1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active Connection Interrupted

Discussion in 'Malware and Virus Removal Archive' started by Chipstah, 2010/01/14.

  1. 2010/01/14
    Chipstah

    Chipstah Inactive Thread Starter

    Joined:
    2010/01/06
    Messages:
    3
    Likes Received:
    0
    [Active]Connection Interrupted

    carried over from this thread http://www.windowsbbs.com/windows-7/90029-connection-interrupted.html

    My logs as requested:
    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\AEADISRV.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\Windows\system32\IoctlSvc.exe
    C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Analog Devices\SoundMAX\SoundMAX.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files\Adobe\Adobe Photoshop Lightroom 2.6\lightroom.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\Chipztah\Desktop\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uDefault_Search_URL = hxxp://www.google.com/ie
    uSearch Bar = hxxp://www.google.com/ie
    uSearch Page = hxxp://www.google.com
    uStart Page = hxxp://www.yahoo.com
    mDefault_Page_URL = hxxp://www.yahoo.com
    mStart Page = hxxp://www.yahoo.com
    uInternet Settings,ProxyOverride = *.local;<local>
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: TSToolbarBHO: {43c6d902-a1c5-45c9-91f6-fd9e90337e18} - c:\program files\trend micro\trendsecure\tisprotoolbar\TSToolbar.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: Trend Micro Toolbar: {ccac5586-44d7-4c43-b64a-f042461a97d2} - c:\program files\trend micro\trendsecure\tisprotoolbar\TSToolbar.dll
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
    uRun: [OE] "c:\program files\trend micro\internet security\tmas_oe\TMAS_OEMon.exe "
    uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
    uRun: [TrendSecure Remote File Lock] c:\program files\trend micro\trendsecure\remotefilelock\FLMain.exe /lock
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe "
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [SoundMAX] c:\program files\analog devices\soundmax\soundmax.exe /tray
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe "
    mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe "
    mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - c:\program files\trend micro\trendsecure\tisprotoolbar\TSToolbar.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe "

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\chipztah\appdata\roaming\mozilla\firefox\profiles\mbwbw3ux.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.nz/ig?hl=en&source=iglk
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
    FF - component: c:\program files\trend micro\trendsecure\tisprotoolbar\firefoxextension\components\FFTMUFEHelper.dll
    FF - component: c:\program files\trend micro\trendsecure\tisprotoolbar\firefoxextension\components\FFToolbarComm.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================

