Connected to the internet but cannot browse!

View previous topic View next topic Go down

Connected to the internet but cannot browse!

Post by Hydra_o0 on Wed Jan 13, 2010 8:28 am

I have tried many different things to try and fix this problem, several malware/adware/spyware removal programs but I just can't seem to find the problem. There is nothing wrong with my internet connection as I have 3 other pcs connected and running just fine. I am trying to fix my friends laptop but I didnt think it would be this frustrating! Mod please move this post if it is the wrong place! I think it is malware stopping me from browsing though. Any help is greatly appreciated - see log below

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:17:24 AM, on 13/01/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\JUSTIN~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Justin Foisy\Desktop\winlogon.scr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; FunWebProducts; GTB6; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.playhub.com/sports-games/470/Snowboarder-XS.html"
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [You must be registered and logged in to see this link.]
O17 - HKLM\System\CCS\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer = 192.168.1.254,192.168.1.70
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe

--
End of file - 5730 bytes


Last edited by Hydra_o0 on Wed Jan 13, 2010 9:01 am; edited 2 times in total (Reason for editing : oops didn't select all when copying and pasting log!)

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Wed Jan 13, 2010 9:09 am

Please download [You must be registered and logged in to see this link.], and save to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.cmd to start.
  • It will finish quickly and launch a log.
  • Post the contents of it in your next reply.


==

Please download [You must be registered and logged in to see this link.], and save to your Desktop.
  • Double-click on vtool.zip, and extract the file to your Desktop.
  • Double-click on vtool.cmd to start.
  • At each prompt ("Press any key to continue..."), wait 3 seconds before pressing a key. This tool needs time to process each prompt.
  • It will finish quickly and launch a log. (vtool.txt)
  • Post the contents of it in your next reply.


==

Please post the log from both tools.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Thu Jan 14, 2010 9:01 pm

Cheetah Anti-Rogue v1.0.35
by DragonMaster Jay

Microsoft Windows [Version 6.0.6002]
14/01/2010 12:55:20.88


-- Known infection --



Extra message: Detection only.


EOF


V-Tool by DragonMaster Jay

Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.765.95 [GMT -8:00]

Username: Justin Foisy - Date: 14/01/2010 - Time: 12:59:09 - Number of processors: 1 - Arch.: x86 SF:


((((( Security Software information )))))

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

((((( System File Verify )))))

c:\windows\system32\eventlog.dll is missing! (If XP or lower)

((((( System File Enumeration )))))

Volume in drive C is OS
Volume Serial Number is 364C-D180

Directory of C:\WINDOWS\ERDNT\cache

scecli.dll beep.sys cngaudit.dll
atapi.sys netlogon.dll
5 File(s) 807,912 bytes

Thanks for helping me out

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Thu Jan 14, 2010 10:58 pm

V-Tool did not fully run.

Please run it till it launches the log. It will exit on its own.

==

Please visit this webpage for instructions for downloading and running ComboFix:

[You must be registered and logged in to see this link.]

Post the log from ComboFix when you've accomplished that.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Fri Jan 15, 2010 12:52 am

V-Tool by DragonMaster Jay

Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.765.190 [GMT -8:00]

Username: Justin Foisy - Date: 14/01/2010 - Time: 15:59:28 - Number of processors: 1 - Arch.: x86 SF:


((((( Security Software information )))))

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

((((( System File Verify )))))

c:\windows\system32\eventlog.dll is missing! (If XP or lower)

((((( System File Enumeration )))))

