Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

help please

$
0
0
i was told by an router tech(net gear) that because of an infection i have i/he was unable to access or change my forgotten wifi passord, he said it was a network infection and both my computers were infected, i hope i am posting this all right, i do have a windows xp cd but i am not sure if it is for my laptop or desktop
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.4.1
Run by amy at 12:44:30 on 2012-09-19
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1135 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled*
.
============== Running Processes ===============
.
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IObit\Advanced SystemCare 5\PMonitor.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\amy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D79D7D72-F59D-406A-843C-294A901FC697} : DhcpNameServer = 192.168.1.1
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-3-1 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-3-1 355632]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2012-3-21 913792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-3-1 21256]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-3-1 44808]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-12 399432]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-9-12 676936]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2009-12-3 97280]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005-10-21 36352]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-9-12 22856]
S0 rpapi;rpapi;c:\windows\system32\drivers\elcwasl.sys --> c:\windows\system32\drivers\elcwasl.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-2-17 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-4 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-2-17 136176]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-8-21 14336]
S4 BZOH;BZOH;c:\docume~1\amy\locals~1\temp\bzoh.exe --> c:\docume~1\amy\locals~1\temp\BZOH.exe [?]
.
=============== Created Last 30 ================
.
2012-09-15 21:37:11 -------- d-----w- C:\Inetpub
2012-09-15 21:16:53 -------- d-----w- c:\program files\OLYMPUS
2012-09-15 21:16:42 -------- d-----w- c:\program files\MSXML 4.0
2012-09-15 05:11:47 388096 ----a-r- c:\documents and settings\amy\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-09-15 00:01:26 -------- d-----w- c:\documents and settings\amy\application data\Registry Mechanic
2012-09-14 23:22:20 -------- d-----w- c:\program files\common files\PC Tools
2012-09-14 22:47:55 -------- d-----w- c:\program files\ESET
2012-09-14 04:07:56 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll
2012-09-14 04:07:56 99328 ----a-w- c:\windows\system32\srusd.dll
2012-09-14 04:07:54 6784 -c--a-w- c:\windows\system32\dllcache\serscan.sys
2012-09-14 04:07:54 6784 ----a-w- c:\windows\system32\drivers\serscan.sys
2012-09-14 04:07:51 71680 -c--a-w- c:\windows\system32\dllcache\fnfilter.dll
2012-09-14 04:07:51 71680 ----a-w- c:\windows\system32\fnfilter.dll
2012-09-13 21:44:13 -------- d-----w- c:\program files\Windows Live SkyDrive
2012-09-13 21:43:36 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2012-09-13 21:43:14 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-09-13 21:40:47 74520 ----a-w- c:\program files\common files\windows live\.cache\6f65c08e1cd91f8\DSETUP.dll
2012-09-13 21:40:47 484632 ----a-w- c:\program files\common files\windows live\.cache\6f65c08e1cd91f8\DXSETUP.exe
2012-09-13 21:40:47 1670936 ----a-w- c:\program files\common files\windows live\.cache\6f65c08e1cd91f8\dsetup32.dll
2012-09-13 21:40:14 1013800 ----a-w- c:\program files\common files\windows live\.cache\5c318fa21cd91f8\WindowsXP-KB954708-x86-ENU.exe
2012-09-13 21:39:01 -------- d-----w- c:\program files\common files\Windows Live
2012-09-13 00:03:46 -------- d-s-a-r- C:\cmdcons
2012-09-13 00:02:44 98816 ----a-w- c:\windows\sed.exe
2012-09-13 00:02:44 518144 ----a-w- c:\windows\SWREG.exe
2012-09-13 00:02:44 256000 ----a-w- c:\windows\PEV.exe
2012-09-13 00:02:44 208896 ----a-w- c:\windows\MBR.exe
2012-09-12 23:50:45 -------- d-----w- c:\documents and settings\amy\application data\Malwarebytes
2012-09-12 23:50:37 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-09-12 23:50:36 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-12 23:50:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-12 19:31:21 -------- d-----w- c:\documents and settings\all users\application data\Sophos
2012-09-12 19:02:35 -------- d-----w- c:\documents and settings\amy\local settings\application data\LogMeIn Rescue Applet
.
==================== Find3M ====================
.
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
2012-08-16 00:28:11 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-16 00:28:11 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-23 20:59:24 22400 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49:33 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49:32 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05:43 385024 ------w- c:\windows\system32\html.iec
.
============= FINISH: 12:45:20.15 ===============

Attached Files
File Type: zip ark.zip (7.8 KB)
File Type: zip attach.zip (3.1 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles