Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Had Antivirus Live Virus now other problems


  • Please log in to reply
20 replies to this topic

#1 Dav1

Dav1

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 17 December 2010 - 10:43 PM

I had Anti-virus Live and thought I was rid of the worst it. The scans I did said it was clean including scans from "Malwarebyes" to "ReimageRepair" etc. This issue then brought on slow start-ups as well as shut-downs and my pc failing to restart (when restarted it would say "Windows is shutting down" etc. and then either crash on that screen or appear on screen like it was off. However the system was still running and no chance of booting again until of course being done through pressing the restart button on the front of my computer). So I did know I still had a heavy problem on my hands. Following this today my computer crashed a couple of times without being able to respond again until physical reboot (ctrl+alt+del failed too). Now I have done a scan through "ReimageRepair" again and it says that I do have some sort of virus with the following text "iexplorer.exe --- Suspicious file a.k.a NirCmd a.k.a File is damaged" and I cannot afford to buy the program to fix it that way. Here is also the log file of the scan I did afterwards with HijackThis.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 03:33:49, on 18/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\PC Tools Security\pctsAuxs.exe
C:\Program Files\PC Tools Security\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Tools Security\pctsGui.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\UnHackMe\hackmon.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Reimage\Reimage Repair\Reimage.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:59274
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Security\pctsGui.exe" /hideGUI
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1078081533-796845957-839522115-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.4.1.10.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.bbc.co.uk
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

--
End of file - 15464 bytes

I am just desperate to get this sorted now and I am grateful of any help I may receive.

Thank You.

I forgot to add that the "ReimageRepair" scan said that the following programs crashed in an unusual frequency...

Msiinstaller
1180474431
Teatimer.exe

I hope this information helps.

Edit: Moved topic from XP to the more appropriate forum. Also merged two topics to make one. ~ Animal

BC AdBot (Login to Remove)

 


#2 shelf life

shelf life

  • Malware Response Team
  • 2,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:@localhost
  • Local time:04:04 PM

Posted 27 December 2010 - 05:49 PM

hi Dav1,

Sorry for the delay. Your post is several days old. If you still need help post back.

How Can I Reduce My Risk to Malware?


#3 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 05 January 2011 - 11:49 AM

Yes I'm still having a lot of the same problems.

#4 shelf life

shelf life

  • Malware Response Team
  • 2,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:@localhost
  • Local time:04:04 PM

Posted 05 January 2011 - 08:10 PM

hi,

Ok We will get two downloads. One is malwarebytes and the other a tool so you can post a general log.
You can run malwarebytes first:

Please download the free version of Malwarebytes to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.

When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click *Remove Selected.*

*A restart of your computer may be required to remove some items. If prompted please restart your computer to complete the fix.*

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

Post the log in your reply.


DDS:

Please download DDS and save it to your desktop.

Double click dds.scr to run the tool. When done, DDS.txt will open.

Save both reports to your desktop.

Please Copy/paste both logs in your reply.

How Can I Reduce My Risk to Malware?


#5 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 07 January 2011 - 03:34 AM

DDS (Ver_10-12-12.02) - NTFSx86
Run by Dave at 8:28:23.28 on 07/01/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.475 [GMT 0:00]

AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\Program Files\PC Tools Security\pctsGui.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\PC Tools Security\pctsAuxs.exe
C:\Program Files\PC Tools Security\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\League of Legends\lol.launcher.exe
C:\Program Files\League of Legends\Air\LOLClient.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dave\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyServer = http=127.0.0.1:59274
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
mURLSearchHooks: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.1.2.7.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\pc tools security\bdt\PCTBrowserDefender.dll
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [NokiaMusic FastStart] "c:\program files\nokia\ovi player\NokiaOviPlayer.exe" /command:faststart
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start
mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe
mRun: [PCTools FGuard] c:\program files\pc tools security\bdt\FGuard.exe
mRun: [ISTray] "c:\program files\pc tools security\pctsGui.exe" /hideGUI
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\dave\applic~1\mozilla\firefox\profiles\i3h9ii0k.default\
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: c:\program files\pc tools security\bdt\firefox\platform\winnt_x86-msvc\components\libheuristic.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Browser Defender Toolbar: {cb84136f-9c44-433a-9048-c5cd9df1dc16} - c:\program files\pc tools security\bdt\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-12-20 64288]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-12-13 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2010-12-13 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2010-12-13 656320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-12-13 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-12-13 59664]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-11-16 108792]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-3 14336]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\pc tools security\bdt\BDTUpdateService.exe [2010-12-14 247760]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-5-28 20968]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2010-12-6 1238408]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-12-3 1389400]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2010-12-14 632792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2010-12-13 366840]
R2 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2010-12-13 1150936]
R2 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service --> c:\program files\threatfire\TFService.exe service [?]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-12-13 33552]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-12 135664]
S3 cpuz134;cpuz134;\??\c:\docume~1\dave\locals~1\temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\dave\locals~1\temp\cpuz134\cpuz134_x32.sys [?]
S3 GEST Service;GEST Service for program management.;c:\program files\gigabyte\gest\GSvr.exe [2010-1-25 47624]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-12-3 15264]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-7-7 14904]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S4 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-11-16 735960]

=============== File Associations ===============

regfile="regedit.exe" "%1"

=============== Created Last 30 ================

2010-12-25 16:49:41 138056 ----a-w- c:\docume~1\dave\applic~1\PnkBstrK.sys
2010-12-25 16:49:18 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-12-24 02:30:51 -------- d-----w- c:\docume~1\alluse~1\applic~1\Codemasters
2010-12-24 02:30:34 -------- d-----w- c:\program files\OpenAL
2010-12-24 02:30:33 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-12-24 02:30:33 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-12-22 17:58:30 -------- d-----w- c:\docume~1\dave\locals~1\applic~1\WMTools Downloaded Files
2010-12-22 16:13:58 -------- d-----w- c:\docume~1\dave\locals~1\applic~1\Sony
2010-12-22 15:05:40 -------- d-----w- c:\program files\Sony
2010-12-22 14:41:20 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-12-22 14:41:08 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-12-22 14:40:46 -------- d-----w- c:\docume~1\dave\applic~1\DAEMON Tools Lite
2010-12-22 14:40:42 -------- d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2010-12-20 02:34:13 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-12-20 01:56:20 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-12-20 01:56:12 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-12-20 01:54:35 -------- d-----w- c:\docume~1\dave\locals~1\applic~1\Sunbelt Software
2010-12-20 01:53:55 -------- dc-h--w- c:\docume~1\alluse~1\applic~1\{2162CCC0-3A5F-4887-B51F-CE5F195B3620}
2010-12-20 01:53:18 -------- d-----w- c:\program files\Lavasoft
2010-12-18 03:04:34 388096 ----a-r- c:\docume~1\dave\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2010-12-18 03:04:33 -------- d-----w- c:\program files\Trend Micro
2010-12-15 16:27:16 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 16:26:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-14 02:48:15 -------- d-----w- c:\docume~1\dave\applic~1\Registry Mechanic
2010-12-14 02:41:32 37336 ----a-w- c:\windows\system32\CleanMFT32.exe
2010-12-14 02:41:31 880640 ----a-w- c:\windows\system32\UniBox10.ocx
2010-12-14 02:41:31 658432 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2010-12-14 02:41:31 212992 ----a-w- c:\windows\system32\UniBoxVB12.ocx
2010-12-14 02:41:31 1101824 ----a-w- c:\windows\system32\UniBox210.ocx
2010-12-14 02:41:31 1081616 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2010-12-14 02:10:46 2 --shatr- c:\windows\winstart.bat
2010-12-14 02:10:35 -------- d-----w- c:\program files\UnHackMe
2010-12-14 00:20:37 -------- d-----w- c:\docume~1\dave\locals~1\applic~1\Threat Expert
2010-12-14 00:12:04 767952 ----a-w- c:\windows\BDTSupport.dll
2010-12-14 00:12:04 1996752 ----a-w- c:\windows\PCTBDCore.dll
2010-12-14 00:12:04 1533904 ----a-w- c:\windows\PCTBDRes.dll
2010-12-14 00:12:04 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-12-13 23:44:56 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2010-12-13 23:44:56 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2010-12-13 23:44:53 249616 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-12-13 23:44:35 239168 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-12-13 23:44:35 160448 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-12-13 23:43:00 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-12-13 23:42:33 -------- d-----w- c:\program files\common files\PC Tools
2010-12-13 23:42:32 -------- d-----w- c:\program files\PC Tools Security
2010-12-13 23:42:32 -------- d-----w- c:\docume~1\dave\applic~1\PC Tools
2010-12-13 23:09:41 -------- d-----w- c:\docume~1\dave\locals~1\applic~1\PackageAware
2010-12-13 23:00:05 -------- d-----w- C:\rei
2010-12-13 23:00:04 -------- d-----w- c:\program files\Reimage
2010-12-13 22:40:12 -------- d-----w- c:\docume~1\dave\applic~1\ParetoLogic
2010-12-13 22:40:12 -------- d-----w- c:\docume~1\dave\applic~1\DriverCure
2010-12-13 22:40:05 -------- d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2010-12-13 22:30:58 59664 ----a-w- c:\windows\system32\drivers\TfSysMon.sys
2010-12-13 22:30:58 51984 ----a-w- c:\windows\system32\drivers\TfFsMon.sys
2010-12-13 22:30:58 33552 ----a-w- c:\windows\system32\drivers\TfNetMon.sys
2010-12-13 22:30:57 -------- d-----w- c:\program files\ThreatFire
2010-12-13 22:24:45 -------- d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2010-12-13 20:55:37 -------- d-----w- c:\docume~1\dave\applic~1\SUPERAntiSpyware.com
2010-12-13 20:55:37 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-12-13 20:55:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-12-13 20:06:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-12-13 20:06:30 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-12-13 19:34:45 -------- d-----w- c:\program files\Secunia
2010-12-13 17:18:16 -------- d-----w- c:\docume~1\dave\applic~1\Malwarebytes
2010-12-13 17:18:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-13 17:18:10 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-12-13 17:18:07 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-13 17:18:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-12-13 16:17:10 -------- d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-12-11 00:19:21 83249512 ----a-w- c:\program files\common files\windows live\.cache\wlc31D1.tmp
2010-12-08 11:44:10 -------- d-----w- c:\program files\LogMeIn Hamachi

