phpzipcodelocator.com

Home > General > Mssmag32.dll

Mssmag32.dll

hamiru Apr 11 2009, 12:38 AM Show posts by this member only | Post #6 On my way Group: Senior Member Posts: 507 Joined: Dec 2006 From: Sepang

scanning hidden autostart entries ... This will start ComboFix again.5. There used to be Autorun.inf folder in each partition created by FlashDisinfector by sUBs.

Style Default Style Contact Us Help Home Top RSS Terms and Rules Copyright © TechGuy, Inc. It will be your best interest..When finished, it shall produce a log for you. no one can read through my HJT log? Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-01-19 4670968]"RocketDock"="d:\program files\RocketDock\RocketDock.exe" [2007-01-28 462848]"IDMan"="e:\safariq\Essential PC Stuff\Program Installer Folder\Internet Download Manager 5.14\crack\IDMan.exe" [2008-10-13 932272][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]"RemoteControl"="d:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]"LanguageShortcut"="d:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2006-06-14 278528]"Eja"="c:\documents and check my blog

I just checked my Task Manager and there no longer unknown .exe in the list and in the tray. This means that the cache was not able to resolve the hostname presented in the URL. If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

  1. Then, I open up Task Manager and to my surprise, the unknown .exe task memoray usage shoots up to 300,000 K.
  2. I've attached both ComboFix and HijackThis log.
  3. Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quietO4 - HKCU\..\Run: [RocketDock] "D:\Program Files\RocketDock\RocketDock.exe"O4 - HKCU\..\Run: [IDMan] E:\safariq\Essential PC Stuff\Program Installer Folder\Internet Download Manager 5.14\crack\IDMan.exe /onbootO4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exeO4

But, Document1 still exists both in my D: and E: drive. Save the above as CFScript.txt4. koppole, Mar 4, 2008 Replies: 3 Views: 2,999 Elvandil Mar 4, 2008 Locked msutb.dll twil354, Apr 26, 2009 Replies: 0 Views: 1,930 twil354 Apr 26, 2009 Locked msupdte.exe mg84, Aug 1, both Document1.exe in D: and E: no longer exists.

Windows XP Getting errors or having problems in Windows XP? Please try the request again. Please try the request again. https://forum.lowyat.net/topic/992295/all Even his Sony Ericsson also has that Document1 in his directory after he tried to transfer his song file from PC to his phone.

Please help yummyturtlemilk, Sep 29, 2007 Replies: 1 Views: 543 blues_harp28 Sep 29, 2007 Locked MSVCIRT.DLL Error Message newbie2, Dec 4, 2008 Replies: 2 Views: 779 newbie2 Dec 5, 2008 Locked After the scan done, there is none shown though SuperAntiSpyware - No threats found tooHijackThisHijackThis Log» Click to show Spoiler - click again to hide... «Logfile of Trend Micro HijackThis v2.0.2Scan thanks fenzodahl512 ComboFix Log:» Click to show Spoiler - click again to hide... «ComboFix 09-04-04.01 - User 2009-04-11 21:33:29.2 - NTFSx86Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.529 [GMT 8:00]Running from: c:\documents and settings\User\Desktop\ComboFix.exeCommand Malwarebytes Anti-Malware log:» Click to show Spoiler - click again to hide... «Malwarebytes' Anti-Malware 1.36Database version: 1961Windows 5.1.2600 Service Pack 24/10/2009 10:05:23 PMmbam-log-2009-04-10 (22-05-05).txtScan type: Full Scan (C:\|D:\|E:\|)Objects scanned: 199280Time elapsed:

Newer Than: Search this forum only Display results as threads Useful Searches Recent Posts More... Attached thumbnail(s) Cybuster Apr 9 2009, 04:19 PM Show posts by this member only | Post #2 Yõu Are Nöt Lònely... Share on | Track this topic | Print this topic farique Apr 9 2009, 08:37 AM, updated 8 years ago Show posts by this member only | Post #1 Look at is it good?

Group: Senior Member Posts: 581 Joined: Aug 2007 From: ◕【ⓜⓨⓢⓣⓔⓡⓨ】◕ try use malwarebytes to clear it. Let ComboFix finishes its job.. Looks like the Document1 is not affected by the fix. What I have done prior to HijackThis scanning were:AVG 8.0 scan - Found one Possibly Danger Item: Tracking Cookie, tried to remove unhealed items but AVG crashed.CCleaner - get all the

scan completed successfullyhidden files: 0**************************************************************************[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ebjbh]"ServiceDll"="c:\windows\system32\jyhrse.dll".--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_USERS\S-1-5-21-1060284298-1757981266-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]@Denied: (Full) (LocalSystem)"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"="c:\\WINDOWS\\System32\\shell32.dll,15""{992CFFA0-F557-101A-88EC-00DD010CCC48}"="c:\\WINDOWS\\system32\\SHELL32.dll,17""{208D2C60-3AEA-1069-A2D7-08002B30309D}"="c:\\WINDOWS\\system32\\SHELL32.dll,17""{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="c:\\WINDOWS\\system32\\shell32.dll,22""{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="c:\\WINDOWS\\system32\\shell32.dll,23""{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="c:\\WINDOWS\\system32\\shell32.dll,24""{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="c:\\WINDOWS\\system32\\shell32.dll,-175""{21EC2020-3AEA-1069-A2DD-08002B30309D}"="c:\\WINDOWS\\System32\\shell32.dll,-137""{2227A280-3AEA-1069-A2DE-08002B30309D}"="c:\\WINDOWS\\System32\\shell32.dll,-138""{D20EA4E1-3957-11d2-A40B-0C5020524152}"="c:\\WINDOWS\\system32\\shell32.dll,38""AudioCD"="c:\\WINDOWS\\System32\\shell32.dll,40""{FBF23B42-E3F0-101B-8488-00AA003E56F8}"="c:\\WINDOWS\\system32\\shell32.dll,220""{450D8FBA-AD25-11D0-98A8-0800361B1103}"="c:\\WINDOWS\\system32\\mydocs.dll,0""{D20EA4E1-3957-11d2-A40B-0C5020524153}"="c:\\WINDOWS\\system32\\main.cpl,10""{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="c:\\WINDOWS\\system32\\wiashext.dll,0""{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="c:\\WINDOWS\\system32\\mstask.dll,-100""{88C6C381-2E85-11D0-94DE-444553540000}"="c:\\WINDOWS\\System32\\occache.dll,0""{BDEADF00-C265-11d0-BCED-00A0C90AB50F}"="c:\\Program Files\\COMMON~1\\MICROS~1\\WEBFOL~1\\MSONSEXT.DLL,0""{FF393560-C2A7-11CF-BFF4-444553540000}"="c:\\WINDOWS\\System32\\shdocvw.dll,-20785""{F5175861-2688-11d0-9C5E-00AA00A45957}"="c:\\WINDOWS\\System32\\webcheck.dll,0""{85BBD920-42A0-1069-A2E4-08002B30309D}"="c:\\WINDOWS\\system32\\syncui.dll,0"[HKEY_USERS\S-1-5-21-1060284298-1757981266-839522115-1003\Software\SecuROM\!CAUTION! Thank you. The system returned: (22) Invalid argument The remote host or network may be down. Group: Senior Member Posts: 2,143 Joined: Mar 2005

Downloaded Malwarebytes Anti-Malware and ran a full scan.

Generated Mon, 13 Feb 2017 17:41:33 GMT by s_wx1221 (squid/3.5.23) 會員登入 置放Google廣告注意原則 管理部落 | 申請部落 | 新浪網 | 微博 | 檢舉 巴哈姆特 流星花園韓版,風色幻想,海綿寶寶,益智小遊戲,酒井法子,高雄民宿,高雄旅館,高鐵時刻表,華納威秀,超偶服務 我的最愛

PLURK Plurk.com 作者檔案 暱稱:xyz軟件補給站 All rights reserved. The system returned: (22) Invalid argument The remote host or network may be down.

Generated Mon, 13 Feb 2017 17:41:32 GMT by s_wx1221 (squid/3.5.23) ERROR The requested URL could not be retrieved The following error was encountered while trying to retrieve the URL: http://0.0.0.10/ Connection

Johnny-be-Good replied Feb 13, 2017 at 8:32 PM Can't use all ram slots. I only notice it because there's a gap between other tray icons. But, since this morning (I'm guessing my brother did something by transfering song file from the computer to his phone) the Autorun.inf folder is no longer existed in both D & Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quietO4 - HKCU\..\Run: [RocketDock] "D:\Program Files\RocketDock\RocketDock.exe"O4 - HKCU\..\Run: [IDMan] E:\safariq\Essential PC Stuff\Program Installer Folder\Internet Download Manager 5.14\crack\IDMan.exe /onbootO4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exeO4

NEVER A OR CHANGE ANY KEY*]"??"=hex:85,31,c7,fa,66,73,d8,64,05,0b,fd,9c,30,9e,85,80,b2,27,9d,43,5e,78,13, 74,d8,e1,24,c6,6b,4b,1a,97,fd,6b,87,16,12,68,33,89,d4,39,c3,ee,25,5c,00,3c,\"??"=hex:cc,01,16,ee,8e,e9,16,05,47,ff,4d,32,88,22,6f,6a[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]@Denied: (Full) (Everyone)"scansk"=hex(0):be,3e,1d,12,d7,dd,72,7c,e5,a2,a9,dc,cb,9f,21,32,62,7a,7f,a6,07, 14,b4,af,51,93,25,f0,a2,2f,d4,83,02,bc,b4,d2,11,44,64,96,00,00,00,00,00,00,\[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ee4709e1-f351-4b2a-bceb-64430c50c301}]@Denied: (Full) (Everyone)"Model"=dword:00000001"Therad"=dword:0000000f"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,48,17,6e,d3,b5, 09,92,11,05,98,32,02,34,2b,da,61,f7,4a,50,ec,7c,ae,6d,69,7b,06,ad,c6,0d,23,\.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'winlogon.exe'(584)d:\program files\SUPERAntiSpyware\SASWINLO.DLL.Completion time: 2009-04-11 12:08:08ComboFix-quarantined-files.txt Please open NotepadIf you don't know how, just go to Start >> Run >> copy/paste notepad.exe >> Enter2. But I've End Process the task. Your cache administrator is webmaster.

Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. Attached File(s) ComboFix.txt ( 20.92k ) Number of downloads: 4 Hijackthislog.txt ( 10.14k ) Number of downloads: 0 fenzodahl512 Apr 11 2009, 12:39 PM Show posts by this member only |