Page 4 of 4 FirstFirst 1234
Results 31 to 40 of 40

Thread: my IE explorer has been hijacked. accidently deleted spybot and cant get it back.

  1. #31
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please go to Kaspersky website and perform an online antivirus scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  2. #32
    Junior Member
    Join Date
    Jul 2009
    Posts
    23

    Default

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0 REPORT
    Saturday, August 1, 2009
    Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Friday, July 31, 2009 13:02:08
    Records in database: 2566297
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\

    Scan statistics:
    Files scanned: 78712
    Threat name: 4
    Infected objects: 7
    Suspicious objects: 0
    Duration of the scan: 02:00:04


    File name / Threat name / Threats count
    C:\Documents and Settings\Nick\Local Settings\Temporary Internet Files\Content.IE5\WTU60HSI\hot[1].htm Infected: Trojan-Downloader.JS.Small.od 1
    C:\Documents and Settings\Nick\My Documents\Downloads\Prototype - Razor1911 No-DVD crack.rar Infected: Trojan-Dropper.Win32.VB.zss 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ESQULatnlprjfdwjgnmrqldnupxcdaehrgcnl.dll.vir Infected: Packed.Win32.Tdss.w 1
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ESQULnqovanvkporufyauwdtniatrlubkbjed.dll.vir Infected: Packed.Win32.Tdss.w 1
    C:\System Volume Information\_restore{E3DB1BAF-DD54-479C-A63C-AADFF869B755}\RP490\A0178882.exe Infected: Backdoor.Win32.Rbot.aezs 1
    C:\System Volume Information\_restore{E3DB1BAF-DD54-479C-A63C-AADFF869B755}\RP512\A0184174.dll Infected: Packed.Win32.Tdss.w 1
    C:\System Volume Information\_restore{E3DB1BAF-DD54-479C-A63C-AADFF869B755}\RP512\A0184176.dll Infected: Packed.Win32.Tdss.w 1

    The selected area was scanned.

  3. #33
    Junior Member
    Join Date
    Jul 2009
    Posts
    23

    Default

    DDS (Ver_09-06-26.01) - NTFSx86
    Run by Nick at 17:31:03.98 on Sat 08/01/2009
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1243 [GMT -5:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ULI5289\ALi5289.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Electronic Arts\EADM\Core.exe
    svchost.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Belkin Corporation\Belkin Wireless Network Monitor Utility and Driver (USB)\BelkinWlanMonitor.exe
    C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\MagicDisc\MagicDisc.exe
    svchost.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Java\jre6\bin\java.exe
    C:\Documents and Settings\Nick\Desktop\FIXERS\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://google.com/
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = localhost
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
    TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Start WingMan Profiler] "c:\program files\logitech\profiler\lwemon.exe" /noui
    uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
    uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe"
    uRun: [igndlm.exe] c:\program files\download manager\DLM.exe /windowsstart /startifwork
    uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [ALi5289] c:\program files\uli5289\ALi5289.exe
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
    StartupFolder: c:\docume~1\nick\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~2.lnk - c:\program files\belkin corporation\belkin wireless network monitor utility and driver (usb)\BelkinWlanMonitor.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\usb f5d7050\wireless utility\Belkinwcui.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab
    DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
    DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
    DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1208918179561
    DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.systemrequirementslab.com/sysreqlab2.cab
    DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://convergysworkathome.com/AppHardT.CAB
    DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} - hxxp://www.srtest.com/srl_bin/sysreqlab_test.cab
    DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [2008-4-22 51840]
    R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [2008-4-22 45056]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-4-25 24652]
    R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-1-2 84992]
    R3 st3bus28;st3bus28;c:\windows\system32\drivers\st3bus28.sys [2002-12-28 8416]
    R3 st3mp28;st3mp28;c:\windows\system32\drivers\st3mp28.sys [2002-12-28 95328]
    R3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [2008-4-22 28672]
    S2 gupdate1c98890794b6b46;Google Update Service (gupdate1c98890794b6b46);c:\program files\google\update\GoogleUpdate.exe [2009-2-6 133104]
    S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; [x]
    S3 SonyPVP1;Sony PTP USB Lower Filter driver;c:\windows\system32\drivers\SonyPVP1.sys [2009-6-19 6920]

    =============== Created Last 30 ================

    2009-07-30 15:59 <DIR> -cd----- c:\windows\system32\dllcache\cache
    2009-07-30 15:40 <DIR> acdshr-- C:\cmdcons
    2009-07-30 15:39 219,648 a------- c:\windows\PEV.exe
    2009-07-30 15:39 161,792 a------- c:\windows\SWREG.exe
    2009-07-30 15:39 98,816 a------- c:\windows\sed.exe
    2009-07-29 14:50 <DIR> --d----- c:\program files\Spybot - Search & Destroy
    2009-07-29 13:10 <DIR> --d----- c:\docume~1\nick\applic~1\Malwarebytes
    2009-07-29 01:52 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-29 01:52 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-29 01:52 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-07-29 01:52 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-07-27 04:23 <DIR> --d----- c:\program files\D-Tools
    2009-07-26 03:51 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\STOPzilla!
    2009-07-24 01:36 <DIR> -cd----- C:\EPSON
    2009-07-24 00:42 800 a------- c:\windows\hpinfo.lnk
    2009-07-24 00:41 376 a------- c:\windows\mozregistry.dat
    2009-07-24 00:41 <DIR> --d----- c:\program files\hp deskjet 825c series
    2009-07-23 00:58 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{5794CDCB-FAB7-4C15-9069-4D8AC02592DE}
    2009-07-22 21:18 <DIR> --d----- c:\windows\system32\Adobe
    2009-07-21 17:28 <DIR> --d----- c:\program files\AC3Filter
    2009-07-18 15:27 <DIR> --d----- c:\program files\AIM6
    2009-07-15 15:55 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
    2009-07-15 15:55 25,856 a------- c:\windows\system32\drivers\usbprint.sys
    2009-07-09 12:02 <DIR> --d----- c:\program files\Realtek AC97
    2009-07-09 10:42 4,096 a------- c:\windows\system32\crash
    2009-07-03 19:32 <DIR> --d----- c:\program files\Alex Feinman

    ==================== Find3M ====================

    2009-07-29 18:35 138,832 a------- c:\windows\system32\drivers\PnkBstrK.sys
    2009-07-29 18:35 202,024 a------- c:\windows\system32\PnkBstrB.exe
    2009-07-03 12:09 915,456 a------- c:\windows\system32\wininet.dll
    2009-07-02 17:29 119,296 a------- c:\windows\system32\zlib.dll
    2009-06-30 18:37 2,269,232 a------- c:\windows\prototypef.exe
    2009-06-21 11:10 721,904 a------- c:\windows\system32\drivers\sptd.sys
    2009-06-16 09:36 119,808 a------- c:\windows\system32\t2embed.dll
    2009-06-16 09:36 81,920 a------- c:\windows\system32\fontsub.dll
    2009-06-12 20:54 21,840 a------- c:\windows\system32\SIntfNT.dll
    2009-06-12 20:54 17,212 a------- c:\windows\system32\SIntf32.dll
    2009-06-12 20:54 12,067 a------- c:\windows\system32\SIntf16.dll
    2009-06-04 06:37 348,160 a------- c:\windows\system32\msvcr71.dll
    2009-06-04 06:37 499,712 a------- c:\windows\system32\msvcp71.dll
    2009-06-03 14:09 1,291,264 a------- c:\windows\system32\quartz.dll
    2009-05-21 10:33 410,984 a------- c:\windows\system32\deploytk.dll
    2009-05-15 22:39 442,368 a------- c:\windows\system32\ATIDEMGX.dll
    2009-05-15 22:38 335,872 a------- c:\windows\system32\ati2dvag.dll
    2009-05-15 22:18 204,800 a------- c:\windows\system32\atipdlxx.dll
    2009-05-15 22:17 155,648 a------- c:\windows\system32\Oemdspif.dll
    2009-05-15 22:17 26,112 a------- c:\windows\system32\Ati2mdxx.exe
    2009-05-15 22:17 43,520 a------- c:\windows\system32\ati2edxx.dll
    2009-05-15 22:17 155,648 a------- c:\windows\system32\ati2evxx.dll
    2009-05-15 22:15 602,112 a------- c:\windows\system32\ati2evxx.exe
    2009-05-15 22:14 53,248 a------- c:\windows\system32\ATIDDC.DLL
    2009-05-15 22:07 2,987,136 a------- c:\windows\system32\ati3duag.dll
    2009-05-15 21:55 11,423,744 a------- c:\windows\system32\atioglxx.dll
    2009-05-15 21:54 2,122,624 a------- c:\windows\system32\ativvaxx.dll
    2009-05-15 21:54 887,724 a------- c:\windows\system32\ativva6x.dat
    2009-05-15 21:51 311,296 a------- c:\windows\system32\atiiiexx.dll
    2009-05-15 21:38 49,664 a------- c:\windows\system32\atimpc32.dll
    2009-05-15 21:38 49,664 a------- c:\windows\system32\amdpcom32.dll
    2009-05-15 21:33 479,232 a------- c:\windows\system32\atikvmag.dll
    2009-05-15 21:31 139,264 a------- c:\windows\system32\atiadlxx.dll
    2009-05-15 21:31 17,408 a------- c:\windows\system32\atitvo32.dll
    2009-05-15 21:26 376,832 a------- c:\windows\system32\atiok3x2.dll
    2009-05-15 21:24 651,264 a------- c:\windows\system32\ati2cqag.dll
    2009-05-15 20:35 45,056 a------- c:\windows\system32\aticalrt.dll
    2009-05-15 20:34 45,056 a------- c:\windows\system32\aticalcl.dll
    2009-05-15 20:33 3,158,016 a------- c:\windows\system32\aticaldd.dll
    2009-05-15 20:05 593,920 -------- c:\windows\system32\ati2sgag.exe
    2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll
    2009-05-05 14:33 118,784 a------- c:\windows\system32\atibtmon.exe
    2009-03-26 17:54 22,328 a------- c:\docume~1\nick\applic~1\PnkBstrK.sys
    2008-06-12 02:27 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008061220080613\index.dat

    ============= FINISH: 17:31:17.00 ===============

  4. #34
    Junior Member
    Join Date
    Jul 2009
    Posts
    23

    Default

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-06-26.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/22/2008 9:12:16 PM
    System Uptime: 7/31/2009 8:16:35 PM (21 hours ago)

    Motherboard: | | 939Dual-SATA2
    Processor: AMD Athlon(tm) 64 Processor 3400+ | CPUSocket | 2200/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 75 GiB total, 5.695 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is CDROM ()
    G: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP417: 5/11/2009 5:19:25 PM - Avg8 Update
    RP418: 5/11/2009 11:29:22 PM - System Checkpoint
    RP419: 5/13/2009 12:55:45 PM - Avg8 Update
    RP420: 5/14/2009 2:00:17 AM - Software Distribution Service 3.0
    RP421: 5/15/2009 2:08:33 AM - System Checkpoint
    RP422: 5/17/2009 4:04:51 PM - System Checkpoint
    RP423: 5/18/2009 1:59:55 PM - Avg8 Update
    RP424: 5/18/2009 2:00:37 PM - Avg8 Update
    RP425: 5/19/2009 11:57:19 PM - System Checkpoint
    RP426: 5/21/2009 5:06:49 PM - Installed Realtek AC'97 Audio
    RP427: 5/22/2009 6:22:30 PM - System Checkpoint
    RP428: 5/23/2009 6:27:15 PM - System Checkpoint
    RP429: 5/25/2009 2:34:31 AM - System Checkpoint
    RP430: 5/25/2009 11:57:58 PM - Removed Ad-Aware
    RP431: 5/26/2009 12:04:12 AM - Removed AVG 8.5
    RP432: 5/26/2009 12:04:40 AM - Installed AVG 8.5
    RP433: 5/26/2009 12:04:59 AM - Removed ISO Recorder
    RP434: 5/27/2009 1:45:38 AM - System Checkpoint
    RP435: 5/28/2009 3:28:43 PM - Installed Java(TM) 6 Update 13
    RP436: 5/28/2009 3:31:58 PM - Installed Java(TM) 6 Update 13
    RP437: 5/28/2009 3:33:28 PM - Installed Java(TM) 6 Update 13
    RP438: 5/29/2009 11:22:45 PM - System Checkpoint
    RP439: 5/30/2009 11:34:53 PM - System Checkpoint
    RP440: 6/1/2009 12:53:41 AM - System Checkpoint
    RP441: 6/2/2009 1:38:26 AM - System Checkpoint
    RP442: 6/3/2009 2:30:23 AM - System Checkpoint
    RP443: 6/4/2009 3:31:08 AM - System Checkpoint
    RP444: 6/5/2009 4:09:03 AM - System Checkpoint
    RP445: 6/7/2009 12:47:45 AM - System Checkpoint
    RP446: 6/8/2009 4:37:07 PM - System Checkpoint
    RP447: 6/9/2009 11:24:56 PM - System Checkpoint
    RP448: 6/10/2009 10:02:18 AM - Software Distribution Service 3.0
    RP449: 6/10/2009 10:20:18 AM - Installed Java(TM) 6 Update 14
    RP450: 6/11/2009 10:41:47 AM - System Checkpoint
    RP451: 6/11/2009 6:36:55 PM - Installed SPORE™
    RP452: 6/11/2009 10:31:40 PM - Removed SPORE™
    RP453: 6/12/2009 6:10:11 PM - Installed SPORE™ Creature Creator Trial Edition
    RP454: 6/12/2009 7:03:22 PM - Configured SPORE™ Creature Creator Trial Edition
    RP455: 6/12/2009 9:02:40 PM - Removed Crysis(R).
    RP456: 6/12/2009 9:03:48 PM - Removed GameSpy Comrade.
    RP457: 6/12/2009 9:32:06 PM - Removed SPORE™ Creature Creator Trial Edition
    RP458: 6/13/2009 4:39:44 PM - Installed SPORE™
    RP459: 6/14/2009 11:40:07 AM - Installed SPORE™
    RP460: 6/16/2009 1:49:11 AM - System Checkpoint
    RP461: 6/17/2009 11:48:10 PM - Configured SPORE™
    RP462: 6/19/2009 5:53:51 PM - Unsigned driver install
