Can't connect to www.tweaks.com at home
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 




Can't connect to www.tweaks.com at homeExpand / Collapse
Author
Message
Posted 10/3/2008 2:52 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 10/25/2007 1:29 PM
Posts: 32, Visits: 54
Hi, following posts on this subject in a forum elsewhere on this site I was asked to post this log here for evaluation 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31:57, on 02/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\slmdmsr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\drivers\STDSB.exe
C:\WINDOWS\system32\drivers\Icon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\drivers\STDSB.exe
O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32\drivers\Icon.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Belkin Network USB Hub Control Center.lnk = C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe

--
End of file - 5849 bytes

Thankyou.

BarneyB

Post #244291
Posted 10/3/2008 3:03 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 29,515, Visits: 54,734
Welcome

First of all download/install Mozilla Firefox 3 from here,let me know if you have any issues using that once you've finished below.
Download a Firefox version that speaks your language:
http://www.mozilla.com/en-US/firefox/all.html


Please disable Spybot S&D’s protection,or it will interfere.
You can enable it after you're clean.

Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Restart the computer.
If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:
http://www.russelltexas.com/malware/teatimer.htm



Download Combofix by sUBs and save to your desktop.
Alternative Combofix download link HERE.
Note
It is important that it is saved directly to your desktop


Close any open browsers.
Click on Start/Run,copy and paste the following bold text into the 'Open:' space,then press OK [See image below]:
"%userprofile%\desktop\combofix.exe" /killall



Combofix.exe will start,please follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
*Note*
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and download Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.


_______________________________________________


ASAP & UNITE member since 2006





Spreadfirefox Affiliate Button Get Thunderbird!
Post #244292
Posted 10/3/2008 1:06 PM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 10/25/2007 1:29 PM
Posts: 32, Visits: 54
Hi Richie, 

I tried all that you suggested in the last post, I still cannot get onto tweaks.com with either Microsoft Internet Explorer or the newly installed Mozilla Firefox browser. A right pain because it means I have to keep saving log files onto portable media and travelling in order to post them in the forums from my workstation. Looks like im working overtime!

Thankyou for your help so far

Here are the log files

Combofix Logfile

ComboFix 08-10-02.04 - Daz 2008-10-03 17:28:16.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.209 [GMT 1:00]
Running from: C:\Documents and Settings\Daz\desktop\combofix.exe
Command switches used :: /killall
 * Created a new restore point

[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.

(((((((((((((((((((((((((   Files Created from 2008-09-03 to 2008-10-03  )))))))))))))))))))))))))))))))
.

2008-10-03 12:09 . 2008-10-03 12:09 0 --a------ C:\WINDOWSsreg.dat
2008-10-02 19:31 . 2008-10-02 19:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-02 10:46 . 2008-06-20 12:51 361,600 --a------ C:\WINDOWS\system32\drivers\tcpip.backup
2008-10-02 10:42 . 2008-10-02 10:42 <DIR> d-------- C:\Program Files\XP TCPIP Repair
2008-10-02 10:42 . 2005-04-15 18:58 1,351,392 --a------ C:\WINDOWS\system32\COMCTL32.OCX
2008-10-02 09:48 . 2008-10-02 09:48 <DIR> d-------- C:\Documents and Settings\TCPIP_Fix
2008-10-02 09:48 . 2006-04-20 07:51 359,808 --a------ C:\Documents and Settings\TCPIP_Fix\tcpip.sys
2008-10-02 09:48 . 2004-09-12 15:10 11,578 --a------ C:\Documents and Settings\TCPIP_Fix\Replacer.cmd
2008-10-02 09:48 . 2007-08-24 13:38 390 --a------ C:\Documents and Settings\TCPIP_Fix\Tcpip_Fix.cmd
2008-10-02 09:46 . 2008-10-02 09:46 <DIR> d-------- C:\Documents and Settings\Daz\TCPIP_Fix
2008-10-01 17:04 . 2008-10-01 17:04 <DIR> d-------- C:\Program Files\CCleaner
2008-10-01 14:10 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-10-01 14:10 . 2008-10-01 14:10 376 --a------ C:\WINDOWS\ODBC.INI
2008-10-01 14:08 . 2008-10-01 14:08 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-10-01 14:08 . 2008-10-01 14:08 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-10-01 14:06 . 2008-10-01 14:08 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-10-01 14:02 . 2008-10-01 14:02 <DIR> dr-h----- C:\MSOCache
2008-09-24 21:48 . 2008-09-30 16:12 <DIR> d-------- C:\Documents and Settings\Daz\Application Data\ZoomBrowser EX
2008-09-24 21:45 . 2008-04-14 01:12 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-09-24 21:45 . 2008-04-13 19:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-24 21:45 . 2008-04-13 19:45 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-24 21:45 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-09-22 21:59 . 2008-09-22 22:33 <DIR> d-------- C:\Program Files\ElectrikaCD
2008-09-21 21:48 . 2008-09-21 21:48 <DIR> d-------- C:\Documents and Settings\Daz\Application Data\Canon
2008-09-17 22:15 . 2008-09-18 21:28 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-09-17 22:15 . 2008-09-17 22:16 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-09-14 23:13 . 2008-10-01 13:28 <DIR> d-------- C:\Documents and Settings\Daz\Application Data\U3
2008-09-09 20:30 . 2008-09-09 21:00 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-09-07 20:27 . 2008-09-07 20:40 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-07 20:27 . 2008-10-03 12:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-05 23:43 . 2008-09-05 23:43 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-09-05 23:41 . 2008-09-05 23:41 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-09-05 23:41 . 2008-09-05 23:42 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-09-05 23:30 . 2008-09-05 23:30 241,704 -----c--- C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-05 23:29 . 2008-09-05 23:29 917,032 -----c--- C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-09-05 22:52 . 2008-09-05 22:52 <DIR> d-------- C:\Program Files\Microsoft Baseline Security Analyzer 2
2008-09-05 22:52 . 2008-09-05 22:52 <DIR> d-------- C:\Documents and Settings\Daz\SecurityScans
2008-09-05 22:36 . 2008-04-13 19:45 26,368 -----c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-05 22:33 . 2008-09-30 16:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-09-05 22:32 . 2008-09-05 22:32 <DIR> d-------- C:\Program Files\Common Files\Canon
2008-09-05 22:32 . 2008-09-05 22:34 <DIR> d-------- C:\Program Files\Canon
2008-09-05 22:29 . 2008-09-05 22:29 <DIR> d-------- C:\Program Files\Common Files\HP
2008-09-05 22:27 . 2008-09-05 22:27 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-09-05 22:26 . 2008-09-05 22:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-09-05 22:25 . 1998-10-29 16:45 306,688 --------- C:\WINDOWS\IsUninst.exe
2008-09-05 22:25 . 2004-09-29 12:12 278,584 --------- C:\WINDOWS\system32\HPZidr12.dll
2008-09-05 22:25 . 2004-09-29 12:15 204,800 --------- C:\WINDOWS\system32\HPZipr12.dll
2008-09-05 22:25 . 2004-09-29 12:09 94,208 --------- C:\WINDOWS\system32\HPZipt12.dll
2008-09-05 22:25 . 2004-09-29 12:14 69,632 --------- C:\WINDOWS\system32\HPZipm12.exe
2008-09-05 22:25 . 2004-09-29 12:08 61,440 --------- C:\WINDOWS\system32\HPZinw12.exe
2008-09-05 22:25 . 2004-09-29 12:09 57,344 --------- C:\WINDOWS\system32\HPZisn12.dll
2008-09-05 22:24 . 2008-09-05 22:29 <DIR> d-------- C:\Program Files\HP
2008-09-05 22:19 . 2008-09-07 21:43 80,897 --------- C:\WINDOWS\hpfins05.dat
2008-09-05 22:19 . 2005-03-08 14:52 51,120 -r------- C:\WINDOWS\system32\drivers\HPZid412.sys
2008-09-05 22:19 . 2005-03-08 14:52 16,496 -r------- C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-09-05 22:19 . 2005-05-27 14:36 1,547 --------- C:\WINDOWS\hpfmdl05.dat
2008-09-05 22:18 . 2005-04-27 21:37 77,824 -r------- C:\WINDOWS\system32\hpzids01.dll
2008-09-05 22:18 . 2005-05-10 20:49 37,376 --------- C:\WINDOWS\system32\hpz3l3xu.dll
2008-09-05 22:17 . 2004-09-30 12:49 274,432 -r------- C:\WINDOWS\system32\HPZc3212.dll
2008-09-05 22:17 . 2005-03-08 14:52 21,744 -r------- C:\WINDOWS\system32\drivers\HPZius12.sys
2008-09-05 22:16 . 2008-04-13 19:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-05 22:16 . 2008-04-13 19:45 32,128 -----c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-09-05 22:16 . 2008-04-13 19:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-09-05 22:16 . 2008-04-13 19:47 25,856 -----c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-09-05 22:10 . 2008-09-05 22:10 <DIR> d-------- C:\Program Files\Belkin
2008-09-05 22:10 . 2007-07-27 04:03 75,008 -r------- C:\WINDOWS\system32\drivers\sxuptp.sys
2008-09-05 21:28 . 2008-09-05 21:37 96,976 --------- C:\WINDOWS\system32\drivers\klin.dat
2008-09-05 21:28 . 2008-09-05 21:37 87,855 --------- C:\WINDOWS\system32\drivers\klick.dat
2008-09-05 21:27 . 2008-09-05 21:27 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-09-05 21:27 . 2008-10-03 17:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-05 21:27 . 2008-10-03 17:33 3,041,056 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-05 21:27 . 2008-10-03 17:33 260,384 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-05 21:27 . 2008-10-03 17:32 42,824 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-05 21:27 . 2008-10-03 17:32 26,480 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-05 21:07 . 2008-09-05 21:07 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-05 21:07 . 2008-09-05 21:07 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-05 21:07 . 2008-09-05 21:07 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-05 21:07 . 2008-09-05 21:07 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-05 21:05 . 2008-09-05 21:05 <DIR> d-------- C:\WINDOWS\ServicePackFiles

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 17:01 0 ----a-w C:\WINDOWS\system32\drivers\eicon.txt
2008-09-05 20:37 112,144 ------w C:\WINDOWS\system32\drivers\kl1.sys
2008-09-05 19:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-05 19:15 --------- d-----w C:\Program Files\IEEE 802.11 Wireless LAN
2008-09-05 19:13 --------- d-----w C:\Program Files\Synaptics
2008-09-05 19:13 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-05 19:11 --------- d-----w C:\Program Files\VIA
2008-09-05 19:10 --------- d-----w C:\Program Files\Realtek AC97
2008-09-05 18:48 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-10-23 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-23 688218]
"STDSB"="C:\WINDOWS\system32\drivers\STDSB.exe" [2005-10-23 28672]
"Icon"="C:\WINDOWS\system32\drivers\Icon.exe" [2005-10-23 221184]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-26 218376]
"SoundMan"="SOUNDMAN.EXE" [2005-10-23 C:\WINDOWS\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-10-23 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-10-23 C:\WINDOWS\system32\VTTrayp.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

C:\Documents and Settings\Daz\Start Menu\Programs\Startup\
Belkin Network USB Hub Control Center.lnk - C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe [2008-09-05 790609]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R2 MTC0007_STDSB;Scroll Bar Driver;C:\WINDOWS\system32\drivers\STDSB.sys [2005-10-23 11279]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-06-25 43520]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
R3 sxuptp;SXUPTP Driver;C:\WINDOWS\system32\DRIVERS\sxuptp.sys [2007-07-27 75008]
S2 STDSB;STDSB;C:\WINDOWS\system32\DRIVERS\STDSB.sys [2005-10-23 11279]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{73579963-82a9-11dd-86dd-0016e32093c9}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2bf664e-7b92-11dd-86ca-0016e32093c9}]
\Shell\AutoRun\command - E:\wd_windows_tools\WDSetup.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Daz\Application Data\Mozilla\Firefox\Profiles\pnwuy2ql.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-03 17:33:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\slmdmsr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Completion time: 2008-10-03 17:38:34 - machine was rebooted
ComboFix-quarantined-files.txt  2008-10-03 16:38:24

Pre-Run: 33,354,203,136 bytes free
Post-Run: 33,279,393,792 bytes free

182 --- E O F --- 2008-10-02 19:15:33

and here's the Hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:09, on 2008-10-03
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\slmdmsr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\drivers\STDSB.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [STDSB] C:\WINDOWS\system32\drivers\STDSB.exe
O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32\drivers\Icon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Belkin Network USB Hub Control Center.lnk = C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slmdmsr.exe

--
End of file - 5036 bytes


BarneyB

Post #244308
Posted 10/3/2008 1:44 PM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 29,515, Visits: 54,734
Click on Start/Run,copy and paste ComboFix /u into the 'Open:' space,then press OK [see image below]
This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.




Please download Malwarebytes Anti-Malware:
http://www.besttechie.net/tools/mbam-setup.exe
http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html

Double Click mbam-setup.exe to install the application.
(If using Windows Vista,be sure to "Run As Administrator").

* Make sure a checkmark is placed/present next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Quick Scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy and paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Does running in "Safe Mode with Networking" make any difference.
Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode with Networking".


How exactly do you connect to the internet.


_______________________________________________


ASAP & UNITE member since 2006





Spreadfirefox Affiliate Button Get Thunderbird!
Post #244309
Posted 10/4/2008 1:35 PM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 10/25/2007 1:29 PM
Posts: 32, Visits: 54
Hi Richie, Still no joy, the MBAM didn't seem to find anything (log attached). I tried connecting to tweaks.com in safe mode with networking but it was just the same.

I connect to the internet via a Virgin Cable Broadband connection (nee: NTL) using their supplied cable modem NTL250 via a Cisco 871W router. I have tried connection via Cat5 direct to the Ethernet LAN connection on the router so as to rule out a wireless connection problem and this also makes no difference.

Here's the log anyway,

Malwarebytes' Anti-Malware 1.28
Database version: 1227
Windows 5.1.2600 Service Pack 3

2008-10-04 18:11:20
mbam-log-2008-10-04 (18-11-20).txt

Scan type: Quick Scan
Objects scanned: 41646
Time elapsed: 3 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Many Thanks,

Darryl


BarneyB

Post #244318
Posted 10/4/2008 4:47 PM