1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Some malware took out my Internet Connection

Discussion in 'Malware and Virus Removal Archive' started by Oldmartian, 2010/06/14.

  1. 2010/06/14
    Oldmartian

    Oldmartian Inactive Thread Starter

    Joined:
    2010/06/14
    Messages:
    5
    Likes Received:
    0
    [Inactive] Some malware took out my Internet Connection

    I have a friend's computer sitting beside my computer at home that has a problem I cannot fix and would like to see if you folks could help me.

    His computer: XP Pro SP3, 300 GB drive, 3+ GB Ram
    Symptoms: No connection to the Internet. I’ve checked everything I know of and find some things are not right. The Device Manager shows the NIC is good. The Network Connection Properties shows the connection is good. But there’s no internet and the browsers (IE8 Firefox ands Slimbrowser) show no connection to the internet.
    My Windows Firewall has been turned off and cannot be re-started. The Avast shield is off and cannot be restarted.
    I've run the boot-time scan and nothhing popped up.

    Avast! Routinely pops up and says it has caught "Dropper" and placed it into the Chest
    MS Device Manager doesn’t show any hard drives (I’ve never seen that before)
    MS Disk Manager doesn’t show any hard drives, but the Disk Defragmenter works on the hard drive. All files are available on Windows Explorer.

    Last month the Internet Connection was broken and after some searching I found that the DNS address to the router was blank. At that time there was no indication of a malware in the computer, although they had installed a Fire-Fox Add-in called Browser Highlighter. An internet search showed a great deal of negative reviews. I took out the BHO and re-scanned the computer, which worked for 40 days before I got this recent call again complaining of no Internet connection. At that time I thought the problem was resolved.

    I currently have the computer connected to my router and the same problem exists. It’s not the router or the modem. He uses cable service and I use DSL.

    I hope this isn't "too much information" but I thought the more you have to work with might simplify the task of solving this. Thank you very much for taking this problem on.

    I ran your DDS.SCR program and the output is shown here:

    DDS.TXT:
    DDS (Ver_10-03-17.01) - NTFSx86
    Run by John at 10:47:07.00 on Mon 06/14/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3574.3122 [GMT -4:00]

    AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\New_Computer\SlimBrowser\sbrowser.exe
    D:\TSF-dds.com

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    uInternet Connection Wizard,ShellNext = hxxp://us.mg3.mail.yahoo.com/dc/launch?.gx=0&.rand=2sn8jlge4k4f7
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [TrojanScanner] c:\program files\trojan remover\Trjscan.exe /boot
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    Trusted Zone: intuit.com\ttlc
    DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    TCP: {7DF8709B-C747-4512-A235-7AAD9DB62778} = 129.2.168.5
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
    Notify: igfxcui - igfxdev.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\john\applic~1\mozilla\firefox\profiles\59i3vjxj.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - www.google.com
    FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
    FF - plugin: c:\documents and settings\john\application data\mozilla\firefox\profiles\59i3vjxj.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
    FF - plugin: c:\documents and settings\john\application data\mozilla\firefox\profiles\59i3vjxj.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);

    ============= SERVICES / DRIVERS ===============

    R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [2009-4-17 15172]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-4-17 164048]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-5-26 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 67656]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-4-17 19024]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-8 40384]
    R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2010-4-4 38144]
    R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2008-2-12 14336]
    R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);c:\windows\system32\drivers\es1370mp.sys [2009-4-17 37120]
    S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-8 40384]
    S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-8 40384]
    S3 mipsinf;mipsinf;c:\windows\system32\mipsinf.sys [2010-6-7 2304]
    S3 radpms;Driver for RADPMS Device;c:\windows\system32\drivers\radpms.sys --> c:\windows\system32\drivers\radpms.sys [?]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 12872]

    =============== Created Last 30 ================

    2010-06-14 05:07:31 77312 ----a-w- c:\windows\system32\ztvunace26.dll
    2010-06-14 05:07:31 75264 ----a-w- c:\windows\system32\unacev2.dll
    2010-06-14 05:07:31 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
    2010-06-14 05:07:31 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
    2010-06-14 05:07:31 153088 ----a-w- c:\windows\system32\UNRAR3.dll
    2010-06-14 05:07:30 0 d-----w- c:\program files\Trojan Remover
    2010-06-14 05:07:30 0 d-----w- c:\docume~1\john\applic~1\Simply Super Software
    2010-06-14 05:07:30 0 d-----w- c:\docume~1\alluse~1\applic~1\Simply Super Software
    2010-06-12 00:19:59 664 ----a-w- c:\windows\system32\d3d9caps.dat
    2010-06-08 10:45:29 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
    2010-06-07 18:49:10 2304 ----a-w- c:\windows\system32\mipsinf.sys
    2010-06-06 18:52:09 112 ----a-w- c:\docume~1\alluse~1\applic~1\EbDiDB1c3.dat

    ==================== Find3M ====================


    ============= FINISH: 10:48:06.46 ===============


    ATTACH.TXT
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/16/2009 10:43:41 PM
    System Uptime: 6/14/2010 10:21:30 AM (0 hours ago)

    Motherboard: ASUSTeK Computer INC. | | P5KPL-CM
    Processor: Intel(R) Celeron(R) CPU E1500 @ 2.20GHz | Socket 775 | 2218/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 233 GiB total, 216.656 GiB free.
    D: is Removable
    X: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI Device
    Device ID: PCI\VEN_8086&DEV_27D8&SUBSYS_82EA1043&REV_01\3&11583659&0&D8
    Manufacturer:
    Name: PCI Device
    PNP Device ID: PCI\VEN_8086&DEV_27D8&SUBSYS_82EA1043&REV_01\3&11583659&0&D8
    Service:

    Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
    Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    Device ID: ACPI\PNP0303\4&2C575ACB&0
    Manufacturer: (Standard keyboards)
    Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    PNP Device ID: ACPI\PNP0303\4&2C575ACB&0
    Service: i8042prt

    Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
    Description: Microsoft PS/2 Mouse
    Device ID: ACPI\PNP0F03\4&2C575ACB&0
    Manufacturer: Microsoft
    Name: Microsoft PS/2 Mouse
    PNP Device ID: ACPI\PNP0F03\4&2C575ACB&0
    Service: i8042prt

    ==== System Restore Points ===================

    RP345: 3/14/2010 1:04:55 AM - System Checkpoint
    RP346: 3/15/2010 10:07:34 AM - System Checkpoint
    RP347: 3/16/2010 10:51:29 AM - System Checkpoint
    RP348: 3/17/2010 6:00:17 PM - System Checkpoint
    RP349: 3/18/2010 6:57:13 PM - System Checkpoint
    RP350: 3/19/2010 7:06:46 PM - System Checkpoint
    RP351: 3/20/2010 8:14:05 PM - System Checkpoint
    RP352: 3/21/2010 9:41:46 PM - System Checkpoint
    RP353: 3/22/2010 9:52:54 PM - System Checkpoint
    RP354: 3/23/2010 10:44:39 PM - System Checkpoint
    RP355: 3/25/2010 3:31:38 PM - System Checkpoint
    RP356: 3/26/2010 3:49:41 PM - System Checkpoint
    RP357: 3/27/2010 4:53:03 PM - System Checkpoint
    RP358: 3/28/2010 5:21:57 PM - System Checkpoint
    RP359: 3/29/2010 5:36:00 PM - System Checkpoint
    RP360: 3/30/2010 6:18:56 PM - System Checkpoint
    RP361: 3/31/2010 6:54:55 PM - System Checkpoint
    RP362: 3/31/2010 11:12:48 PM - Software Distribution Service 3.0
    RP363: 4/1/2010 11:16:27 PM - System Checkpoint
    RP364: 4/2/2010 11:44:33 PM - System Checkpoint
    RP365: 4/4/2010 10:28:39 AM - System Checkpoint
    RP366: 4/4/2010 8:18:56 PM - Installed Belkin Wireless G USB Adapter Software
    RP367: 4/5/2010 8:59:51 PM - System Checkpoint
    RP368: 4/6/2010 9:25:56 PM - System Checkpoint
    RP369: 4/7/2010 9:45:06 PM - System Checkpoint
    RP370: 4/9/2010 6:40:50 AM - System Checkpoint
    RP371: 4/10/2010 8:55:40 AM - System Checkpoint
    RP372: 4/11/2010 9:39:35 AM - System Checkpoint
    RP373: 4/12/2010 7:06:13 PM - System Checkpoint
    RP374: 4/13/2010 10:26:10 PM - Software Distribution Service 3.0
    RP375: 4/14/2010 10:40:34 PM - Software Distribution Service 3.0
    RP376: 4/16/2010 7:14:33 AM - System Checkpoint
    RP377: 4/17/2010 7:48:26 AM - System Checkpoint
    RP378: 4/18/2010 9:35:47 AM - System Checkpoint
    RP379: 4/19/2010 4:10:35 PM - System Checkpoint
    RP380: 4/20/2010 7:53:08 PM - System Checkpoint
    RP381: 4/21/2010 8:04:46 PM - System Checkpoint
    RP382: 4/22/2010 8:08:10 PM - System Checkpoint
    RP383: 4/23/2010 8:45:08 PM - System Checkpoint
    RP384: 4/24/2010 9:40:45 PM - System Checkpoint
    RP385: 4/25/2010 9:43:07 PM - System Checkpoint
    RP386: 4/26/2010 9:53:22 PM - System Checkpoint
    RP387: 4/27/2010 11:18:22 PM - System Checkpoint
    RP388: 4/29/2010 4:59:45 PM - System Checkpoint
    RP389: 4/30/2010 6:23:58 PM - System Checkpoint
    RP390: 5/1/2010 6:37:03 PM - System Checkpoint
    RP391: 5/2/2010 7:12:55 PM - System Checkpoint
    RP392: 5/3/2010 8:14:45 PM - System Checkpoint
    RP393: 5/4/2010 10:12:45 PM - System Checkpoint
    RP394: 5/5/2010 7:27:03 PM - Installed Belkin Wireless G USB Adapter Software
    RP395: 5/5/2010 7:38:56 PM - Installed Belkin Wireless G USB Adapter Software
    RP396: 5/5/2010 7:43:12 PM - Installed Belkin Wireless G USB Adapter Software
    RP397: 5/5/2010 7:47:10 PM - Installed Belkin Wireless G USB Adapter Software
    RP398: 5/5/2010 8:29:12 PM - Installed Belkin Wireless G USB Adapter Software
    RP399: 5/6/2010 8:49:14 PM - System Checkpoint
    RP400: 5/7/2010 9:01:46 PM - System Checkpoint
    RP401: 5/8/2010 9:25:09 PM - System Checkpoint
    RP402: 5/9/2010 10:51:21 PM - System Checkpoint
    RP403: 5/11/2010 3:42:47 PM - System Checkpoint
    RP404: 5/11/2010 11:06:00 PM - Software Distribution Service 3.0
    RP405: 5/13/2010 6:06:21 PM - System Checkpoint
    RP406: 5/14/2010 6:56:23 PM - System Checkpoint
    RP407: 5/15/2010 7:36:16 PM - System Checkpoint
    RP408: 5/16/2010 8:20:46 PM - System Checkpoint
    RP409: 5/17/2010 9:31:44 PM - System Checkpoint
    RP410: 5/18/2010 10:24:14 PM - System Checkpoint
    RP411: 5/19/2010 10:44:50 PM - System Checkpoint
    RP412: 5/21/2010 3:36:08 PM - System Checkpoint
    RP413: 5/22/2010 3:46:51 PM - System Checkpoint
    RP414: 5/23/2010 4:22:18 PM - System Checkpoint
    RP415: 5/24/2010 6:33:56 PM - System Checkpoint
    RP416: 5/25/2010 6:48:55 PM - System Checkpoint
    RP417: 5/26/2010 7:07:24 AM - Software Distribution Service 3.0
    RP418: 5/27/2010 7:33:50 AM - System Checkpoint
    RP419: 5/28/2010 3:36:20 PM - System Checkpoint
    RP420: 5/30/2010 11:48:01 AM - System Checkpoint
    RP421: 5/31/2010 12:06:13 PM - System Checkpoint
    RP422: 6/1/2010 2:12:32 PM - System Checkpoint
    RP423: 6/5/2010 9:38:56 AM - System Checkpoint
    RP424: 6/5/2010 11:22:26 AM - Removed Browser Highlighter - Firefox
    RP425: 6/6/2010 6:43:43 PM - System Checkpoint
    RP426: 6/7/2010 7:43:05 PM - System Checkpoint
    RP427: 6/8/2010 6:45:40 AM - avast! Free Antivirus Setup
    RP428: 6/9/2010 5:12:11 PM - System Checkpoint
    RP429: 6/11/2010 2:40:52 PM - System Checkpoint
    RP430: 6/14/2010 12:04:55 AM - Removed Skype Toolbars
    RP431: 6/14/2010 12:05:28 AM - Removed Skypeâ„¢ 4.1
    RP432: 6/14/2010 12:06:02 AM - Removed Skypeâ„¢ 4.1
    RP433: 6/14/2010 12:07:52 AM - Removed Safari
    RP434: 6/14/2010 12:08:58 AM - Removed QuickTime
    RP435: 6/14/2010 12:10:15 AM - Removed WebEx Support Manager for Internet Explorer
    RP436: 6/14/2010 12:10:42 AM - Removed Bonjour
    RP437: 6/14/2010 12:11:18 AM - Removed Adobe Reader 8.1.1

    ==== Installed Programs ======================


    ACDSee 32
    Adobe Flash Player 10 Plugin
    AiO_Scan_CDA
    AiOSoftwareNPI
    Apple Mobile Device Support
    Apple Software Update
    avast! Free Antivirus
    Backyard Baseball 2003
    Belarc Advisor 7.2
    BufferChm
    Compatibility Pack for the 2007 Office system
    CustomerResearchQFolder
    Destinations
    DeviceManagementQFolder
    doPDF 5.2 printer
    eSupportQFolder
    F300
    F300_Help
    Fax_CDA
    Free eXPert PDF Reader
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    HP Customer Participation Program 7.0
    HP Imaging Device Functions 7.0
    HP Photosmart Essential
    HP Photosmart, Officejet and Deskjet 7.0.A
    HP Software Update
    HP Solution Center 7.0
    HPPhotoSmartExpress
    HPProductAssistant
    InstantShareDevicesMFC
    Intel(R) Graphics Media Accelerator Driver
    iTunes
    Java(TM) 6 Update 14
    Java(TM) 6 Update 3
    MarketResearch
    MemoriesOnTV 4.0.4
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Office Professional Edition 2003
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Mozilla Firefox (3.5.9)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB925673)
    NewCopy_CDA
    ONES (E)
    ProductContextNPI
    Readme
    Right Click Image Converter
    Scan
    ScannerCopy
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB979402)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB980232)
    Simple Sudoku 4.2
    SlimBrowser (remove only)
    SolutionCenter
    Status
    SUPERAntiSpyware Professional
    TestCheck Geometry
    Toolbox
    TrayApp
    Trojan Remover 6.8.1
    TurboTax 2009
    TurboTax 2009 WinPerFedFormset
    TurboTax 2009 WinPerReleaseEngine
    TurboTax 2009 WinPerTaxSupport
    TurboTax 2009 wohiper
    TurboTax 2009 wrapper
    UltraISO Premium V8.2
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB978506)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Video Edit Magic 4.4
    VideoLAN VLC media player 0.8.6c
    WebFldrs XP
    WebReg
    Windows Genuine Advantage Notifications (KB905474)
    Windows Internet Explorer 8
    Windows Presentation Foundation
    WinRAR archiver
    XML Paper Specification Shared Components Pack 1.0

    ==== Event Viewer Messages From Past Week ========

    6/9/2010 9:02:35 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
    6/9/2010 9:02:34 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Themes service to connect.
    6/9/2010 9:02:34 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the DHCP Client service to connect.
    6/9/2010 9:02:34 AM, error: Service Control Manager [7000] - The Themes service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/9/2010 9:02:34 AM, error: Service Control Manager [7000] - The DHCP Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/9/2010 9:02:18 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
    6/9/2010 3:38:27 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
    6/9/2010 10:48:29 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments " " in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
    6/8/2010 6:49:00 AM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting.
    6/8/2010 6:47:44 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
    6/8/2010 6:47:44 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Workstation service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Wireless Zero Configuration service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Audio service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Task Scheduler service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Shell Hardware Detection service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Network Security service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Logical Disk Manager service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Cryptographic Services service to connect.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7001] - The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Workstation service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Wireless Zero Configuration service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Windows Audio service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Task Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Network Security service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Logical Disk Manager service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/8/2010 6:47:35 AM, error: Service Control Manager [7000] - The Cryptographic Services service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/7/2010 11:14:08 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    6/14/2010 12:22:32 AM, error: IPRIP [29028] - IPRIP was unable to create a socket for address 192.168.0.105. The data is the error code.
    6/14/2010 1:12:27 AM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
    6/13/2010 9:55:53 AM, error: Service Control Manager [7023] - The Network Security service terminated with the following error: The system cannot find the file specified.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HID Input Service service to connect.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Help and Support service to connect.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Error Reporting Service service to connect.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COM+ Event System service to connect.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7001] - The System Event Notification service depends on the COM+ Event System service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7000] - The HID Input Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7000] - The Help and Support service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/13/2010 9:21:11 AM, error: Service Control Manager [7000] - The COM+ Event System service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/13/2010 9:14:46 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    6/13/2010 8:48:03 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments " " in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    6/13/2010 8:42:47 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments " " in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    6/13/2010 8:42:39 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    6/13/2010 8:40:29 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi BANTExt Fips i8042prt intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip Tcpip6
    6/13/2010 8:40:29 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    6/13/2010 8:40:29 PM, error: Service Control Manager [7001] - The Simple TCP/IP Services service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    6/13/2010 8:40:29 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/13/2010 8:40:29 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/13/2010 8:40:29 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    6/13/2010 8:39:51 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    6/13/2010 8:22:39 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: An address incompatible with the requested protocol was used.
    6/13/2010 8:22:39 PM, error: Service Control Manager [7023] - The Simple TCP/IP Services service terminated with the following error: The support for the specified socket type does not exist in this address family.
    6/13/2010 8:22:39 PM, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: The support for the specified socket type does not exist in this address family.
    6/13/2010 8:22:34 PM, error: IPRIP [29028] - IPRIP was unable to create a socket for address 192.168.1.106. The data is the error code.
    6/13/2010 6:04:31 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 480 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    6/13/2010 2:04:31 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 240 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    6/13/2010 12:04:31 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 120 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    6/13/2010 11:53:38 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments " " in order to run the server: {000C101C-0000-0000-C000-000000000046}
    6/13/2010 11:47:38 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments " " in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    6/13/2010 11:04:30 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    6/13/2010 10:10:07 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the RIP Listener service to connect.
    6/13/2010 10:10:07 AM, error: Service Control Manager [7000] - The RIP Listener service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/10/2010 5:11:50 PM, error: System Error [1003] - Error code 10000050, parameter1 a7b77000, parameter2 00000001, parameter3 89967c19, parameter4 00000000.

    ==== End Of File ===========================
     
  2. 2010/06/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. Click Start>Run (Start> "Start search" in Vista).

    2. Type in (or copy and paste):

    cmd /c ping google.com>%temp%\$.$&notepad %temp%\$.$

    and press Enter.

    3. Notepad will open.

    4. Copy all text in Notepad ([Ctrl-A], then [Ctrl-C]), and then post it (paste = [Ctrl-V]) in your next reply.
     

  3. to hide this advert.

  4. 2010/06/15
    Oldmartian

    Oldmartian Inactive Thread Starter

    Joined:
    2010/06/14
    Messages:
    5
    Likes Received:
    0
    I'm running XP. Results:

    Ping request could not find host google.com. Please check the name and try again.
     
  5. 2010/06/15
    Oldmartian

    Oldmartian Inactive Thread Starter

    Joined:
    2010/06/14
    Messages:
    5
    Likes Received:
    0
    Broni,

    I'm afraid I'm going to have to discontinue this. I know you're a volunteer but I cannot wait this long between exchanges. I'm more experienced in this than the average guy and it would be quicker to re-format the drive and start over. I looked at your web-site and figure you're doing a lot of these tech boards and those people need you more than I do.

    Thank you anyway.
    Old Martian
     
  6. 2010/06/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Not a problem :)
    Thanks for letting me know :)
    Some people just leave....hmmmm
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.