1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Error 1068: Totally unprotected!

Discussion in 'Malware and Virus Removal Archive' started by LadyYepperz, 2009/03/05.

Thread Status:
Not open for further replies.
  1. 2009/03/05
    LadyYepperz

    LadyYepperz Inactive Thread Starter

    Joined:
    2009/03/05
    Messages:
    6
    Likes Received:
    0
    Please Help Me! Many of my windows services arent working. Windows Firewall for one. I cant update my AVP, Spybot or any other exe on my pc. And I am unable to download anything from any where including microsoft.

    When I tried to restart my firewall I got this elert.
    windows firewall settings cannot be displayed because the associated service is not running. do you want to start the windows firewall/interent connection sharing (ics) service.

    I hit yes and i get another alert saying...
    windows cannot start the windows firewall/internet connection sharing (ics) service.

    When i tried to restart ICS in services.msc, I got this error...
    Could not start the windows firewall/interent connection sharing (ics) service on local computer. Error 1068: the dependancy service or group failed to start.

    I clicked properties and the dependency tab and i get an elert saying...
    interface: class not registered
    and there is no dependencies listed

    In the event viewer I have a repeating error...
    DCOM got error "The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. " attempting to start the service StiSvc with arguments " " in order to run the server:
    {A1F4E726-8CF1-11D1-BF92-0060081ED811}



    Im running Windows Home XP SP3.
    I hope Ive provided enough information to allow you to diagnois my problem. I have no idea how to correct this problem. Can you guys please help me?
     
  2. 2009/03/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)

    Strong possibility of malware at work here - I have moved your thread to the Malware & Virus Removal forum.

    There is an announcement at the head of the forum .....

    *** READ THIS BEFORE POSTING IN THIS FORUM ***

    Please read and post the logs requested in this thread.
     

  3. to hide this advert.

  4. 2009/03/05
    LadyYepperz

    LadyYepperz Inactive Thread Starter

    Joined:
    2009/03/05
    Messages:
    6
    Likes Received:
    0
    Its not a virus! Its the results of a virus. Its been removed. Now I need to repair the damage.
     
  5. 2009/03/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I would not be so sure :) There is a lot more malware around which is not viral in nature.
    is symptomatic of a lot of infections currently around.

    I suggest you post the logs requested - if you are unable to download on this computer use another and transfer DDS across and run it on the troublesome computer. It's your call.
     
  6. 2009/03/05
    LadyYepperz

    LadyYepperz Inactive Thread Starter

    Joined:
    2009/03/05
    Messages:
    6
    Likes Received:
    0
    I couldnt figure out how to upload the logs so copy & paste it is.

    Attach.txt

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-02-01.01)


    ==== Disk Partitions =========================


    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    Active Desktop Calendar 7.57
    ActivePerl 5.10.0 Build 1004
    ActiveState Komodo Edit 5.0.0
    Adobe Bridge 1.0
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 7.1.0
    Advanced SystemCare 3
    AIM 6
    Aleks 3.8
    ALEKS Plugin 3.8
    AOpen FM56-SVV Soft PCI Modem
    ASIO4ALL
    AutoUpdate
    AVG Free 8.0
    Azureus
    Boggle (remove only)
    CCleaner (remove only)
    DivX Web Player
    DzSoft PHP Editor 4.2.1
    ebgcInfra
    ebgcRes
    ebgcSDK
    FileZilla Client 3.2.0
    Gateway Drivers and Applications Recovery
    Gimp 2.6.2 Debug
    GMail Drive Shell Extension
    Google Toolbar for Internet Explorer
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    hp psc 700 series
    Intel(R) Extreme Graphics 2 Driver
    Intel(R) Network Connections 13.2.8.0
    Intel(R) PRO Network Adapters and Drivers
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 10
    Java(TM) 6 Update 7
    Kiran's Typing Tutor 1.0
    Logitech Audio Echo Cancellation Component
    Logitech Desktop Messenger
    Logitech Legacy USB Camera Driver Package
    Logitech QuickCam
    Logitech QuickCam Driver Package
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0
    Microsoft Calculator Plus
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Data Access Components KB870669
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.0.6)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MVision
    OpenOffice.org 3.0
    PHP 5.2.6
    QuickTime
    RCT3 Soaked
    RealArcade
    RegCure 1.5.0.0
    RollerCoaster Tycoon 2 Triple Thrill Pack
    RollerCoaster Tycoon® 3
    Security Update for Microsoft .NET Framework 2.0 (KB928365)
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB911565)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB958687)
    Soft Data Fax Modem with SmartCP
    Spybot - Search & Destroy
    Spybot - Search & Destroy 1.5.2.20
    SUPERAntiSpyware Free Edition
    SuperOthello
    Ulead COOL 3D 3.5 Trial
    Update for Windows XP (KB951072-v2)
    WebFldrs XP
    WildTangent Games
    WindowBlinds
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage v1.3.0254.0
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Live OneCare safety scanner
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    XAMPP 1.6.8
    Yahoo! Anti-Spy
    Yahoo! Browser Services
    Yahoo! Messenger
    Yahoo! Music Jukebox
    Yahoo! Toolbar

