Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Closed Thread
 
Thread Tools
Old 03-31-2007, 11:47 PM   #1 (permalink)
Registered User
 
Join Date: Nov 2005
Posts: 6
OS: XP


Log full o' trouble

I'm getting continual pop ups from ad-w-a-r-e.com and its driving me absolutely insane. As a side note, Microsoft won't let me update to sp2 for some reason, Im working on that as well. Here are my man and extra logs, any help would be greatly appreciated!


Main:
Run by Andy on 2007-04-01 at 01:33:54
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
11: 2007-04-01 07:33:57 UTC - RP18 - Deckard's System Scanner Restore Point
10: 2007-04-01 07:00:37 UTC - RP17 - Installed Windows XP KB842773.
9: 2007-04-01 07:00:22 UTC - RP16 - Installed Windows XP KB898461.
8: 2007-04-01 07:00:15 UTC - RP15 - Software Distribution Service 2.0
7: 2007-04-01 05:53:02 UTC - RP14 - Installed Windows Installer KB893803v2.


-- First Restore Point --
1: 2007-03-31 21:00:40 UTC - RP8 - Removed PunkBuster for Battlefield Vietnam


Backed up registry hives.

Performed disk cleanup.


-- HijackThis (run as Andy.exe) ------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 1:36:06 AM, on 4/1/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\sQusi\sQusi Tracking Blocker\sQusiBasicApp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Andy\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Andy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - Startup: sQusi Tracking Blocker.lnk = C:\Program Files\sQusi\sQusi Tracking Blocker\sQusiBasicApp.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1073430860687
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1073430854718
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O20 - AppInit_DLLs: sQusiStub.dll
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\o448lehu1h48.dll


-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 irda (IrDA Protocol) - c:\windows\system32\drivers\irda.sys
R3 cmudax (C-Media High Definition Audio Interface) - c:\windows\system32\drivers\cmudax.sys
R3 ialm - c:\windows\system32\drivers\ialmnt5.sys
R3 irsir (Microsoft Serial Infrared Driver) - c:\windows\system32\drivers\irsir.sys
R3 Rasirda (WAN Miniport (IrDA)) - c:\windows\system32\drivers\rasirda.sys
R3 yukonwxp (NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter) - c:\windows\system32\drivers\yukonwxp.sys

S3 ADM8511 (ADMtek ADM8511/AN986 USB To Fast Ethernet Converter) - c:\windows\system32\drivers\adm8511.sys
S3 ET5Drv - c:\windows\system32\drivers\et5drv.sys
S3 MarkFun_NT - c:\program files\gigabyte\et5\markfun.w32
S3 wg111nd5 (NETGEAR WG111 802.11g Wireless USB Adapter Driver) - c:\windows\system32\drivers\wg111nd5.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Irmon (Infrared Monitor) - c:\windows\system32\svchost.exe -k netsvcs
R2 uploadmgr (Upload Manager) - c:\windows\system32\svchost.exe -k netsvcs
R2 WmdmPmSp (Portable Media Serial Number) - c:\windows\system32\svchost.exe -k netsvcs


-- Files created between 2007-03-01 and 2007-04-01 -----------------------------

2007-04-01 01:23:10 0 d-------- C:\ie-spyad_zo<IE-SPY~1>
2007-04-01 01:17:22 21312 --a------ C:\WINDOWS\choice.exe
2007-04-01 01:16:25 0 d-------- C:\ie-spyad
2007-04-01 01:09:42 0 d-------- C:\WINDOWS\LastGood
2007-04-01 01:08:23 224859 -r--s---- C:\WINDOWS\System32\sdi.dll
2007-04-01 01:08:23 225831 -r--s---- C:\WINDOWS\System32\s2pu0c79ef.dll<S2PU0C~1.DLL>
2007-04-01 01:00:41 118784 --a------ C:\WINDOWS\System32\MSSTDFMT.DLL
2007-04-01 01:00:41 0 d-------- C:\Program Files\SpywareBlaster<SPYWAR~1>
2007-04-01 01:00:22 0 d-------- C:\WINDOWS\System32\PreInstall<PREINS~1>
2007-04-01 01:00:11 0 d-------- C:\agnis-sites<AGNIS-~1>
2007-04-01 00:48:16 0 d-------- C:\!KillBox
2007-04-01 00:41:16 1168 --a------ C:\WINDOWS\mozver.dat
2007-04-01 0023 224859 -r--s---- C:\WINDOWS\System32\o448lehu1h48.dll<O448LE~1.DLL>
2007-03-31 22:36:58 0 d-------- C:\Documents and Settings\Andy\Application Data\Lavasoft
2007-03-31 22:36:55 0 d-------- C:\Program Files\Lavasoft
2007-03-31 22:36:45 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard<WISEIN~1>
2007-03-31 20:55:15 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<SPYBOT~1>
2007-03-31 18:05:19 224348 -r--s---- C:\WINDOWS\System32\gplol3331.dll<GPLOL3~1.DLL>
2007-03-31 17:27:24 224332 -r--s---- C:\WINDOWS\System32\ktjol7131.dll<KTJOL7~1.DLL>
2007-03-31 15:26:51 0 d--h---c- C:\WINDOWS\$MSI30UninstallMSI30-KB884016$<$MSI30~1>
2007-03-31 15:24:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage<WINDOW~1>
2007-03-31 15:23:13 0 d--h----- C:\WINDOWS\msdownld.tmp
2007-03-31 15:23:09 0 d-------- C:\WINDOWS\Windows Update Setup Files<WINDOW~1>
2007-03-31 15:10:47 401408 --a------ C:\WINDOWS\System32\sqlsrv32.dll
2007-03-31 15:10:47 24576 --a------ C:\WINDOWS\System32\odbcbcp.dll
2007-03-31 15:10:46 24576 --a------ C:\WINDOWS\System32\dbmsvinn.dll
2007-03-31 15:10:46 24576 --a------ C:\WINDOWS\System32\dbmsrpcn.dll
2007-03-31 15:10:46 28672 --a------ C:\WINDOWS\System32\dbmsgnet.dll
2007-03-31 15:10:46 24576 --a------ C:\WINDOWS\System32\dbmsadsn.dll
2007-03-31 15:10:45 180800 --a------ C:\WINDOWS\System32\sqlunirl.dll
2007-03-31 15:10:45 28672 --a------ C:\WINDOWS\System32\dbnmpntw.dll
2007-03-31 15:10:45 73728 --a------ C:\WINDOWS\System32\dbnetlib.dll
2007-03-31 15:10:45 20480 --a------ C:\WINDOWS\System32\cliconfg.exe
2007-03-31 15:10:45 73728 --a------ C:\WINDOWS\System32\cliconfg.dll
2007-03-31 15:10:43 44032 --a------ C:\WINDOWS\System32\msxml3r.dll
2007-03-31 15:10:42 1129472 --a------ C:\WINDOWS\System32\msxml3.dll
2007-03-31 15:10:42 36864 --a------ C:\WINDOWS\System32\mscpxl32.dll
2007-03-31 15:10:41 26224 --a------ C:\WINDOWS\System32\odbc16gt.dll
2007-03-31 15:10:41 139264 --a------ C:\WINDOWS\System32\msorcl32.dll
2007-03-31 15:10:41 20480 --a------ C:\WINDOWS\System32\msorc32r.dll
2007-03-31 15:10:41 4656 --a------ C:\WINDOWS\System32\ds16gt.dll
2007-03-31 15:10:40 147456 --a------ C:\WINDOWS\System32\odbctrac.dll
2007-03-31 15:10:40 61440 --a------ C:\WINDOWS\System32\odbccr32.dll
2007-03-31 15:10:40 102400 --a------ C:\WINDOWS\System32\odbccp32.dll
2007-03-31 15:10:40 32768 --a------ C:\WINDOWS\System32\odbcad32.exe
2007-03-31 15:10:40 16384 --a------ C:\WINDOWS\System32\odbc32gt.dll
2007-03-31 15:10:40 221184 --a------ C:\WINDOWS\System32\odbc32.dll
2007-03-31 15:10:39 94208 --a------ C:\WINDOWS\System32\odbcint.dll
2007-03-31 15:10:39 143360 --a------ C:\WINDOWS\System32\msdart.dll
2007-03-31 15:10:38 61440 --a------ C:\WINDOWS\System32\odbccu32.dll
2007-03-31 15:10:38 16384 --a------ C:\WINDOWS\System32\ds32gt.dll
2007-03-31 15:10:33 0 d-------- C:\WINDOWS\RegisteredPackages<REGIST~2>
2007-03-31 15:10:13 69632 --a------ C:\WINDOWS\System32\odbcconf.exe
2007-03-31 15:10:13 126976 --a------ C:\WINDOWS\System32\odbcconf.dll
2007-03-31 15:03:04 0 d-------- C:\Program Files\sQusi
2007-03-31 15:03:04 0 d-------- C:\Documents and Settings\All Users\Application Data\sQusi
2007-03-31 15:01:16 331776 --a------ C:\WINDOWS\System32\winhttp.dll
2007-03-31 15:01:16 17408 --a------ C:\WINDOWS\System32\qmgrprxy.dll


-- Find3M Report ---------------------------------------------------------------

2007-03-31 22:43:06 0 d-------- C:\Program Files\XML
2007-03-31 22:43:06 0 d-------- C:\Program Files\Common Files\Java
2007-03-31 22:37:59 6797 --a------ C:\WINDOWS\agknek.dll
2007-03-31 15:00:40 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>


-- Registry Dump ---------------------------------------------------------------


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="sQusiStub.dll"


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Syncmgr

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0



-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.igetnet.com
127.0.0.1 code.ignphrases.com
127.0.0.1 clear-search.com
127.0.0.1 r1.clrsch.com
127.0.0.1 sds.clrsch.com
127.0.0.1 status.clrsch.com
127.0.0.1 www.clrsch.com
127.0.0.1 clr-sch.com
127.0.0.1 sds-qckads.com
127.0.0.1 status.qckads.com

2 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2007-04-01 at 01:36:32 ---------

















Deckard's System Scanner v20070328.36
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 1.0
Architecture: X86; Language: English

CPU 0: Intel(R) Pentium(R) 4 CPU 3.20GHz
CPU 1: Intel(R) Pentium(R) 4 CPU 3.20GHz
Percentage of Memory in Use: 40%
Physical Memory (total/avail): 1015.48 MiB / 608.04 MiB
Pagefile Memory (total/avail): 2446.52 MiB / 2174.42 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1990.68 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 111.78 GiB total, 98.94 GiB free.
D: is CDROM (CDFS)


-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Andy\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=AKAC
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Andy
LOGONSERVER=\\AKAC
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\WBEM;C:\Program Files\Mozilla Firefox
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 4, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0304
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Andy\LOCALS~1\Temp
TMP=C:\DOCUME~1\Andy\LOCALS~1\Temp
USERDOMAIN=AKAC
USERNAME=Andy
USERPROFILE=C:\Documents and Settings\Andy
windir=C:\WINDOWS
WriteD=FALSE