==================== Find3M ====================

2010-12-30 20:21:58 270904 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-12-30 20:21:58 270904 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-12-30 19:01:18 270904 ----a-w- c:\windows\system32\PnkBstrB.ex0
2010-12-25 17:00:40 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-11-20 22:21:32 2373712 ----a-w- c:\windows\system32\pbsvc.exe
2010-11-18 18:12:44 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26:58 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26:58 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25:54 385024 ----a-w- c:\windows\system32\html.iec
2010-10-28 13:13:22 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2010-10-22 11:43:18 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-10-22 11:43:18 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-10-14 01:36:52 15451288 ----a-w- c:\windows\system32\xlive.dll
2010-10-14 01:36:50 13642904 ----a-w- c:\windows\system32\xlivefnt.dll

============= FINISH: 8:32:27.75 ===============

#6 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 07 January 2011 - 03:36 AM

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 07/05/2005 16:24:05
System Uptime: 07/01/2011 07:46:42 (1 hours ago)

Motherboard: Gigabyte Technology Co., Ltd. | | EP31-DS3L
Processor: Intel Pentium III Xeon processor | Socket 775 | 2666/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 699 GiB total, 370.076 GiB free.
D: is CDROM (UDF)
E: is CDROM ()
F: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP208: 10/10/2010 19:13:22 - System Checkpoint
RP209: 11/10/2010 01:38:10 - Installed LogMeIn Hamachi
RP210: 13/10/2010 15:54:09 - System Checkpoint
RP211: 14/10/2010 18:26:15 - System Checkpoint
RP212: 14/10/2010 19:45:53 - Software Distribution Service 3.0
RP213: 16/10/2010 17:45:35 - System Checkpoint
RP214: 17/10/2010 18:53:58 - System Checkpoint
RP215: 19/10/2010 01:21:42 - System Checkpoint
RP216: 21/10/2010 12:15:37 - Installed DirectX
RP217: 23/10/2010 16:18:58 - System Checkpoint
RP218: 24/10/2010 19:07:33 - System Checkpoint
RP219: 26/10/2010 18:59:49 - System Checkpoint
RP220: 29/10/2010 19:24:09 - System Checkpoint
RP221: 31/10/2010 02:20:42 - System Checkpoint
RP222: 01/11/2010 03:54:33 - System Checkpoint
RP223: 02/11/2010 18:17:39 - System Checkpoint
RP224: 03/11/2010 18:57:10 - System Checkpoint
RP225: 05/11/2010 19:24:03 - System Checkpoint
RP226: 07/11/2010 08:31:30 - System Checkpoint
RP227: 08/11/2010 16:18:22 - System Checkpoint
RP228: 09/11/2010 18:54:59 - System Checkpoint
RP229: 10/11/2010 19:08:48 - System Checkpoint
RP230: 12/11/2010 01:33:21 - System Checkpoint
RP231: 13/11/2010 14:04:18 - System Checkpoint
RP232: 17/11/2010 03:17:17 - System Checkpoint
RP233: 18/11/2010 16:58:23 - System Checkpoint
RP234: 19/11/2010 18:59:18 - System Checkpoint
RP235: 20/11/2010 22:20:19 - Installed Quake Live Internet Explorer Plugin
RP236: 22/11/2010 16:19:03 - System Checkpoint
RP237: 23/11/2010 19:40:54 - System Checkpoint
RP238: 25/11/2010 15:19:58 - System Checkpoint
RP239: 26/11/2010 19:17:40 - System Checkpoint
RP240: 27/11/2010 19:38:27 - System Checkpoint
RP241: 28/11/2010 23:37:23 - Installed DirectX
RP242: 28/11/2010 23:38:53 - Installed Bloodline Champions Beta
RP243: 01/12/2010 18:22:20 - System Checkpoint
RP244: 01/12/2010 22:10:27 - Installed Microsoft Games for Windows - LIVE Redistributable
RP245: 01/12/2010 22:10:42 - Removed Microsoft Games for Windows - LIVE Redistributable
RP246: 01/12/2010 22:13:44 - Removed Windows Live Sign-in Assistant
RP247: 01/12/2010 22:13:51 - Installed Windows Live ID Sign-in Assistant
RP248: 01/12/2010 22:14:12 - Installed Microsoft Games for Windows - LIVE Redistributable
RP249: 01/12/2010 22:14:27 - Removed Microsoft Games for Windows - LIVE Redistributable
RP250: 01/12/2010 22:18:19 - Installed Grand Theft Auto IV
RP251: 03/12/2010 17:13:19 - System Checkpoint
RP252: 04/12/2010 17:26:23 - System Checkpoint
RP253: 05/12/2010 18:37:07 - System Checkpoint
RP254: 07/12/2010 22:21:54 - System Checkpoint
RP255: 09/12/2010 17:37:24 - System Checkpoint
RP256: 12/12/2010 11:44:13 - System Checkpoint
RP257: 13/12/2010 16:17:10 - avast! Free Antivirus Setup
RP258: 13/12/2010 23:23:36 - Removed ESET Smart Security
RP259: 13/12/2010 23:34:57 - avast! Free Antivirus Setup
RP260: 14/12/2010 02:22:02 - RegRun Virus Scan
RP261: 14/12/2010 10:19:50 - RegRun Virus Scan
RP262: 15/12/2010 19:58:36 - Removed Bloodline Champions Beta
RP263: 16/12/2010 03:00:17 - Software Distribution Service 3.0
RP264: 17/12/2010 12:47:51 - System Checkpoint
RP265: 18/12/2010 03:04:29 - Installed HiJackThis
RP266: 18/12/2010 12:34:27 - RegRun Virus Scan
RP267: 18/12/2010 20:50:21 - Cleaned registry with Windows Live OneCare safety scanner
RP268: 20/12/2010 06:13:38 - System Checkpoint
RP269: 21/12/2010 06:20:14 - System Checkpoint
RP270: 22/12/2010 14:41:19 - SPTD setup V1.62
RP271: 22/12/2010 15:05:37 - Installed Vegas Pro 9.0
RP272: 23/12/2010 16:49:34 - System Checkpoint
RP273: 25/12/2010 04:41:07 - System Checkpoint
RP274: 25/12/2010 16:48:09 - Installed DirectX
RP275: 26/12/2010 19:13:59 - System Checkpoint
RP276: 27/12/2010 20:41:46 - System Checkpoint
RP277: 29/12/2010 04:59:05 - System Checkpoint
RP278: 30/12/2010 18:10:44 - System Checkpoint
RP279: 31/12/2010 19:17:55 - System Checkpoint
RP280: 01/01/2011 19:58:07 - System Checkpoint
RP281: 04/01/2011 16:34:12 - System Checkpoint
RP282: 05/01/2011 20:15:15 - System Checkpoint
RP283: 06/01/2011 03:00:20 - Software Distribution Service 3.0

==== Installed Programs ======================

7-Zip 4.65
Acrobat.com
Ad-Aware
Adobe AIR
Adobe Community Help
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Photoshop CS5
Adobe Reader 9.3
Adobe Shockwave Player 11.5
Akamai NetSession Interface
ASIO4ALL
µTorrent
Audiosurf
Battlefield: Bad Company 2
BitComet 0.84
Browser Defender 3.0
Command & Conquer™ Red Alert™ 3
Counter-Strike
Counter-Strike: Source
CPUID CPU-Z 1.54
DiRT 2 - Demo
DivX Setup
Drumaxx
Dynamic Energy Saver 1.0 B8.0128.1
EA Download Manager
FIFA 11
FIFA 11 Demo
FL Studio 9
Football Superstars
Fraps
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Grand Theft Auto IV
GRID
GunboundS2
High Definition Audio Driver Package - KB888111
HiJackThis
HLSW v1.3.2.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB938759)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Hotspot Shield 1.47
IL Download Manager
IsoBuster 2.7
Java Auto Updater
Java™ 6 Update 20
Junk Mail filter update
Korean Language Support
League of Legends
Left 4 Dead
Left 4 Dead 2
LogMeIn Hamachi
Malwarebytes' Anti-Malware
McAfee Security Scan Plus
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Windows Journal Viewer
Microsoft Xbox 360 Accessories 1.2
Microsoft XNA Framework Redistributable 3.1
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
mIRC
Mozilla Firefox (3.6.3)
MSVCRT
MSXML 6.0 Parser (KB925673)
Mumble and Murmur
Nero 7 Ultra Edition
Nokia Connectivity Cable Driver
Nokia Ovi Player
Nokia_Multimedia_Common_Components_2_5
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA nView Desktop Manager
NVIDIA PhysX
OpenAL
OpenOffice.org 3.2
Pando Media Booster
PC Connectivity Solution
PDF Settings CS5
Peggle Extreme
PFPortChecker 1.0.36
PKR
PoiZone
PoxNora 1.4.7.0
PunkBuster Services
Quake Live Internet Explorer Plugin
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Registry Mechanic 10.0
Reimage Repair
RocketDock 1.3.5
Sakura
Sawer
Secunia PSI
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
Skype Toolbars
Skype™ 5.0
SopCast 3.2.4
SpeedFan (remove only)
Spybot - Search & Destroy
Spyware Doctor 8.0
Steam
SUPERAntiSpyware
Team Fortress 2
TeamSpeak 3 Client
TeamViewer 5
ThreatFire
Toxic Biohazard
TrackMania Nations Forever
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.4053
Vegas Pro 9.0
Ventrilo Client
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 1.0.3
Warsow 0.5
WebFldrs XP
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Imaging Component
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
X-ray Anti-Cheat
XML Paper Specification Shared Components Pack 1.0
Zune Desktop Theme

