flashing dos screen

Post your HijackThis! Log here for spyware removal

Moderators: Admin Team, Moderators

Forum rules
ATTN:!! Only users pre-approved by TeMerc may offer help and assistance in malware removal. Any and all unauthorized posts will be removed without notice. Please read this thread for proper HijackThis! installation.
Posts: 2
Joined: Sat Oct 16, 2010 4:52 am

flashing dos screen

Postby mcarlin » Mon Oct 18, 2010 4:23 am

I keep getting a flashing dos screen every 5-10 seconds with the computer running much slower. Also outlook express keeps receiving errors when trying to receive mail although I can send out mail. I have run malwarebytes and it does not detect anything. I also cannot install adaware as it keeps giving me an error saying it can't install microsoft visual c++. Superantispyware found some unwanted stuff and deleted them but it still did not fix the problem. I also have a new version of Mcafee total protection which when I run a completer scan says it found 1 potential unwanted program but then gets an error before the scan completes.
Here is a Hijack this log
thanks for your help
Logfile of HijackThis v1.99.1
Scan saved at 7:18:33 AM, on 10/18/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Running processes:
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
C:\Program Files\eFilm Medical\eFilm\efPMNT.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\eFilm Medical\eFilm\efDBM.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\eFilm Medical\eFilm\efUpM.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Synology Data Replicator 3\SynoDrService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eFilm Medical\eFilm\efDM.exe
C:\Program Files\eFilm Medical\eFilm\efDicomM.exe
C:\Program Files\eFilm Medical\eFilm\efServer.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Documents and Settings\MINGUS\Desktop\h.exe\h.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20101017182650.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Norton Ghost 15.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International
O15 - Trusted IP range:
O16 - DPF: MIW Deployment - https://mynewhvrapatients.com/downloads/MIWDeploy.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 6086802625
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 6086789875
O16 - DPF: {786E2AA4-522B-4AE3-910C-1E8EB4D32239} (SmartUpdate Control) - https://rocklandimaging.net/SmartUpdate.Cab
O16 - DPF: {8B7D2210-CC81-4F59-A486-4409FB485D4A} (RegConfig Class) - http://www2.verizon.net/help/fios_setti ... Config.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9F02104-BC94-4684-AED3-F168F5DFD801}: NameServer =,
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DM1Service - OLYMPUS Corporation - C:\Program Files\Olympus\DeviceDetector\DM1Service.exe
O23 - Service: eFilmProcessManagerNT - Unknown owner - C:\Program Files\eFilm Medical\eFilm\efPMNT.exe
O23 - Service: GCXFJLM - Unknown owner - C:\DOCUME~1\MINGUS\LOCALS~1\Temp\GCXFJLM.exe (file missing)
O23 - Service: GenericMount Helper Service - Unknown owner - C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe (file missing)
O23 - Service: GoToAssist - Unknown owner - C:\Program Files\Citrix\GoToAssist\570\g2aservice.exe" Start=service (file missing)
O23 - Service: Google Update Service (gupdate1ca06d41e480ca) (gupdate1ca06d41e480ca) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - Unknown owner - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc (file missing)
O23 - Service: NAR - Sysinternals - www.sysinternals.com - C:\DOCUME~1\michael\LOCALS~1\Temp\NAR.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SynoDrService - Unknown owner - C:\Program Files\Synology Data Replicator 3\SynoDrService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

User avatar
Site Admin
Site Admin
Posts: 15995
Joined: Fri Jan 28, 2005 5:16 pm
Area Of Expertise: Security
experience: I know the functions, OS settings, registry tweaks and more
PC time: What else is there in life?
Location: PHX, AZ

Re: flashing dos screen

Postby TeMerc » Tue Oct 19, 2010 12:30 am

Hello and w^* to TeMerc Internet Countermeasures Forum and thanks for joining. 1rokon

If you've run a scan with Malwarebytes' Anti-Malware, please paste the results from the latest scan log which is located in the 'logs' tab of the Malwarebytes' Anti-Malware interface.

Open Malwarebytes' Anti-Malware>>Click the 'Logs' tab
Select log from date, they're named mbam-log-2010-xx-xx [10-11-12].txt

Nothing in the Hijackthis log, what were the other scan results from SAS and McAfee? Don't include any cookies, those cannot hurt your system.

Posts: 2
Joined: Sat Oct 16, 2010 4:52 am

Re: flashing dos screen

Postby mcarlin » Tue Oct 19, 2010 5:02 pm

thanks for your reply
Here is the last malware bytes log which does'nt find anything
Malwarebytes' Anti-Malware 1.46

Database version: 4832

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

10/15/2010 9:38:35 AM
mbam-log-2010-10-15 (09-38-35).txt

Scan type: Full scan (C:\|)
Objects scanned: 286841
Time elapsed: 1 hour(s), 15 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Here is the SAS log

Generated 10/16/2010 at 11:58 AM

Application Version : 4.44.1000

Core Rules Database Version : 5695
Trace Rules Database Version: 3507

Scan type : Complete Scan
Total Scan Time : 02:24:24

Memory items scanned : 506
Memory threats detected : 0
Registry items scanned : 9232
Registry threats detected : 0
File items scanned : 28951
File threats detected : 37

Adware.Tracking Cookie
C:\Documents and Settings\MINGUS\Cookies\mingus@doubleclick[4].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@advertising[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@insightexpressai[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@insightexpressai[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@fastclick[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ads.neudesicmediagroup[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@chitika[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@adbrite[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@2o7[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@content.yieldmanager[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ad.yieldmanager[4].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ad.yieldmanager[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ad.yieldmanager[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@imrworldwide[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@doubleclick[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@doubleclick[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@content.yieldmanager[3].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@atdmt[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@revsci[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@citi.bridgetrack[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@content.yieldmanager[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@invitemedia[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@collective-media[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@atdmt[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@atdmt[4].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ad.wsod[4].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ad.wsod[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@ad.wsod[3].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@interclick[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@msnservices.112.2o7[1].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@apmebf[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@mediaplex[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@msnportal.112.2o7[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@questionmarket[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@microsoftsto.112.2o7[2].txt
C:\Documents and Settings\MINGUS\Cookies\mingus@microsoftsto.112.2o7[1].txt

I dont see where to acess the mcafee log
thanks for your help

User avatar
Site Admin
Site Admin
Posts: 15995
Joined: Fri Jan 28, 2005 5:16 pm
Area Of Expertise: Security
experience: I know the functions, OS settings, registry tweaks and more
PC time: What else is there in life?
Location: PHX, AZ

Re: flashing dos screen

Postby TeMerc » Thu Nov 11, 2010 12:34 am

Apologies for long over due reply, are you still needing help on this?

Return to “Countermeasures: HijackThis! Spyware Help”

Who is online

Users browsing this forum: No registered users and 1 guest