Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 793
  • Last Modified:

I have a dell computer pc running xp media and for some reason I keep getting an error message win 32 API FUNCTION FAILED, how do I get rid of this'

I have a dell pc computer running windows xp media edition and I keep getting an error message of win 32 API FUNCTION FAILED when it appears 10 to 20 windows come up saying the same thing win 32 API FUNCTION FAILED, how do I get rid of this
0
GILDA1
Asked:
GILDA1
  • 3
  • 2
2 Solutions
 
Delphineous SilverwingGood Ol' GeekCommented:
When are you seeing this?  At start-up, when doing nothing?

This might be caused by an existing or a previously existing malicious software on the machine.
0
 
flubbsterCommented:
This is typically indicative of a windows resource issue. Are you running a database? Custom scripts? Calls to window functions? More detail is needed here.
0
 
GILDA1Author Commented:
this pops up at any time, but usually when the computer is idle. It can be two windows or up to 18-20.
IMG-0858.jpg
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
GILDA1Author Commented:
HERE IS ANOTHER PHOTO
IMG-0858.jpg
0
 
Delphineous SilverwingGood Ol' GeekCommented:
This looks like it could be malicious software.  

Download ComboFix (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save on your hard drive.

Run ComboFix and let it finish - do not click outside the window or run any software.  ComboFix will restart windows as part of its process then run "Find 3m".  Once complete it will display a log in notepad showing what it found and removed, as well as some other information.  You are welcome to post the log file as a "Code Snippet" for further analysis by an Expert here.

Ashampoo Antispyware has proven itself an excellent tool for removing malware.  You can download it from download.com (http://www.download.com/Ashampoo-AntiSpyWare/3000-8022_4-10883292.html) - install it, make sure to "check for updates", and run a full scan.  Don't bother requesting a 30-day trial license; the download comes with 10 days, which is long enough to do what you need without surrendering your e-mail address.
0
 
GILDA1Author Commented:
I hope this works, so far I have not received any error messages.
ComboFix 08-11-03.04 - CHRIS ROHAN 2008-11-04  0:47:56.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1210 [GMT -8:00]
Running from: c:\documents and settings\CHRIS ROHAN\Desktop\ComboFix.exe
 * Resident AV is active
 
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\Downloaded Program Files\ODCTOOLS\ef6b26db-344d-4ad3-ba24-aca0bdaa999a.cab
c:\windows\Downloaded Program Files\ODCTOOLS\f04d289f-c60a-422b-8396-6c372047042e.cab
c:\windows\Downloaded Program Files\setup.inf
c:\windows\IE4 Error Log.txt
 
.
(((((((((((((((((((((((((   Files Created from 2008-10-04 to 2008-11-04  )))))))))))))))))))))))))))))))
.
 
2008-11-02 16:02 . 2008-11-02 16:02	<DIR>	d--------	c:\program files\CoolIris
2008-11-02 16:02 . 1997-06-25 15:24	40,448	--a------	c:\windows\system32\regobj.dll
2008-10-29 06:19 . 2008-10-29 06:20	<DIR>	d--------	c:\program files\CCleaner
2008-10-29 06:04 . 2008-10-29 06:04	<DIR>	d--------	c:\documents and settings\CHRIS ROHAN\Application Data\MailFrontier
2008-10-29 05:49 . 2008-10-09 13:25	1,221,008	--a------	c:\windows\system32\zpeng25.dll
2008-10-27 18:31 . 2008-11-04 01:22	642	--a--c---	C:\rollback.ini
2008-10-27 11:35 . 2008-10-27 11:35	<DIR>	d--------	c:\program files\PicLensIE
2008-10-26 13:29 . 2008-11-04 01:25	242,805,280	--ahs----	c:\windows\system32\drivers\fidbox.dat
2008-10-26 13:29 . 2008-11-04 01:00	3,252,476	--ahs----	c:\windows\system32\drivers\fidbox.idx
2008-10-26 13:26 . 2008-10-26 13:26	<DIR>	d--------	c:\program files\ZoneAlarmSB
2008-10-26 13:25 . 2008-11-02 15:18	<DIR>	d--------	c:\documents and settings\All Users\Application Data\MailFrontier
2008-10-26 13:25 . 2008-10-09 13:25	73,104	--a------	c:\windows\zllsputility.exe
2008-10-26 13:25 . 2008-11-03 09:33	4,212	--ah-----	c:\windows\system32\zllictbl.dat
2008-10-26 13:24 . 2008-11-04 00:32	<DIR>	d--------	c:\windows\system32\ZoneLabs
2008-10-26 13:24 . 2008-10-26 13:24	<DIR>	d--------	c:\program files\Zone Labs
2008-10-26 13:24 . 2008-11-04 01:09	349,221	--a------	c:\windows\system32\vsconfig.xml
2008-10-26 13:23 . 2008-11-04 01:26	<DIR>	d--------	c:\windows\Internet Logs
2008-10-23 19:01 . 2008-10-15 08:34	337,408	---------	c:\windows\system32\dllcache\netapi32.dll
2008-10-23 16:18 . 2008-10-23 16:18	2,302,017	--a------	c:\windows\system32\GPhotos.scr
2008-10-23 14:04 . 2008-10-23 14:04	<DIR>	d--------	c:\program files\YouSendIt
2008-10-22 13:05 . 2008-10-22 13:05	<DIR>	d--------	c:\documents and settings\CHRIS ROHAN\Application Data\GTek
2008-10-21 16:27 . 2008-10-21 16:27	3,407,848	--a------	c:\program files\YouSendItExpressSetup1_7_3.exe
2008-10-18 23:02 . 2008-09-14 17:36	25,272	--a------	c:\windows\system32\drivers\purendis.sys
2008-10-18 23:02 . 2008-09-14 17:36	23,992	--a------	c:\windows\system32\drivers\pnarp.sys
2008-10-18 23:01 . 2008-10-18 23:01	<DIR>	d--------	c:\program files\Common Files\Pure Networks Shared
2008-10-15 23:41 . 2008-10-15 23:41	<DIR>	d--------	c:\program files\iTunes
2008-10-15 23:41 . 2008-10-15 23:41	<DIR>	d--------	c:\program files\iPod
2008-10-15 23:41 . 2008-10-15 23:41	<DIR>	d--------	c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-15 22:50 . 2008-10-15 22:50	7,507,296	--a------	c:\program files\rminstall.exe
2008-10-15 18:57 . 2008-10-01 12:01	32,000	--a------	c:\windows\system32\drivers\usbaapl.sys
2008-10-15 16:50 . 2008-10-15 23:36	67,167,528	--a------	c:\program files\iTunes801Setup.exe
2008-10-15 12:59 . 2008-10-15 12:59	42	--a------	c:\windows\system32\Jiii_PNUCT.pnc
2008-10-15 12:32 . 2008-10-15 12:45	2,387,180	--a------	c:\program files\PerfectUninstaller_Setup.exe
2008-10-15 11:47 . 2008-10-15 12:54	<DIR>	d--------	c:\program files\Perfect Uninstaller
2008-10-15 11:47 . 2008-09-16 17:09	30,080	--a------	c:\windows\system32\drivers\RKHit.sys
2008-10-15 11:47 . 2008-10-15 11:47	42	--a------	c:\windows\system32\AK083E209605E394C.lie
2008-10-15 11:00 . 2008-10-15 11:00	<DIR>	d--------	c:\program files\Windows Installer Clean Up
2008-10-14 13:50 . 2008-09-15 04:12	1,846,400	---------	c:\windows\system32\dllcache\win32k.sys
2008-10-14 13:50 . 2008-09-08 02:41	333,824	---------	c:\windows\system32\dllcache\srv.sys
2008-10-14 13:49 . 2008-08-14 02:11	2,189,184	---------	c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-14 13:49 . 2008-08-14 02:09	2,145,280	---------	c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-14 13:49 . 2008-08-14 01:33	2,066,048	---------	c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-14 13:49 . 2008-08-14 01:33	2,023,936	---------	c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-12 08:01 . 2008-10-12 08:01	7,820,864	--a------	c:\program files\picasa3-setup.exe
2008-10-10 08:33 . 2006-05-15 15:24	86,880	--a------	c:\windows\system32\drivers\WscNetDr.sys
2008-10-10 08:25 . 2008-10-10 08:25	<DIR>	d--------	c:\documents and settings\JAMES ROHAN\Application Data\Viewpoint
2008-10-10 08:20 . 2008-10-10 08:20	<DIR>	d--------	c:\documents and settings\JAMES ROHAN\Application Data\HP
2008-10-10 07:56 . 2008-10-10 07:56	<DIR>	d--------	c:\program files\Common Files\AnswerWorks 4.0
2008-10-10 07:56 . 2008-10-10 07:56	<DIR>	d--------	c:\documents and settings\CHRIS ROHAN\Application Data\McAfee
2008-10-09 15:55 . 2008-10-09 15:55	<DIR>	d--------	c:\program files\HP
2008-10-09 15:55 . 2008-10-09 15:55	<DIR>	d--------	c:\documents and settings\CHRIS ROHAN\Application Data\HP
2008-10-09 15:55 . 2003-05-27 09:11	151,552	--a------	c:\windows\system32\LLHttpsUpload2.dll
2008-10-09 15:55 . 2003-05-15 15:03	77,824	--a------	c:\windows\system32\LLClientMiddleWare.dll
2008-10-09 15:55 . 2003-05-27 09:10	36,864	--a------	c:\windows\system32\LLMetricsWrapper.exe
2008-10-09 15:55 . 2003-05-15 15:03	36,864	--a------	c:\windows\system32\LLInstances.dll
2008-10-09 15:55 . 2003-05-15 15:03	32,768	--a------	c:\windows\system32\XLLDFRequest.dll
2008-10-09 15:55 . 2003-05-15 15:03	32,768	--a------	c:\windows\system32\LLClasses.dll
2008-10-09 15:55 . 2003-05-27 09:11	28,672	--a------	c:\windows\system32\WebTalk.dll
2008-10-08 08:07 . 2008-10-11 08:15	<DIR>	d--------	c:\documents and settings\CHRIS ROHAN\Application Data\GetRightToGo
2008-10-08 08:07 . 2008-10-08 08:07	375,648	--a------	c:\program files\X12-30196-DLM.exe
2008-10-08 07:20 . 2006-10-26 18:56	32,592	--a------	c:\windows\system32\msonpmon.dll
2008-10-05 18:32 . 2008-10-05 21:26	<DIR>	d--------	c:\program files\Flypaper
2008-10-04 21:13 . 2008-10-04 21:13	<DIR>	d--------	c:\documents and settings\CHRIS ROHAN\Application Data\AdobeAUM
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 09:16	---------	d---a-w	c:\documents and settings\All Users\Application Data\TEMP
2008-11-04 09:07	7,304	----a-w	c:\windows\TMP0001.TMP
2008-11-04 07:32	---------	d-----w	c:\windows\system32\config\systemprofile\Application Data\SolidDocuments
2008-11-03 00:02	---------	d--h--w	c:\program files\InstallShield Installation Information
2008-10-29 14:39	---------	d-----w	c:\program files\Yahoo!
2008-10-27 16:25	---------	d-----w	c:\program files\Pure Networks
2008-10-27 16:23	---------	d-----w	c:\documents and settings\CHRIS ROHAN\Application Data\InstallShield
2008-10-27 02:33	1,006,592	----a-w	c:\windows\Internet Logs\xDB1.tmp
2008-10-27 01:09	---------	d-----w	c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-26 03:36	---------	d-----w	c:\program files\Common Files\McAfee
2008-10-26 03:36	---------	d-----w	c:\documents and settings\All Users\Application Data\McAfee
2008-10-26 03:34	---------	d-----w	c:\program files\McAfee
2008-10-24 07:33	---------	d-----w	c:\documents and settings\CHRIS ROHAN\Application Data\SolidDocuments
2008-10-22 07:13	---------	d-----w	c:\documents and settings\CHRIS ROHAN\Application Data\Apple Computer
2008-10-22 00:00	---------	d-----w	c:\documents and settings\CHRIS ROHAN\Application Data\YouSendIt
2008-10-19 07:02	---------	d-----w	c:\documents and settings\All Users\Application Data\Pure Networks
2008-10-17 20:34	25,120	----a-w	c:\program files\ncl7557.JPG
2008-10-17 05:59	---------	d-----w	c:\program files\Microsoft Works
2008-10-17 02:42	---------	d-----w	c:\program files\Intuit
2008-10-16 21:26	32,507	----a-w	c:\program files\lkf6qee.JPG
2008-10-16 17:54	2,891,264	----a-w	c:\program files\FabulousPhotography.pps
2008-10-16 06:52	---------	d-----w	c:\documents and settings\LocalService\Application Data\SACore
2008-10-16 04:16	---------	d-----w	c:\program files\Java
2008-10-15 21:02	---------	d-----w	c:\program files\Conversions Plus
2008-10-15 19:00	---------	d-----w	c:\program files\MSECache
2008-10-14 06:30	1,226,248	-c--a-w	c:\program files\DMSetup.exe
2008-10-12 19:39	---------	d-----w	c:\program files\Web Wipe
2008-10-12 16:25	---------	d-----w	c:\program files\Common Files\Adobe
2008-10-12 16:01	---------	d-----w	c:\program files\Google
2008-10-11 05:28	2,900,992	----a-w	c:\program files\cooliris-win-iefull-release-1.8.3.14080.msi
2008-10-10 15:56	---------	d-----w	c:\program files\Logitech
2008-10-10 15:52	---------	d-----w	c:\program files\Hewlett-Packard
2008-10-10 05:15	---------	d-----w	c:\program files\Common Files\Intuit
2008-10-06 05:28	---------	d-----w	c:\program files\Common Files\Logishrd
2008-10-03 20:33	0	---ha-w	c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-03 20:33	0	---ha-w	c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-10-03 20:33	0	---ha-w	c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-10-03 20:31	---------	d-----w	c:\documents and settings\All Users\Application Data\Logitech
2008-10-03 20:31	---------	d-----w	c:\documents and settings\All Users\Application Data\LogiShrd
2008-10-03 17:41	6,066,176	------w	c:\windows\system32\dllcache\ieframe.dll
2008-09-29 18:14	---------	d-----w	c:\program files\OpenOffice.org 2.4
2008-09-29 18:02	16,384	----a-w	c:\program files\Nov08Pediatrictoys.WPS
2008-09-29 16:38	---------	d-----w	c:\program files\Common Files\AnswerWorks 5.0
2008-09-26 02:15	773,120	----a-w	c:\program files\Nov08Pediatrictoys.DOC
2008-09-26 02:15	773,120	----a-w	c:\program files\Nov08Pediatrictoys (2).DOC
2008-09-24 05:49	---------	d-----w	c:\documents and settings\CHRIS ROHAN\Application Data\OpenOffice.org2
2008-09-19 18:30	---------	d-----w	c:\program files\Common Files\Adobe Systems Shared
2008-09-16 11:40	1,343,584	----a-w	c:\windows\system32\drivers\athw.sys
2008-09-15 12:12	1,846,400	----a-w	c:\windows\system32\win32k.sys
2008-09-13 07:28	---------	d-----w	c:\program files\Bonjour
2008-09-13 07:27	---------	d-----w	c:\program files\QuickTime
2008-09-13 07:27	---------	d-----w	c:\program files\Common Files\Apple
2008-09-11 01:13	---------	d-----w	c:\documents and settings\All Users\Application Data\Macrovision
2008-09-10 07:37	4,754	----a-w	c:\program files\girls.jpg.JPG
2008-09-10 07:37	4,754	----a-w	c:\program files\girls.jpg (2).JPG
2008-09-10 00:30	---------	d-----w	c:\program files\GemMaster
2008-09-08 10:41	333,824	----a-w	c:\windows\system32\drivers\srv.sys
2008-09-08 04:14	697,744	----a-w	c:\program files\signature995.exe
2008-09-08 03:17	---------	d-----w	c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-09-07 22:32	4,331	-c--a-w	c:\program files\logo.jpg.JPG
2008-09-07 02:32	0	-c--a-w	c:\program files\starburst_1.JPG
2008-08-29 17:18	87,336	----a-w	c:\windows\system32\dns-sd.exe
2008-08-29 16:53	61,440	----a-w	c:\windows\system32\dnssd.dll
2008-08-27 08:24	3,593,216	------w	c:\windows\system32\dllcache\mshtml.dll
2008-08-25 08:38	13,824	------w	c:\windows\system32\dllcache\ieudinit.exe
2008-08-25 08:37	70,656	------w	c:\windows\system32\dllcache\ie4uinit.exe
2008-08-23 05:56	635,848	------w	c:\windows\system32\dllcache\iexplore.exe
2008-08-23 05:54	161,792	----a-w	c:\windows\system32\dllcache\ieakui.dll
2008-08-14 10:09	2,145,280	----a-w	c:\windows\system32\ntoskrnl.exe
2008-08-14 10:04	138,496	------w	c:\windows\system32\dllcache\afd.sys
2008-08-14 09:33	2,023,936	----a-w	c:\windows\system32\ntkrnlpa.exe
2008-08-12 23:58	59,294,408	-c--a-w	c:\program files\Quicken_Home_Business_2008.exe
2008-08-11 18:33	65,024	-c--a-w	c:\program files\capitalone20073.XLS
2008-08-10 17:03	133,227,519	-c--a-w	c:\program files\OOo_2.4.1_Win32Intel_install_wJRE_en-US.exe
2008-07-18 19:19	321,742	-c--a-w	c:\program files\lisamatt.jpg.WMF
2008-05-24 23:16	194,146,304	-c--a-w	c:\program files\Nero-8.3.2.1_eng_update.exe
2008-05-21 00:13	16,384	-c--a-w	c:\program files\MedicareAnswers0608_FINAL.WPS
2008-04-28 01:49	35,634,176	-c--a-w	c:\program files\BookSmart_1.9.5.exe
2008-04-24 18:14	3,298,376	-c--a-w	c:\program files\YouSendItExpressSetup1_5_1.exe
2008-04-22 21:43	194,167,288	-c--a-w	c:\program files\Audible_Nero_English.exe
2008-03-30 04:23	16,208	-c--a-w	c:\program files\logo2.PCX
2007-12-29 17:13	6,412,509	-c--a-w	c:\program files\klcodec320s.exe
2007-12-29 17:12	9,679,815	-c--a-w	c:\program files\vlc-0.8.6c-win32.exe
2007-12-24 00:06	216,108,560	-c--a-w	c:\program files\SETUP2.EXE
2007-12-12 22:41	621,808	-c--a-w	c:\program files\AmazonMP3Installer.exe
2007-12-12 05:41	234,460	-c--a-w	c:\program files\HolidayLabels-2007.jpg
2007-12-11 16:30	13,621,320	-c--a-w	c:\program files\wwb818Setup.exe
2007-12-03 21:45	984,923	-c--a-w	c:\program files\_MG_100_2_[1].JPG
2007-12-03 21:45	984,923	-c--a-w	c:\program files\_MG_100_2_[1] (2).JPG
2007-11-19 18:05	166,400	-c--a-w	c:\program files\long termcare2.DOC
2007-11-19 18:01	192,512	-c--a-w	c:\program files\long termcare.DOC
2007-11-19 02:54	17,010,054	-c--a-w	c:\program files\giftgiode.BMP
2007-11-19 02:46	365,454	-c--a-w	c:\program files\holly.BMP
2007-11-19 02:42	1,432,326	-c--a-w	c:\program files\CHRISTMASHOLLY.BMP
2007-11-19 02:33	25,221,046	-c--a-w	c:\program files\200711161.BMP
2007-11-19 02:31	41,470	-c--a-w	c:\program files\top_info.BMP
2007-11-19 02:28	2,877,174	-c--a-w	c:\program files\nissin1.BMP
2007-11-19 02:27	7,023,222	-c--a-w	c:\program files\nissin2 (2).BMP
2007-11-19 02:27	203,014	-c--a-w	c:\program files\a82c_1 (2).BMP
2007-11-19 02:26	2,127,654	-c--a-w	c:\program files\blankfile (2).BMP
2007-07-27 04:32	88	-csh--r	c:\windows\system32\[u]0[/u]CB36C55BB.sys
2007-03-04 20:46	88	-csh--r	c:\windows\system32\113A3FF0C5.sys
2007-08-04 22:37	8,398	-csha-w	c:\windows\system32\KGyGaAvL.sys
2008-07-30 17:14	32,768	-csha-w	c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008073020080731\index.dat
.
 
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-30 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-28 395776]
"AOL Fast Start"="c:\program files\America Online 9.0a\AOL.EXE" [2005-07-12 50776]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-08 7630848]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"HostManager"="c:\program files\Common Files\AOL\1168472373\ee\AOLSoftware.exe" [2007-10-08 41824]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2003-10-13 1732608]
"HP Metrics"="c:\program files\HP\Personal Printing Solutions Product Research\HP Product Research.exe" [2003-06-24 360448]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-09-14 648488]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-09-14 705832]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-10-09 981904]
"CTHelper"="CTHELPER.EXE" [2005-11-08 c:\windows\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 c:\windows\system32\CTXFIHLP.EXE]
"kmw_run.exe"="kmw_run.exe" [2002-12-23 c:\windows\system32\kmw_run.exe]
 
c:\documents and settings\CHRIS ROHAN\Start Menu\Programs\Startup\
AOL Desktop.lnk - c:\program files\Common Files\AOL\Launch\aollaunch.exe [2007-10-08 41824]
progname.lnk - c:\program files\Web Wipe\wwipe.exe [2008-08-17 1036800]
 
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-01-17 110592]
Event Reminder.lnk - c:\program files\PrintMaster Platinum 17\Remind.exe [2006-02-22 344064]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-04-11 394856]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ePad995.lnk]
backup=c:\windows\pss\ePad995.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
backup=c:\windows\pss\Event Reminder.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MySoftware InterCom.lnk]
backup=c:\windows\pss\MySoftware InterCom.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MySoftware NewsFlash.lnk]
backup=c:\windows\pss\MySoftware NewsFlash.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MySoftware WebBackup.lnk]
backup=c:\windows\pss\MySoftware WebBackup.lnkCommon Startup
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McENUI
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MWLExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NoteBurner
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Opware14
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PicasaNet
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorkFlowTray
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
--------- 2006-10-23 04:50 71216 c:\program files\Common Files\AOL\ACS\AOLDial.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
-----c--- 2003-06-17 23:00 45056 c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2006-08-28 19:57 395776 c:\program files\Dell Support\DSAgnt.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a--c--- 2005-09-29 12:01 67584 c:\windows\ehome\ehtray.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a--c--- 2007-05-22 22:54 240640 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2007-10-08 13:50 41824 c:\program files\Common Files\AOL\1168472373\ee\aolsoftware.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a--c--- 2006-07-06 05:15 151552 c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2006-03-20 17:34 86960 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 16:12 1695232 c:\program files\Messenger\msmsgs.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpAgent]
--a--c--- 2005-08-11 13:56 155648 c:\program files\ScanSoft\OmniPage15.0\OpAgent.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Opware15]
--a--c--- 2005-08-11 13:52 69632 c:\program files\ScanSoft\OmniPage15.0\OpWare15.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF3 Registry Controller]
--a--c--- 2005-07-12 10:05 106496 c:\program files\ScanSoft\OmniPage15.0\PDFConverter3\registrycontroller.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a--c--- 2006-12-08 10:04 26112 c:\program files\Real\RealPlayer\realplay.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ReminderApp]
--a--c--- 2006-09-19 13:41 155648 c:\program files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
-----c--- 2003-10-14 09:22 155648 c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
-----c--- 2005-10-14 09:01 122880 c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
--a------ 2005-07-15 13:48 479232 c:\program files\Google\Gmail Notifier\gnotify.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kensington\\MouseWorks\\k_update.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\AOL\\1168472373\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\Documents and Settings\\CHRIS ROHAN\\Desktop\\My Pictures\\ryan\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\Common Files\\AOL\\1168472373\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Broderbund\\PrintMaster Greeting Cards\\ArtDiscInstall\\Setup.exe"=
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"67:UDP"= 67:UDP:DHCP Discovery Service
 
R3 ha20x2k;Creative 20X HAL Driver;c:\windows\system32\drivers\ha20x2k.sys [2006-02-15 1096192]
R3 KMW_KBD;Kensington Input Devices Class filter driver;c:\windows\system32\DRIVERS\KMW_KBD.sys [2002-12-09 5120]
R3 KMW_SYS;Kensington MouseWorks Mouse filter driver;c:\windows\system32\DRIVERS\KMW_SYS.sys [2002-12-09 89856]
R3 KMW_USB;Kensington MouseWorks USB filter driver;c:\windows\system32\DRIVERS\KMW_USB.sys [2002-12-09 9856]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys [ ]
S3 NAL;Nal Service ;c:\windows\system32\Drivers\iqvw32.sys [2006-06-05 24064]
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
 
2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
 
2008-11-04 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2007-09-26 08:53]
 
2008-11-04 c:\windows\Tasks\User_Feed_Synchronization-{BF724AA1-A33F-4667-8A4F-934CA84B876A}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
- - - - ORPHANS REMOVED - - - -
 
HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
 
 
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\CHRIS ROHAN\Application Data\Mozilla\Firefox\Profiles\e6n7lpm4.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.aol.com
.
 
**************************************************************************
 
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-04 01:09:59
Windows 5.1.2600 Service Pack 3 NTFS
 
scanning hidden processes ... 
 
scanning hidden autostart entries ...
 
scanning hidden files ... 
 
scan completed successfully
hidden files: 0
 
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
PROCESS: c:\windows\explorer.exe
-> c:\program files\Web Wipe\hook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\ZoneLabs\avsys\ScanningProcess.exe
c:\windows\system32\ZoneLabs\avsys\ScanningProcess.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\PSIService.exe
c:\program files\IMSI\IMSI PDF to Word\SCPDF\SolidPdfService.exe
c:\windows\wanmpsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\CTXFISPI.EXE
c:\windows\system32\kmw_show.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\America Online 9.0a\waol.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\AOL\1168472373\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\progra~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
c:\program files\Common Files\AOL\1168472373\ee\AOLDesktop.exe
c:\program files\America Online 9.0a\shellmon.exe
c:\program files\Common Files\AOL\1168472373\ee\anotify.exe
.
**************************************************************************
.
Completion time: 2008-11-04  1:49:13 - machine was rebooted [CHRIS ROHAN]
ComboFix-quarantined-files.txt  2008-11-04 09:48:52
 
Pre-Run: 30,072,614,912 bytes free
Post-Run: 34,511,273,984 bytes free
 
424	--- E O F ---	2008-10-24 10:01:01

Open in new window

0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now