1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Help! Someone Keeps Hacking Into My Computer!

Discussion in 'Malware and Virus Removal Archive' started by IDLERACER, 2008/12/11.

  1. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I told you how to access the modem's control panel here.

    Please download DDS and save it to your desktop.
    • Disable any script blocking protection
    • Double click dds.scr to run the tool.
    • When done, DDS.txt will open.
    • Click Yes at the next prompt for Optional Scan.
    • Save both reports to your desktop.
    ---------------------------------------------------

    Please include the contents of the following in your next reply:

    DDS.txt


    I may ask for the Attach.txt log later, so keep it handy.
     
  2. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    I just realized there's a plastic antenna sticking out of the modem itself. Shall I unscrew it?
     

  3. to hide this advert.

  4. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    Doing it
     
  5. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    It's asking me "Are You Sure You Want To Run This Software" and giving me the usual stuff about unknown publishers. Shall I click "Run "?
     
  6. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Of course. :)
     
  7. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    It's asking me "Do You Want To Perform The Optional Scan? It's Another Good For Nothing Scan" What shall I do?
     
  8. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15

    Yes, do the optional scan.
     
  9. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    Shall I just copy & paste the results of what's come up here?
     
  10. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yes, but if you close them without saving them first they will be gone. Click File>Save and save them to your desktop.
     
  11. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    Here is the DDS content:

    DDS (Version 1.0.1) - NTFSx86
    Run by Owner at 21:10:30.06 on Thu 12/11/2008
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_07
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.161 [GMT -8:00]

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Digital Media Reader\shwiconem.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Creative\ShareDLL\Mediadet.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Owner\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-

    US&ie=utf8&oe=utf8
    uInternet Connection Wizard,ShellNext = "c:\program files\outlook express\msimn.exe "
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\rpbrowserrecordplugin.dll
    BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\3.1.807.1746

    \swg.dll
    TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    uRun: [SetDefaultMIDI] MIDIDef.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common

    files\ahead\lib\NMBgMonitor.exe "
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
    mRun: [<NO NAME>]
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe "
    mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    mRun: [WINDVDPatch] CTHELPER.EXE
    mRun: [Jet Detection] "c:\program files\creative\sblive\program\ADGJDet.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe "
    mRun: [Disc Detector] c:\program files\creative\sharedll\CtNotify.exe
    mRun: [RegistryMechanic]
    mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe "
    mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe "
    mRun: [Motive SmartBridge] c:\progra~1\verizon\smartb~1\MotiveSB.exe
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common

    files\adobe\calibration\Adobe Gamma Loader.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0

    \reader\reader_sl.exe
    IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} -

    c:\program files\java\jre1.6.0_07\bin\ssv.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1

    \micros~2\office11\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} -

    c:\windows\system32\Shdocvw.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program

    files\spybot - search & destroy\SDHelper.dll
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    Notify: igfxcui - igfxsrvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32

    \WPDShServiceObj.dll
    SEH: {54D9498B-CF93-414F-8984-8CE7FDE0D391} - c:\program files\ewido anti-malware\shellhook.dll

    ================= FIREFOX ===================


    ============= SERVICES / DRIVERS ===============

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-5 111184]
    R1 ewido security suite driver;ewido security suite driver;\??\c:\program files\ewido anti-malware\guard.sys [2005-12-30 3072]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-5 20560]
    R2 avast! Antivirus;avast! Antivirus; "c:\program files\alwil software\avast4\ashServ.exe" [2006-2-25 155160]
    R2 ewido security suite control;ewido security suite control;c:\program files\ewido anti-malware\ewidoctrl.exe [2005-11-30

    13888]
    R3 avast! Mail Scanner;avast! Mail Scanner; "c:\program files\alwil software\avast4\ashMaiSv.exe" /service [2006-2-25

    254040]
    R3 avast! Web Scanner;avast! Web Scanner; "c:\program files\alwil software\avast4\ashWebSv.exe" /service [2006-2-25

    352920]
    S4 ewido security suite guard;ewido security suite guard;c:\program files\ewido anti-malware\ewidoguard.exe [2005-12-18

    151616]

    =============== Created Last 30 ================

    2008-11-17 21:25 61,224 a------- c:\documents and settings\owner\GoToAssistDownloadHelper.exe
    2008-11-11 22:17 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-11 22:17 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll

    ==================== Find3M ====================

    2008-10-24 03:21 455,296 a------- c:\windows\system32\drivers\mrxsmb.sys
    2008-10-23 04:36 286,720 a------- c:\windows\system32\gdi32.dll
    2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
    2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
    2008-10-16 12:38 826,368 a------- c:\windows\system32\wininet.dll
    2008-10-13 16:27 961,204 a------- c:\program files\extractnow.exe
    2008-10-11 19:34 1,234,120 a------- c:\program files\wrar380.exe
    2008-10-03 02:02 247,326 a------- c:\windows\system32\strmdll.dll
    2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
    2008-09-15 04:12 1,846,400 a------- c:\windows\system32\win32k.sys
    2008-07-20 11:20 38,005,024 a------- c:\program files\AVSVideoConverter.exe
    2008-05-03 19:14 243,864 a------- c:\program files\prismsetup.exe
    2007-08-15 22:15 381,952 ac------ c:\program files\justzipit.exe
    2007-01-26 09:45 439,296 ac------ c:\documents and settings\owner\GoToAssist_phone__317_en.exe
    2007-01-09 22:43 14,994,392 ac------ c:\program files\GoogleEarthWin.exe
    2006-12-11 00:48 9,918,872 ac------ c:\program files\WMEncoder.exe
    2005-12-31 15:24 7,079 ac------ c:\program files\hijackthis.log
    2005-12-31 12:57 532,480 ac------ c:\program files\CWShredder.exe
    2005-12-30 18:46 218,112 a------- c:\program files\HijackThis.exe
    2008-09-03 21:34 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5

    \mshist012008090320080904\index.dat

    ============= FINISH: 21:10:55.43 ===============

    And here is the other attachment:

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Version 1.0)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/26/2005 9:32:51 PM
    System Uptime: 12/11/2008 7:01:39 PM (2 hours ago)

    Motherboard: Intel Corporation | | D865GVHZ
    Processor: Intel(R) Celeron(R) CPU 2.93GHz | J2E1 | 2926/133mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 90 GiB total, 69.482 GiB free.
    D: is FIXED (FAT32) - 3 GiB total, 1.179 GiB free.
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable
    I: is Removable

    ==== Disabled Device Manager Items =============

    Class GUID:
    Description: Multimedia Audio Controller
    Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_4043107B&REV_02\3&267A616A&0&FD
    Manufacturer:
    Name: Multimedia Audio Controller
    PNP Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_4043107B&REV_02\3&267A616A&0&FD
    Service:

    ==== System Restore Points ===================

    RP1126: 9/12/2008 8:12:43 PM - System Checkpoint
    RP1127: 9/13/2008 8:54:35 PM - System Checkpoint
    RP1128: 9/14/2008 10:05:06 PM - System Checkpoint
    RP1129: 9/16/2008 12:07:34 AM - System Checkpoint
    RP1130: 9/16/2008 3:00:19 AM - Software Distribution Service 3.0
    RP1131: 9/17/2008 3:23:23 AM - System Checkpoint
    RP1132: 9/18/2008 3:50:54 AM - System Checkpoint
    RP1133: 9/19/2008 4:42:43 AM - System Checkpoint
    RP1134: 9/20/2008 5:06:32 AM - System Checkpoint
    RP1135: 9/21/2008 5:11:23 AM - System Checkpoint
    RP1136: 9/22/2008 6:11:25 AM - System Checkpoint
    RP1137: 9/23/2008 6:32:54 AM - System Checkpoint
    RP1138: 9/24/2008 7:18:33 AM - System Checkpoint
    RP1139: 9/25/2008 7:41:48 AM - System Checkpoint
    RP1140: 9/26/2008 7:44:03 AM - System Checkpoint
    RP1141: 9/27/2008 7:55:17 AM - System Checkpoint
    RP1142: 9/28/2008 8:02:49 AM - System Checkpoint
    RP1143: 9/29/2008 8:24:42 AM - System Checkpoint
    RP1144: 9/30/2008 5:09:52 PM - System Checkpoint
    RP1145: 10/1/2008 5:30:36 PM - System Checkpoint
    RP1146: 10/2/2008 5:51:02 PM - System Checkpoint
    RP1147: 10/3/2008 9:20:14 PM - System Checkpoint
    RP1148: 10/4/2008 9:45:28 PM - System Checkpoint
    RP1149: 10/6/2008 12:09:07 AM - System Checkpoint
    RP1150: 10/7/2008 1:58:02 AM - System Checkpoint
    RP1151: 10/8/2008 2:25:40 AM - System Checkpoint
    RP1152: 10/9/2008 2:34:34 AM - System Checkpoint
    RP1153: 10/10/2008 3:02:05 AM - System Checkpoint
    RP1154: 10/11/2008 3:36:15 AM - System Checkpoint
    RP1155: 10/12/2008 4:11:53 AM - System Checkpoint
    RP1156: 10/13/2008 4:25:41 AM - System Checkpoint
    RP1157: 10/14/2008 5:12:13 AM - System Checkpoint
    RP1158: 10/15/2008 1:50:17 AM - Software Distribution Service 3.0
    RP1159: 10/16/2008 2:35:57 AM - System Checkpoint
    RP1160: 10/17/2008 3:34:56 AM - System Checkpoint
    RP1161: 10/18/2008 3:39:15 AM - System Checkpoint
    RP1162: 10/19/2008 4:13:02 AM - System Checkpoint
    RP1163: 10/20/2008 5:13:02 AM - System Checkpoint
    RP1164: 10/21/2008 8:46:49 PM - System Checkpoint
    RP1165: 10/23/2008 12:04:00 AM - System Checkpoint
    RP1166: 10/24/2008 1:08:05 AM - System Checkpoint
    RP1167: 10/24/2008 3:00:18 AM - Software Distribution Service 3.0
    RP1168: 10/25/2008 3:11:42 AM - System Checkpoint
    RP1169: 10/26/2008 4:03:24 AM - System Checkpoint
    RP1170: 10/27/2008 4:30:52 AM - System Checkpoint
    RP1171: 10/28/2008 5:27:13 AM - System Checkpoint
    RP1172: 10/29/2008 6:27:35 AM - System Checkpoint
    RP1173: 10/30/2008 8:48:11 AM - System Checkpoint
    RP1174: 10/31/2008 10:18:14 AM - System Checkpoint
    RP1175: 11/1/2008 3:59:21 PM - System Checkpoint
    RP1176: 11/2/2008 6:13:17 PM - System Checkpoint
    RP1177: 11/3/2008 8:32:40 PM - System Checkpoint
    RP1178: 11/4/2008 11:47:30 PM - System Checkpoint
    RP1179: 11/6/2008 1:35:21 AM - System Checkpoint
    RP1180: 11/7/2008 1:46:08 AM - System Checkpoint
    RP1181: 11/8/2008 2:43:51 AM - System Checkpoint
    RP1182: 11/9/2008 8:14:57 AM - System Checkpoint
    RP1183: 11/10/2008 8:23:13 AM - System Checkpoint
    RP1184: 11/11/2008 9:17:01 AM - System Checkpoint
    RP1185: 11/11/2008 10:42:36 PM - Software Distribution Service 3.0
    RP1186: 11/13/2008 5:48:22 AM - System Checkpoint
    RP1187: 11/14/2008 6:18:20 AM - System Checkpoint
    RP1188: 11/15/2008 7:31:19 AM - System Checkpoint
    RP1189: 11/16/2008 7:33:43 AM - System Checkpoint
    RP1190: 11/17/2008 8:09:05 AM - System Checkpoint
    RP1191: 11/17/2008 7:58:53 PM - Restore Operation
    RP1192: 11/17/2008 8:17:36 PM - Restore Operation
    RP1193: 11/19/2008 1:19:35 AM - System Checkpoint
    RP1194: 11/20/2008 1:46:07 AM - System Checkpoint
    RP1195: 11/21/2008 2:03:07 AM - System Checkpoint
    RP1196: 11/22/2008 9:17:34 AM - System Checkpoint
    RP1197: 11/23/2008 10:21:00 AM - System Checkpoint
    RP1198: 11/24/2008 11:51:56 PM - System Checkpoint
    RP1199: 11/26/2008 11:13:26 AM - System Checkpoint
    RP1200: 11/27/2008 12:26:12 PM - System Checkpoint
    RP1201: 11/28/2008 1:40:24 PM - System Checkpoint
    RP1202: 11/29/2008 2:12:02 PM - System Checkpoint
    RP1203: 11/30/2008 3:50:11 PM - System Checkpoint
    RP1204: 12/1/2008 4:19:57 PM - System Checkpoint
    RP1205: 12/2/2008 4:52:47 PM - System Checkpoint
    RP1206: 12/3/2008 5:15:14 PM - System Checkpoint
    RP1207: 12/5/2008 8:22:48 PM - System Checkpoint
    RP1208: 12/6/2008 8:59:29 PM - System Checkpoint
    RP1209: 12/7/2008 9:42:34 PM - System Checkpoint
    RP1210: 12/9/2008 1:00:25 AM - System Checkpoint
    RP1211: 12/9/2008 7:13:13 PM - Restore Operation
    RP1212: 12/10/2008 9:17:49 AM - Software Distribution Service 3.0
    RP1213: 12/10/2008 9:05:13 PM - Software Distribution Service 3.0

    ==== Installed Programs ======================

    Adobe Acrobat 4.0
    Adobe Flash Player 10 ActiveX
    Adobe Photoshop 7.0
    Adobe Reader 7.0.5 Language Support
    Adobe Reader 7.1.0
    Adobe® Photoshop® Album Starter Edition 3.0
    AOL You've Got Pictures Screensaver
    avast! Antivirus
    AVS Video Converter 6
    AVS4YOU Software Navigator 1.2
    Canon PhotoRecord
    Canon S330
    Canon Utilities Easy-PhotoPrint
    Canon Utilities PhotoStitch 3.1
    Canon Utilities ZoomBrowser EX
    Creative PlayCenter
    Digital Media Reader
    DreamStation DXi2
    ewido anti-malware
    Google Earth
    Google Toolbar for Internet Explorer
    HijackThis 1.99.1
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB952287)
    Intel(R) Extreme Graphics 2 Driver
    Intel(R) PRO Network Adapters and Drivers
    InterActual Player
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Learn2 Player (Uninstall Only)
    Macromedia Fireworks MX
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft IntelliPoint 5.3
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Standard Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (2.0)
    MSN
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    Music Creator 2
    Nero 7 Essentials
    Nero BurnRights
    neroxml
    PowerDVD
    QuickTime
    RealPlayer
    Recovery Software Suite eMachines
    Registry Mechanic 5.1
    Score Writer 2.1
    Security Update for CAPICOM (KB931906)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Media Encoder (KB954156)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    SoftV92 Data Fax Modem with SmartCP
    Sound Blaster Live!
    Spybot - Search & Destroy
    Spybot - Search & Destroy 1.4
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Verizon Online Help and Support
    VideoEgg Publisher
    Viewpoint Media Player
    Virtual Sound Canvas DXi
    WAV to MP3 Encoder
    WavePad Uninstall
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage v1.3.0254.0
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Media Encoder 9 Series
    Windows Media Format 11 runtime
    Windows XP Service Pack 3
    WinRAR archiver
    Yahoo! Mail Quick Select Tool (PhotoMail)

    ==== Event Viewer Messages ===================


    ==== End Of File ===========================
     
  12. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Download GMER

    Right click and extract it to it's own folder on the desktop.

    Open the program and click on the Rootkit tab.
    Make sure all the boxes on the right of the screen are checked, EXCEPT for "˜Show All’.
    Click on Scan.
    When the scan has completed, click Copy and paste the results (if any) into this topic.
     
  13. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    I downloaded it on to my desktop, but I don't know how to open it. When I double-click it, it just creates another folder. How do I get to the "Rootkit" tab?
     
  14. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Open the folder. The program is inside of it.
     
  15. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    The inside of the folder appears to be blank. :confused:
     
  16. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please RIGHT CLICK the zip file you downloaded then select Extract. Just click OK from there out and you should succeed in finding the app.
     
  17. 2008/12/11
    Ried

    Ried Inactive

    Joined:
    2008/10/16
    Messages:
    13
    Likes Received:
    1
    Hello IDLERACER,

    All the information you need has been given to you.. Take a deep breath..slow down, relax a bit and read through the instructions noahdfear has provided you.
     
  18. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    It doesn't say "Extract" but I'll assume that "Unzip It" means the same thing...
     
  19. 2008/12/11
    Ried

    Ried Inactive

    Joined:
    2008/10/16
    Messages:
    13
    Likes Received:
    1
    It sure does. :)
     
  20. 2008/12/11
    IDLERACER

    IDLERACER Inactive Thread Starter

    Joined:
    2005/06/24
    Messages:
    136
    Likes Received:
    0
    No, that just creates another empty folder as well. in addition to "JustUnzipIt" and "Explore" it's also giving me the option of a drop-down menu entitled "Open With..." Should I look for something there?
     
  21. 2008/12/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please delete everything named gmer, right click your Avast antivirus icon and disable protection, then download gmer again and extract it.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.