Volume in drive C is OS
Volume Serial Number is 364C-D180

Directory of C:\WINDOWS\ERDNT\cache

scecli.dll beep.sys cngaudit.dll
atapi.sys netlogon.dll
5 File(s) 807,912 bytes

Directory of C:\WINDOWS\System32

scecli.dll netlogon.dll cngaudit.dll
3 File(s) 781,824 bytes

Directory of C:\WINDOWS\System32\drivers

atapi.sys beep.sys
2 File(s) 26,088 bytes

Directory of C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84

atapi.sys
1 File(s) 19,944 bytes

Directory of C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699

atapi.sys
1 File(s) 19,048 bytes

Directory of C:\WINDOWS\System32\DriverStore\FileRepository\mshdc.inf_cc18792d

atapi.sys
1 File(s) 21,560 bytes

Directory of C:\WINDOWS\winsxs\x86_microsoft-windows-beepsys_31bf3856ad364e35_6.0.6001.nȯne

beep.sys
1 File(s) 6,144 bytes

Directory of C:\WINDOWS\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.nȯne

cngaudit.dll
1 File(s) 11,776 bytes

Directory of C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.nȯne

scecli.dll
1 File(s) 177,152 bytes

Directory of C:\WINDOWS\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.nȯne

scecli.dll
1 File(s) 177,152 bytes

Directory of C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.nȯne

netlogon.dll
1 File(s) 592,384 bytes

Directory of C:\WINDOWS\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.nȯne

netlogon.dll
1 File(s) 592,896 bytes

Directory of C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.nȯne

atapi.sys
1 File(s) 21,560 bytes

Directory of C:\WINDOWS\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.nȯne

atapi.sys
1 File(s) 19,944 bytes

Total Files Listed:
21 File(s) 3,275,384 bytes
0 Dir(s) 90,265,985,024 bytes free

-----------------------------

+++ End-of-file +++

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Fri Jan 15, 2010 12:53 am

ComboFix 10-01-14.02 - Justin Foisy 14/01/2010 16:19:54.2.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.765.269 [GMT -8:00]
Running from: c:\users\Justin Foisy\Desktop\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.

