Jump to content

deisl

Members
  • Posts

    1
  • Joined

  • Last visited

Posts posted by deisl

  1. Hi, I followed the prep guide and I couldn't get DDS to work. The black cmd window popped up for a second then went away. Here's the Hijack file if that helps.

    Logfile of Trend Micro HijackThis v2.0.4

    Scan saved at 8:53:25 AM, on 8/3/2011

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    C:\Program Files\AVG\AVG10\avgwdsvc.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe

    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

    C:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe

    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

    C:\Program Files\AVG\AVG10\avgnsx.exe

    C:\Program Files\AVG\AVG10\avgemcx.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\PROGRA~1\AVG\AVG10\avgrsx.exe

    C:\Program Files\AVG\AVG10\avgcsrvx.exe

    C:\Documents and Settings\Johnny\Local Settings\Application

    Data\Google\Chrome\Application\chrome.exe

    C:\Documents and Settings\Johnny\My Documents\Downloads\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

    http://www.ask.com?o=14196&l=dis

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

    http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

    http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

    *.local

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program

    Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter -

    {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program

    Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} -

    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program

    Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program

    Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -

    C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll

    O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program

    Files\Microsoft\BingBar\BingExt.dll" (file missing)

    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program

    Files\Ask.com\GenericAskToolbar.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} -

    C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} -

    C:\Program Files\STOPzilla!\SZIEBHO.dll (file missing)

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program

    Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program

    Files\PageRage\YontooIEClient.dll (file missing)

    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program

    Files\Ask.com\GenericAskToolbar.dll

    O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)

    O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program

    Files\Microsoft\BingBar\BingExt.dll" (file missing)

    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program

    Files\Google\Google Toolbar\GoogleToolbar_32.dll

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java

    Update\jusched.exe"

    O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader

    10.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program

    Files\Acronis\TrueImageHome\TrueImageMonitor.exe

    O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program

    Files\Acronis\TrueImageHome\TimounterMonitor.exe

    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common

    Files\Acronis\Schedule2\schedhlp.exe"

    O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common

    Files\ArcSoft\Connection Service\Bin\ACDaemon.exe

    O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common

    Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"

    O4 - HKLM\..\Run: [switchBoard] C:\Program Files\Common

    Files\Adobe\SwitchBoard\SwitchBoard.exe

    O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

    O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes'

    Anti-Malware\mbamgui.exe" /starttray

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Johnny\Local

    Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

    O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL

    SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx

    nLite.inf,C,,4,N (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-19\..\RunOnce: [*mgractioncpl.exe] "C:\Documents and Settings\All

    Users\Application Data\mgractioncpl.exe" (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK

    SERVICE')

    O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')

    O8 - Extra context menu item: E&xport to Microsoft Excel -

    res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google

    Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.ht

    ml

    O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program

    Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} -

    C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program

    Files\AVG\AVG10\avgpp.dll

    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -

    C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

    C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - Winlogon Notify: TPSvc - TPSvc.dll (file missing)

    O22 - SharedTaskScheduler: Browseui preloader -

    {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: Component Categories cache daemon -

    {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

    O22 - SharedTaskScheduler: ObjectDockShellExt -

    {1984D045-52CF-49cd-DB77-08F378FEA4DB} - C:\Program

    Files\Stardock\ObjectDockFree\ODMenu.dll

    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program

    Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe

    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common

    Files\Acronis\Schedule2\schedul2.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common

    Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program

    Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program

    Files\AVG\AVG10\avgwdsvc.exe

    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program

    Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program

    Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program

    Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program

    Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -

    C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common

    Files\Macromedia Shared\Service\Macromedia Licensing.exe

    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes'

    Anti-Malware\mbamservice.exe

    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero

    BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common

    Files\Nero\Lib\NMIndexingService.exe

    O23 - Service: PACE License Services (PaceLicenseDServices) - PACE Anti-Piracy, Inc. -

    C:\Program Files\Common Files\PACE\Services\LicenseServices\LDSvc.exe

    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE

    Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe

    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - Unknown owner - C:\Program

    Files\Spyware Doctor\pctsAuxs.exe (file missing)

    O23 - Service: PC Tools Security Service (sdCoreService) - Unknown owner - C:\Program

    Files\Spyware Doctor\pctsSvc.exe (file missing)

    O23 - Service: Adobe SwitchBoard (SwitchBoard) - Unknown owner - C:\Program

    Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

    O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common

    Files\iS3\Anti-Spyware\SZServer.exe

    O23 - Service: ThreatFire - Unknown owner - C:\Program Files\Spyware

    Doctor\TFEngine\TFService.exe (file missing)

    O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner -

    C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

    --

    End of file - 13644 bytes

    By the way the problem is that I keep getting redirected from googles results to an unrelated website.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.