    2010-01-13 23:13:25 108544 ----a-w- c:\windows\system32\t2embed.dll
    2010-01-13 23:13:24 70656 ----a-w- c:\windows\system32\fontsub.dll
    2010-01-10 02:48:16 96256 ----a-w- c:\windows\system32\Csp3osu.dll
    2010-01-10 02:48:16 45568 ----a-w- c:\windows\ScFBPPM3.DLL
    2010-01-10 02:48:16 16896 ----a-w- c:\windows\system32\Csp3utl.dll
    2010-01-10 02:48:16 16032 ----a-w- c:\windows\system32\drivers\ScFBPNT3.sys
    2010-01-10 02:48:15 318976 ----a-w- c:\windows\system32\Ucs32p.dll
    2010-01-10 02:48:11 0 d-----w- c:\windows\system32\Color
    2010-01-10 02:48:10 0 d-----w- c:\program files\Canon
    2010-01-10 02:47:46 304128 ----a-w- c:\windows\IsUninst.exe
    2010-01-10 02:29:48 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-01-10 02:26:15 0 d-----w- c:\programdata\Lavasoft
    2010-01-10 02:26:15 0 d-----w- c:\program files\Lavasoft
    2010-01-10 02:05:44 3619264 ----a-w- c:\users\chipztah\AppRemover.exe
    2010-01-10 01:25:53 0 dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
    2010-01-10 00:29:11 257024 ----a-w- c:\windows\system32\msv1_0.dll
    2010-01-10 00:29:10 91338304 ----a-w- c:\users\chipztah\Ad-AwareInstallation.exe
    2010-01-10 00:25:43 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-01-10 00:20:49 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2010-01-10 00:20:49 507568 ----a-w- c:\windows\system32\winload.exe
    2010-01-10 00:20:49 442920 ----a-w- c:\windows\system32\winresume.exe
    2010-01-10 00:20:49 293888 ----a-w- c:\windows\system32\atmfd.dll
    2010-01-10 00:20:49 2613248 ----a-w- c:\windows\explorer.exe
    2010-01-10 00:20:49 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
    2010-01-10 00:20:48 12625408 ----a-w- c:\windows\system32\wmploc.DLL
    2010-01-10 00:18:34 34816 ----a-w- c:\windows\system32\msasn1.dll
    2010-01-06 10:46:06 0 d-----w- c:\programdata\LightScribe
    2010-01-06 06:58:32 0 d-----w- c:\windows\Panther
    2010-01-06 06:46:01 0 d--h--w- C:\$WINDOWS.~Q
    2010-01-06 06:39:38 0 d--h--w- C:\$INPLACE.~TR
    2010-01-06 03:23:21 0 d-----w- c:\windows\system32\appmgmt
    2010-01-05 11:03:12 632 --sha-r- c:\users\chipztah\ntuser.pol
    2010-01-05 11:02:38 20 --sh--w- c:\users\chipztah\ntuser.ini
    2010-01-05 11:00:21 713888 ----a-w- c:\windows\system32\PerfStringBackup.INI
    2010-01-05 10:57:54 0 d-----w- c:\windows\system32\wbem\Performance
    2010-01-05 10:41:45 21316 ----a-w- c:\windows\system32\emptyregdb.dat
    2010-01-05 10:03:02 0 d-----w- c:\programdata\SonicFocus
    2010-01-05 10:03:01 0 d-----w- c:\program files\Analog Devices
    2010-01-05 08:41:11 1890 ----a-w- c:\windows\diagwrn.xml
    2010-01-05 08:41:11 1890 ----a-w- c:\windows\diagerr.xml
    2009-12-25 23:13:04 0 d-----w- c:\program files\Topaz Labs
    2009-12-25 22:41:05 0 d-----w- c:\programdata\Google
    2009-12-24 09:09:48 0 d-----w- C:\divx
    2009-12-24 06:18:43 0 d-----w- c:\program files\DivX
    2009-12-24 02:47:05 0 d-----w- c:\programdata\CanonBJ
    2009-12-23 01:54:01 0 d-----w- c:\users\chipztah\appdata\roaming\AVS4YOU
    2009-12-23 01:53:27 0 d-----w- c:\program files\AVS4YOU
    2009-12-23 01:49:33 0 d-----w- c:\users\chipztah\appdata\roaming\AVSMedia
    2009-12-23 01:49:24 0 d-----w- c:\programdata\AVS4YOU
    2009-12-23 01:45:59 0 d-----w- c:\program files\common files\AVSMedia
    2009-12-23 01:45:50 0 d-----w- c:\program files\AVSMedia
    2009-12-20 06:57:50 153775688 ----a-w- c:\users\chipztah\LTRM2_WWEFG_win_2_6.exe
    2009-12-16 06:19:00 0 d-----w- c:\program files\Amazon

    ==================== Find3M ====================

    2009-11-21 08:38:44 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-11-17 05:34:19 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
    2009-11-14 23:55:57 413696 ----a-w- c:\windows\system32\wrap_oal.dll
    2009-11-14 23:55:57 110592 ----a-w- c:\windows\system32\OpenAL32.dll
    2009-11-02 07:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-30 00:29:08 2146304 ----a-w- c:\windows\system32\GPhotos.scr
    2009-10-21 00:30:25 57996 ----a-w- c:\windows\fonts\Romantic_font_by_estilojb.ttf
    2009-10-21 00:26:58 38488 ----a-w- c:\windows\fonts\Katy_Berry___Katy_Perry_Font_by_KeepWaiting.ttf
    2009-10-20 23:45:23 16544 ----a-w- c:\windows\fonts\Twilight_Font_by_KristianasCoven.ttf
    2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
    2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
    2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

    ============= FINISH: 21:35:06.13 ===============
     
  2. 2010/01/14
    crunchie

    crunchie Inactive

    Joined:
    2010/01/12
    Messages:
    982
    Likes Received:
    5
    I am not seeing anything wrong in that log. Can you please post the other log called attach.txt.
    Have you tried resetting the router?
     

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.