    ==== End Of File ===========================

    DDS.txt

    DDS (Ver_09-02-01.01) - NTFSx86
    Run by Retta at 13:22:50.79 on Thu 03/05/2009
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_10

    ============== Running Processes ===============


    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uStart Page = hxxp://www.msn.com
    uLocal Page = c:\windows\system32\blank.htm
    mStart Page = hxxp://www.msn.com
    mLocal Page = c:\windows\system32\blank.htm
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn3\yt.dll
    BHO: NoExplorer - No File
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0

    \activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450

    \swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google

    toolbar\component\fastsearch_219B3E1547538286.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn3\YTSingleInstance.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn3\yt.dll
    TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
    TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
    uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [Active Desktop Calendar] c:\program files\xemicomputers\active desktop calendar\ADC.exe
    uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!

    \common\yiesrvc.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
    DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
    DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F}
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
    Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480

    \program\GAPlugProtocol-8876480.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxsrvc.dll
    Notify: WBSrv - c:\program files\stardock\object desktop\windowblinds\wbsrv.dll
    AppInit_DLLs: wbsys.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll
    SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File
    LSA: Notification Packages = scecli scecli scecli

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\retta\applic~1\mozilla\firefox\profiles\2cqbgucb.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
    FF - prefs.js: browser.startup.homepage -

    hxxp://fridayhosting.com/forums/usercp.php|http://www.ieroticxpressions.com/home.php|http://www.ieroticxpressions.com:2082/frontend/x3/index.

    html
    FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPMySrch.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npzylomgamesplayer.dll
    FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll

    ============= SERVICES / DRIVERS ===============


    ============== File Associations ===============

    regfile=regedit.exe "%1" %*
    scrfile= "%1" %*

    =============== Created Last 30 ================

    2009-03-04 22:47 116,224 a------- c:\winnt\system32\dllcache\OLDD8A.tmp
    2009-03-04 22:47 23,040 a------- c:\winnt\system32\dllcache\OLDD86.tmp
    2009-03-04 22:47 18,944 a------- c:\winnt\system32\dllcache\OLDD82.tmp
    2009-03-04 22:47 27,648 a------- c:\winnt\system32\dllcache\OLDD7E.tmp
    2009-03-04 22:47 4,608 a------- c:\winnt\system32\dllcache\OLDD7A.tmp
    2009-03-04 22:47 99,865 a------- c:\winnt\system32\dllcache\OLDD76.tmp
    2009-03-04 22:47 16,970 a------- c:\winnt\system32\dllcache\OLDD72.tmp
    2009-03-04 22:47 19,455 a------- c:\winnt\system32\dllcache\OLDD6E.tmp
    2009-03-04 22:47 12,063 a------- c:\winnt\system32\dllcache\OLDD6A.tmp
    2009-03-04 22:47 8,192 a------- c:\winnt\system32\dllcache\OLDD66.tmp
    2009-03-04 22:47 8,832 a------- c:\winnt\system32\dllcache\OLDD62.tmp
    2009-03-04 22:47 154,624 a------- c:\winnt\system32\dllcache\OLDD5E.tmp
    2009-03-04 22:45 60,032 a------- c:\winnt\system32\dllcache\OLDCD5.tmp
    2009-03-04 22:44 103,936 a------- c:\winnt\system32\dllcache\OLDC1E.tmp
    2009-03-04 22:43 238,592 a------- c:\winnt\system32\dllcache\OLDB45.tmp
    2009-03-04 22:42 9,216 a------- c:\winnt\system32\dllcache\OLDA8A.tmp
    2009-03-04 22:41 5,504 a------- c:\winnt\system32\dllcache\OLD9D9.tmp
    2009-03-04 22:40 60,480 a------- c:\winnt\system32\dllcache\OLD93A.tmp
    2009-03-04 22:39 92,416 a------- c:\winnt\system32\dllcache\OLD8C3.tmp
    2009-03-04 22:38 5,632 ac------ c:\winnt\system32\dllcache\OLD807.tmp
    2009-03-04 22:37 58,592 a------- c:\winnt\system32\dllcache\OLD780.tmp
    2009-03-04 22:36 454,912 a------- c:\winnt\system32\dllcache\OLD6C4.tmp
    2009-03-04 22:35 144,896 a------- c:\winnt\system32\dllcache\OLD5CD.tmp
    2009-03-04 22:34 37,735 a------- c:\winnt\system32\dllcache\OLD4F4.tmp
    2009-03-04 22:33 10,240 a------- c:\winnt\system32\dllcache\OLD441.tmp
    2009-03-04 22:32 10,752 a------- c:\winnt\system32\dllcache\OLD3A6.tmp
    2009-03-04 22:31 9,728 a------- c:\winnt\system32\dllcache\OLD2CE.tmp
    2009-03-04 22:30 12,032 a------- c:\winnt\system32\dllcache\OLD20F.tmp
    2009-03-04 22:29 16,384 ac------ c:\winnt\system32\dllcache\OLD18D.tmp
    2009-03-04 19:20 46,954 ac------ C:\MGlogs.zip
    2009-03-04 19:04 605,696 a------- c:\winnt\system32\getuname.dll
    2009-03-04 18:23 <DIR> --d----- c:\winnt\system32\CatRoot2
    2009-03-04 17:31 575 a------- c:\winnt\imsins.BAK
    2009-03-03 22:42 319 ---shr-- C:\autorun.inf
    2009-03-03 21:08 63 a------- c:\winnt\WINHELP.BMK
    2009-03-03 21:08 50 a------- c:\winnt\INSTALL.INI
    2009-03-03 20:25 <DIR> --d----- c:\program files\Happy Note
    2009-02-26 23:48 <DIR> --d----- c:\winnt\SuperOthello
    2009-02-26 23:48 <DIR> --d----- c:\program files\SuperOthello
    2009-02-26 23:30 434,271 a------- c:\program files\Uninstall Fun Web Products.dll
    2009-02-20 15:45 <DIR> --d-h--- C:\XP Pro Install Disk
    2009-02-15 13:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NeptunesAdve
    2009-02-09 18:55 10,520 a------- c:\winnt\system32\avgrsstx.dll
    2009-02-09 17:27 0 a------- c:\winnt\system32\commonpriv.log.lock
    2009-02-09 17:22 107,272 a------- c:\winnt\system32\drivers\avgtdix.sys
    2009-02-09 17:22 325,128 a------- c:\winnt\system32\drivers\avgldx86.sys
    2009-02-09 17:22 <DIR> --d----- c:\winnt\system32\drivers\Avg
    2009-02-09 14:03 <DIR> --d----- c:\docume~1\retta\applic~1\aAvgApi
    2009-02-09 13:39 21,504 a------- c:\winnt\system32\hidserv.dll
    2009-02-09 13:39 21,504 a------- c:\winnt\system32\dllcache\hidserv.dll
    2009-02-09 13:39 14,592 a------- c:\winnt\system32\drivers\kbdhid.sys
    2009-02-09 13:39 14,592 a------- c:\winnt\system32\dllcache\kbdhid.sys

    ==================== Find3M ====================

    2009-02-09 15:13 324,872 a------- c:\winnt\system32\drivers\avgldx86.sys.old
    2009-01-30 19:45 61,268 a------- c:\winnt\system32\sndvol32.zip
    2009-01-16 21:35 3,594,752 a------- c:\winnt\system32\dllcache\mshtml.dll
    2009-01-14 16:11 38,496 a------- c:\winnt\system32\drivers\mbamswissarmy.sys
    2009-01-14 16:11 15,504 a------- c:\winnt\system32\drivers\mbam.sys
    2008-12-19 04:10 70,656 a------- c:\winnt\system32\dllcache\ie4uinit.exe
    2008-12-19 04:10 13,824 -------- c:\winnt\system32\dllcache\ieudinit.exe
    2008-12-19 00:25 634,024 a--s---- c:\winnt\system32\dllcache\iexplore.exe
    2008-12-19 00:23 161,792 a------- c:\winnt\system32\dllcache\ieakui.dll
    2008-12-11 05:57 333,952 a------- c:\winnt\system32\dllcache\srv.sys
    2008-02-29 23:37 0 ac------ c:\program files\temp01
    2007-07-14 16:29 774,144 ac------ c:\program files\RngInterstitial.dll

    ============= FINISH: 13:23:34.60 ===============
     
  7. 2009/03/05
    LadyYepperz

    LadyYepperz Inactive Thread Starter

    Joined:
    2009/03/05
    Messages:
    6
    Likes Received:
    0
    ok its done
     
    Last edited: 2009/03/05
  8. 2009/03/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Thanks :)

    One of our trained malware analysts will take a look at your logs ASAP, but it may be a day or so before you get a response as they are always very busy. All logs are dealt with in the order received.

    Thank you for your patience.
     
  9. 2009/03/06
    LadyYepperz

    LadyYepperz Inactive Thread Starter

    Joined:
    2009/03/05
    Messages:
    6
    Likes Received:
    0
    Thank you all for giving my situation thought... Since starting this thread Ive corrected my system's problems.

    As I do not know how, could an Admin or Mod please close this thread.

    Happy Debugging! :)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.