2010-01-15 00:35 . 2010-01-15 00:35 -------- d-----w- c:\users\Justin Foisy\AppData\Local\temp
2010-01-15 00:35 . 2010-01-15 00:35 -------- d-----w- c:\users\test\AppData\Local\temp
2010-01-15 00:35 . 2010-01-15 00:35 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-15 00:35 . 2010-01-15 00:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-13 07:32 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 07:32 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-13 07:28 . 2010-01-13 07:28 -------- d-----w- c:\users\test\AppData\Roaming\ATI
2010-01-13 07:28 . 2010-01-13 07:28 -------- d-----w- c:\users\test\AppData\Local\ATI
2010-01-13 07:27 . 2010-01-13 07:27 72184 ----a-w- c:\users\test\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-13 00:07 . 2010-01-13 00:40 190247 ----a-w- C:\MGlogs.zip
2010-01-13 00:07 . 2010-01-13 00:40 -------- d-----w- C:\MGtools
2010-01-11 11:01 . 2010-01-11 11:01 0 ----a-w- c:\users\Justin Foisy\settings.dat
2010-01-10 10:12 . 2010-01-10 10:12 -------- d-----w- c:\users\Justin Foisy\AppData\Roaming\Malwarebytes
2010-01-10 10:12 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-10 10:12 . 2010-01-10 10:12 -------- d-----w- c:\programdata\Malwarebytes
2010-01-10 10:12 . 2010-01-10 10:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-10 10:12 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-10 08:30 . 2010-01-10 08:30 52224 ----a-w- c:\users\Justin Foisy\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-10 08:29 . 2010-01-10 08:29 117760 ----a-w- c:\users\Justin Foisy\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-10 08:29 . 2010-01-10 08:29 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-01-10 08:28 . 2010-01-10 08:28 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-10 08:28 . 2010-01-10 08:28 -------- d-----w- c:\users\Justin Foisy\AppData\Roaming\SUPERAntiSpyware.com
2010-01-10 08:26 . 2010-01-10 08:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-10 08:24 . 2010-01-10 08:24 -------- d-----w- c:\users\Justin Foisy\AppData\Local\Threat Expert
2010-01-10 08:10 . 2010-01-10 08:06 2387816 ----a-w- C:\MGtools.exe
2010-01-10 01:07 . 2010-01-10 01:07 -------- d-----w- c:\program files\Windows Portable Devices
2010-01-09 20:50 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-01-09 20:50 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2010-01-09 20:50 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2010-01-09 20:50 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2010-01-09 20:50 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2010-01-09 20:50 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-01-09 20:50 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2010-01-09 20:50 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2010-01-09 20:50 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2010-01-09 20:50 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2010-01-09 20:50 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2010-01-09 20:50 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2010-01-09 20:48 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-01-09 20:48 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-01-09 20:48 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-01-08 02:54 . 2010-01-08 02:55 -------- d-----w- c:\windows\system32\ca-ES
2010-01-08 02:54 . 2010-01-08 02:54 -------- d-----w- c:\windows\system32\eu-ES
2010-01-08 02:54 . 2010-01-08 02:54 -------- d-----w- c:\windows\system32\vi-VN
2010-01-07 01:43 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2010-01-07 01:43 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2010-01-07 01:43 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2010-01-07 01:43 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2010-01-07 01:43 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2010-01-07 01:43 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2010-01-07 01:43 . 2009-04-11 06:28 1480704 ----a-w- c:\windows\system32\mssrch.dll
2010-01-07 01:41 . 2009-04-11 06:28 758784 ----a-w- c:\windows\system32\qmgr.dll
2010-01-07 01:40 . 2009-04-11 06:28 302592 ----a-w- c:\windows\system32\QAGENTRT.DLL
2010-01-07 01:38 . 2009-04-11 06:28 342528 ----a-w- c:\windows\system32\zipfldr.dll
2010-01-07 01:37 . 2009-04-11 06:28 200704 ----a-w- c:\windows\system32\input.dll
2010-01-07 01:36 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2010-01-07 01:36 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2010-01-07 01:36 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2010-01-07 01:36 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2010-01-07 01:36 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2010-01-07 01:36 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2010-01-07 01:36 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2010-01-07 01:36 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2010-01-07 01:36 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2010-01-07 01:36 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2010-01-07 01:35 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2010-01-04 03:59 . 2010-01-04 03:59 -------- d-----w- c:\windows\system32\EventProviders
2010-01-04 03:59 . 2010-01-07 01:58 -------- d-----w- C:\ee64b6266bd939872850aad6e5aeee
2010-01-04 03:56 . 2009-11-03 04:42 195456 ------w- c:\windows\system32\MpSigStub.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-15 00:17 . 2009-12-05 20:07 -------- d-----w- c:\users\Justin Foisy\AppData\Roaming\uTorrent
2010-01-13 07:43 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-11 06:53 . 2009-03-16 04:07 -------- d-----w- c:\program files\Cheat Engine
2010-01-10 01:07 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-01-10 01:05 . 2010-01-10 01:05 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-01-08 02:55 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2010-01-08 02:55 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2010-01-08 02:55 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2010-01-08 02:55 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2010-01-08 02:55 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2010-01-07 01:58 . 2008-08-27 23:03 -------- d-----w- c:\programdata\Symantec
2010-01-07 01:58 . 2008-08-27 23:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-04 03:54 . 2009-07-20 19:22 -------- d-----w- c:\programdata\Norton
2010-01-04 03:54 . 2009-12-12 02:04 -------- d-----w- c:\program files\Norton Security Scan
2010-01-04 03:39 . 2008-08-27 23:03 -------- d-----w- c:\program files\Symantec
2010-01-03 23:47 . 2008-12-25 17:16 -------- d-----w- c:\program files\Google
2010-01-03 22:04 . 2008-08-27 22:53 -------- d-----w- c:\program files\eMachines GameZone
2010-01-03 21:55 . 2009-01-02 01:13 -------- d-----w- c:\programdata\Apple Computer
2010-01-03 21:55 . 2009-01-02 01:10 -------- d-----w- c:\program files\Common Files\Apple
2010-01-03 21:52 . 2009-09-15 03:26 -------- d-----w- c:\program files\Outspark
2010-01-03 21:52 . 2008-08-27 22:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-03 21:45 . 2009-02-07 17:46 -------- d-----w- c:\programdata\WildTangent
2010-01-03 21:45 . 2009-02-07 17:44 -------- d-----w- c:\program files\WildGames
2010-01-03 21:39 . 2009-07-10 00:52 -------- d-----w- c:\program files\EA GAMES
2010-01-02 20:55 . 2008-12-25 20:59 39 ----a-w- c:\users\Justin Foisy\jagex_runescape_preferences.dat
2010-01-02 20:46 . 2009-09-02 20:20 69 ----a-w- c:\users\Justin Foisy\jagex_runescape_preferences2.dat
2009-12-12 02:04 . 2009-07-20 19:22 -------- d-----w- c:\programdata\NortonInstaller
2009-12-10 11:50 . 2008-08-27 23:19 -------- d-----w- c:\programdata\Microsoft Help
2009-12-05 20:07 . 2009-12-05 20:07 -------- d-----w- c:\program files\uTorrent
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-12-03 15:14 . 2009-12-03 15:14 484976 ----a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Google Toolbar\Update\gtbFD22.tmp.exe
2009-11-27 02:23 . 2009-11-27 02:23 -------- d-----w- c:\programdata\WindowsSearch
2009-11-21 06:40 . 2009-12-09 17:26 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 17:25 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 17:25 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 17:25 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-03 21:43 . 2009-12-09 17:25 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-03 21:42 . 2009-12-09 17:25 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-03 19:41 . 2009-12-09 17:25 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-25 15:56 2048 ----a-w- c:\windows\system32\tzres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-12-05 289584]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe" [2009-06-05 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-14 6253088]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-09-02 809480]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-25 136600]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(b):ac,88,f4,1f,0f,90,ca,01

