|
Registered User
Join Date: Dec 2008
Posts: 1
OS: Win XP Home SP2
|
Please help...strange popups and other things
Strange things have been happening to my computer for a while. I can give more details if necessary, but I don't want to waste your time if you can get everything you need from the log. I would greatly appreciate any assistance.
Thanks,
Nathan Sharpe
Here is my DDS log:
DDS (Version 1.0) - NTFSx86
Run by Nathan at 13:48:07.12 on Wed 12/10/2008
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.619 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\TmF0aGFuIFNoYXJwZQ\command.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Documents and Settings\Nathan\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Documents and Settings\Nathan\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\Nathan\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Nathan\My Documents\Downloads\dds.com
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - c:\program files\webtools\webtools.dll
BHO: {3C3D6A39-B167-4506-A377-E262402A29F5} - c:\windows\system32\geBssrSi.dll
BHO: {49bbfdf9-ea00-43fc-9fba-3df85251f2f5} - c:\windows\system32\znmcky.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {94039c0d-8564-497e-9d42-9751801509b9} - c:\windows\system32\botapepe.dll
BHO: {AC690E51-94E1-43D4-B6F4-9CDC523276AF} - c:\windows\system32\jkkiGAqN.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [vetipabuyu] Rundll32.exe "c:\windows\system32\tesavohi.dll",s
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-system: HideFastUserSwitching = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Notify: geBssrSi - geBssrSi.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\vanuvera.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {3C3D6A39-B167-4506-A377-E262402A29F5} - c:\windows\system32\geBssrSi.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\jkkiGAqN
LSA: Notification Packages = scecli c:\windows\system32\vanuvera.dll
============= SERVICES / DRIVERS ===============
R2 cmdService;Command Service;c:\windows\tmf0agfuifnoyxjwzq\command.exe [2008-12-10 293888]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\viewpoint\common\ViewpointService.exe" [2008-11-30 24652]
S4 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" [2008-5-12 611664]
S4 Network Monitor;Network Monitor;c:\program files\network monitor\netmon.exe service []
S4 OpenCASE Media Agent;OpenCASE Media Agent;"c:\program files\opencase\opencase media agent\MediaAgent.exe" [2008-1-16 814728]
S4 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [2008-1-12 23856]
=============== Created Last 30 ================
2008-12-10 13:45 250 a------- c:\windows\gmer.ini
2008-12-10 11:21 687,592 a------- c:\windows\system32\atmtd.dll._
2008-12-10 11:21 687,592 a------- c:\windows\system32\atmtd.dll
2008-12-10 11:21 1,989 a------- c:\windows\uninstall_nmon.vbs
2008-12-10 11:21 <DIR> --dsh--- c:\windows\TmF0aGFuIFNoYXJwZQ
2008-12-10 11:21 <DIR> --d----- c:\program files\Network Monitor
2008-12-10 11:21 <DIR> --d----- c:\program files\InetGet2
2008-12-10 11:16 <DIR> --d----- c:\docume~1\nathan\applic~1\SpeedRunner
2008-12-10 11:11 <DIR> --d----- c:\docume~1\nathan\applic~1\Twain
2008-12-10 10:56 <DIR> --d----- c:\program files\Webtools
2008-12-09 22:25 126,464 a------- c:\windows\system32\znmcky.dll
2008-12-09 22:25 126,464 a------- c:\windows\system32\imxnyisa.dll
2008-12-09 22:25 2,011,189 ---sh--- c:\windows\system32\xcmqmdlc.ini
2008-12-09 22:25 73,216 a------- c:\windows\system32\cldmqmcx.dll
2008-12-09 18:48 <DIR> --d----- c:\program files\Mjcore
2008-12-08 22:25 1,989,471 ---sh--- c:\windows\system32\bukxnhpj.ini
2008-12-08 22:25 126,464 a------- c:\windows\system32\upfalj.dll
2008-12-08 22:25 126,464 a------- c:\windows\system32\nxchgcbd.dll
2008-12-07 22:26 1,870,542 ---sh--- c:\windows\system32\ynlimcuy.ini
2008-12-07 22:26 126,464 a------- c:\windows\system32\hqgpcv.dll
2008-12-07 22:26 126,464 a------- c:\windows\system32\rntoudrh.dll
2008-12-06 23:06 <DIR> --d----- c:\docume~1\nathan\applic~1\gadcom
2008-12-06 23:06 <DIR> --d----- c:\docume~1\nathan\applic~1\GetModule
2008-12-06 23:06 34,816 a------- c:\windows\system32\iifefeEt.dll
2008-12-06 23:05 198,710 a------- c:\windows\system32\wpv161228549885.cpx
2008-12-06 22:28 126,464 a------- c:\windows\system32\rrewru.dll
2008-12-06 22:28 126,464 a------- c:\windows\system32\xfualaqv.dll
2008-12-06 22:25 1,870,542 ---sh--- c:\windows\system32\katxgbah.ini
2008-12-05 22:25 126,464 a------- c:\windows\system32\xiegnv.dll
2008-12-05 22:25 126,464 a------- c:\windows\system32\hrarrlno.dll
2008-12-05 22:23 1,870,542 ---sh--- c:\windows\system32\hvgjdjjn.ini
2008-12-05 18:08 <DIR> --d----- c:\program files\Fwink
2008-12-05 17:30 <DIR> --d----- c:\program files\STMicroelectronics
2008-12-05 17:30 506 a------- c:\windows\videoimp.ini
2008-12-05 17:30 38,160 a------- c:\windows\system32\LMRTREND.dll
2008-12-05 17:30 140,800 a------- c:\windows\system32\tm20dec.ax
2008-12-05 17:30 182,032 a------- c:\windows\system32\dxtmsft3.dll
2008-12-05 17:30 221,184 a------- c:\windows\system32\wmpns.dll
2008-12-05 17:30 63,488 a------- c:\windows\system32\unam4ie.exe
2008-12-05 17:30 194,320 a------- c:\windows\system32\qcut.dll
2008-12-05 17:30 11,776 a------- c:\windows\system32\mciqtz.drv
2008-12-05 17:30 10,240 a------- c:\windows\system32\vidx16.dll
2008-12-05 17:30 5,672 a------- c:\windows\system32\quartz.vxd
2008-12-05 17:30 4,608 a------- c:\windows\system32\w95inf32.dll
2008-12-05 17:30 2,272 a------- c:\windows\system32\w95inf16.dll
2008-12-05 17:27 21 a------- c:\windows\CS_setup.ini
2008-12-05 15:48 126,464 a------- c:\windows\system32\edonfl.dll
2008-12-05 15:48 126,464 a------- c:\windows\system32\gofvxloo.dll
2008-12-05 15:45 1,870,542 ---sh--- c:\windows\system32\faqxruib.ini
2008-12-04 22:00 <DIR> --d----- c:\docume~1\nathan\applic~1\Songbird2
2008-12-04 22:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SongbirdVLC
2008-12-04 21:59 <DIR> --d----- c:\program files\Songbird
2008-12-04 15:45 126,464 a------- c:\windows\system32\fpvekz.dll
2008-12-04 15:45 126,464 a------- c:\windows\system32\sqvupdoc.dll
2008-12-04 15:43 1,870,542 ---sh--- c:\windows\system32\khdwsokm.ini
2008-12-04 08:06 1,869,649 ---sh--- c:\windows\system32\dnrbgqod.ini
2008-12-04 08:03 126,464 a------- c:\windows\system32\pyrvlt.dll
2008-12-04 08:03 126,464 a------- c:\windows\system32\jkemexrn.dll
2008-12-03 08:04 1,869,649 ---sh--- c:\windows\system32\mfioaeno.ini
2008-12-03 08:01 126,464 a------- c:\windows\system32\nnobfm.dll
2008-12-03 08:01 126,464 a------- c:\windows\system32\iwnvdffy.dll
2008-12-02 07:18 1,782,274 ---sh--- c:\windows\system32\ajbumbam.ini
2008-12-02 07:15 126,464 a------- c:\windows\system32\eamtzb.dll
2008-12-02 07:15 126,464 a------- c:\windows\system32\oeqmotvr.dll
2008-12-01 07:58 126,464 a------- c:\windows\system32\hsdyhh.dll
2008-12-01 07:58 126,464 a------- c:\windows\system32\pmquwteq.dll
2008-11-30 16:20 <DIR> --d----- c:\program files\Viewpoint
2008-11-30 16:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\acccore
2008-11-30 13:38 125,952 a------- c:\windows\system32\dimqsb.dll
2008-11-30 13:38 125,952 a------- c:\windows\system32\yvaxtgqc.dll
2008-11-29 01:15 125,952 a------- c:\windows\system32\cylqqo.dll
2008-11-29 01:15 125,952 a------- c:\windows\system32\kqpppnuh.dll
2008-11-29 01:12 1,709,971 ---sh--- c:\windows\system32\hnjnewup.ini
2008-11-28 16:41 410,984 a------- c:\windows\system32\deploytk.dll
2008-11-28 09:37 126,464 a------- c:\windows\system32\nptudu.dll
2008-11-28 09:37 126,464 a------- c:\windows\system32\qpoikxcg.dll
2008-11-28 09:34 1,709,971 ---sh--- c:\windows\system32\tiljufgd.ini
2008-11-27 01:11 122,368 a------- c:\windows\system32\esinjg.dll
2008-11-27 01:11 122,368 a------- c:\windows\system32\wgdmbmlq.dll
2008-11-27 01:11 1,667,051 ---sh--- c:\windows\system32\paaophyp.ini
2008-11-26 11:36 122,368 a------- c:\windows\system32\gvbnsj.dll
2008-11-26 11:36 122,368 a------- c:\windows\system32\uanqftny.dll
2008-11-26 11:30 1,667,051 ---sh--- c:\windows\system32\mcwsnwoj.ini
2008-11-25 01:16 1,652,336 ---sh--- c:\windows\system32\uedwlhpg.ini
2008-11-25 01:13 122,368 a------- c:\windows\system32\rmwkqs.dll
2008-11-25 01:13 122,368 a------- c:\windows\system32\rkpxqfwo.dll
2008-11-24 10:42 1,648,749 ---sh--- c:\windows\system32\pocotkyg.ini
2008-11-24 10:39 122,368 a------- c:\windows\system32\xrgpmt.dll
2008-11-24 10:39 122,368 a------- c:\windows\system32\cgnjcpis.dll
2008-11-23 14:37 121,856 a------- c:\windows\system32\qdyrgn.dll
2008-11-23 14:37 121,856 a------- c:\windows\system32\odqcwscm.dll
2008-11-23 14:32 1,642,223 ---sh--- c:\windows\system32\cbfnsjrx.ini
2008-11-22 09:40 122,368 a------- c:\windows\system32\hhspwl.dll
2008-11-22 09:40 122,368 a------- c:\windows\system32\fkrdrscn.dll
2008-11-21 01:10 122,368 a------- c:\windows\system32\dhxlgp.dll
2008-11-21 01:10 122,368 a------- c:\windows\system32\xixlilkn.dll
2008-11-21 01:05 1,632,503 ---sh--- c:\windows\system32\yxufuhtq.ini
2008-11-19 20:10 2,086,083 ---sh--- c:\windows\system32\hicljcas.ini
2008-11-19 20:07 122,368 a------- c:\windows\system32\vefucw.dll
2008-11-19 20:07 122,368 a------- c:\windows\system32\xjiemlro.dll
2008-11-18 14:54 125,952 a------- c:\windows\system32\uqawbp.dll
2008-11-18 14:54 125,952 a------- c:\windows\system32\ijvxejav.dll
2008-11-17 14:54 1,992,943 ---sh--- c:\windows\system32\noqbmupa.ini
2008-11-17 14:54 76,288 a------- c:\windows\system32\apumbqon.dll
2008-11-17 14:54 125,952 a------- c:\windows\system32\uioigw.dll
2008-11-17 14:54 125,952 a------- c:\windows\system32\nujsrhgo.dll
2008-11-16 17:42 125,952 a------- c:\windows\system32\fwjhzc.dll
2008-11-16 17:42 125,952 a------- c:\windows\system32\drsrqfql.dll
2008-11-16 17:39 1,975,884 ---sh--- c:\windows\system32\tnwsrjtm.ini
2008-11-15 15:17 125,952 a------- c:\windows\system32\oqooeq.dll
2008-11-15 15:17 125,952 a------- c:\windows\system32\eseimjao.dll
2008-11-14 15:05 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2008-11-14 15:05 <DIR> --d----- c:\documents and settings\nathan\.housecall6.6
2008-11-14 14:50 125,952 a------- c:\windows\system32\qvdeii.dll
2008-11-14 14:50 125,952 a------- c:\windows\system32\pqtfbbwt.dll
2008-11-14 14:47 1,975,884 ---sh--- c:\windows\system32\rtehgsat.ini
2008-11-12 22:23 15 a------- c:\windows\entpack.ini
2008-11-12 07:12 132,608 a------- c:\windows\system32\lumsgw.dll
2008-11-12 07:12 132,608 a------- c:\windows\system32\djesnhrt.dll
2008-11-11 12:58 132,608 a------- c:\windows\system32\qmdiqp.dll
2008-11-11 12:58 132,608 a------- c:\windows\system32\piyhcedt.dll
2008-11-11 12:55 1,975,883 ---sh--- c:\windows\system32\ftjnatwq.ini
==================== Find3M ====================
2008-12-10 13:45 829,657 a--sh--- c:\windows\system32\NqAGikkj.ini2
2008-11-10 02:10 132,608 a------- c:\windows\system32\ifllyikf.dll
2008-11-10 02:10 132,608 a------- c:\windows\system32\cjrrmw.dll
2008-11-09 09:54 132,608 a------- c:\windows\system32\psaeoh.dll
2008-11-09 09:54 132,608 a------- c:\windows\system32\pjhvqvko.dll
2008-11-08 23:41 132,608 a------- c:\windows\system32\mmhqws.dll
2008-11-08 23:41 132,608 a------- c:\windows\system32\dblslmtm.dll
2008-11-07 22:04 132,608 a------- c:\windows\system32\vrqvaoef.dll
2008-11-07 22:04 132,608 a------- c:\windows\system32\qwagpt.dll
2008-11-06 22:12 1,409 a------- c:\windows\fonts\SToccata.fot
2008-11-06 17:15 75,392 a------- c:\windows\system32\xdmuktcn.dll
2008-11-06 17:13 132,096 a------- c:\windows\system32\smpxpe.dll
2008-11-06 17:13 132,096 a------- c:\windows\system32\dmutpawu.dll
2008-11-05 12:18 133,120 a------- c:\windows\system32\fweidcks.dll
2008-11-05 12:18 133,120 a------- c:\windows\system32\ayhshy.dll
2008-11-04 12:20 132,608 a------- c:\windows\system32\qhxlinig.dll
2008-11-04 12:20 132,608 a------- c:\windows\system32\ezbwmw.dll
2008-11-03 12:17 132,608 a------- c:\windows\system32\juypzk.dll
2008-11-03 12:17 132,608 a------- c:\windows\system32\eqnympba.dll
2008-11-02 12:18 133,120 a------- c:\windows\system32\qrbesz.dll
2008-11-02 12:18 133,120 a------- c:\windows\system32\jyqlhtbn.dll
2008-11-01 12:19 132,608 a------- c:\windows\system32\xmwwvjqd.dll
2008-11-01 12:19 132,608 a------- c:\windows\system32\xmaaik.dll
2008-10-31 12:19 132,608 a------- c:\windows\system32\irymbl.dll
2008-10-31 12:19 132,608 a------- c:\windows\system32\iljdsrln.dll
2008-10-30 12:16 132,096 a------- c:\windows\system32\kkdfiqxr.dll
2008-10-30 12:16 132,096 a------- c:\windows\system32\khuaqb.dll
2008-10-29 11:46 132,608 a------- c:\windows\system32\icofey.dll
2008-10-29 11:46 132,608 a------- c:\windows\system32\bdukplfm.dll
2008-10-29 08:52 132,096 a------- c:\windows\system32\luhwac.dll
2008-10-29 08:52 132,096 a------- c:\windows\system32\hsiwyfuu.dll
2008-10-28 08:49 133,120 a------- c:\windows\system32\ngicyp.dll
2008-10-28 08:49 133,120 a------- c:\windows\system32\fypcqlyk.dll
2008-10-26 20:19 133,120 a------- c:\windows\system32\ndmzhi.dll
2008-10-26 20:19 133,120 a------- c:\windows\system32\mvifhbdb.dll
2008-10-25 20:13 132,608 a------- c:\windows\system32\mkaonngc.dll
2008-10-25 20:13 132,608 a------- c:\windows\system32\ghyabw.dll
2008-10-24 20:15 132,096 a------- c:\windows\system32\sbeqnc.dll
2008-10-24 20:15 132,096 a------- c:\windows\system32\qmwlgktf.dll
2008-10-23 20:21 133,120 a------- c:\windows\system32\bygebs.dll
2008-10-23 20:21 133,120 a------- c:\windows\system32\acqonnal.dll
2008-10-22 20:18 132,096 a------- c:\windows\system32\vpwpyu.dll
2008-10-22 20:18 132,096 a------- c:\windows\system32\rlorjbco.dll
2008-10-21 18:27 132,096 a------- c:\windows\system32\kusufb.dll
2008-10-21 18:27 132,096 a------- c:\windows\system32\fnjitlre.dll
2008-10-18 18:23 132,608 a------- c:\windows\system32\wzczud.dll
2008-10-18 18:23 132,608 a------- c:\windows\system32\sftghwsm.dll
2008-10-17 18:23 132,608 a------- c:\windows\system32\rkpnmvlf.dll
2008-10-17 18:23 132,608 a------- c:\windows\system32\pzrtgx.dll
2008-10-16 22:25 139,701 a------- c:\windows\hpoins15.dat
2008-10-16 18:23 137,728 a------- c:\windows\system32\opsnpf.dll
2008-10-16 18:23 137,728 a------- c:\windows\system32\lyqgbskf.dll
2008-10-15 18:22 137,216 a------- c:\windows\system32\sjcxds.dll
2008-10-15 18:22 137,216 a------- c:\windows\system32\pfetggie.dll
2008-10-14 18:20 136,704 a------- c:\windows\system32\hqgidj.dll
2008-10-14 18:20 136,704 a------- c:\windows\system32\edlmbhbb.dll
2008-10-13 18:20 137,216 a------- c:\windows\system32\nnfecbpl.dll
2008-10-13 18:20 137,216 a------- c:\windows\system32\gdrfvf.dll
2008-10-12 19:54 137,216 a------- c:\windows\system32\zpysnp.dll
2008-10-12 19:54 137,216 a------- c:\windows\system32\cnjmorgn.dll
2008-10-10 18:15 137,216 a------- c:\windows\system32\mbsdfb.dll
2008-10-10 18:15 137,216 a------- c:\windows\system32\awafxhby.dll
2008-10-10 12:13 137,216 a------- c:\windows\system32\sghaqe.dll
2008-10-10 12:13 137,216 a------- c:\windows\system32\ftmgqaub.dll
2008-10-10 12:12 326,016 a------- c:\windows\system32\jkkiGAqN.dll
2008-10-10 12:07 38,272 a------- c:\windows\system32\jkkjIYpO.dll
2008-10-10 12:07 38,272 a------- c:\windows\system32\geBssrSi.dll
2008-10-10 12:06 94,104 a------- c:\windows\FreeOCR.net Uninstaller.exe
2008-10-10 12:02 108,067 a------- c:\windows\hpqins01.dat
2008-05-22 21:20 0 a------- c:\program files\temp01
2008-09-10 11:17 63,488 a--sh--- c:\windows\system32\botapepe.dll
2008-09-10 11:17 63,488 a--sh--- c:\windows\system32\tesavohi.dll
2008-09-10 11:17 63,488 a--sh--- c:\windows\system32\vanuvera.dll
2005-08-02 16:46 187,904 a--shr-- c:\windows\tmf0agfuifnoyxjwzq\asappsrv.dll
2005-08-02 16:58 293,888 a--shr-- c:\windows\tmf0agfuifnoyxjwzq\command.exe
2005-07-29 16:24 472 a--shr-- c:\windows\tmf0agfuifnoyxjwzq\nAIXu3IRKIhCsrLTtk.vbs
============= FINISH: 13:48:33.82 ===============
|