Dear friends !
I am facing a very strange problem. I have McAfee Enterprise Edition Trial Version installed in my pc. I want to remove because I want to install Kaspersky Antivirus 6.0 but when I go in Control Panel--->Add and Remove Programs, then I can't see it in the list of programs. Even I am unable to see Microsoft Office 2003 Professional Edition there. I have Office 2003 installed on my pc and it is working well but I can't see it there in the list of programs.
These are the programs in the list of Add/Remove Programs:
Adobe Flash Player ActiveX
Adobe Photoshop 7.0
Adobe Reader 6.0
AnswerWorks Runtime
I don't know what is this AnswerWorks Runtime. Is it something like malware ?
I can't remove McAfee and when I use McAfee Removal Tool and run it it shows me to remove the components from Control Panel first, but I can't see any component of McAfee in Control Panel.
When I used ComboFix and SDFix, I found the messages....Access is denied. But for SDFix it generated the report.
I am sending HijackThis log and HijcakThis log:
SDFix Log
**************************
**********
**********
**********
**********
**********
**********
**********
**********
**********
**********
SDFix: Version 1.107
Run by Administrator on Tue 10/02/2007 at 02:21 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchos
t.exe
No streams found.
C:\WINDOWS\system32\ntoskr
nl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\s
ervices\sh
aredaccess
\parameter
s\firewall
policy\sta
ndardprofi
le\authori
zedapplica
tions\list
]
"%windir%\\system32\\sessm
gr.exe"="%
windir%\\s
ystem32\\s
essmgr.exe
:*:enabled
:@xpsp2res
.dll,-2201
9"
"C:\\Program Files\\Hewlett-Packard\\To
olbox\\jre
\\bin\\jav
aw.exe"="C
:\\Program
Files\\Hewlett-Packard\\To
olbox\\jre
\\bin\\jav
aw.exe:*:D
isabled:ja
vaw"
"C:\\Documents and Settings\\Administrator\\A
pplication
Data\\U3\\0000176C6960DEB5
\\0DE4F643
-C398-46ec
-9339-2362
F2311932\\
Exec\\skyp
e.exe"="C:
\\Document
s and Settings\\Administrator\\A
pplication
Data\\U3\\0000176C6960DEB5
\\0DE4F643
-C398-46ec
-9339-2362
F2311932\\
Exec\\skyp
e.exe:*:En
abled:Skyp
e"
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkServic
e.exe"="C:
\\Program Files\\McAfee\\Common Framework\\FrameworkServic
e.exe:*:En
abled:McAf
ee Framework Service"
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\s
ervices\sh
aredaccess
\parameter
s\firewall
policy\dom
ainprofile
\authorize
dapplicati
ons\list]
"%windir%\\system32\\sessm
gr.exe"="%
windir%\\s
ystem32\\s
essmgr.exe
:*:enabled
:@xpsp2res
.dll,-2201
9"
Remaining Files:
---------------
Files with Hidden Attributes:
Thu 31 May 2007 850,432 ...H. --- "C:\Documents and Settings\Administrator\My Documents\~WRL1038.tmp"
Tue 17 Apr 2007 130,048 ...H. --- "C:\Documents and Settings\Administrator\My Documents\Estate incomes 2007\~WRL0530.tmp"
Finished!
**************************
**********
**********
**********
**********
**********
**********
**********
**********
**********
**********
HijackThis Log
**************************
**********
**********
**********
**********
**********
**********
**********
**********
**********
**********
Logfile of HijackThis v1.99.1
Scan saved at 2:33:02 AM, on 10/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService
.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
C:\WINDOWS\system32\igfxtr
ay.exe
C:\WINDOWS\system32\hkcmd.
exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.ex
e
C:\Program Files\Hewlett-Packard\Tool
box\Status
Client\Sta
tusClient.
exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\Tool
box\jre\bi
n\javaw.ex
e
C:\WINDOWS\system32\HPBPRO
.EXE
E:\Utilities\Cleaning and Fixing Tools\HijackThis\alternati
v.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = 192.168.5.223:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
309F01C523
1} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\2
.0.301.716
4\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.ex
e
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\Se
tRefresh.e
xe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Tool
box\Status
Client\Sta
tusClient.
exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Tool
box\hpbpst
tp.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0\bin\np
jpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0\bin\np
jpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0
060B0FCC12
2} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0
010830243B
D} (InstaFred Control) - file://C:\Program Files\AutoCAD 2000i\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0
010830243B
D} (AcPreview Control) - file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
vc.dll
O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - cmd.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService
.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
**************************
**********
**********
**********
**********
**********
**********
**********
**********
**********
********
Please help me in this regard.
Thanks
Hemant