Hi,
Hopefully I've made everything that I was supposed to do in first place.
1. Antivirus temporarely disabled.
2. Daemon uninstalled
3. Torrent uninstalled
I've also ran chkdsk (no errors) and sfc (no errors)
Additionally I've uninstalled all the programmes that Im not using currently
DDS:
DDS (Ver_10-11-01.01) - NTFSx86
Run by Jarekexe at 18:20:21,85 on 2010-11-02
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1033.18.3327.2779 [GMT 1:00]
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ACSPMonitor\ASMonitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\svchost77.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
C:\Program Files\Mozilla Firefox2\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
E:\Download\dds.scr
============== Pseudo HJT Report ===============
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [AutoConnect] c:\program files\autoconnect\AutoConnect.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [{C5B77C71-210A-5AF5-F622-78F6E94C2A79}] "c:\documents and settings\jarekexe\application data\othu\abreo.exe"
uRun: [windows ftp3] c:\documents and settings\jarekexe\application data\ft3.exe
uRun: [WindowsUpdateFTP] C:\svchost77.exe
uRun: [Bcazatiyuw] rundll32.exe "c:\windows\nvcmshpt.dll",Startup
uRun: [{C52FEE07-CB99-87E0-BA6E-9EB9C537D538}] "c:\documents and settings\jarekexe\application data\ixyhin\rihu.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [Corel Photo Downloader] "c:\program files\common files\corel\corel photodownloader\Corel Photo Downloader.exe" -startup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
mExplorerRun: [application] c:\program files\acspmonitor\ASMonitor.exe hs
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {A561FE8E-79C3-45A8-B861-7D4DCF1C24D1} = 62.233.233.233 87.204.204.204
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jarekexe\applic~1\mozilla\firefox\profiles\di1ek9ts.default\
FF - prefs.js: browser.search.selectedEngine - YouTube
FF - prefs.js: browser.startup.homepage - google.pl
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\operations\program\plugins\npdsplay.dll
FF - plugin: c:\program files\operations\program\plugins\NPOFF12.DLL
FF - plugin: c:\program files\operations\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\operations\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-6-20 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-6-20 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-6-20 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-6-20 60936]
R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2010-3-18 172328]
R4 nltdi;nltdi;\??\c:\windows\system32\drivers\nltdi.sys --> c:\windows\system32\drivers\nltdi.sys [?]
S2 SSHNAS;SSHNAS;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2010-10-16 50704]
=============== Created Last 30 ================
2010-11-01 15:00:36 1409 ----a-w- c:\windows\QTFont.for
2010-11-01 14:40:54 -------- d-----w- c:\docume~1\jarekexe\applic~1\Ihuvdo
2010-11-01 14:40:54 -------- d-----w- c:\docume~1\jarekexe\applic~1\Botei
2010-11-01 09:48:31 197120 ----a-w- c:\windows\patchw32.dll
2010-11-01 09:48:31 -------- d-----w- c:\program files\common files\PocketSoft
2010-11-01 09:45:00 -------- d-----w- c:\docume~1\jarekexe\applic~1\Atari
2010-11-01 02:27:58 431104 ----a-w- C:\svchost77.exe
2010-10-29 12:05:45 269824 --sha-r- c:\docume~1\jarekexe\applic~1\ft3.exe
2010-10-28 14:30:16 -------- d-----w- c:\docume~1\jarekexe\applic~1\Othu
2010-10-28 14:30:16 -------- d-----w- c:\docume~1\jarekexe\applic~1\Hais
2010-10-27 05:30:35 -------- d-----w- c:\program files\TeamViewer
2010-10-23 16:46:01 -------- d-----w- c:\docume~1\alluse~1\applic~1\Komputerowa Gratka
2010-10-23 16:45:37 -------- d-----w- c:\program files\Pluszaki Rozrabiaki
2010-10-21 12:39:53 -------- d-----w- c:\docume~1\jarekexe\applic~1\Bitrix Security
2010-10-17 22:49:50 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\SKIDROW
2010-10-17 15:54:54 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\OtstoiSoft
2010-10-16 21:17:09 -------- d-----w- c:\docume~1\jarekexe\applic~1\Octoshape
2010-10-16 07:57:36 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\GHISLER
2010-10-16 05:12:44 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\Focus Home Interactive
2010-10-16 05:09:54 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2010-10-16 05:09:54 281104 ----a-w- c:\windows\system32\wpcap.dll
2010-10-16 05:09:54 100880 ----a-w- c:\windows\system32\Packet.dll
2010-10-15 06:36:47 -------- d-----w- c:\docume~1\jarekexe\applic~1\Jumb-O-Fun Games
2010-10-14 05:12:51 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-13 04:35:19 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 04:35:19 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 04:35:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-11 10:14:37 -------- d-----w- c:\docume~1\jarekexe\applic~1\OpenOffice.org
2010-10-11 10:10:46 -------- d-----w- c:\program files\OpenOffice.org 3
2010-10-10 19:31:25 20968 ----a-w- c:\windows\system32\drivers\cpuz133_x32.sys
==================== Find3M ====================
2010-09-24 22:33:22 3777 ----a-w- C:\a.bat
2010-09-18 10:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-16 13:21:23 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-09 22:39:14 2826240 ----a-w- c:\windows\system32\GPhotos.scr
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-15 06:42:26 217180 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-08-15 06:42:26 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-08-15 06:41:47 217180 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-08-08 06:28:46 2828 --sha-w- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2010-08-08 06:28:35 88 --sh--r- c:\docume~1\alluse~1\applic~1\49A916B900.sys
============= FINISH: 18:21:23,68 ===============
Attach.zip attached.
Problem? There's only one. From time to time, access to www gets blocked. Whenever I open internet browser (I have 3 installed, checked all of them - same, or similliar, result) Im getting a blank page. When I type the address like www(.)google(.)com - ofc w/o brackets - and press enter, nothing happens. There's nothing loading, no errors, no popups, no nothing. No reaction at all (Mozilla). On IE, there's the same situation except that there's no blan page, but 404 page.
I've noticed that at that time, in my task manager, there's like 10-30 processes running named cmd.exe
Also, there are some suspect processes like:
svchost77.exe
rundll32.exe (few instances)
reg.exe
mmc.exe
sometimes more, right now I can't recall any others.
Killing them doesn't help. I need to reboot. Which is problematic, because sometimes I cant. When I press shutdown button, nothing happens. So I have to press power button for 5-7 secs to turn computer off. Sometimes it does turn off as it should.
Would that help if I attach printscreen of task manager?
That's it. Thanks in advance for any help.
Hopefully I've made everything that I was supposed to do in first place.
1. Antivirus temporarely disabled.
2. Daemon uninstalled
3. Torrent uninstalled
I've also ran chkdsk (no errors) and sfc (no errors)
Additionally I've uninstalled all the programmes that Im not using currently
DDS:
DDS (Ver_10-11-01.01) - NTFSx86
Run by Jarekexe at 18:20:21,85 on 2010-11-02
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1033.18.3327.2779 [GMT 1:00]
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ACSPMonitor\ASMonitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\svchost77.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
C:\Program Files\Mozilla Firefox2\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
E:\Download\dds.scr
============== Pseudo HJT Report ===============
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [AutoConnect] c:\program files\autoconnect\AutoConnect.exe
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [{C5B77C71-210A-5AF5-F622-78F6E94C2A79}] "c:\documents and settings\jarekexe\application data\othu\abreo.exe"
uRun: [windows ftp3] c:\documents and settings\jarekexe\application data\ft3.exe
uRun: [WindowsUpdateFTP] C:\svchost77.exe
uRun: [Bcazatiyuw] rundll32.exe "c:\windows\nvcmshpt.dll",Startup
uRun: [{C52FEE07-CB99-87E0-BA6E-9EB9C537D538}] "c:\documents and settings\jarekexe\application data\ixyhin\rihu.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [Corel Photo Downloader] "c:\program files\common files\corel\corel photodownloader\Corel Photo Downloader.exe" -startup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
mExplorerRun: [application] c:\program files\acspmonitor\ASMonitor.exe hs
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {888078C6-70B2-4F88-8EE7-1F50DDEA6120} - hxxps://as.photoprintit.de/ips-opdata/activex/ImageUploader6.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {A561FE8E-79C3-45A8-B861-7D4DCF1C24D1} = 62.233.233.233 87.204.204.204
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\jarekexe\applic~1\mozilla\firefox\profiles\di1ek9ts.default\
FF - prefs.js: browser.search.selectedEngine - YouTube
FF - prefs.js: browser.startup.homepage - google.pl
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\operations\program\plugins\npdsplay.dll
FF - plugin: c:\program files\operations\program\plugins\NPOFF12.DLL
FF - plugin: c:\program files\operations\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\operations\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\operations\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\mozilla firefox2\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-6-20 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-6-20 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-6-20 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-6-20 60936]
R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2010-3-18 172328]
R4 nltdi;nltdi;\??\c:\windows\system32\drivers\nltdi.sys --> c:\windows\system32\drivers\nltdi.sys [?]
S2 SSHNAS;SSHNAS;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2010-10-16 50704]
=============== Created Last 30 ================
2010-11-01 15:00:36 1409 ----a-w- c:\windows\QTFont.for
2010-11-01 14:40:54 -------- d-----w- c:\docume~1\jarekexe\applic~1\Ihuvdo
2010-11-01 14:40:54 -------- d-----w- c:\docume~1\jarekexe\applic~1\Botei
2010-11-01 09:48:31 197120 ----a-w- c:\windows\patchw32.dll
2010-11-01 09:48:31 -------- d-----w- c:\program files\common files\PocketSoft
2010-11-01 09:45:00 -------- d-----w- c:\docume~1\jarekexe\applic~1\Atari
2010-11-01 02:27:58 431104 ----a-w- C:\svchost77.exe
2010-10-29 12:05:45 269824 --sha-r- c:\docume~1\jarekexe\applic~1\ft3.exe
2010-10-28 14:30:16 -------- d-----w- c:\docume~1\jarekexe\applic~1\Othu
2010-10-28 14:30:16 -------- d-----w- c:\docume~1\jarekexe\applic~1\Hais
2010-10-27 05:30:35 -------- d-----w- c:\program files\TeamViewer
2010-10-23 16:46:01 -------- d-----w- c:\docume~1\alluse~1\applic~1\Komputerowa Gratka
2010-10-23 16:45:37 -------- d-----w- c:\program files\Pluszaki Rozrabiaki
2010-10-21 12:39:53 -------- d-----w- c:\docume~1\jarekexe\applic~1\Bitrix Security
2010-10-17 22:49:50 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\SKIDROW
2010-10-17 15:54:54 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\OtstoiSoft
2010-10-16 21:17:09 -------- d-----w- c:\docume~1\jarekexe\applic~1\Octoshape
2010-10-16 07:57:36 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\GHISLER
2010-10-16 05:12:44 -------- d-----w- c:\docume~1\jarekexe\locals~1\applic~1\Focus Home Interactive
2010-10-16 05:09:54 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2010-10-16 05:09:54 281104 ----a-w- c:\windows\system32\wpcap.dll
2010-10-16 05:09:54 100880 ----a-w- c:\windows\system32\Packet.dll
2010-10-15 06:36:47 -------- d-----w- c:\docume~1\jarekexe\applic~1\Jumb-O-Fun Games
2010-10-14 05:12:51 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-10-13 04:35:19 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 04:35:19 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 04:35:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-11 10:14:37 -------- d-----w- c:\docume~1\jarekexe\applic~1\OpenOffice.org
2010-10-11 10:10:46 -------- d-----w- c:\program files\OpenOffice.org 3
2010-10-10 19:31:25 20968 ----a-w- c:\windows\system32\drivers\cpuz133_x32.sys
==================== Find3M ====================
2010-09-24 22:33:22 3777 ----a-w- C:\a.bat
2010-09-18 10:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-16 13:21:23 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-09 22:39:14 2826240 ----a-w- c:\windows\system32\GPhotos.scr
2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-15 06:42:26 217180 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-08-15 06:42:26 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-08-15 06:41:47 217180 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-08-08 06:28:46 2828 --sha-w- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2010-08-08 06:28:35 88 --sh--r- c:\docume~1\alluse~1\applic~1\49A916B900.sys
============= FINISH: 18:21:23,68 ===============
Attach.zip attached.
Problem? There's only one. From time to time, access to www gets blocked. Whenever I open internet browser (I have 3 installed, checked all of them - same, or similliar, result) Im getting a blank page. When I type the address like www(.)google(.)com - ofc w/o brackets - and press enter, nothing happens. There's nothing loading, no errors, no popups, no nothing. No reaction at all (Mozilla). On IE, there's the same situation except that there's no blan page, but 404 page.
I've noticed that at that time, in my task manager, there's like 10-30 processes running named cmd.exe
Also, there are some suspect processes like:
svchost77.exe
rundll32.exe (few instances)
reg.exe
mmc.exe
sometimes more, right now I can't recall any others.
Killing them doesn't help. I need to reboot. Which is problematic, because sometimes I cant. When I press shutdown button, nothing happens. So I have to press power button for 5-7 secs to turn computer off. Sometimes it does turn off as it should.
Would that help if I attach printscreen of task manager?
That's it. Thanks in advance for any help.