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 7:56 AM 74480]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [03/03/2008 12:11 PM 16384]
R2 ETService;Empowering Technology Service;c:\program files\EMACHINES\eMachines Recovery Management\Service\ETService.exe [25/12/2008 9:23 AM 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [06/04/2008 9:42 PM 50424]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [17/04/2007 8:09 PM 11032]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 7:56 AM 7408]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [19/02/2009 11:31 AM 41008]
R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [27/08/2008 2:52 PM 22072]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [04/04/2008 2:03 AM 131072]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [20/01/2008 6:33 PM 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride = *.local
TCP: {9320EF47-532A-4291-998C-C147787C40C9} = 192.168.1.254,192.168.1.70
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-14 16:35
Windows 6.0.6002 Service Pack 2 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************
.
Completion time: 2010-01-14 16:42:16
ComboFix-quarantined-files.txt 2010-01-15 00:42
ComboFix2.txt 2010-01-14 23:56
ComboFix3.txt 2010-01-11 07:02

Pre-Run: 90,253,242,368 bytes free
Post-Run: 90,263,490,560 bytes free

- - End Of File - - A9A692F5E0F6A19ECAC9D2E7A7BA5217

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Fri Jan 15, 2010 1:26 am

Please download Malwarebytes Anti-Malware from [You must be registered and logged in to see this link.].
Alternate link: [You must be registered and logged in to see this link.].
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Fri Jan 15, 2010 9:16 am

Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

15/01/2010 1:09:15 AM
mbam-log-2010-01-15 (01-09-15).txt

Scan type: Full Scan (C:\|)
Objects scanned: 222932
Time elapsed: 1 hour(s), 7 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Justin Foisy\Desktop\winlogon.scr (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Fri Jan 15, 2010 10:18 am

Please run a free online scan with the [You must be registered and logged in to see this link.]
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Fri Jan 15, 2010 10:22 am

I cannot access the internet therefore I am unable to run this scan

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Fri Jan 15, 2010 10:23 am

Is it Internet Explorer that will not work, or is your computer not able to connect to the Internet?


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Fri Jan 15, 2010 10:24 am

I am connected to the internet but I cannot browse using internet explorer. My other pcs are using the internet fine.

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Fri Jan 15, 2010 1:07 pm

Please start Internet Explorer, and when the program is open, click on the Tools menu and then select Internet Options.
  • Now click on the Connections tab and then the Lan Settings button
  • Under the Proxy Server section, please uncheck the checkbox labeled Use a proxy server for your LAN. Then press the OK button to close this screen. Then press the Apply button and then the OK button to close the Internet Options screen. Now that you have disabled the proxy server you will be able to browse the web again with Internet Explorer.


Then, see if you can work the scan now. Smile


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Fri Jan 15, 2010 9:16 pm

this did not work Sad tearing

I already had the "Use a proxy server for your lan" box unchecked.

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Fri Jan 15, 2010 11:45 pm

Please download Dial-A-Fix from [You must be registered and logged in to see this link.].

Save it to your Desktop.

Open Dial-a-fix.exe

Click the green checkmark at the bottom of the window; this should select all options.

Now, click GO.

Allow it to run (the status will be displayed at the bottom), and follow any prompts you receive.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Sat Jan 16, 2010 8:13 am

this program will not run on vista :'(

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Sat Jan 16, 2010 8:36 am

Please download [You must be registered and logged in to see this link.] (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Double-click smitfraudfix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Sat Jan 16, 2010 8:47 am

SmitFraudFix v2.424

Scan done at 0:43:24.84, 16/01/2010
Run from C:\Users\Justin Foisy\Desktop\SmitfraudFix
OS: Microsoft Windows [Version 6.0.6002] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\JUSTIN~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Justin Foisy


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\JUSTIN~1\AppData\Local\Temp


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Justin Foisy\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\Users\JUSTIN~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, following keys are not inevitably infected!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, following keys are not inevitably infected!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, following keys are not inevitably infected!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\Windows\\system32\\userinit.exe,"

»»»»»»»»»»»»»»»»»»»»»»»» RK

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""




»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Atheros AR5007EG Wireless Network Adapter
DNS Server Search Order: 64.59.144.18
DNS Server Search Order: 64.59.144.19

HKLM\SYSTEM\CCS\Services\Tcpip\..\{31ACEB1F-49A9-4F9A-9E49-A5190977EE7A}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer=192.168.1.254,192.168.1.70
HKLM\SYSTEM\CS1\Services\Tcpip\..\{31ACEB1F-49A9-4F9A-9E49-A5190977EE7A}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer=192.168.1.254,192.168.1.70
HKLM\SYSTEM\CS3\Services\Tcpip\..\{31ACEB1F-49A9-4F9A-9E49-A5190977EE7A}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: DhcpNameServer=192.168.1.254 192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer=192.168.1.254,192.168.1.70
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=64.59.144.18 64.59.144.19


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Dr Jay on Sat Jan 16, 2010 9:04 am

All of this information:
Description: Atheros AR5007EG Wireless Network Adapter
DNS Server Search Order: 64.59.144.18
DNS Server Search Order: 64.59.144.19

HKLM\SYSTEM\CCS\Services\Tcpip\..\{31ACEB1F-49A9-4F9A-9E49-A5190977EE7A}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CCS\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer=192.168.1.254,192.168.1.70
HKLM\SYSTEM\CS1\Services\Tcpip\..\{31ACEB1F-49A9-4F9A-9E49-A5190977EE7A}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer=192.168.1.254,192.168.1.70
HKLM\SYSTEM\CS3\Services\Tcpip\..\{31ACEB1F-49A9-4F9A-9E49-A5190977EE7A}: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: DhcpNameServer=192.168.1.254 192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9320EF47-532A-4291-998C-C147787C40C9}: NameServer=192.168.1.254,192.168.1.70
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=64.59.144.18 64.59.144.19
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=64.59.144.18 64.59.144.19

Is set by your Internet Service Provider. I recommend to call them and have them deal with this issue from here. They have settings on your computer, that if we were to change, your Internet connection might be lost.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13713
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302059
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Connected to the internet but cannot browse!

Post by Hydra_o0 on Sat Jan 16, 2010 9:06 am

I see, thank you for your help I will take your advice

Hydra_o0
Novice
Novice

Posts Posts : 15
Joined Joined : 2010-01-13
Gender Gender : Male
OS OS : Windows 7 Home Premium 64bit
Points Points : 25361
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum