FF - user.js: content.notify.backoffcount - 5
    FF - user.js: content.notify.interval - 1000000
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.switch.threshold - 1000000
    FF - user.js: dom.disable_window_status_change - true
    FF - user.js: network.http.max-connections - 48
    FF - user.js: network.http.max-connections-per-server - 16
    FF - user.js: network.http.max-persistent-connections-per-proxy - 16
    FF - user.js: network.http.max-persistent-connections-per-server - 8
    FF - user.js: network.http.pipelining - true
    FF - user.js: network.http.pipelining.firstrequest - true
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.proxy.pipelining - true
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: nglayout.initialpaint.delay - 1000
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    c:\program files\FIREFOX 3.0.1, 16 August 2008\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    .
    - - - - ORPHANS REMOVED - - - -

    AddRemove-avast! - c:\program files - security\AVAST 4 Home Edition antivirus scanner
    AddRemove-Everything - c:\program files - security\Everything - freeware for searching things on computer
    AddRemove-Malwarebytes' Anti-Malware_is1 - c:\program files - security\MALWAREbytes
    AddRemove-Mozilla Firefox (3.5.3) - c:\program files\FIREFOX 3.0.1
    AddRemove-Revo Uninstaller - c:\program files - security\REVO UNinstaller
    AddRemove-SiteHoundFirefox - c:\program files - security\SITE HOUND



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2009-11-17 16:02
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
    "ImagePath"=""
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
    "OODEFRAG10.00.00.01WORKSTATION"="CD277A3427F6A91C9786C792A6EAC46C95C5D60DF30ED7D9FC9421347CD54E4548AC88A6068042CBCF73FDACF1BE8F9DC1A97452DE662B6BDA2727A1FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E667A2D97226D213B5555D575E7D6A3B9808A01B5F075116E3DAFA5382D9C971486B9ADCA8D09981B2953B0AB1BF7992DB49C28902B578B5C665D794E2E7447B836E48BC2D2EB44149CAC33F448D2B94561AE46A6650469C249487174231E21CEEFE72AC6D18697D07AECF3998626D747A9876189EBD262702F5FE24E19426F24BF63287F706EBB78C033C06A76E4D34E510B6EE330A18799A7E030CF397A0651111702CCD1409332C6D35B5DF88E598682EBAD21DE32FF6DA852CA12260FB17E96F6CFEE1051B77ECF7425D23AB6B2B07056A27CE9C914DE3C4E9B9883CF476359538E71F3D15D18B8DB915C773A3B97A0D8457A72D7BE78BDDFCAFB5195B30046CBB5262C37B51F78146791724E8542F9D185001AF3C795C53FBE2AE8D93389DBFB1AEFCC8674B540AE82C5021A950C5770B0425E2B6F9920C4F366CCE94467D40A76E331B85D6783E75D1A47667C6113B956653A9E120A0D3B610583BEC55CF02010CBDAF99D0F09D939139D1B8951C71C474BE0BCAECAB5A4259D4513B247AFD7601C920F5597C87BE99AA04C8DCA10279A80DB18EA18C32D803353534359010104DF9A806548EC3C6198383D40314BDE7075A6C614551D4B37EC12F20D1DE78ACF5612CC5E84F7A4F46496A303016D59893B6AE0BA03C9AE042B52ADA82E25D01018A2CC70598B850586FF53FD180606958231066C1C1C4414A413755994FC4927B7053B058FCEE168DE109FE99E0570B6398C9E17B8BF68B94880994270B1C3D7306EEB8D7BC7540A4FCA87B7B771B8146003B81E4F73749A2A478AF83B0B42E7EB0EF2E38D183C2E394FE57B137ECA596B9685E5618F2D8FC2081D1C98D41E8B2C76A72F96637E3146CD949384AF324ED9976A06F31776B2E7C433E5A26DBC3AB97187ADADA134000402C1CD10D39FE69643208903D7907C1AB034756AF006B0AE45550DE41F9487ABE8AAC028FAB0AABD6896AE1699084CE97A65526940D5CF1E0A28F5062B6BF56072FEE93969D6ED91F8E2C4C173692E81CBCE4747449E98936A5EBB7BAF53DEDB1F8E7131B45A79D61F9C9FEDC4C33AC87F186B09FDC3CFC03A72869F74B2E1CC8E8B2D0C8BE88253425536B0394BBB69F1D5D8E20D2CCFBD5941E757E29D0C248A37D638106B421A110EA4707B7552B1DB3A3832D1DE9BAB5FDBCB7E4EBB947A4F589A25700A448A9DCC80D1BBF7F3029D3A3CBB60F38EF9A18844A78CDD010C1CB2E2C157026533ED2B6FBA41D0AF0663C3F665F61ACD7723C"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(764)
    c:\program files - security\SUPERAntiSpyWare - Anti Spyware program\SASWINLO.dll
    c:\windows\system32\WININET.dll
    c:\program files\McAfee\SiteAdvisor\saHook.dll
    .
    Completion time: 2009-11-17 16:05
    ComboFix-quarantined-files.txt 2009-11-18 00:05

    Pre-Run: 209,262,563,328 bytes free
    Post-Run: 209,216,954,368 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" oexecute=optin /fastdetect

    - - End Of File - - 0C6ABC89ACB8C7D2ABAE07DC2774498A
     
  5. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Re: Got a window re "cmd.exe"

    Hi Mara,

    It's not my money [​IMG]

    You can always guarantee that CF will uncover something!
    Because of what CF deleted,
    c:\recycler\S-1-5-21-1507342847-483047397-1139445416-500
    c:\recycler\S-1-5-21-1691757890-1773251546-1096039709-500

    i want to make sure that you are safe in the future.
    I take it that you use Usb sticks?
    These lines may be created by a USB infection.

    Step 1

    Temporarily disable your anti-virus, script blocking and any real time protection programs before downloading this tool as it can be falsely flagged as malware.

    Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
    • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the utility to clean up those drives as well.
    • Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
    • Wait until it has finished scanning and then exit the program.
    • Reboot your computer when done.
    Note: As part of its routine, Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that was plugged in when you ran it. Do not delete this folder...it will help protect your drives from future infection by keeping the autorun file from being installed on the root drive and running other malicious files.

    Step 2
    Let's double check everything with an online scan.
    Just to see if there's any left overs.

    Please run a BitDefender Online Scan
    • Click I Agree to agree to the EULA.
    • Allow the ActiveX control to install when prompted.
    • Click Click here to scan to begin the scan.
    • Please refrain from using the computer until the scan is finished. This might take a while to run, but it is important that nothing else is running while you scan.
    • When the scan is finished, click on Click here to export the scan results.
    • Save the report to your desktop so you can post it in your next reply.
    Note: You will need to use Internet Explorer for this scan.

    In your next reply, please submit:
    BitDefender scan report


    Thanks.
     
  6. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Re: Got a window re "cmd.exe"

    It may not be your "money" - but it's surely been your time and I truly thank you so very much, starbuck!!!!!!!!:):):):):):)

    BitDefender QuickScan Beta v0.9.7.8
    -----------------------------------

    Scan date: Tue Nov 17 18:50:38 2009
    Machine ID: C00B8FD4



    No infection found.
    ---------------------


    Processes
    ---------
    <unsigned> InstallShield Update Service Scheduler 720 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    <unsigned> VAIO Entertainment UPnP Client Adapter 2332 C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    <unsigned> VAIO Entertainment Database Service 2516 C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    <unsigned> VAIO Entertainment File Import Service 2868 C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    <unsigned> SonicStageMonitoring Module 2200 C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    <unsigned> Event Monitor User Notification Tool 648 C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    <unsigned> RAID Monitor 1724 C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    <unsigned> SQL Server Windows NT 1684 C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
    <unsigned> RM_SV Module 3664 C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
    <unsigned> SMceMan Module 2256 C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
    <unsigned> VAIOUpdt.exe 672 C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe

    <verified> NMSAccessU.exe 2068 C:\Program Files - for Glen and children PLUS misc\CD BURNER XP - recommended by Kim Komando\CDBurnerXP\NMSAccessU.exe
    <verified> avast! service GUI component 772 C:\Program Files - Security\AVAST 4 Home Edition antivirus scanner, 16 Aug 2008\ashDisp.exe
    <verified> avast! e-Mail Scanner Service 3696 C:\Program Files - Security\AVAST 4 Home Edition antivirus scanner, 16 Aug 2008\ashMaiSv.exe
    <verified> avast! antivirus service 1584 C:\Program Files - Security\AVAST 4 Home Edition antivirus scanner, 16 Aug 2008\ashServ.exe
    <verified> avast! Web Scanner 3144 C:\Program Files - Security\AVAST 4 Home Edition antivirus scanner, 16 Aug 2008\ashWebSv.exe
    <verified> avast! Antivirus updating service 1508 C:\Program Files - Security\AVAST 4 Home Edition antivirus scanner, 16 Aug 2008\aswUpdSv.exe
    <verified> Firefox 1628 C:\Program Files\FIREFOX 3.0.1, 16 August 2008\firefox.exe
    <verified> Internet Explorer 2820 C:\Program Files\internet explorer\iexplore.exe
    <verified> Internet Explorer 876 C:\Program Files\internet explorer\iexplore.exe
    <verified> Java(TM) Quick Starter Service 716 C:\Program Files\Java\jre6\bin\jqs.exe
    <verified> McSACore.exe 1028 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    <verified> SoftModem Messaging Applet 592 C:\WINDOWS\AGRSMMSG.exe
    <verified> Media Center Media Status Aggregator Service 1980 C:\WINDOWS\eHome\ehmsas.exe
    <verified> Media Center Receiver Service 340 C:\WINDOWS\eHome\ehRecvr.exe
    <verified> Media Center Scheduler Service 324 C:\WINDOWS\eHome\ehSched.exe
    <verified> Media Center Tray Applet 600 C:\WINDOWS\ehome\ehtray.exe
    <verified> Windows Explorer 3036 C:\WINDOWS\explorer.exe
    <verified> Application Layer Gateway Service 3896 C:\WINDOWS\System32\alg.exe
    <verified> Client Server Runtime Process 740 C:\WINDOWS\system32\csrss.exe
    <verified> CTF Loader 1552 C:\WINDOWS\system32\ctfmon.exe
    <verified> COM Surrogate 3584 C:\WINDOWS\system32\dllhost.exe
    <verified> hkcmd Module 1220 C:\WINDOWS\system32\hkcmd.exe
    <verified> persistence Module 1240 C:\WINDOWS\system32\igfxpers.exe
    <verified> igfxsrvc Module 1332 C:\WINDOWS\system32\igfxsrvc.exe
    <verified> igfxTray Module 712 C:\WINDOWS\system32\igfxtray.exe
    <verified> LSA Shell (Export Version) 824 C:\WINDOWS\system32\lsass.exe
    <verified> Services and Controller app 812 C:\WINDOWS\system32\services.exe
    <verified> Windows NT Session Manager 692 C:\WINDOWS\System32\smss.exe
    <verified> Spooler SubSystem App 224 C:\WINDOWS\system32\spoolsv.exe
    <verified> Generic Host Process for Win32 Services 956 C:\WINDOWS\system32\svchost.exe
    <verified> Generic Host Process for Win32 Services 1172 C:\WINDOWS\System32\svchost.exe
    <verified> Generic Host Process for Win32 Services 1076 C:\WINDOWS\system32\svchost.exe
    <verified> Generic Host Process for Win32 Services 1008 C:\WINDOWS\system32\svchost.exe
    <verified> Generic Host Process for Win32 Services 2280 C:\WINDOWS\system32\svchost.exe
    <verified> Generic Host Process for Win32 Services 532 C:\WINDOWS\System32\svchost.exe
    <verified> Generic Host Process for Win32 Services 1280 C:\WINDOWS\system32\svchost.exe
    <verified> Generic Host Process for Win32 Services 1372 C:\WINDOWS\system32\svchost.exe
    <verified> Windows NT Logon Application 764 C:\WINDOWS\system32\winlogon.exe


    Network activity
    ----------------
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - a208-38-45-161.deploy.akamaitechnologies.com
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - a69-192-92-20.deploy.akamaitechnologies.com
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - px-in-f148.1e100.net
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - px-in-f138.1e100.net
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - Sony USA
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - a96-17-114-67.deploy.akamaitechnologies.com
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - a69-192-92-20.deploy.akamaitechnologies.com
    Process ashWebSv.exe (3144) connected on port 80 (HTTP) - a96-6-204-20.deploy.akamaitechnologies.com

    Process svchost.exe (1076) listens on ports: 135 (RPC)
    Process VCSW.exe (2332) listens on ports: 51493


    Autoruns and critical files
    ---------------------------
    <unsigned> ShellExecuteHook C:\Program Files - Security\SUPERAntiSpyWare - Anti Spyware program\SASSEH.DLL
    <unsigned> SUPERAntiSpyware WinLogon Processor C:\Program Files - Security\SUPERAntiSpyWare - Anti Spyware program\SASWINLO.dll
    <unsigned> ATI Desktop Control Panel C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    <unsigned> InstallShield Update Service Scheduler C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    <unsigned> Event Monitor User Notification Tool C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    <unsigned> QuickTime Task C:\Program Files\QuickTime\QTTask.exe
    <unsigned> VAIOUpdt.exe C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
    <unsigned> InstallShield Update Service Update Manager C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
    <unsigned> PartSeal C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe

    <verified> avast! service GUI component C:\Program Files - Security\AVAST 4 Home Edition antivirus scanner, 16 Aug 2008\ashDisp.exe
    <verified> WinPatrol System Monitor C:\Program Files - Security\WIN PATROL, 19 August 2008\WinPatrol\winpatrol.exe
    <verified> Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    <verified> Windows Media Player Network Sharing Service Confi C:\Program Files\Windows Media Player\WMPNSCFG.exe
    <verified> Sygate Agent Firewall C:\PROGRA~2\SYGATE~1.6FI\smc.exe
    <verified> SoftModem Messaging Applet C:\WINDOWS\AGRSMMSG.exe
    <verified> Media Center Tray Applet C:\WINDOWS\ehome\ehtray.exe
    <verified> Shell Browser UI Library C:\WINDOWS\system32\browseui.dll
    <verified> Crypto API32 C:\WINDOWS\system32\crypt32.dll
    <verified> Crypto Network Related API C:\WINDOWS\system32\cryptnet.dll
    <verified> Offline Network Agent C:\WINDOWS\system32\cscdll.dll
    <verified> DIMS Notification Handler C:\WINDOWS\system32\dimsntfy.dll
    <verified> hkcmd Module C:\WINDOWS\system32\hkcmd.exe
    <verified> igfxdev Module C:\WINDOWS\system32\igfxdev.dll
    <verified> persistence Module C:\WINDOWS\system32\igfxpers.exe
    <verified> igfxTray Module C:\WINDOWS\system32\igfxtray.exe
    <verified> Windows Logon UI C:\WINDOWS\system32\LogonUI.exe
    <verified> Secondary Logon Service Notification DLL C:\WINDOWS\system32\sclgntfy.dll
    <verified> Windows Shell Common Dll C:\WINDOWS\system32\shell32.dll
    <verified> Systray shell service object C:\WINDOWS\system32\stobject.dll
    <verified> Userinit Logon Application c:\windows\system32\userinit.exe
    <verified> Web Site Monitor C:\WINDOWS\system32\webcheck.dll
    <verified> Common DLL to receive Winlogon notifications C:\WINDOWS\system32\wlnotify.dll
    <verified> Windows Portable Device Shell Service Object C:\WINDOWS\system32\WPDShServiceObj.dll


    Browser plugins
    ---------------
    <unsigned> Adobe Shockwave for Director Netscape plug-in, ver C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\np32dsw.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin2.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin3.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin4.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin5.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin6.dll
    <unsigned> The QuickTime Plugin allows you to view a wide var C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npqtplugin7.dll
    <unsigned> Google IE Client Toolbar c:\program files\google\googletoolbar1.dll
    <unsigned> Java(TM) Quick Starter binary C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    <unsigned> Adobe Shockwave for Director Netscape plug-in, ver C:\WINDOWS\system32\Adobe\Director\np32dsw.dll

    <verified> Adobe PDF Helper for Internet Explorer C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    <verified> getplusplusadobe16236 C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\np_gp.dll
    <verified> NPRuntime Script Plug-in Library for Java(TM) Depl C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npdeploytk.dll
    <verified> NPFxViewer.dll C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\NPFxViewer.dll
    <verified> Default Plug-in C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\npnul32.dll
    <verified> Adobe PDF Plug-In For Firefox and Netscape C:\Program Files\FIREFOX 3.0.1, 16 August 2008\plugins\nppdf32.dll
    <verified> Java(TM) Platform SE binary c:\program files\java\jre6\bin\jp2ssv.dll
    <verified> mcieplg.dll c:\program files\mcafee\siteadvisor\mcieplg.dll
    <verified> Windows Messenger C:\Program Files\Messenger\msmsgs.exe
    <verified> Panda ActiveScan 2.0 Plugin for Firefox C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll
    <verified> Unity Player 2.6.0f7 C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll
    <verified> getPlus+(R) C:\WINDOWS\Downloaded Program Files\gp.ocx
    <verified> mhLbl Module C:\WINDOWS\Downloaded Program Files\mhLbl.dll
    <verified> PCPitstop Module C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
    <verified> PC Pitstop 3D Performance Test C:\WINDOWS\Downloaded Program Files\PCPitstop3D.dll
    <verified> BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.ocx
    <verified> Symantec Security Check Registry and File Informat C:\WINDOWS\Downloaded Program Files\rufsi.dll
    <verified> Windows Live OneCare Safety Scanner Base Module C:\WINDOWS\Downloaded Program Files\wlscBase.dll
    <verified> Windows Presentation Foundation (WPF) plug-in for c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    <verified> Network Diagnostic for Windows XP C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    <verified> Internet Explorer C:\WINDOWS\system32\ieframe.dll
    <verified> NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
    <verified> Microsoft Windows Sockets 2.0 Service Provider C:\WINDOWS\system32\mswsock.dll
    <verified> Microsoft Windows Rsvp 1.0 Service Provider C:\WINDOWS\system32\rsvpsp.dll
    <verified> LDAP RnR Provider DLL C:\WINDOWS\system32\winrnr.dll


    Scan
    ----

    No file uploaded.

    Scan finished - communication took 5 sec
    Total traffic - 0.06 MB sent, 3.05 KB recvd
    Scanned 1278 files and modules - 70 seconds
     
  7. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Re: Got a window re "cmd.exe"

    Hi Mara,

    Thanks for those words. It's no problem at all.

    It seems as though the malware issue is now done and dusted.
    There wasn't really much, it seemed like leftovers more than anything.
    I'd say any problems you still may have, are not related to malware now.

    Let's tidy up what we have done:

    Step 1
    Hide System Files
    1. Click Start.
    2. Open My Computer.
    3. Select Tools menu
    4. Click Folder Options.
    5. Select the View Tab.
    6. Uncheck Show hidden files and foldersin the Hidden files and folders section.
    7. Select Hide protected operating system files (recommended) option.
    8. Check the Hide file extensions for known file types option.
    9. Click Yes.
    10. Click OK.

    Step 2
    • Please double-click OTL.exe to run it.
    • You should see a CleanUp! button, press that button,
    • This will remove any programs we have asked you to download along with there associated folders.. plus itself.

    Note:
    MBAM will not be removed. This is left to your discretion.

    Step 3
    Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

    The easiest and safest way to do this is:
    • Go to Start > Programs > Accessories > System Tools and click "System Restore".
    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Then go to Start > Run and type: Cleanmgr
    • Click "OK".
    • Select the drive for cleaning then click OK (usually 'C' drive)
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

    To find out how you may have been infected....read this topic:
    So how did i get infected?

    Some of the following may not apply to you, but it's a standard speech.

    Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
    • Use an AntiVirus Software
      Note*:
      Upon installation MS Security Essentials will check that your OS is a legal copy.

      Only install one AntiVirus program
    • Update your AntiVirus Software regularly
    • Use a 3rd party Firewall NOTE: If choosing Zone Alarm be aware that the free version also installs ZoneAlarm Spy Blocker. It is recommended however that you UNcheck this option.

      Only install one software Firewall
    • Scan regularly with a 'Stand Alone' Anti-Malware scanner:
      Installing another scanner that you can run once or twice a week is always beneficial.
      Something like:
      Malwarebytes Anti-Malware
      SUPERAntiSypware
      Remember to update these programs each time before running.
      You can install more than one of these if you only run them as stand alone programs.
    • Use an alternative browser:
      Some excellent alternatives to MS Internet Explorer are:

      Firefox
      For added security, add the NoScript extension to this browser:
      Allow active content to run only from sites you trust, and protect yourself against XSS and Clickjacking attacks

      Opera

      They offer better security, more stability, and better speed.
    • Keep your system clean of temp files etc, using a 'Cleaner':

      Cleaners are programs that will help to clean out your:
      Windows temp files
      Current user temp files
      Cookies
      Temporary Internet flies
      Browser history
      Recycle bin
      Etc.......
      In other words.... all the rubbish that you accumalate over the course of your browsing and day to day usage of your pc.
      Programs like:
      CCleaner
      TFC by OldTimer
      ATF Cleaner
    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

      A tutorial on installing & using this product can be found here:
      Using and installing SpywareBlaster
    • Update all your 'Security' programs regularly - Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Glad I was able to help.

    Safe surfing.
     
  8. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Re: Got a window re "cmd.exe"

    Mara, once you finish up with Starbuck and you get your all clear, :) let us know what the remaining symptoms are, if any, in a new thread and we will all take it from there.
     
  9. Mara

    Mara Registered Members

    Joined:
    Jun 20, 2009
    Messages:
    2,261
    Location:
    British Columbia, Canada
    Operating System:
    Windows XP Home
    Re: Got a window re "cmd.exe"

    [​IMG]



    And thanks, BeeCeeBee ... I'll do that:)
     
  10. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Re: Got a window re "cmd.exe"

    [​IMG]
     

Share This Page