==== Event Viewer Messages From Past Week ========

31/12/2010 04:37:01, error: Dhcp [1002] - The IP address lease 10.72.80.27 for the Network Card with network address 00FF62A7F2DD has been denied by the DHCP server 10.8.23.254 (The DHCP Server sent a DHCPNACK message).
07/01/2011 00:51:27, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 001FD086845A has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
06/01/2011 03:23:28, error: Dhcp [1002] - The IP address lease 10.48.24.31 for the Network Card with network address 00FF62A7F2DD has been denied by the DHCP server 10.77.31.254 (The DHCP Server sent a DHCPNACK message).
05/01/2011 19:52:41, error: Dhcp [1002] - The IP address lease 192.168.2.2 for the Network Card with network address 001FD086845A has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
04/01/2011 21:03:12, error: Dhcp [1002] - The IP address lease 192.168.2.4 for the Network Card with network address 001FD086845A has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
03/01/2011 04:13:24, error: Dhcp [1002] - The IP address lease 10.8.16.8 for the Network Card with network address 00FF62A7F2DD has been denied by the DHCP server 10.48.31.254 (The DHCP Server sent a DHCPNACK message).
01/01/2011 17:54:40, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the NMIndexingService service to connect.
01/01/2011 17:54:40, error: Service Control Manager [7000] - The NMIndexingService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
01/01/2011 17:54:36, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service NMIndexingService with arguments "" in order to run the server: {C6A811AB-F8FF-45A4-93E5-FC5CCB650BE7}

==== End Of File ===========================

#7 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 07 January 2011 - 02:18 PM

Nothing found through Malwarebytes (used program before though).

#8 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 08 January 2011 - 08:56 PM

Any ideas anyone? The main problem at the moment is start-up and shut-down times (and the problem that sometimes the shut-downs fail). A lot of applications are also slower now and now the system has become slightly prone to crashes.

Again any feedback and possible solutions are very much appreciated.

#9 shelf life

shelf life

  • Malware Response Team
  • 2,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:@localhost
  • Local time:04:04 PM

Posted 09 January 2011 - 07:19 PM

Iam still looking for malware issues. Not all problems are malware related. I wouldnt rely on ReimageRepair to detect malware and virus issues.
I see alot of malware apps installed. You only have one Antivirus correct? Because thats all you need.

How Can I Reduce My Risk to Malware?


#10 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 10 January 2011 - 02:39 AM

As far as I know I do yes. I had ESET Security but had to uninstall as this was forcing the computer to crash on stat-up because of as I imagine there was conflict between programs.

#11 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 10 January 2011 - 03:29 AM

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5475

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/01/2011 08:21:45
mbam-log-2011-01-10 (08-21-45).txt

Scan type: Quick scan
Objects scanned: 172276
Time elapsed: 24 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


^^ Results from MalwareBytes quickscan this morning.

#12 shelf life

shelf life

  • Malware Response Team
  • 2,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:@localhost
  • Local time:04:04 PM

Posted 10 January 2011 - 07:30 PM

ok we can get another check for malware with combofix. There is a guide you need to read first. Read through the guide then apply the directions on your own machine. Post the combofix log in your reply.

Guide to using Combofix

How Can I Reduce My Risk to Malware?


#13 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 11 January 2011 - 08:08 PM

I started this and left it while it was doing the command prompt stuff and the next thing I know it's on this "q flash utility 2.05" bios thing and i really don't have a clue what to do :S.

I'm desperate for help with this asap.

#14 Dav1

Dav1
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:08:04 PM

Posted 11 January 2011 - 09:24 PM

It must have restarted onto this and now i can't do anything. It comes up every times I restart. I am really really desperate for help here. Really do need this as soon as possible too, thanks.

#15 shelf life

shelf life

  • Malware Response Team
  • 2,657 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:@localhost
  • Local time:04:04 PM

Posted 12 January 2011 - 07:57 PM

Can you boot the computer into safe mode? To reach safe mode you would tap the f8 key during a computer restart, chose the first option from the list: safe mode

How Can I Reduce My Risk to Malware?





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users