Hi i'm new to these forums and after spending the last couple of weeks running round in circles trying to solve my own problems i finally realised that this is the place to get real help. Its been suggested i probably need a fresh install but thought i would see if you guys could help. My browser is really slow and some strange things have been happening. Tried to follow the five steps before posting but had problems with panda antivirus and no extra.txt in deckard scan. I would be very grateful if someone could take a look for me. Regards, Dave.
Deckard's System Scanner v20071014.68
Run by User on 2007-11-25 20:58:40
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 256 MiB (512 MiB recommended).
-- HijackThis (run as User.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:58:44, on 25/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\User\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\User.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [F-StopW] "C:\Program Files\FSI\F-Prot\F-StopW.EXE"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/wind...?1182973105563
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) -
http://www.superadblocker.com/activex/sabspx.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 5344 bytes
-- Files created between 2007-10-25 and 2007-11-25 -----------------------------
2007-11-25 20:23:23 0 d-------- C:\ie-spyad_zo
2007-11-25 20:05:45 0 d-------- C:\Program Files\SpywareBlaster
2007-11-25 19:40:39 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-11-25 19:40:37 0 d-------- C:\WINDOWS\LastGood
2007-11-25 19:08:50 0 d-------- C:\Program Files\Sun
2007-11-25 03:50:19 0 dr-h----- C:\Documents and Settings\User\Recent
2007-11-25 03:48:29 0 d-------- C:\Program Files\CCleaner
2007-11-25 00:46:51 0 d-------- C:\WINDOWS\BDOSCAN8
2007-11-23 01:51:13 0 d-------- C:\Documents and Settings\All Users\Application Data\eMule
2007-11-23 00:37:42 0 d-------- C:\Program Files\eMule
2007-11-22 22:29:43 0 d-------- C:\Program Files\uTorrent
2007-11-19 23:14:56 0 d-------- C:\Program Files\Common Files\xing shared
2007-11-19 23:14:29 0 d-------- C:\Documents and Settings\All Users\Application Data\TomTom
2007-11-19 23:14:12 0 d-------- C:\Documents and Settings\User\Application Data\InstallShield
2007-11-19 23:13:37 0 d-------- C:\Documents and Settings\User\Application Data\uTorrent
2007-11-17 16:34:00 0 d-------- C:\Program Files\Keyfinder Advanced 2007 (Trial Version)
2007-11-13 22:48:18 0 d-------- C:\Documents and Settings\User\Application Data\uTorrent(2)
2007-11-01 14:11:45 3678208 --a------ C:\Documents and Settings\User\ntuser.dat
2007-11-01 14:11:45 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2007-10-31 13:11:11 0 d-------- C:\Program Files\TomTom DesktopSuite
2007-10-25 10:26:48 53248 --a------ C:\WINDOWS\bdoscandel.exe
-- Find3M Report ---------------------------------------------------------------
2007-11-25 19:05:12 0 d-------- C:\Program Files\Java
2007-11-23 08:02:04 0 d-------- C:\Documents and Settings\User\Application Data\AVG7
2007-11-19 23:11:23 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-19 21:12:12 0 d-------- C:\Program Files\InterVideo
2007-11-19 18:49:03 0 d-------- C:\Program Files\Google
2007-11-14 20:24:38 0 d-------- C:\Program Files\SUPERAntiSpyware
2007-11-03 22:59:19 0 d-------- C:\Program Files\VirtualDJ
2007-11-03 16:52:03 0 d-------- C:\Program Files\QuickTime
2007-11-03 16:01:17 0 d-------- C:\Program Files\Common Files
2007-11-03 16:01:09 0 d-------- C:\Program Files\Common Files\Real
2007-10-29 01:29:15 0 d-------- C:\Program Files\C-Media Audio
2007-10-09 12:15:30 0 d-------- C:\Program Files\iTunes
2007-10-09 12:15:20 0 d-------- C:\Program Files\iPod
2007-10-06 21:38:20 0 d-------- C:\Documents and Settings\User\Application Data\Google
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [26/04/2002 09:17]
"Cmaudio"="cmicnfg.cpl" []
"AtiPTA"="atiptaxx.exe" [26/09/2001 22:39 C:\WINDOWS\system32\atiptaxx.exe]
"F-StopW"="C:\Program Files\FSI\F-Prot\F-StopW.EXE" []
"PCTVOICE"="pctspk.exe" [04/11/2002 07:48 C:\WINDOWS\system32\pctspk.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 10:50]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/05/2007 02:06]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [25/10/2007 03:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/09/2007 19:34]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 01:07]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [01/05/2007 08:29]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d147534d-85a3-11dc-aa55-00e04d0b452a}]
AutoRun\command- F:\InstallTomTomHOME.exe
-- End of Deckard's System Scanner: finished at 2007-11-25 20:59:06 ------------