    RP463: 6/20/2009 11:27:41 AM - Installed DirectX
    RP464: 6/20/2009 11:09:45 PM - Installed Project64 1.6
    RP465: 6/21/2009 11:10:22 AM - SPTD setup V1.58
    RP466: 6/22/2009 11:22:38 AM - System Checkpoint
    RP467: 6/23/2009 11:35:37 AM - System Checkpoint
    RP468: 6/24/2009 6:29:21 PM - System Checkpoint
    RP469: 6/24/2009 8:09:13 PM - Installed Prototype(TM)
    RP470: 6/24/2009 8:17:58 PM - Removed SPORE™
    RP471: 6/24/2009 8:26:25 PM - Installed Prototype(TM)
    RP472: 6/24/2009 8:33:48 PM - Installed Prototype(TM)
    RP473: 6/24/2009 9:00:25 PM - Installed Prototype(TM)
    RP474: 6/24/2009 9:01:11 PM - Installed Prototype(TM)
    RP475: 6/24/2009 9:15:56 PM - Installed Prototype(TM)
    RP476: 6/24/2009 9:21:11 PM - Installed Prototype(TM)
    RP477: 6/24/2009 9:34:28 PM - Removed Prototype(TM)
    RP478: 6/24/2009 9:37:27 PM - Removed Prototype(TM)
    RP479: 6/24/2009 9:38:10 PM - Installed Prototype(TM)
    RP480: 6/24/2009 11:49:45 PM - Removed Prototype(TM)
    RP481: 6/25/2009 12:17:15 AM - Installed Prototype(TM)
    RP482: 6/26/2009 2:40:41 AM - System Checkpoint
    RP483: 6/26/2009 1:29:10 PM - Installed Pinnacle Game Profiler
    RP484: 6/26/2009 1:41:53 PM - Installed DirectX
    RP485: 6/27/2009 1:58:43 PM - System Checkpoint
    RP486: 6/27/2009 5:15:23 PM - Configured Prototype(TM)
    RP487: 6/28/2009 4:31:23 PM - Removed Steam
    RP488: 6/30/2009 4:34:03 AM - Software Distribution Service 3.0
    RP489: 6/30/2009 5:42:33 PM - Installed Prototype(TM)
    RP490: 6/30/2009 5:54:05 PM - Installed Prototype(TM)
    RP491: 6/30/2009 10:52:06 PM - Software Distribution Service 3.0
    RP492: 7/3/2009 1:51:02 AM - System Checkpoint
    RP493: 7/3/2009 7:32:41 PM - Installed ISO Recorder
    RP494: 7/3/2009 10:20:53 PM - Removed Pinnacle Game Profiler
    RP495: 7/4/2009 11:08:13 PM - System Checkpoint
    RP496: 7/6/2009 12:38:13 AM - System Checkpoint
    RP497: 7/7/2009 2:07:17 AM - System Checkpoint
    RP498: 7/8/2009 2:17:48 AM - System Checkpoint
    RP499: 7/9/2009 4:17:45 AM - System Checkpoint
    RP500: 7/9/2009 12:02:25 PM - Installed Realtek AC'97 Audio
    RP501: 7/10/2009 2:39:30 PM - System Checkpoint
    RP502: 7/11/2009 9:59:11 PM - System Checkpoint
    RP503: 7/12/2009 10:19:01 PM - System Checkpoint
    RP504: 7/15/2009 4:07:21 PM - Software Distribution Service 3.0
    RP505: 7/16/2009 8:53:08 PM - System Checkpoint
    RP506: 7/17/2009 10:41:53 PM - System Checkpoint
    RP507: 7/19/2009 4:03:51 AM - System Checkpoint
    RP508: 7/20/2009 4:18:28 AM - System Checkpoint
    RP509: 7/21/2009 4:47:32 AM - System Checkpoint
    RP510: 7/27/2009 5:21:55 AM - System Checkpoint
    RP511: 7/28/2009 5:22:36 AM - System Checkpoint
    RP512: 7/29/2009 6:29:29 AM - System Checkpoint
    RP513: 7/30/2009 5:41:13 PM - System Checkpoint
    RP514: 7/31/2009 7:16:02 PM - System Checkpoint

    ==== Installed Programs ======================

    AAC Decoder
    AC3Filter (remove only)
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 8.1.4
    Adobe Shockwave Player 11.5
    AIM 6
    Alarm 2.0.4
    ALi mini IDE driver
    Apple Software Update
    Athlon 64 Processor Driver
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Display Driver
    ATI HYDRAVISION
    AutoUpdate
    Belkin Wireless Network Monitor Utility and Driver (USB)
    Belkin Wireless USB Utility
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center HydraVision Full
    ccc-core-preinstall
    ccc-core-static
    ccc-utility
    CCC Help English
    Critical Update for Windows Media Player 11 (KB959772)
    Crysis Wars(R)
    Crysis Wars(R) Patch
    DivX Codec
    DivX Converter
    DivX Player
    DivX Plus DirectShow Filters
    DivX Version Checker
    DivX Web Player
    Download Manager 2.3.7
    EA Download Manager
    Eusing Free Registry Cleaner
    File Splitter and Joiner (FFSJ v3.2)
    Free Create-Burn ISO Image v2.0
    Google Earth
    Google Update Helper
    Google Updater
    H.264 Decoder
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    hp deskjet 825c series (Remove only)
    ImagXpress
    IOGEAR Bluetooth Software
    ISO Recorder
    Java(TM) 6 Update 14
    Logitech Gaming Software
    Magic ISO Maker v5.5 (build 0276)
    MagicDisc 2.6.93
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Xbox 360 Accessories 1.1
    MKV Splitter
    MSXML 4.0 SP2 (KB954430)
    MyIdentityDefender Toolbar (CyberDefender Corporation)
    neroxml
    Project64 1.6
    Prototype(TM)
    PunkBuster Services
    Realtek AC'97 Audio
    Roxio Creator Audio
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator DE
    Roxio Creator Tools
    Roxio Drag-to-Disc
    Roxio Update Manager
    Security Update for CAPICOM (KB931906)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB969897)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB973346)
    Skins
    Sonic Activation Module
    Sony PTP USB Driver
    Spybot - Search & Destroy
    System Requirements Lab
    TuxGuitar
    ULi AGP Driver
    ULi LAN Driver
    ULi M5289 SATA Driver
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VC80CRTRedist - 8.0.50727.762
    Ventrilo Client
    Veoh Web Player
    Viewpoint Media Player
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Format SDK Hotfix - KB891122
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    XML Paper Specification Shared Components Pack 1.0

    ==== Event Viewer Messages From Past Week ========

    8/1/2009 7:23:39 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer THOMASPATHIK-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{1A1D83B7-DA1. The master browser is stopping or an election is being forced.
    7/30/2009 3:49:14 PM, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: The specified module could not be found.
    7/30/2009 3:42:03 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    7/29/2009 3:46:46 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
    7/29/2009 3:44:14 PM, error: Service Control Manager [7000] - The nlaagcrf service failed to start due to the following error: The system cannot find the file specified.
    7/29/2009 2:43:28 PM, error: System Error [1003] - Error code 000000fc, parameter1 f78deb30, parameter2 0abe4163, parameter3 f78dea98, parameter4 00000001.
    7/29/2009 2:41:57 PM, error: System Error [1003] - Error code 000000fc, parameter1 f78dab30, parameter2 13058163, parameter3 f78daa98, parameter4 00000001.
    7/29/2009 2:10:03 PM, error: Service Control Manager [7000] - The Nero BackItUp Scheduler 4.0 service failed to start due to the following error: The system cannot find the path specified.
    7/29/2009 2:08:31 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    7/29/2009 2:07:38 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    7/29/2009 2:06:02 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AmdK8 Fips
    7/29/2009 10:43:36 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume3'. It has stopped monitoring the volume.
    7/25/2009 9:24:26 PM, error: m5289 [9] - The device, \Device\Scsi\m52891, did not respond within the timeout period.

    ==== End Of File ===========================

  5. #35
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please go to Kaspersky website and perform an online antivirus scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #36
    Junior Member
    Join Date
    Jul 2009
    Posts
    23

    Default

    my last 3 posts are from that scanner and dds report. after u told me to do it already. should i do it again?

  7. #37
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Sorry, that was brain fart

    Delete this:

    C:\Documents and Settings\Nick\My Documents\Downloads\Prototype - Razor1911 No-DVD crack.rar

    Empty this folder:

    C:\Qoobox\Quarantine\

    Empty Recycle Bin.

    Please download ATF Cleaner by Atribune and save
    it to desktop.

    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.

    If you use Firefox browser

    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit to close ATF-Cleaner.

    Still problems?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #38
    Junior Member
    Join Date
    Jul 2009
    Posts
    23

    Default

    nope cant see any problems. my spybot works again and my internet isnt all jacked up anymore. thanks for the help man.

  9. #39
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    So we continue with this.

    Looking over your log, it seems you don't have any evidence of an anti-virus software.

    Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

    1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Free support.
    2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
    3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

    You should run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and results in program conflicts and false virus alerts.

    Please a fresh dds log afterwards.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  10. #40
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

    Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

    If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •