Windows XP
--
Questions
--
Followers
Top Experts
When I returned she told me that the machine now would boot to the desktop and then restart itself. I treid several times to start it normally with no success. Then I started the machine in Safe Mode and everything seemed to work except for her mouse. (It is not a PS/2 or USB but a parallel port mouse). I returned to the Advanced Options screen and chose "Disable Auto Restart on System Fail." This gave me a blue screen when the computer tried to restart. The error message was "The Problem seems to be caused by the following file - spooldr.sys." Again I had the "PAGE_FAULT_IN_NONPAGED_AR
STOP 0x00000050(0x00000000, 0xF89B69BD, 0x00000002).
The maouse also will not work in Debugging mode. From what I can tell spooldr.sys is a rootkit. With all I have mentioned above, how can I get rid of it.
Thanks!
Robert
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
If you are able to download the combofix using another pc, and if still able to run it on the infected machine;
Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
-Rob
ComboFix 07-08-14.4 - "Robert" 2007-08-18 13:40:06.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.
((((((((((((((((((((((((((
C:\DOCUME~1\Robert\Desktop
C:\WINDOWS\DOWNLO~1.\ODCTO
C:\WINDOWS\system32\MabryO
((((((((((((((((((((((((( Â Files Created from 2007-07-18 to 2007-08-18 Â ))))))))))))))))))))))))))
2007-08-18 13:26 Â Â Â Â Â 51,200 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\nircmd.exe
2007-08-16 21:11 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\Program Files\Common Files\Avery
2007-08-16 13:42 Â Â Â Â Â 93,184 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\wvjava
2007-08-16 13:42 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\Program Files\PLATINUM technology
2007-08-14 21:31 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\Program Files\MSXML 4.0
2007-08-07 10:35 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\WINDOWS\system32\NtmsDa
2007-08-01 16:03 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\DOCUME~1\Robert\APPLIC~
2007-08-01 15:54 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\Program Files\Common Files\Roxio Shared
2007-08-01 15:53 Â Â Â Â Â 61,424 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\driver
2007-08-01 15:53 Â Â Â Â Â 57,344 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\uneng.exe
2007-08-01 15:53 Â Â Â Â Â 49,152 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\cdrtc.
2007-08-01 15:53 Â Â Â Â Â 45,056 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\cdral.
2007-08-01 15:53 Â Â Â Â Â 23,436 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\driver
2007-08-01 15:53 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\Program Files\Common Files\Adaptec Shared
2007-07-30 17:41 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\WINDOWS\PhotoBackup
2007-07-23 12:28 Â Â Â Â Â <DIR> Â Â Â Â Â d-------- Â Â Â Â Â C:\DOCUME~1\ALLUSE~1\APPLI
((((((((((((((((((((((((((
2007-07-27 18:07 Â Â Â Â Â 783224 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\aswBoo
2007-07-27 18:02 Â Â Â Â Â 94416 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\driver
2007-07-27 18:02 Â Â Â Â Â 92848 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\driver
2007-07-27 18:00 Â Â Â Â Â 23152 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\driver
2007-07-27 17:59 Â Â Â Â Â 42912 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\driver
2007-07-27 17:58 Â Â Â Â Â 26624 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\driver
2007-07-27 17:57 Â Â Â Â Â 95608 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\AVASTS
2007-07-19 02:59 Â Â Â Â Â 3583488 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-07-12 19:31 Â Â Â Â Â 765952 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 15:14 Â Â Â Â Â 1152 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\windrv
2007-06-27 10:34 Â Â Â Â Â 823808 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 671232 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 6058496 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 52224 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 477696 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 459264 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 44544 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 384512 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 383488 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 27648 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 267776 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 232960 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 230400 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 193024 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 153088 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 132608 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 124928 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 1152000 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 105984 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 10:34 Â Â Â Â Â 102400 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 04:27 Â Â Â Â Â 63488 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 04:27 Â Â Â Â Â 625152 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 04:27 Â Â Â Â Â 13824 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-27 03:00 Â Â Â Â Â 161792 Â Â Â Â Â --a--c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-26 02:08 Â Â Â Â Â 1104896 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\msxml3
2007-06-26 02:08 Â Â Â Â Â 1104896 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-19 09:31 Â Â Â Â Â 282112 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\system32\gdi32.
2007-06-19 09:31 Â Â Â Â Â 282112 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
2007-06-13 06:23 Â Â Â Â Â 1033216 Â Â Â Â Â --a------ Â Â Â Â Â C:\WINDOWS\explorer.exe
2007-06-13 06:23 Â Â Â Â Â 1033216 Â Â Â Â Â -----c--- Â Â Â Â Â C:\WINDOWS\system32\dllcac
((((((((((((((((((((((((((
Â
Â
*Note* empty entries &Â legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA
"\\HOME-8F2B915D5D\EPSON Stylus Photo R200 Series"="C:\WINDOWS\System
"avast!"="E:\PROGRA~1\ALWI
"Auto EPSON Stylus Photo R200 Series on FAMILY-HGJM2O4R"="C:\WINDO
"MCUpdateExe"="c:\PROGRA~1
"MCAgentExe"="c:\PROGRA~1\
[HKEY_CURRENT_USER\SOFTWAR
"ctfmon.exe"="C:\WINDOWS\s
[HKEY_LOCAL_MACHINE\softwa
ACNotify.dll
[HKEY_LOCAL_MACHINE\softwa
tphklock.dll 2005-11-30 21:16 24576 C:\WINDOWS\system32\tphklo
[HKEY_LOCAL_MACHINE\system
"Notification Packages"= scecli ACGina
[HKEY_LOCAL_MACHINE\softwa
backup=C:\WINDOWS\pss\Adob
[HKEY_LOCAL_MACHINE\softwa
backup=C:\WINDOWS\pss\Adob
[HKEY_LOCAL_MACHINE\softwa
backup=C:\WINDOWS\pss\Forg
[HKEY_LOCAL_MACHINE\softwa
backup=C:\WINDOWS\pss\Micr
[HKEY_LOCAL_MACHINE\softwa
backup=C:\WINDOWS\pss\WinZ
[HKEY_LOCAL_MACHINE\softwa
backup=C:\WINDOWS\pss\Open
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\ThinkPad\ConnectUtil
[HKEY_LOCAL_MACHINE\softwa
"E:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.
[HKEY_LOCAL_MACHINE\softwa
"E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\softwa
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\softwa
C:\WINDOWS\System32\spool\
[HKEY_LOCAL_MACHINE\softwa
rundll32.exe C:\PROGRA~1\ThinkPad\UTILI
[HKEY_LOCAL_MACHINE\softwa
RunDll32 C:\PROGRA~1\ThinkPad\UTILI
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\ThinkPad\Utilities\B
[HKEY_LOCAL_MACHINE\softwa
rundll32.exe C:\PROGRA~1\ThinkPad\UTILI
[HKEY_LOCAL_MACHINE\softwa
C:\WINDOWS\system32\ctfmon
[HKEY_LOCAL_MACHINE\softwa
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
[HKEY_LOCAL_MACHINE\softwa
c:\PROGRA~1\mcafee.com\age
[HKEY_LOCAL_MACHINE\softwa
c:\PROGRA~1\mcafee.com\age
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\softwa
C:\WINDOWS\MWW32\manager\m
[HKEY_LOCAL_MACHINE\softwa
[HKEY_LOCAL_MACHINE\softwa
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\softwa
[HKEY_LOCAL_MACHINE\softwa
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\McAfee.com\VSO\oascl
[HKEY_LOCAL_MACHINE\softwa
"E:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\softwa
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\SpyNoMore\SNM.exe /startup
[HKEY_LOCAL_MACHINE\softwa
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\softwa
"C:\Program Files\Java\jre1.5.0_10\bin
[HKEY_LOCAL_MACHINE\softwa
tp4ex.exe
[HKEY_LOCAL_MACHINE\softwa
C:\PROGRA~1\Lenovo\PkgMgr\
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\ThinkPad\Utilities\T
[HKEY_LOCAL_MACHINE\softwa
tp4serv.exe
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Common Files\Lenovo\Scheduler\sch
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\McAfee.com\VSO\mcvss
[HKEY_LOCAL_MACHINE\softwa
"C:\PROGRA~1\McAfee.com\VS
[HKEY_LOCAL_MACHINE\softwa
E:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
[HKEY_LOCAL_MACHINE\softwa
C:\Program Files\Microsoft Works\wkfud.exe
R1 ANC;ANC;C:\WINDOWS\system3
R1 BIOS;BIOS;\??\C:\WINDOWS\s
R1 IBMTPCHK;IBMTPCHK;\??\C:\W
R1 TPPWR;TPPWR;C:\WINDOWS\sys
R3 Tp4Track;PS/2 TrackPoint Driver;C:\WINDOWS\system32
S3 AEIWL;IBM High Rate Wireless LAN MiniPCI Combo Card Driver;C:\WINDOWS\system32
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\WINDOWS\syst
S3 LSWPCv4;Wireless-B Notebook Adapter Driver;C:\WINDOWS\system32
S3 LucentSoftModem;Lucent Technologies Soft Modem;C:\WINDOWS\system32\
S3 neo20xx;neo20xx;C:\WINDOWS
S3 ThinkPadDSP;ThinkPad DSP Driver Service;C:\WINDOWS\system3
[HKEY_CURRENT_USER\softwar
AutoRun\command- D:\AUTORUN\AUTORUN.EXE
[HKEY_CURRENT_USER\softwar
AutoRun\command- E:\Program Files\Broderbund\AG CreataCard\Unlock\autorun.
[HKEY_CURRENT_USER\softwar
AutoRun\command- setupSNK.exe
Contents of the 'Scheduled Tasks' folder
2007-08-17 21:28:03 C:\WINDOWS\Tasks\AppleSoft
2007-01-17 14:25:54 C:\WINDOWS\Tasks\BMMTask.j
2007-08-18 21:37:34 C:\WINDOWS\Tasks\RegCure Program Check.job
2007-08-16 12:42:57 C:\WINDOWS\Tasks\RegCure.j
2007-08-18 21:37:29 C:\WINDOWS\Tasks\XoftSpySE
2007-08-14 12:44:23 C:\WINDOWS\Tasks\XoftSpySE
**************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-18 17:41:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
[HKEY_LOCAL_MACHINE\SOFTWA
"\\\\HOME-8F2B915D5D\\EPSO
Completion time: 2007-08-18 18:23:00 - machine was rebooted
C:\ComboFix-quarantined-fi
      --- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 6:42:46 PM, on 08/18/07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\ibmpms
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
E:\Program Files\Alwil Software\Avast4\aswUpdSv.e
E:\Program Files\Alwil Software\Avast4\ashServ.ex
C:\WINDOWS\system32\spools
C:\Program Files\ThinkPad\ConnectUtil
c:\program files\mcafee.com\agent\mcd
c:\PROGRA~1\mcafee.com\vso
c:\PROGRA~1\mcafee.com\age
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\system32\TpKmpS
C:\Program Files\Common Files\Lenovo\Scheduler\tvt
C:\Program Files\ThinkPad\ConnectUtil
E:\Program Files\Alwil Software\Avast4\ashMaiSv.e
E:\Program Files\Alwil Software\Avast4\ashWebSv.e
C:\Program Files\ThinkPad\ConnectUtil
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.ex
E:\PROGRA~1\ALWILS~1\Avast
C:\PROGRA~1\mcafee.com\age
C:\WINDOWS\system32\ctfmon
E:\PROGRA~1\CAMDEV~1\CAMUN
C:\DOCUME~1\Robert\LOCALS~
c:\program files\mcafee.com\agent\mcu
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-9
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
O4 - HKLM\..\Run: [\\HOME-8F2B915D5D\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R200 Series on FAMILY-HGJM2O4R] C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01012101-5E80-11D8-9E86-0
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
O16 - DPF: {74FFE28D-2378-11D5-990C-0
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklo
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtil
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtil
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Alwil Software\Avast4\aswUpdSv.e
O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashServ.ex
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpms
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcd
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
O23 - Service: mysql - Unknown owner - E:\Program Files\xampp\mysql\bin\mysq
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv
O23 - Service: System Update (SUService) - Â - c:\program files\lenovo\system update\suservice.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpS
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvt
Please help me determine the problem and also advise on how to read these reports.
Thank you!
Robert

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
So the solution that I can offer is as follows:
A) Start Windows in Safe Mode with Command Prompt.
B) Rename C:\Windows\System32\sysldr
c) Reboot and run a virus scanning/cleaning utility as well as an adware tool (Make sure to clean any infected files.
This worked for me.
-Rob
-Rob
A) Start Windows in Safe Mode with Command Prompt.
B) Rename C:\Windows\System32\sysldr
c) Reboot and run a virus scanning/cleaning utility as well as an adware tool (Make sure to clean any infected files."
I did all of that and no infected files were found. The above logs were the results after running the scans.






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
You have 2 antivirus there? Avast and McAfee? You need to only have one antivirus with real-time protection, having 2 will only conflict each other and corrupt the system.
Please uninstall one of them.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Something must be going around. Â We have one client machine and possibly two (a different client) experiencing the same sudden onset Random BSOD. Â Both reported starting this past week. Â Same precursors with the 0x0000050 errors suggesting RAM or drivers problems. Â On the one, I finally (after scanning online with TrendMicro and removing a Trojan) got it to consistenly crash and the error message was a problem with spooldr.sys. Â I'm going down the rootkit path to see if that clears things up and will keep advised as to progress or not.
I've fixed my first problem. Â It was indeed a virus, several in fact. Â Housecall (TrendMicro) only got part of them. Â BitDefender's online free scan got lots more and after scanning, rebooting, scanning, rebooting and scanning again, I've got a clean report and no more crashes.
Here's the BitDefender report in case there is anything in it that triggers something to look for for the rest. Â TCPIP.SYS was, in fact, part of the problem. Â I don't see that SPOOLDR.SYS (which I renamed to SPOOLDR._YS was, but since I can identify no reason for it, I'me deleting it too. Â Oops. Â Just did a search and indeed nasty SPOOLDR was found (by TrendMicro in the initial scans and again by BitDefender). Â Looks like this was like Yeller's situation. Â Must be something going around. Â Hope this helps. Â Sorry for how the paste turned out.
BitDefender Online Scanner
Â
Â
Â
Scan report generated at: Sun, Aug 19, 2007 - 14:34:13
Â
Â
 ***BitDefender log removed by rpggamergirl, Zone Advisor***
Â
Â
Thanks!!
Robert






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
both antivirus are showing in your running processes, that's why I asked.
Not scanning both at the same time I hope.
BitDefender's log found most files that are already in Trend's quarantine and in the System Restore points which can be easily deleted by flushing the restore points. But most importantly it deleted the infected tcpip.sys
tcpip.sys are patched(of filesize around 375168 bytes) and it's the one loading the 2 spooldr's
spooldr.exe runs as a process and spooldr.sys stealths it.
If the exe process gets killed, the machine BSODs during reboot
The  tcpip.sys copies from System32\drivers & dllcache are patched so they need to be replaced/deleted. You can then copy from the remaining uninfected file or from another machine.

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
smithfraudfix.exe
vundofix.exe
rustbfix.exe
AVG Rootkit Scanner
Dr.Web.Cureit
sdfix.exe
SpyBot Search and Destroy
SuperAntispyware
AdwarePersonal
Very important scan is mwav.exe.The problem with it is that you have to manually delete the infected files or buy the e-scan.It will also show registry errors,that might be slowing down the computer.If you cant find how to delete the errors,post the log file.
And make sure you update the ones that could be updated
E:\PROGRA~1\CAMDEV~1\CAMUN
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O16 - DPF: {01012101-5E80-11D8-9E86-0
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: mysql - Unknown owner - E:\Program Files\xampp\mysql\bin\mysq
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.e
In a run dialog box type:
msconfig and hit enter
On the window opened click the Startup tab,uncheck all entries except for your current antivirus,firewall and you could leave ctfmon.exe as well.,apply and reboot.
Download CCleaner(it is free) ,install and run it.Click the analyze button first and when scan complete,run cleaner button.Click on the issues tab and scan again,fix issues.
And also,after you are sure your system is clean,turn off system restore and then turn it back on.This will delete the system restore points.
After you scan your system and do all of the above,post a hijackthis log file again
Sorry for the brief explanation,but there is so much to do on your system,that I could be a day if I have to give you detailed instructions.If you have problems with any of the above,post a message.Good luck!






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
I assume it was BitDefender's log when I read the lines below that says;
>>BitDefender Online Scanner
Â
 Scan report generated at: Sun, Aug 19, 2007 - 14:34:13<<
snazy,
Please be careful what you suggest to Askers especially when you ask them to fix hijackthis entries which can have bad consequences.
Hijackthis has a bug that false positively reports 09 and 023 entries a "file missing" even if the file really exists.
As you can see from those 023 Avast entries where it says "file missing" but the file is there, that's his other antivirus and Avast is there in the running processes. If he fix those entries it will greatly affect Avast, 023 entries corresponds to program's services.
rpggamergirl, the emphasis there should be on "my", that report was posted by a different poster, leading to some confusion :)

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
Boot into Safe Mode.
open Folder Options and select "Show all files" and Uncheck "Hide system files"
Go to C:\Windows and rename SPOOLDR.EXE to anything (ex. "SPOOLDR.EXE.OLD")
expand TCPIP.SYS from XP Cd to C:\Windows\System32\Driver
Reboot into Normal mode and no more BSOD caused by SPOOLDR.SYS
You can run anything that you want to delete rest of files.
What have we done to cause this?
Thanks!!
Robert






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Thanks!!
Robert
You can also go to http://virusscan.jotti.org/Â
browse to C:\Windows\System32\Driver
Note that it might take a few minutes for the submit button to appear

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
I have not been folowing this thread too closely, but did you run RootkitRevealer yet?
If not, please do, and save the resulting log to a text file, then copy and paste here (or just the first 30 lines or so if it is too long)
http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx
HKU\DEFAULT\Control Panel\Internetional_combof
HKU\S-1-5-18 Â Â Â Â Â Â Â Â Â Â Error dumping hive. The system cannot find the
HKLM\SAM Â Â Â Â Â Â Â Â Â Â Â Â Error mapping hive file. The system cannot find
HKLM\SECURITY Â Â Â Â Â Â Â Â Error dumping hive. Insufficient system resources
HKLM\SYSTEM Â Â Â Â Â Â Â Â Â Error dumping hive. The system cannot find the
F: Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Error muniting volume
An error occurred in CMD.EXE that prevents RootkitRevealer form accurately analyzing your system.
If CMD.EXE is available on your system please report this failure.
I tried running again and got this message:
"Error loading helper driver: Access denied." But after clicking OK it ran and I got the following:
HKU\DEFAULT\Control Panel\Internetional_combof
HKU\DEFAULT\Control Panel\Internetional_combof
HKU\S-1-5-18\Control Panel\Internetional_combof
HKU\S-1-5-18\Control Panel\Internetional_combof
HKLM\SECURITY\Policy\Secre
HKLM\SECURITY\Policy\Secre
HKLM\SOFTWARE\Microsoft\Cr
I ran it once more and got the same thinh as the second list above. After each attempt I got the same error message - An error occurred in CMD.EXE that prevents RootkitRevealer form accurately analyzing your system.
If CMD.EXE is available on your system please report this failure.
The second and third time I ran the application there was no mention of the F: drive.
The only way to shut the computer down now is with the power button. If I click to shutdown all I get it the window asking me to switch users and there is only one user on this machine. Â
I kow this question was opened and answered a couple of months ago. I've just encountered someone with this issue and they were running avast. They're wondering how it got past the antivirus software.
Any ideas on how to prevent this and other issues from infecting the user again?
Thanks,
Chris






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Windows XP
--
Questions
--
Followers
Top Experts
Microsoft Windows XP is the sixth release of the NT series of operating systems, and was the first to be marketed in a variety of editions: XP Home and XP Professional, designed for business and power users. The advanced features in XP Professional are generally disabled in Home Edition, but are there and can be activated. There were two 64-bit editions, an embedded edition and a tablet edition.