| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
|
29-Jul-2010, 04:58 AM
#1 |
| plz help me. last night i was able to open yahoo mail and also signed in in messenger. Suddenly i got dc after reconnection i m unable to open yahoo mail and yahoo messenger (it says to check https..bla bla..) but i can open yahoo mail in any other browser like opera. Now i got something more. so i connect to internet by usb modem and a gprs enabled sim. the problem is with uninor network and works f9 with any other network. i called to uninor CC, but they are more noob than me n says they have no idea about this. I tried to update my IE to 8, but it failed in both methods 1) by automatic update 2) by offline installer.. now what to do? i dont want to use opera..mail is ok but how to open yahoo messenger? any help would b appreciated. thank you |
| |
29-Jul-2010, 06:27 AM
#2 | |||||
| Can you please try & type in English not text speak as it makes it very diificult to understand what you are saying Download to Desktop: DDS by sUBs from one of these locations: http://download.bleepingcomputer.com/sUBs/dds.com http://download.bleepingcomputer.com/sUBs/dds.scr http://www.forospyware.com/sUBs/dds double click DDS.scr to run When complete, DDS.txt will open. Click Yes for Optional Scan. Save both reports to your desktop. DDS.txt Attach.txt post the contents of both logs back here.
__________________ Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue |
|
29-Jul-2010, 09:32 AM
#3 |
| thanks for this quick reply and sorry for my english. the two reports are as : DDS (Ver_10-03-17.01) - NTFSx86 Run by Peeyush Kumar at 18:00:17.92 on Thu 07/29/2010 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.371 [GMT 5.5:30] AV: avast! antivirus 4.8.1368 [VPS 100728-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\agrsmsvc.exe C:\WINDOWS\system32\ChgService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Sandboxie\SbieSvc.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files\Cyberlink\Shared files\brs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Vista Start Menu\VistaStartMenu.exe C:\Program Files\Circle Dock\CircleDock.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\WINDOWS\BricoPacks\LeopardXP\Glass2k.exe C:\Program Files\MacSearch_v.1.4.3\MacSearch.exe C:\Program Files\RK Launcher\RK Launcher 0.41 Beta Nightly\RKLauncher.exe C:\Program Files\tclock2_120\tclock2.exe C:\Program Files\UberIcon\UberIcon Manager.exe C:\Program Files\CursorXP\CursorXP.exe D:\desktop customization\WFlip050\WinFlip.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\MMX300G 3G USB Manager\USB Modem.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\opera\opera.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Peeyush Kumar\Desktop\dds.com ============== Pseudo HJT Report =============== BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: AC-Pro: {0fb6a909-6086-458f-bd92-1f8ee10042a0} - c:\program files\autocompletepro\AutocompletePro.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Loader Class: {f880a4a8-c436-4ac4-afd1-aa0bdc9552dd} - c:\windows\bricopacks\leopardxp\FindeXer.dll TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [CursorXP] "c:\program files\cursorxp\CursorXP.exe" -s uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [VistaStartMenu] "c:\program files\vista start menu\VistaStartMenu.exe" uRun: [CircleDock] c:\program files\circle dock\CircleDock.exe uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [RemoteControl10] "c:\program files\cyberlink\powerdvd10\PDVD10Serv.exe" mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\glass2k.lnk - c:\windows\bricopacks\leopardxp\Glass2k.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\macsea~1.lnk - c:\program files\macsearch_v.1.4.3\MacSearch.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\panthe~1.lnk - c:\program files\cursorxp\themes\panther.CurXPTheme StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\rklaun~1.lnk - c:\program files\rk launcher\rk launcher 0.41 beta nightly\RKLauncher.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\tclock2.lnk - c:\program files\tclock2_120\tclock2.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\ubericon.lnk - c:\program files\ubericon\UberIcon Manager.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\winflip.lnk - d:\desktop customization\wflip050\WinFlip.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1) mPolicies-system: SynchronousMachineGroupPolicy = 0 (0x0) mPolicies-system: SynchronousUserGroupPolicy = 0 (0x0) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab TCP: {A59B6824-09C2-4100-AD13-43C7D8AEDE3F} = 202.138.96.2 4.2.2.2 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL Hosts: 66.98.148.65 auto.search.msn.com Hosts: 66.98.148.65 auto.search.msn.es ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2010-6-17 114768] R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/06/19 13:41:56];c:\program files\cyberlink\powerdvd10\navfilter\000.fcl [2010-4-2 87536] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2010-6-17 138680] R2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [2010-6-29 135168] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-6-17 304464] R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2010-6-17 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2010-6-17 352920] R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\drivers\cmnsusbser.sys [2010-6-29 103424] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-6-17 20952] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2010-2-3 115432] S3 cpuz130;cpuz130;\??\c:\docume~1\peeyus~1\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\peeyus~1\locals~1\temp\cpuz130\cpuz_x32.sys [?] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] =============== Created Last 30 ================ 2010-07-29 15:44:16 0 d-----r- C:\Sandbox 2010-07-29 15:42:18 1548 ----a-w- c:\windows\Sandboxie.ini 2010-07-29 15:42:10 0 d-----w- c:\program files\Sandboxie 2010-07-29 11:10:47 0 d-----w- c:\docume~1\peeyus~1\applic~1\HU2011 2010-07-29 11:03:34 0 d-----w- c:\program files\Hunting Unlimited 2011 2010-07-26 20:57:46 0 d-----w- c:\program files\Xenocode 2010-07-26 20:57:27 0 d-----w- c:\program files\High Quality Photo Resizer 2010-07-25 17:01:36 334792 ----a-w- c:\windows\system32\_AxShlEx.dll 2010-07-25 17:00:38 0 d-----w- c:\program files\Alcohol Soft 2010-07-25 16:24:08 0 d-----w- c:\program files\Photo Resize Magic 2010-07-25 15:49:36 78 ----a-w- c:\documents and settings\peeyush kumar\Config.INI 2010-07-25 15:49:36 54 ----a-w- c:\documents and settings\peeyush kumar\score.DAT 2010-07-25 13:27:18 0 d-----w- c:\program files\Circle Dock 2010-07-25 13:27:18 0 d-----w- C:\Circle Dock AddIns 2010-07-23 14:51:49 0 d-----w- c:\program files\GameTop.com 2010-07-22 11:13:38 69296 ---ha-w- c:\windows\system32\mlfcache.dat 2010-07-21 14:24:47 0 d-----w- c:\docume~1\alluse~1\applic~1\Anvsoft 2010-07-21 14:24:46 0 d-----w- c:\docume~1\peeyus~1\applic~1\Wedding Album Maker 2010-07-21 14:24:17 0 d-----w- c:\program files\Wedding Album Maker Gold 2010-07-21 14:21:17 0 d--h--w- c:\windows\PIF 2010-07-13 14:55:04 0 d-----w- c:\docume~1\peeyus~1\applic~1\Vista Start Menu 2010-07-13 14:54:45 0 d-----w- c:\program files\Vista Start Menu 2010-07-11 12:10:31 0 d-----w- c:\program files\Dont Get Angry 3 2010-07-09 09:27:21 0 d-----w- c:\program files\FormatFactory 2010-07-08 08:50:07 0 d-----w- c:\program files\Essentials Codec Pack 2010-07-08 05:39:28 0 d-----w- c:\program files\AutocompletePro 2010-07-05 16:22:57 0 d-----w- c:\program files\foobar 2010-06-29 17:36:48 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2010-06-29 17:29:52 103424 ----a-w- c:\windows\system32\drivers\cmnsusbser.sys 2010-06-29 17:29:51 135168 ----a-w- c:\windows\system32\ChgService.exe 2010-06-29 17:29:51 103424 ----a-w- c:\windows\system32\MyDIT_GenClassCoInst.dll 2010-06-29 17:29:50 0 d-----w- c:\program files\MMX300G 3G USB Manager ==================== Find3M ==================== 2010-07-25 16:57:17 716272 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-07-09 20:47:55 29480 ----a-w- c:\windows\system32\msxml3a.dll 2010-06-19 04:55:53 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-18 08:44:46 7102 ----a-w- c:\windows\BricoPackFoldersDelete.cmd 2010-06-18 08:44:46 154080 ----a-w- c:\windows\BricoPackUninst.cmd 2010-06-18 08:27:50 2023936 ----a-w- c:\windows\system32\HFX285.tmp 2010-06-18 08:15:48 361344 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2010-06-17 15:16:48 218624 ----a-w- c:\windows\system32\uxtheme.dll 2010-06-17 14:39:43 21640 ----a-w- c:\windows\system32\emptyregdb.dat 2010-05-18 12:28:24 1085440 ----a-w- c:\windows\system32\VSFilter.dll 2010-05-17 20:17:52 108032 ----a-w- c:\windows\system32\ff_vfw.dll 2010-05-04 17:20:39 328192 ----a-w- c:\windows\system32\nsi158.tmp 2010-05-04 17:20:39 2522624 ----a-w- c:\windows\system32\Wininet.dll 2010-05-04 17:20:34 78336 ----a-w- c:\windows\system32\ieencode.dll 2010-05-04 17:20:32 17408 ----a-w- c:\windows\system32\corpol.dll 2010-05-02 05:22:50 1851264 ----a-w- c:\windows\system32\win32k.sys ============= FINISH: 18:00:51.85 =============== 2) UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 6/17/2010 8:16:55 PM System Uptime: 7/29/2010 5:46:33 PM (1 hours ago) Motherboard: Hewlett-Packard | | 3618 Processor: Intel(R) Core(TM)2 Duo CPU T5270 @ 1.40GHz | U10 | 1396/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 39 GiB total, 9.522 GiB free. D: is FIXED (NTFS) - 39 GiB total, 7.85 GiB free. E: is FIXED (NTFS) - 34 GiB total, 2.945 GiB free. F: is CDROM () G: is CDROM () H: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Device ID: ACPI\HPQ0006\2&DABA3FF&0 Manufacturer: Name: PNP Device ID: ACPI\HPQ0006\2&DABA3FF&0 Service: ==== System Restore Points =================== RP53: 7/7/2010 10:03:55 PM - Unsigned driver install RP54: 7/7/2010 11:12:37 PM - Unsigned driver install RP55: 7/7/2010 11:13:11 PM - Unsigned driver install RP56: 7/7/2010 11:17:58 PM - Unsigned driver install RP57: 7/9/2010 2:27:50 PM - Removed System Requirements Lab RP58: 7/9/2010 2:31:18 PM - Removed Ask Toolbar. RP59: 7/9/2010 5:26:55 PM - Removed Opera 10.54. RP60: 7/9/2010 5:27:11 PM - Installed Opera 10.60. RP61: 7/10/2010 2:16:51 AM - Configured PowerDVD RP62: 7/10/2010 2:18:03 AM - Installed PowerDVD RP63: 7/19/2010 1:37:50 PM - Unsigned driver install RP64: 7/19/2010 1:38:53 PM - Unsigned driver install RP65: 7/21/2010 1:48:23 AM - System Checkpoint RP66: 7/22/2010 3:12:57 PM - System Checkpoint RP67: 7/22/2010 4:42:56 PM - Installed Safari RP68: 7/24/2010 4:02:17 PM - System Checkpoint RP69: 7/25/2010 10:27:17 PM - SPTD setup V1.55 RP70: 7/25/2010 10:32:11 PM - Unsigned driver install RP71: 7/29/2010 4:23:37 PM - Installed Imploder RP72: 7/29/2010 4:33:29 PM - Installed Hunting Unlimited 2011 RP73: 7/29/2010 4:35:54 PM - Installed DirectX RP74: 7/29/2010 4:36:54 PM - Removed Imploder RP75: 7/29/2010 1:28:29 PM - Software Distribution Service 3.0 RP76: 7/29/2010 5:49:47 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== µTorrent 7-Zip 4.65 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Agere Systems HDA Modem Apple Application Support Apple Software Update AutocompletePro avast! Antivirus Broadcom 802.11 Wireless LAN Adapter CDCheck Circle Dock Classic Menu 4.x for Office 2007 ClearType Tuning Control Panel Applet CursorXP CyberLink PowerDVD 10 FormatFactory 2.40 Foxit Reader Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) HP Integrated Module with Bluetooth wireless technology Hunting Unlimited 2011 iColorFolder Intel(R) Graphics Media Accelerator Driver Intel(R) PRO Network Connections Drivers Java Auto Updater Java(TM) 6 Update 20 Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Software Update for Web Folders (English) 14 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 MMX300G 3G USB Manager version 5.254 Opera 10.60 Pack LeopardXP 1.0 Photo Resize Magic 1.1 Safari Sandboxie 3.44 Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Skype™ 4.2 SoundMAX Splinter Cell Gold Edition Styler Synaptics Pointing Device Driver Trillian Ubuntu Unlocker 1.8.9 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows XP (KB898461) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973815) USB Disk Security Vista Codec Package Vista Start Menu 3.31 VLC media player 1.1.0 WebFldrs XP Windows Essentials Media Codec Pack 3.0 [32-Bit] Windows Media Format 11 runtime Windows Media Player 11 Yahoo! Messenger ==== Event Viewer Messages From Past Week ======== 7/29/2010 9:33:18 PM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -172776 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.nist.gov (ntp.m|0x1|180.178.20.92:123->192.43.244.18:123) is working properly. 7/29/2010 12:19:29 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP Fips intelppm 7/29/2010 12:18:41 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} 7/29/2010 12:18:25 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/24/2010 4:11:13 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\D. 7/23/2010 9:40:13 AM, error: Service Control Manager [7000] - The Windows Service Pack Installer update service service failed to start due to the following error: Access is denied. 7/23/2010 12:02:00 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 7/22/2010 9:57:46 PM, error: Print [23] - Printer Send To OneNote 2010 failed to initialize because a suitable Send To Microsoft OneNote 2010 Driver driver could not be found. 7/22/2010 4:00:00 PM, error: Schedule [7901] - The At1.job command failed to start due to the following error: %%2147942402 7/22/2010 10:53:56 PM, error: PlugPlayManager [12] - The device 'Intel(R) 82562GT 10/100 Network Connection' (PCI\VEN_8086&DEV_10C4&SUBSYS_30D8103C&REV_04\3&b1bfb68&0&C8) disappeared from the system without first being prepared for removal. ==== End Of File =========================== |
|
29-Jul-2010, 09:33 AM
#4 |
| thanks for this quick reply and sorry for my english. the two reports are as : DDS (Ver_10-03-17.01) - NTFSx86 Run by Peeyush Kumar at 18:00:17.92 on Thu 07/29/2010 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.371 [GMT 5.5:30] AV: avast! antivirus 4.8.1368 [VPS 100728-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\agrsmsvc.exe C:\WINDOWS\system32\ChgService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Sandboxie\SbieSvc.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\USB Disk Security\USBGuard.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files\Cyberlink\Shared files\brs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Vista Start Menu\VistaStartMenu.exe C:\Program Files\Circle Dock\CircleDock.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\WINDOWS\BricoPacks\LeopardXP\Glass2k.exe C:\Program Files\MacSearch_v.1.4.3\MacSearch.exe C:\Program Files\RK Launcher\RK Launcher 0.41 Beta Nightly\RKLauncher.exe C:\Program Files\tclock2_120\tclock2.exe C:\Program Files\UberIcon\UberIcon Manager.exe C:\Program Files\CursorXP\CursorXP.exe D:\desktop customization\WFlip050\WinFlip.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\Program Files\MMX300G 3G USB Manager\USB Modem.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\opera\opera.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Peeyush Kumar\Desktop\dds.com ============== Pseudo HJT Report =============== BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: AC-Pro: {0fb6a909-6086-458f-bd92-1f8ee10042a0} - c:\program files\autocompletepro\AutocompletePro.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Loader Class: {f880a4a8-c436-4ac4-afd1-aa0bdc9552dd} - c:\windows\bricopacks\leopardxp\FindeXer.dll TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [CursorXP] "c:\program files\cursorxp\CursorXP.exe" -s uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [VistaStartMenu] "c:\program files\vista start menu\VistaStartMenu.exe" uRun: [CircleDock] c:\program files\circle dock\CircleDock.exe uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe" mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [RemoteControl10] "c:\program files\cyberlink\powerdvd10\PDVD10Serv.exe" mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\glass2k.lnk - c:\windows\bricopacks\leopardxp\Glass2k.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\macsea~1.lnk - c:\program files\macsearch_v.1.4.3\MacSearch.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\panthe~1.lnk - c:\program files\cursorxp\themes\panther.CurXPTheme StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\rklaun~1.lnk - c:\program files\rk launcher\rk launcher 0.41 beta nightly\RKLauncher.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\tclock2.lnk - c:\program files\tclock2_120\tclock2.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\ubericon.lnk - c:\program files\ubericon\UberIcon Manager.exe StartupFolder: c:\docume~1\peeyus~1\startm~1\programs\startup\winflip.lnk - d:\desktop customization\wflip050\WinFlip.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1) mPolicies-system: SynchronousMachineGroupPolicy = 0 (0x0) mPolicies-system: SynchronousUserGroupPolicy = 0 (0x0) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab TCP: {A59B6824-09C2-4100-AD13-43C7D8AEDE3F} = 202.138.96.2 4.2.2.2 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL Hosts: 66.98.148.65 auto.search.msn.com Hosts: 66.98.148.65 auto.search.msn.es ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2010-6-17 114768] R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/06/19 13:41:56];c:\program files\cyberlink\powerdvd10\navfilter\000.fcl [2010-4-2 87536] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-17 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2010-6-17 138680] R2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [2010-6-29 135168] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-6-17 304464] R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2010-6-17 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2010-6-17 352920] R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\drivers\cmnsusbser.sys [2010-6-29 103424] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-6-17 20952] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2010-2-3 115432] S3 cpuz130;cpuz130;\??\c:\docume~1\peeyus~1\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\peeyus~1\locals~1\temp\cpuz130\cpuz_x32.sys [?] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] =============== Created Last 30 ================ 2010-07-29 15:44:16 0 d-----r- C:\Sandbox 2010-07-29 15:42:18 1548 ----a-w- c:\windows\Sandboxie.ini 2010-07-29 15:42:10 0 d-----w- c:\program files\Sandboxie 2010-07-29 11:10:47 0 d-----w- c:\docume~1\peeyus~1\applic~1\HU2011 2010-07-29 11:03:34 0 d-----w- c:\program files\Hunting Unlimited 2011 2010-07-26 20:57:46 0 d-----w- c:\program files\Xenocode 2010-07-26 20:57:27 0 d-----w- c:\program files\High Quality Photo Resizer 2010-07-25 17:01:36 334792 ----a-w- c:\windows\system32\_AxShlEx.dll 2010-07-25 17:00:38 0 d-----w- c:\program files\Alcohol Soft 2010-07-25 16:24:08 0 d-----w- c:\program files\Photo Resize Magic 2010-07-25 15:49:36 78 ----a-w- c:\documents and settings\peeyush kumar\Config.INI 2010-07-25 15:49:36 54 ----a-w- c:\documents and settings\peeyush kumar\score.DAT 2010-07-25 13:27:18 0 d-----w- c:\program files\Circle Dock 2010-07-25 13:27:18 0 d-----w- C:\Circle Dock AddIns 2010-07-23 14:51:49 0 d-----w- c:\program files\GameTop.com 2010-07-22 11:13:38 69296 ---ha-w- c:\windows\system32\mlfcache.dat 2010-07-21 14:24:47 0 d-----w- c:\docume~1\alluse~1\applic~1\Anvsoft 2010-07-21 14:24:46 0 d-----w- c:\docume~1\peeyus~1\applic~1\Wedding Album Maker 2010-07-21 14:24:17 0 d-----w- c:\program files\Wedding Album Maker Gold 2010-07-21 14:21:17 0 d--h--w- c:\windows\PIF 2010-07-13 14:55:04 0 d-----w- c:\docume~1\peeyus~1\applic~1\Vista Start Menu 2010-07-13 14:54:45 0 d-----w- c:\program files\Vista Start Menu 2010-07-11 12:10:31 0 d-----w- c:\program files\Dont Get Angry 3 2010-07-09 09:27:21 0 d-----w- c:\program files\FormatFactory 2010-07-08 08:50:07 0 d-----w- c:\program files\Essentials Codec Pack 2010-07-08 05:39:28 0 d-----w- c:\program files\AutocompletePro 2010-07-05 16:22:57 0 d-----w- c:\program files\foobar 2010-06-29 17:36:48 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2010-06-29 17:29:52 103424 ----a-w- c:\windows\system32\drivers\cmnsusbser.sys 2010-06-29 17:29:51 135168 ----a-w- c:\windows\system32\ChgService.exe 2010-06-29 17:29:51 103424 ----a-w- c:\windows\system32\MyDIT_GenClassCoInst.dll 2010-06-29 17:29:50 0 d-----w- c:\program files\MMX300G 3G USB Manager ==================== Find3M ==================== 2010-07-25 16:57:17 716272 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-07-09 20:47:55 29480 ----a-w- c:\windows\system32\msxml3a.dll 2010-06-19 04:55:53 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-18 08:44:46 7102 ----a-w- c:\windows\BricoPackFoldersDelete.cmd 2010-06-18 08:44:46 154080 ----a-w- c:\windows\BricoPackUninst.cmd 2010-06-18 08:27:50 2023936 ----a-w- c:\windows\system32\HFX285.tmp 2010-06-18 08:15:48 361344 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2010-06-17 15:16:48 218624 ----a-w- c:\windows\system32\uxtheme.dll 2010-06-17 14:39:43 21640 ----a-w- c:\windows\system32\emptyregdb.dat 2010-05-18 12:28:24 1085440 ----a-w- c:\windows\system32\VSFilter.dll 2010-05-17 20:17:52 108032 ----a-w- c:\windows\system32\ff_vfw.dll 2010-05-04 17:20:39 328192 ----a-w- c:\windows\system32\nsi158.tmp 2010-05-04 17:20:39 2522624 ----a-w- c:\windows\system32\Wininet.dll 2010-05-04 17:20:34 78336 ----a-w- c:\windows\system32\ieencode.dll 2010-05-04 17:20:32 17408 ----a-w- c:\windows\system32\corpol.dll 2010-05-02 05:22:50 1851264 ----a-w- c:\windows\system32\win32k.sys ============= FINISH: 18:00:51.85 =============== 2) UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 6/17/2010 8:16:55 PM System Uptime: 7/29/2010 5:46:33 PM (1 hours ago) Motherboard: Hewlett-Packard | | 3618 Processor: Intel(R) Core(TM)2 Duo CPU T5270 @ 1.40GHz | U10 | 1396/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 39 GiB total, 9.522 GiB free. D: is FIXED (NTFS) - 39 GiB total, 7.85 GiB free. E: is FIXED (NTFS) - 34 GiB total, 2.945 GiB free. F: is CDROM () G: is CDROM () H: is Removable ==== Disabled Device Manager Items ============= Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Device ID: ACPI\HPQ0006\2&DABA3FF&0 Manufacturer: Name: PNP Device ID: ACPI\HPQ0006\2&DABA3FF&0 Service: ==== System Restore Points =================== RP53: 7/7/2010 10:03:55 PM - Unsigned driver install RP54: 7/7/2010 11:12:37 PM - Unsigned driver install RP55: 7/7/2010 11:13:11 PM - Unsigned driver install RP56: 7/7/2010 11:17:58 PM - Unsigned driver install RP57: 7/9/2010 2:27:50 PM - Removed System Requirements Lab RP58: 7/9/2010 2:31:18 PM - Removed Ask Toolbar. RP59: 7/9/2010 5:26:55 PM - Removed Opera 10.54. RP60: 7/9/2010 5:27:11 PM - Installed Opera 10.60. RP61: 7/10/2010 2:16:51 AM - Configured PowerDVD RP62: 7/10/2010 2:18:03 AM - Installed PowerDVD RP63: 7/19/2010 1:37:50 PM - Unsigned driver install RP64: 7/19/2010 1:38:53 PM - Unsigned driver install RP65: 7/21/2010 1:48:23 AM - System Checkpoint RP66: 7/22/2010 3:12:57 PM - System Checkpoint RP67: 7/22/2010 4:42:56 PM - Installed Safari RP68: 7/24/2010 4:02:17 PM - System Checkpoint RP69: 7/25/2010 10:27:17 PM - SPTD setup V1.55 RP70: 7/25/2010 10:32:11 PM - Unsigned driver install RP71: 7/29/2010 4:23:37 PM - Installed Imploder RP72: 7/29/2010 4:33:29 PM - Installed Hunting Unlimited 2011 RP73: 7/29/2010 4:35:54 PM - Installed DirectX RP74: 7/29/2010 4:36:54 PM - Removed Imploder RP75: 7/29/2010 1:28:29 PM - Software Distribution Service 3.0 RP76: 7/29/2010 5:49:47 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== µTorrent 7-Zip 4.65 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Agere Systems HDA Modem Apple Application Support Apple Software Update AutocompletePro avast! Antivirus Broadcom 802.11 Wireless LAN Adapter CDCheck Circle Dock Classic Menu 4.x for Office 2007 ClearType Tuning Control Panel Applet CursorXP CyberLink PowerDVD 10 FormatFactory 2.40 Foxit Reader Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) HP Integrated Module with Bluetooth wireless technology Hunting Unlimited 2011 iColorFolder Intel(R) Graphics Media Accelerator Driver Intel(R) PRO Network Connections Drivers Java Auto Updater Java(TM) 6 Update 20 Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Software Update for Web Folders (English) 14 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 MMX300G 3G USB Manager version 5.254 Opera 10.60 Pack LeopardXP 1.0 Photo Resize Magic 1.1 Safari Sandboxie 3.44 Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Skype™ 4.2 SoundMAX Splinter Cell Gold Edition Styler Synaptics Pointing Device Driver Trillian Ubuntu Unlocker 1.8.9 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows XP (KB898461) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973815) USB Disk Security Vista Codec Package Vista Start Menu 3.31 VLC media player 1.1.0 WebFldrs XP Windows Essentials Media Codec Pack 3.0 [32-Bit] Windows Media Format 11 runtime Windows Media Player 11 Yahoo! Messenger ==== Event Viewer Messages From Past Week ======== 7/29/2010 9:33:18 PM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -172776 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.nist.gov (ntp.m|0x1|180.178.20.92:123->192.43.244.18:123) is working properly. 7/29/2010 12:19:29 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP Fips intelppm 7/29/2010 12:18:41 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} 7/29/2010 12:18:25 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/24/2010 4:11:13 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\D. 7/23/2010 9:40:13 AM, error: Service Control Manager [7000] - The Windows Service Pack Installer update service service failed to start due to the following error: Access is denied. 7/23/2010 12:02:00 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 7/22/2010 9:57:46 PM, error: Print [23] - Printer Send To OneNote 2010 failed to initialize because a suitable Send To Microsoft OneNote 2010 Driver driver could not be found. 7/22/2010 4:00:00 PM, error: Schedule [7901] - The At1.job command failed to start due to the following error: %%2147942402 7/22/2010 10:53:56 PM, error: PlugPlayManager [12] - The device 'Intel(R) 82562GT 10/100 Network Connection' (PCI\VEN_8086&DEV_10C4&SUBSYS_30D8103C&REV_04\3&b1bfb68&0&C8) disappeared from the system without first being prepared for removal. ==== End Of File =========================== |
29-Jul-2010, 10:15 AM
#5 | |||||
| Delete any existing version of ComboFix you have sitting on your desktop Please read and follow all these instructions very carefully Download ComboFix from Here or Hereto your Desktop. **Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer** -------------------------------------------------------------------- 1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
2. Close any open browsers and any other programs you might have running Double click on combofix.exe & follow the prompts. If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?"Please select yes & let it download the files it needs to do this When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze **** Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser. Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell us when you reply. Read HERE why we disable autoruns Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version. Please tell us if it has cured the problems or if there are any outstanding issues
__________________ Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue |
|
29-Jul-2010, 11:06 AM
#6 |
| thank you, I want to tell you that when executed combofix.exe it restarted my laptop and asked for an internet connection so i had to start my usb network manager manually from task manager, sorry if this has caused any problem. the report is as : ComboFix 10-07-28.03 - Peeyush Kumar 07/29/2010 19:19:56.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.567 [GMT 5.5:30] Running from: c:\documents and settings\Peeyush Kumar\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 100728-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_OSPPSVC -------\Service_osppsvc ((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-29 ))))))))))))))))))))))))))))))) . 2010-07-29 15:44 . 2010-07-29 15:44 -------- d-----r- C:\Sandbox 2010-07-29 15:42 . 2010-07-29 15:42 -------- d-----w- c:\program files\Sandboxie 2010-07-29 11:10 . 2010-07-29 11:55 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\HU2011 2010-07-29 11:03 . 2010-07-29 11:10 -------- d-----w- c:\program files\Hunting Unlimited 2011 2010-07-26 20:57 . 2010-07-26 20:57 -------- d-----w- c:\program files\Xenocode 2010-07-26 20:57 . 2010-07-26 20:57 -------- d-----w- c:\documents and settings\Peeyush Kumar\Local Settings\Application Data\Xenocode 2010-07-26 20:57 . 2010-07-29 11:06 -------- d-----w- c:\program files\High Quality Photo Resizer 2010-07-25 17:01 . 2008-02-22 11:30 334792 ----a-w- c:\windows\system32\_AxShlEx.dll 2010-07-25 17:00 . 2010-07-25 17:00 -------- d-----w- c:\program files\Alcohol Soft 2010-07-25 16:24 . 2010-07-25 16:37 -------- d-----w- c:\program files\Photo Resize Magic 2010-07-25 15:49 . 2010-07-25 15:55 54 ----a-w- c:\documents and settings\Peeyush Kumar\score.DAT 2010-07-25 13:27 . 2010-07-25 13:27 -------- d-----w- c:\documents and settings\Peeyush Kumar\Local Settings\Application Data\CircleDock 2010-07-25 13:27 . 2010-07-25 13:27 -------- d-----w- c:\program files\Circle Dock 2010-07-25 13:27 . 2010-07-25 13:27 -------- d-----w- C:\Circle Dock AddIns 2010-07-23 14:51 . 2010-07-23 14:51 -------- d-----w- c:\program files\GameTop.com 2010-07-22 11:13 . 2010-07-22 11:13 69296 ---ha-w- c:\windows\system32\mlfcache.dat 2010-07-22 11:13 . 2010-07-22 11:13 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Apple Computer 2010-07-22 11:13 . 2010-07-22 11:13 -------- d-----w- c:\documents and settings\Peeyush Kumar\Local Settings\Application Data\Apple Computer 2010-07-22 11:13 . 2010-07-22 11:13 -------- d-----w- c:\program files\Safari 2010-07-22 11:13 . 2010-07-22 11:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2010-07-22 11:12 . 2010-07-22 11:12 -------- d-----w- c:\program files\Common Files\Apple 2010-07-22 11:12 . 2010-07-22 11:12 -------- d-----w- c:\documents and settings\Peeyush Kumar\Local Settings\Application Data\Apple 2010-07-22 11:12 . 2010-07-22 11:12 -------- d-----w- c:\program files\Apple Software Update 2010-07-22 11:12 . 2010-07-22 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple 2010-07-21 14:24 . 2010-07-21 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Anvsoft 2010-07-21 14:24 . 2010-07-21 14:24 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Wedding Album Maker 2010-07-21 14:24 . 2010-07-29 11:08 -------- d-----w- c:\program files\Wedding Album Maker Gold 2010-07-21 14:21 . 2010-07-21 14:21 -------- d--h--w- c:\windows\PIF 2010-07-13 19:00 . 2010-07-20 07:14 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\dvdcss 2010-07-13 14:55 . 2010-07-29 09:57 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Vista Start Menu 2010-07-13 14:54 . 2010-07-13 14:59 -------- d-----w- c:\program files\Vista Start Menu 2010-07-11 12:10 . 2010-07-29 11:06 -------- d-----w- c:\program files\Dont Get Angry 3 2010-07-09 20:48 . 2010-07-09 20:47 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe 2010-07-09 09:27 . 2010-07-09 09:27 -------- d-----w- c:\program files\FormatFactory 2010-07-08 11:08 . 2010-07-28 19:15 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\vlc 2010-07-08 08:50 . 2010-07-08 08:50 -------- d-----w- c:\program files\Essentials Codec Pack 2010-07-08 05:39 . 2010-07-08 05:39 -------- d-----w- c:\program files\AutocompletePro 2010-07-05 16:22 . 2010-07-05 16:23 -------- d-----w- c:\program files\foobar 2010-06-29 17:36 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2010-06-29 17:29 . 2009-12-17 04:52 103424 ----a-w- c:\windows\system32\drivers\cmnsusbser.sys 2010-06-29 17:29 . 2010-02-25 07:56 135168 ----a-w- c:\windows\system32\ChgService.exe 2010-06-29 17:29 . 2009-12-17 04:52 103424 ----a-w- c:\windows\system32\MyDIT_GenClassCoInst.dll 2010-06-29 17:29 . 2010-06-29 17:20 -------- d-----w- c:\program files\MMX300G 3G USB Manager . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-29 13:10 . 2010-06-18 08:43 -------- d-----w- c:\program files\MacSearch_v.1.4.3 2010-07-29 11:03 . 2010-06-17 14:56 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-07-29 09:48 . 2010-06-17 15:45 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\uTorrent 2010-07-25 18:08 . 2010-06-17 16:21 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Skype 2010-07-25 18:01 . 2010-06-17 16:22 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\skypePM 2010-07-25 17:36 . 2010-06-17 15:33 -------- d-----w- c:\program files\Trillian 2010-07-25 16:57 . 2010-06-18 06:33 716272 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-07-23 09:30 . 2010-06-18 07:16 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-07-09 20:47 . 2010-06-19 08:10 29480 ----a-w- c:\windows\system32\msxml3a.dll 2010-07-09 20:46 . 2010-06-19 08:09 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}\PostBuild.exe 2010-07-09 11:57 . 2010-06-17 16:14 -------- d-----w- c:\program files\Opera 2010-07-09 11:49 . 2010-06-29 07:55 -------- d-----w- c:\program files\Yahoo! 2010-07-09 09:01 . 2010-06-29 08:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! 2010-06-29 08:59 . 2010-06-29 08:58 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Yahoo! 2010-06-27 12:30 . 2010-06-27 12:26 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\MagicBall4 2010-06-27 02:24 . 2010-06-17 15:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-06-25 07:39 . 2010-06-25 07:39 -------- d-----w- c:\program files\CDCheck 2010-06-23 09:51 . 2010-06-17 15:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Zbshareware Lab 2010-06-22 16:36 . 2010-06-22 16:36 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\TeamViewer 2010-06-22 13:41 . 2010-06-22 13:41 -------- d-----w- c:\program files\VistaCodecPack 2010-06-22 13:41 . 2010-06-22 13:41 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\VistaCodecs 2010-06-22 13:41 . 2010-06-22 13:41 -------- d-----w- c:\documents and settings\All Users\Application Data\VistaCodecs 2010-06-22 13:38 . 2010-06-17 16:16 -------- d-----r- c:\program files\Skype 2010-06-22 13:37 . 2010-06-17 20:53 -------- d-----w- c:\program files\Combined Community Codec Pack 2010-06-21 17:17 . 2010-06-21 17:17 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Media Player Classic 2010-06-20 21:19 . 2010-06-20 21:19 -------- d-----w- c:\program files\Babylon 2010-06-19 09:45 . 2010-06-19 09:41 -------- d-----w- c:\program files\Splinter Cell Gold 2010-06-19 08:19 . 2010-06-19 08:18 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Ashampoo 2010-06-19 08:14 . 2010-06-19 08:12 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\CyberLink 2010-06-19 08:12 . 2010-06-19 08:11 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink 2010-06-19 08:11 . 2010-06-19 08:10 -------- d-----w- c:\program files\CyberLink 2010-06-19 08:11 . 2010-06-19 08:11 -------- d-----w- c:\program files\Common Files\CyberLink 2010-06-19 05:09 . 2010-06-19 05:09 -------- d-----w- c:\program files\Unlocker 2010-06-19 05:00 . 2010-06-18 06:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-06-19 04:57 . 2010-06-19 04:57 503808 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e7d2f02-n\msvcp71.dll 2010-06-19 04:57 . 2010-06-19 04:57 499712 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e7d2f02-n\jmc.dll 2010-06-19 04:57 . 2010-06-19 04:57 348160 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4e7d2f02-n\msvcr71.dll 2010-06-19 04:56 . 2010-06-19 04:56 -------- d-----w- c:\program files\Common Files\Java 2010-06-19 04:56 . 2010-06-19 04:56 12800 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-702a2a62-n\decora-d3d.dll 2010-06-19 04:56 . 2010-06-19 04:56 61440 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-702a2a62-n\decora-sse.dll 2010-06-19 04:55 . 2010-06-19 04:56 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-06-19 04:55 . 2010-06-19 04:55 -------- d-----w- c:\program files\Java 2010-06-19 04:55 . 2010-06-19 04:55 79488 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll 2010-06-19 04:55 . 2010-06-19 04:55 152576 ----a-w- c:\documents and settings\Peeyush Kumar\Application Data\Sun\Java\jre1.6.0_20\lzma.dll 2010-06-18 22:53 . 2010-06-17 14:42 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2010-06-18 08:47 . 2010-06-18 08:47 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\FindeXer 2010-06-18 08:46 . 2010-06-17 15:15 -------- d-----w- c:\program files\iColorFolder 2010-06-18 08:44 . 2010-06-18 08:40 7102 ----a-w- c:\windows\BricoPackFoldersDelete.cmd 2010-06-18 08:44 . 2010-06-17 15:16 154080 ----a-w- c:\windows\BricoPackUninst.cmd 2010-06-18 08:43 . 2010-06-18 08:43 -------- d-----w- c:\program files\tclock2_120 2010-06-18 08:43 . 2010-06-17 15:15 -------- d-----w- c:\program files\CursorXP 2010-06-18 08:43 . 2010-06-18 08:43 -------- d-----w- c:\program files\TrueTransparency 2010-06-18 08:43 . 2010-06-18 08:43 -------- d-----w- c:\program files\UberIcon 2010-06-18 08:43 . 2010-06-18 08:43 -------- d-----w- c:\program files\YzShadow 2010-06-18 08:27 . 2010-06-18 08:27 2023936 ----a-w- c:\windows\system32\HFX285.tmp 2010-06-18 08:15 . 2010-06-18 08:15 361344 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL 2010-06-18 07:46 . 2010-06-17 15:08 84528 ----a-w- c:\documents and settings\Peeyush Kumar\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-06-18 07:16 . 2010-06-18 07:16 -------- d-----w- c:\program files\Classic Menu for Office 2010-06-18 06:47 . 2010-06-17 19:32 -------- d-----w- c:\program files\MSBuild 2010-06-18 06:46 . 2010-06-18 06:46 -------- d-----w- c:\program files\Microsoft Synchronization Services 2010-06-18 06:45 . 2010-06-18 06:45 -------- d-----w- c:\program files\Microsoft.NET 2010-06-18 06:45 . 2010-06-18 06:45 -------- d-----w- c:\program files\Microsoft Sync Framework 2010-06-18 06:45 . 2010-06-18 06:45 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition 2010-06-18 06:44 . 2010-06-18 06:44 -------- d-----w- c:\program files\Microsoft Visual Studio 8 2010-06-18 06:43 . 2010-06-18 06:43 -------- d-----w- c:\program files\Microsoft Analysis Services 2010-06-18 06:41 . 2010-06-18 06:37 -------- d-----w- c:\program files\DAEMON Tools Pro 2010-06-18 06:40 . 2010-06-18 06:39 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro 2010-06-18 06:39 . 2010-06-18 06:38 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\DAEMON Tools Pro 2010-06-17 20:34 . 2010-06-17 20:34 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Styler 2010-06-17 20:34 . 2010-06-17 20:33 -------- d-----w- c:\program files\Styler 2010-06-17 20:33 . 2010-06-17 20:33 15086 ----a-r- c:\documents and settings\Peeyush Kumar\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_7b12541d.exe 2010-06-17 20:33 . 2010-06-17 20:33 15086 ----a-r- c:\documents and settings\Peeyush Kumar\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe 2010-06-17 19:32 . 2010-06-17 19:32 -------- d-----w- c:\program files\Reference Assemblies 2010-06-17 16:22 . 2010-06-17 16:22 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2010-06-17 16:17 . 2010-06-17 15:37 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Trillian 2010-06-17 16:16 . 2010-06-17 16:16 -------- d-----w- c:\program files\Common Files\Skype 2010-06-17 16:16 . 2010-06-17 16:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2010-06-17 15:58 . 2010-06-17 15:58 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Malwarebytes 2010-06-17 15:58 . 2010-06-17 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-06-17 15:47 . 2010-06-17 15:47 -------- d-----w- c:\program files\Foxit Software 2010-06-17 15:47 . 2010-06-17 15:47 -------- d-----w- c:\documents and settings\Peeyush Kumar\Application Data\Foxit 2010-06-17 15:45 . 2010-06-17 15:45 -------- d-----w- c:\program files\uTorrent 2010-06-17 15:29 . 2010-06-17 15:29 -------- d-----w- c:\program files\7-Zip 2010-06-17 15:24 . 2010-06-17 15:24 -------- d-----w- c:\program files\USB Disk Security 2010-06-17 15:16 . 2008-04-14 00:42 218624 ----a-w- c:\windows\system32\uxtheme.dll 2010-06-17 15:16 . 2010-06-17 15:16 -------- d-----w- c:\program files\RK Launcher 2010-06-17 15:11 . 2010-06-17 15:11 -------- d-----w- c:\program files\VideoLAN 2010-06-17 15:10 . 2010-06-17 15:10 -------- d-----w- c:\program files\Alwil Software 2010-06-17 15:05 . 2010-06-17 15:05 -------- d-----w- c:\program files\Synaptics 2010-06-17 15:03 . 2010-06-17 15:03 -------- d-----w- c:\program files\WIDCOMM 2010-06-17 15:01 . 2010-06-17 15:01 -------- d-----w- c:\program files\Broadcom 2010-06-17 15:01 . 2010-06-17 14:56 -------- d-----w- c:\program files\Common Files\InstallShield 2010-06-17 14:59 . 2010-06-17 14:59 -------- d-----w- c:\program files\Intel 2010-06-17 14:56 . 2010-06-17 14:56 -------- d-----w- c:\program files\Analog Devices 2010-06-17 14:44 . 2010-06-17 14:44 -------- d-----w- c:\program files\microsoft frontpage 2010-06-17 14:39 . 2010-06-17 14:39 21640 ----a-w- c:\windows\system32\emptyregdb.dat 2010-06-17 14:39 . 2010-06-17 14:39 -------- d-----w- c:\program files\Windows Media Connect 2 2010-06-04 06:59 . 2010-06-04 06:59 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe 2010-05-18 12:28 . 2010-05-18 12:28 1085440 ----a-w- c:\windows\system32\VSFilter.dll 2010-05-17 20:17 . 2010-05-17 20:17 108032 ----a-w- c:\windows\system32\ff_vfw.dll . ------- Sigcheck ------- [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\atapi.sys [-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\asyncmac.sys [-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys [-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys [-] 2001-08-23 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys [-] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ndis.sys [-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ntfs.sys [-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys [-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys [-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys [-] 2010-06-18 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys [-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll [-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\browser.dll [-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe [-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\lsass.exe [-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll [-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\netman.dll [-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll [-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\system32\dllcache\qmgr.dll [-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3GDR\rpcss.dll [-] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3QFE\rpcss.dll [-] 2009-02-09 . 01095FEBF33BEEA00C2A0730B9B3EC28 . 399360 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2GDR\rpcss.dll [-] 2009-02-09 . 24B5D53B9ACCC1E2EDCF0A878D6659D4 . 401408 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2QFE\rpcss.dll [-] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\system32\rpcss.dll [-] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\rpcss.dll [-] 2009-02-06 . 37561F8D4160D62DA86D24AE41FAE8DE . 110592 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2GDR\services.exe [-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3GDR\services.exe [-] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3QFE\services.exe [-] 2009-02-06 . 4712531AB7A01B7EE059853CA17D39BD . 110592 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2QFE\services.exe [-] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\system32\services.exe [-] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\services.exe [-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe [-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\spoolsv.exe [-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe [-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe [-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\system32\comctl32.dll [-] 2001-08-23 . 8D94786F48553651FDB92CE307D23B95 . 1492992 . . [6.0] . . c:\windows\system32\dllcache\comctl32.dll [-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll [-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\cryptsvc.dll [-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\s p3gdr\es.dll [-] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\SoftwareDistribution\Download\8cac00e8efc87d728c0261686f85c975\s p3qfe\es.dll [-] 2008-04-14 00:41 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\system32\es.dll [-] 2008-04-14 00:41 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\system32\dllcache\es.dll [-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll [-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\imm32.dll [-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\s p3gdr\kernel32.dll [-] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\SoftwareDistribution\Download\022593ca08eb4cd8e9681a7116f902d9\s p3qfe\kernel32.dll [-] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\system32\kernel32.dll [-] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\kernel32.dll [-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll [-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\linkinfo.dll [-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll [-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\lpk.dll [-] 2010-05-04 . 3D0173AEFB8E60E3FC03DE2002EDF058 . 6797824 . . [7.00.6000.17063] . . c:\windows\system32\mshtml.dll [-] 2010-05-04 . 3D0173AEFB8E60E3FC03DE2002EDF058 . 6797824 . . [7.00.6000.17063] . . c:\windows\system32\dllcache\mshtml.dll [-] 2010-05-04 . C466BDCDFAE6F6EFD618F34BA90B1923 . 3603456 . . [7.00.6000.21264] . . c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\mshtml.dll [-] 2008-06-24 . 65D045264A1781E24AAD47AAC2757222 . 6789632 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB982381-IE7\mshtml.dll [-] 2008-06-23 . 28B8231CA8D55FC85E027A57C90F5C88 . 3594240 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll [-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll [-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\dllcache\msvcrt.dll [-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\mswsock.dll [-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\mswsock.dll [-] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll [-] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\mswsock.dll [-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll [-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\netlogon.dll [-] 2010-02-17 . D41C3CBAD0E1C0728D1CDFD541F60CFA . 2189952 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P3GDR\ntoskrnl.exe [-] 2010-02-16 . 97E2BF68857818A4D142B872404DC41B . 2186880 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P2QFE\ntoskrnl.exe [-] 2010-02-16 . EBB75B113E74E90074382347B74D652B . 2181376 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P2GDR\ntoskrnl.exe [-] 2010-02-16 . E1F653A542449D54FA2D27463D99B6B6 . 2190080 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P3QFE\ntoskrnl.exe [-] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3QFE\ntoskrnl.exe [-] 2009-02-06 . FACEBB0CA3154F77009CDFEE78A00BBB . 2180480 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2GDR\ntoskrnl.exe [-] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3GDR\ntoskrnl.exe [-] 2009-02-06 . 6A936E9D7BADAF3CAAEED1E1966EC1B0 . 2186112 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2QFE\ntoskrnl.exe [-] 2008-04-13 . 40F8880122A030A7E9E1FEDEA833B33D . 2145280 . . [5.1.2600.5512] . . c:\windows\system32\ntoskrnl.exe [-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll [-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\powrprof.dll [-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll [-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\scecli.dll [-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll [-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\sfc.dll [-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe [-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\svchost.exe [-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll [-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\tapisrv.dll [-] 2008-04-14 . 93FFACC9A9B610BFA20364CC481BD87A . 571904 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll [-] 2008-04-14 . 93FFACC9A9B610BFA20364CC481BD87A . 571904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll [-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe [-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\userinit.exe [-] 2010-05-04 . 43A6DAC870B472D0DB7F2EA997884285 . 2522624 . . [7.00.6000.17055] . . c:\windows\system32\Wininet.dll [-] 2010-05-04 . 43A6DAC870B472D0DB7F2EA997884285 . 2522624 . . [7.00.6000.17055] . . c:\windows\system32\dllcache\Wininet.dll [-] 2010-05-04 . 506B3DCB9C26070072E3047C6910F844 . 841216 . . [7.00.6000.21256] . . c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\wininet.dll [-] 2008-06-23 . C66402A06B83B036C195242C0C8CF83C . 827904 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll [-] 2008-06-23 . 01C133B3CBB8B4C67BCD70765FCF71C2 . 2516480 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB982381-IE7\wininet.dll [-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll [-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ws2_32.dll [-] 2008-04-14 . 9789E95E1D88EEB4B922BF3EA7779C28 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll [-] 2008-04-14 . 9789E95E1D88EEB4B922BF3EA7779C28 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ws2help.dll [-] 2008-04-14 . 9E232A4DE04D746E39F08B28B05A1520 . 3188736 . . [6.00.2900.5512] . . c:\windows\explorer.exe [-] 2008-04-14 . 9E232A4DE04D746E39F08B28B05A1520 . 3188736 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe [-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll [-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\srsvc.dll [-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe [-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\wscntfy.exe [-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll [-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\xmlprov.dll [-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll [-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\eventlog.dll [-] 2008-08-29 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll [-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe [-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ctfmon.exe [-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll [-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\shsvcs.dll [-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll [-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\regsvc.dll [-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll [-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\schedsvc.dll [-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll [-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ssdpsrv.dll [-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll [-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\termsrv.dll [-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll [-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\appmgmts.dll [-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys [-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\dllcache\aec.sys [-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\ip6fw.sys [-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys [-] 2008-04-14 00:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll [-] 2008-04-14 00:41 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\system32\dllcache\mfc40u.dll [-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll [-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\msgsvc.dll [-] 2008-08-29 22:12 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll [-] 2008-08-29 22:12 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll [-] 2010-02-17 . 1811AFC2FADB60B88947E3D08E250860 . 2063744 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P2QFE\ntkrnlpa.exe [-] 2010-02-16 . A046C627EC20456E2959B7BD628E1FD0 . 2066816 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P3GDR\ntkrnlpa.exe [-] 2010-02-16 . 1EE6B94ACA7BE115A1813BBCA65099A8 . 2058368 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P2GDR\ntkrnlpa.exe [-] 2010-02-16 . DED8B5A89B085284634502E9D75AC78C . 2066944 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\S P3QFE\ntkrnlpa.exe [-] 2009-02-07 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3GDR\ntkrnlpa.exe [-] 2009-02-06 . 3006410E24772CC6953F0B5C01BEB35F . 2057728 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2GDR\ntkrnlpa.exe [-] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P3QFE\ntkrnlpa.exe [-] 2009-02-06 . 9D832AF3FD1917DB0E1E8B2F000A2E3A . 2062976 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\S P2QFE\ntkrnlpa.exe [-] 2008-04-14 . 7F653A89F6E89E3AE0D49830EECE35D4 . 2023936 . . [5.1.2600.5512] . . c:\windows\system32\ntkrnlpa.exe [-] 2008-04-14 00:42 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll [-] 2008-04-14 00:42 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\system32\dllcache\ntmssvc.dll [-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll [-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\upnphost.dll [-] 2008-04-14 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll [-] 2008-04-14 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dllcache\dsound.dll [-] 2008-04-14 . 0607CBC6FA20114CB491EFE4B2F9EFAD . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll [-] 2008-04-14 . 0607CBC6FA20114CB491EFE4B2F9EFAD . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\dllcache\d3d9.dll [-] 2008-04-14 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll [-] 2008-04-14 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512] . . c:\windows\system32\dllcache\ddraw.dll [-] 2008-04-14 00:42 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll [-] 2008-04-14 00:42 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\olepro32.dll [-] 2008-04-14 . DBE2B62353660ECCA0D75EA307A717E9 . 39936 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll [-] 2008-04-14 . DBE2B62353660ECCA0D75EA307A717E9 . 39936 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\perfctrs.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}] 2010-01-16 03:29 561552 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2005-01-19 128000] "VistaStartMenu"="c:\program files\Vista Start Menu\VistaStartMenu.exe" [2010-07-13 2431720] "CircleDock"="c:\program files\Circle Dock\CircleDock.exe" [2010-05-01 2534400] "AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2010-07-25 4608] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-02-03 394984] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-05-22 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-05-22 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-05-22 137752] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1040384] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2010-01-10 819200] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "RemoteControl10"="c:\program files\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336] "BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-04-02 75048] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] c:\documents and settings\Peeyush Kumar\Start Menu\Programs\Startup\ Glass2k.lnk - c:\windows\BricoPacks\LeopardXP\Glass2k.exe [2008-5-22 56325] MacSearch.lnk - c:\program files\MacSearch_v.1.4.3\MacSearch.exe [2006-2-19 201911] panther.CurXPTheme.lnk - c:\program files\CursorXP\Themes\panther.CurXPTheme [2010-6-17 29383] RK Launcher.lnk - c:\program files\RK Launcher\RK Launcher 0.41 Beta Nightly\RKLauncher.exe [2007-3-17 708608] tclock2.lnk - c:\program files\tclock2_120\tclock2.exe [2003-8-3 90624] UberIcon.lnk - c:\program files\UberIcon\UberIcon Manager.exe [2005-8-13 180224] WinFlip.lnk - d:\desktop customization\WFlip050\WinFlip.exe [2010-1-16 483328] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-6 561213] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\syste m] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explor er] "NoRecentDocsNetHood"= 1 (0x1) [HKLM\~\startupfolder\C:^Documents and Settings^Peeyush Kumar^Start Menu^Programs^Startup^Styler.lnk] path=c:\documents and settings\Peeyush Kumar\Start Menu\Programs\Startup\Styler.lnk backup=c:\windows\pss\Styler.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Peeyush Kumar^Start Menu^Programs^Startup^TrueTransparency.lnk] path=c:\documents and settings\Peeyush Kumar\Start Menu\Programs\Startup\TrueTransparency.lnk backup=c:\windows\pss\TrueTransparency.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Peeyush Kumar^Start Menu^Programs^Startup^YzShadow.lnk] path=c:\documents and settings\Peeyush Kumar\Start Menu\Programs\Startup\YzShadow.lnk backup=c:\windows\pss\YzShadow.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent] 2007-09-06 13:08 136136 ----a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2010-06-01 04:47 5252408 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Opera\\opera.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/17/2010 8:40 PM 114768] R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2010/06/19 13:41];c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl [4/2/2010 9:11 AM 87536] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/17/2010 8:40 PM 20560] R2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [6/29/2010 10:59 PM 135168] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/17/2010 9:28 PM 304464] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/17/2010 9:28 PM 20952] S3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\drivers\cmnsusbser.sys [6/29/2010 10:59 PM 103424] S3 cpuz130;cpuz130;\??\c:\docume~1\PEEYUS~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\PEEYUS~1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/18/2010 12:03 PM 716272] . Contents of the 'Scheduled Tasks' folder 2010-07-29 c:\windows\Tasks\Windows Codec Update Service.job - c:\program files\Essentials Codec Pack\WECPUpdate.exe [2010-05-30 13:17] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyServer = 10.58.10.58:8080 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL . - - - - ORPHANS REMOVED - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-07-29 19:25 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}] "ImagePath"="\??\c:\program files\CyberLink\PowerDVD10\NavFilter\000.fcl" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_Ac tiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(896) c:\windows\system32\SETUPAPI.dll c:\windows\system32\sfc_os.dll c:\windows\system32\cscui.dll - - - - - - - > 'lsass.exe'(952) c:\windows\system32\setupapi.dll - - - - - - - > 'explorer.exe'(2808) c:\windows\system32\SHDOCVW.dll c:\windows\system32\WININET.dll c:\program files\RK Launcher\RK Launcher 0.41 Beta Nightly\RKLauncher.dll c:\program files\UberIcon\UberIcon.dll c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll c:\windows\System32\cscui.dll d:\desktop customization\WFlip050\WFHook.dll c:\windows\system32\btmmhook.dll c:\program files\Vista Start Menu\VistaStartMenu.dll c:\program files\CursorXP\CurXP0.dll c:\windows\system32\msi.dll c:\windows\system32\SETUPAPI.dll c:\windows\system32\ieframe.dll c:\windows\system32\credui.dll c:\windows\system32\MSVCP60.dll c:\program files\tclock2_120\tc2dll.tclock c:\windows\system32\comdlg32.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\btncopy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\windows\system32\agrsmsvc.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Sandboxie\SbieSvc.exe c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe c:\program files\Alwil Software\Avast4\ashMaiSv.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe c:\windows\system32\igfxsrvc.exe c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE . ************************************************************************** . Completion time: 2010-07-29 19:30:29 - machine was rebooted ComboFix-quarantined-files.txt 2010-07-29 14:00 Pre-Run: 10,097,917,952 bytes free Post-Run: 13,551,583,232 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect C:\wubildr.mbr = "Ubuntu" - - End Of File - - 88F6B9132D975AECAB0BAC5C7510323D |
|
29-Jul-2010, 11:12 AM
#7 |
| One more thing i want to say..after combofix i tried again IE and omg it says HTTP 403 forbidden !!! what to do now!!! |
29-Jul-2010, 02:55 PM
#8 | |||||
| whay are you using a proxy server on your network modem whay aren't you connecting directly that is teh most likely cause of the problem In IE: Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously. In Firefox in Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
__________________ Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue |
|
30-Jul-2010, 04:15 AM
#9 |
| ok i will give as much detail as i can. my mobile service provider uninor says me that they use proxy 10.58.10.58 and port 8080 so i added this. when i add this i get results as forbidden in IE, no matter the website i try to access. If i remove this proxy, then problem is again with yahoo mail and messenger. After combofix yahoo mail says that automatic page update is causing problem with screen reader bal..bla..and now i cant open yahoo mail in opera too earlier i was able. wat to do now..plzzz help me!!! |
30-Jul-2010, 06:57 AM
#10 | |||||
| I am not sure we can actaully do much here using 10.58.10.58 as a proxy means the proxy is your modem & that isn't set as a proxy I would remove that from IE & reboot & see what happens then You do need to reinstall XPSP3 as there are numerous crypytographic errors and the only cure for those is reinstall SP3 The errors frequently casue problems you are experiencing http://www.microsoft.com/downloads/d...displaylang=en
__________________ Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue |
|
30-Jul-2010, 07:58 AM
#11 |
| ok thanks for reply n ur help |
30-Jul-2010, 08:06 AM
#12 | |||||
| once you have reinstalled SP3 let us know and if that hasn't cured it then we will move you to networking & see if there is a networking error I do think the wrong cryptographic signatures is respoonsible but there just might be other causes |
|
30-Jul-2010, 12:17 PM
#13 |
| Once again thanks, but i didnt go for that sp3 package as i have my project in one month so not ready for a format (just pre-caution). Anyways thanks for your support and help. I was thinking that no one will reply, but i was amazed with ur support. Thanks a lot!!! ![]() |
| Tags |
| ie 8 unable to install, yahoo mail, yahoo messenger |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| | ||||
| Title | Thread Starter | Forum | Replies | Last Post |
| Solved: Unable to open Yahoo mail | dellisea | Windows 7 | 15 | 11-Dec-2009 10:53 PM |
| Strange Problem IE7 unable to open yahoo mail | vichoo | Web & Email | 9 | 25-May-2007 12:11 PM |
| unable to open yahoo mail | lbrtylvr | Web & Email | 15 | 12-Aug-2005 01:07 PM |
| unable to open yahoo mail. blank screen?? | cziembo | Windows XP | 3 | 12-Apr-2005 05:06 PM |
| unable to open pdf files in IE 6.0 | rwoodrin | All Other Software | 5 | 16-Dec-2002 06:32 AM |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 12:28 AM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