-- User Profiles ---------------------------------------------------------------

Andy (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware SE Personal --> MsiExec.exe /X{78CC3BAB-DE2A-4FB4-8FBB-E4DADDC26747}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Battlecraft Vietnam --> C:\WINDOWS\iun6002.exe "C:\Program Files\EA GAMES\Battlecraft Vietnam\irunin.ini"
Battlefield 1942 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\setup.exe" -l0x9
Battlefield Vietnam(TM) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E35B3C63-E958-4E31-A178-95D22024109A}\setup.exe" -l0x9
C-Media High Definition Audio Driver --> C:\WINDOWS\system32\cmirmdrv.exe
EasyTune5 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Gigabyte\ET5\Uninst.isu" -c"C:\Program Files\Gigabyte\ET5\uninstdrv.dll"
Guild Wars --> "C:\Program Files\Guild Wars\Gw.exe" -uninstall
HijackThis 1.99.1 --> C:\Documents and Settings\Andy\Local Settings\Temp\hijackthis\HijackThis.exe /uninstall
Intel(R) Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2782 PCI\VEN_8086&DEV_2582
Lavasoft VX2 Cleaner --> C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\Plugins\INSTALL.LOG
Marvell Miniport Driver --> MsiExec.exe /X{C950420B-4182-49EA-850A-A6A2ABF06C6B}
Medal of Honor Pacific Assault(tm) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}\Setup.exe" -l0x9 -removeonly
Medal of Honor Pacific Assault(tm) Patch --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA586D1D-6E4B-4A05-B956-4ACF063BA711}\setup.exe" -l0x9 -removeonly
Mozilla Firefox (2.0.0.3) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
sQusi Tracking Blocker --> MsiExec.exe /X{F741B83D-46A6-439E-A1B5-5AC27DEA8745}
Viewpoint Manager (Remove Only) --> C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe /u /k
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Installer 3.0 (KB884016) --> C:\WINDOWS\$MSI30UninstallMSI30-KB884016$\spuninst\spuninst.exe


-- End of Deckard's System Scanner: finished at 2007-04-01 at 01:36:32 ---------
and11200 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 04-02-2007, 10:00 AM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 25,526
OS: 2000 Pro; XP Pro; XP Home


Re: Log full o' trouble

Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

---------------------------------------------------------------------------------------------

It's not a good idea to update to SP2 on an infected machine. Let's clean it first, then see about going to SP2.

---------------------------------------------------------------------------------------------

Download LSPFix.exe

Instructions for using LSPFix
  1. Double click on LSPFix.exe to run it.
  2. Once running, you will be required to tick the disclaimer - "I know what I'm doing".
  3. You'll find a windows with 2 panes.
    In the left pane which is labeled 'Keep', select all instances of:
    • aklsp.dll
  4. Then click on the arrow pointing to the right, >>.
    This will move the entry to the right pane labeled 'Remove'
  5. Click the Finish button to complete the fix.
Only aklsp.dll needs to be removed. If you see any other entries in the right pane, move them back to the "Keep" pane & post the filenames to inform me.

---------------------------------------------------------------------------------------------
  1. Download combofix from one of these locations:

    * IMPORTANT !!! Place it on your Desktop.

  2. Click the Windows 'Start' button > Select 'Run' - then copy/paste this into the run box & click OK
    "%userprofile%\desktop\combofix.exe" /v aklsp
  3. When finished, it shall produce a log for you. Post that log in your next reply.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

---------------------------------------------------------------------------------------------



I see no evidence of an AntiVirus program on your system. This must be resolved. Connecting to the Internet without antivirus protection is a "Welcome" doormat for malware. It can take as little as eight seconds to infect an unprotected computer.

Here are a few very good free Antivirus products which are available:Select one of these, or another of your choice. Do not install more than one antivirus program because they will conflict with each other. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come out.


You don't seem to have a firewall program installed. Using a third-party firewall will allow you to give/deny access for applications that want to go online. Select one of these, or another of your choice:.

---------------------------------------------------------------------------------------------

Please run Deckard's System Scanner once again, this time using these instructions:

Click the Windows 'Start' button > Select 'Run' - then copy/paste this into the run box & click OK
"%userprofile%\desktop\dss.exe" /config
Click on "Check All"

Click Scan!

When finished, it shall produce two logs for you. Post those logs in your next reply.


---------------------------------------------

Please return with results from:

ComboFix (C:\ComboFix .txt)
DSS (main.txt and extra.txt)
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006
Our help is voluntary, but this site needs donations to operate.
Please consider Donating to the Forum.


Please do not ask for help via Private Message. Ask in the forums, so all may gain from the experience.
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 07:17 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82