![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Feb 2009
Posts: 16
OS: xp
|
i posted in the Xp help area and they redirected me here. I have uTorrent and Frostwire installed...
I am having issus with my computer starting up.When it starts up it runs everything it and when it gets to my desktop all i can see is the background and it won't allow me to do anything.I had to go into safe mode and do a system restore to get it to turn on. Then while playing AA my game keeps locking up. I haven't had any reports from my antivirus or firewall so i don't know if i have malware i just followed the like someone gave me. Thank you. DDS (Ver_09-03-16.01) - NTFSx86 Run by ed at 16:15:42.37 on Tue 05/12/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1440 [GMT -7:00] AV: Windows Live OneCare *On-access scanning enabled* (Updated) FW: Windows Live OneCare Firewall *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe C:\Program Files\Microsoft Windows OneCare Live\winss.exe C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\Mixer.exe C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe C:\WINDOWS\system32\taskswitch.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\oodtray.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDCountdown.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\ed\Desktop\dds.scr ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" mRun: [OneCareUI] "c:\program files\microsoft windows onecare live\winssnotify.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [C-Media Mixer] Mixer.exe /startup mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [Launch LCDMon] "c:\program files\common files\logitech\lcd manager\lcdmon.exe" mRun: [<NO NAME>] mRun: [Launch LGDCore] "c:\program files\common files\logitech\g-series software\LGDCore.exe" /SHOWHIDE mRun: [CoolSwitch] c:\windows\system32\taskswitch.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [OODefragTray] c:\windows\system32\oodtray.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240178366140 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1240180977625 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\ed\applic~1\mozilla\firefox\profiles\tj89x820.default\ FF - component: c:\documents and settings\ed\application data\mozilla\firefox\profiles\tj89x820.default\extensions\piclens@cooliris.com\components\coolirisstub.dll ---- FIREFOX POLICIES ---- ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-21 64160] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 953168] R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\microsoft windows onecare live\OcHealthMon.exe [2009-3-22 24936] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-4-19 603904] =============== Created Last 30 ================ 2009-05-08 23:28 <DIR> --d----- c:\program files\common files\Windows Live 2009-05-06 20:44 <DIR> --d----- c:\program files\SystemRequirementsLab 2009-05-01 22:25 <DIR> --d----- c:\program files\2.8.4 AA 2009-04-30 21:20 131,072 a------- c:\windows\system32\dzip32.dll 2009-04-30 21:20 110,592 a------- c:\windows\system32\dunzip32.dll 2009-04-30 21:20 <DIR> --d----- c:\program files\Windows Media Bonus Pack for Windows XP 2009-04-30 19:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DFX 2009-04-30 19:52 <DIR> --d----- c:\program files\common files\DFX 2009-04-23 19:30 138,016 a------- c:\windows\system32\drivers\PnkBstrK.sys 2009-04-23 19:30 189,392 a------- c:\windows\system32\PnkBstrB.exe 2009-04-23 19:30 189,392 a------- c:\windows\system32\PnkBstrB.xtr 2009-04-23 19:30 75,064 a------- c:\windows\system32\PnkBstrA.exe 2009-04-22 20:45 <DIR> --d----- c:\program files\America's Army 2009-04-21 20:38 107,368 a------- c:\windows\system32\GEARAspi.dll 2009-04-21 20:38 23,400 a------- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-04-21 20:38 <DIR> --d----- c:\program files\iPod 2009-04-21 20:38 <DIR> --d----- c:\program files\iTunes 2009-04-21 20:38 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-04-21 20:38 <DIR> --d----- c:\program files\Bonjour 2009-04-21 17:56 15,688 a------- c:\windows\system32\lsdelete.exe 2009-04-21 16:03 64,160 a------- c:\windows\system32\drivers\Lbd.sys 2009-04-21 16:00 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-04-21 16:00 <DIR> --d----- c:\program files\Lavasoft 2009-04-21 15:40 <DIR> --d----- c:\program files\ErrorFix 2009-04-21 15:40 <DIR> --d----- c:\program files\Downloaded Installers 2009-04-20 15:43 221,184 a------- c:\windows\system32\wmpns.dll 2009-04-20 15:41 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat 2009-04-20 15:38 27,496 a------- c:\windows\system32\mucltui.dll.mui 2009-04-20 15:38 268,648 a------- c:\windows\system32\mucltui.dll 2009-04-20 03:33 8 a------- c:\windows\system32\nvModes.dat 2009-04-20 02:24 <DIR> --d----- c:\windows\system32\oodag 2009-04-20 00:49 <DIR> --d----- c:\documents and settings\ed\Incomplete 2009-04-20 00:48 <DIR> --d----- c:\docume~1\ed\applic~1\FrostWire 2009-04-19 20:13 139,186 a------- c:\windows\system32\oodbs.lor 2009-04-19 19:47 116 a------- c:\windows\NeroDigital.ini 2009-04-19 19:23 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys 2009-04-19 18:52 101 a------- c:\windows\CMMIXER.INI 2009-04-19 18:08 77,587 a------- c:\windows\War3Unin.dat 2009-04-19 18:08 2,829 a------- c:\windows\War3Unin.pif 2009-04-19 18:08 139,264 a------- c:\windows\War3Unin.exe 2009-04-19 17:56 <DIR> --d----- c:\program files\Spybot - Search & Destroy 2009-04-19 17:56 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-04-19 17:53 <DIR> --d----- c:\program files\OO Software 2009-04-19 17:46 151 a------- c:\windows\PhotoSnapViewer.INI 2009-04-19 17:44 73,728 a------- c:\windows\system32\javacpl.cpl 2009-04-19 17:43 <DIR> --d----- c:\program files\AskBarDis 2009-04-19 17:42 <DIR> --d----- c:\docume~1\ed\applic~1\uTorrent 2009-04-19 17:06 603,904 a------- c:\windows\system32\TUProgSt.exe 2009-04-19 17:06 360,192 a------- c:\windows\system32\TuneUpDefragService.exe 2009-04-19 17:06 27,904 a------- c:\windows\system32\uxtuneup.dll 2009-04-19 17:06 <DIR> --d----- c:\docume~1\ed\applic~1\TuneUp Software 2009-04-19 17:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TuneUp Software 2009-04-19 17:06 <DIR> --d----- c:\program files\TuneUp Utilities 2009 2009-04-19 17:06 <DIR> --dsh--- c:\docume~1\alluse~1\applic~1\{55A29068-F2CE-456C-9148-C869879E2357} 2009-04-19 17:05 266,360 a------- c:\windows\system32\TweakUI.exe 2009-04-19 17:05 160,217 a------- c:\windows\system32\PowerToysLicense.rtf 2009-04-19 17:05 <DIR> --d----- c:\program files\Schmads Inc 2009-04-19 17:04 <DIR> --d----- c:\windows\Downloaded Installations 2009-04-19 16:59 <DIR> --d----- c:\program files\Yahoo! 2009-04-19 16:57 34,064 a------- c:\windows\system32\lhacm.acm 2009-04-19 16:57 <DIR> --d----- c:\program files\Teamspeak2_RC2 2009-04-19 16:56 <DIR> --d----- c:\program files\common files\Logitech 2009-04-19 16:52 <DIR> --d----- c:\program files\Nero 2009-04-19 16:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Nero 2009-04-19 16:12 25 a------- c:\windows\mixerdef.ini 2009-04-19 16:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\America's Army Deploy Client 2009-04-19 16:11 <DIR> --d----- c:\program files\America's Army Deploy Client 2009-04-19 16:05 <DIR> --d----- c:\windows\system32\XPSViewer 2009-04-19 16:05 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-04-19 16:05 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll 2009-04-19 16:05 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-04-19 16:05 575,488 -------- c:\windows\system32\xpsshhdr.dll 2009-04-19 16:05 117,760 -------- c:\windows\system32\prntvpt.dll 2009-04-19 16:05 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll 2009-04-19 16:05 <DIR> --d----- C:\457de8dd21c6dea9844ba4002991 2009-04-19 16:05 1,676,288 -------- c:\windows\system32\xpssvcs.dll 2009-04-19 15:59 <DIR> --d----- c:\program files\Windows Media Connect 2 2009-04-19 15:57 <DIR> --d----- c:\windows\system32\URTTEMP 2009-04-19 15:42 <DIR> --dsh--- c:\documents and settings\ed\PrivacIE 2009-04-19 15:39 <DIR> --d----- c:\windows\nvidia icons 2009-04-19 15:39 182,038 a------- c:\windows\system32\nvapps.xml 2009-04-19 15:39 181,895 a------- c:\windows\system32\nvdsp.chm 2009-04-19 15:39 121,529 a------- c:\windows\system32\nvcpl.chm 2009-04-19 15:39 116,384 a------- c:\windows\system32\nv3d.chm 2009-04-19 15:39 54,988 a------- c:\windows\system32\nvmob.chm 2009-04-19 15:39 442,368 a------- c:\windows\system32\nvudisp.exe 2009-04-19 15:39 18,070 a------- c:\windows\system32\nvdisp.nvu 2009-04-19 15:39 <DIR> --d----- c:\windows\nview 2009-04-19 15:39 442,368 a------- c:\windows\system32\NVUNINST.EXE 2009-04-19 15:39 <DIR> --d----- C:\NVIDIA 2009-04-19 15:37 <DIR> --dsh--- c:\documents and settings\ed\IETldCache 2009-04-19 15:36 <DIR> --d----- c:\windows\ie8updates 2009-04-19 15:35 <DIR> -cd-h--- c:\windows\ie8 2009-04-19 15:34 105,984 -c------ c:\windows\system32\dllcache\iecompat.dll 2009-04-19 15:24 91,328 a------- c:\windows\system32\drivers\msfwdrv.sys 2009-04-19 15:24 116,416 a------- c:\windows\system32\drivers\msfwhlpr.sys 2009-04-19 15:24 53,168 a------- c:\windows\system32\drivers\MpFilter.sys 2009-04-19 15:20 272,128 -c------ c:\windows\system32\dllcache\bthport.sys 2009-04-19 15:17 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll 2009-04-19 15:17 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll 2009-04-19 15:17 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb 2009-04-19 15:17 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe 2009-04-19 15:17 2,560 -------- c:\windows\system32\xpsp4res.dll 2009-04-19 15:17 <DIR> --d----- c:\program files\Microsoft Windows OneCare Live 2009-04-19 15:12 <DIR> --d----- c:\windows\system32\scripting 2009-04-19 15:12 <DIR> --d----- c:\windows\system32\en 2009-04-19 15:12 <DIR> --d----- c:\windows\system32\bits 2009-04-19 15:12 <DIR> --d----- c:\windows\l2schemas 2009-04-19 15:10 <DIR> --d----- c:\windows\network diagnostic 2009-04-19 15:00 <DIR> --d----- c:\windows\system32\PreInstall 2009-04-19 15:00 <DIR> --d-h--- c:\windows\$hf_mig$ 2009-04-19 14:59 <DIR> --d----- c:\windows\system32\SoftwareDistribution 2009-04-19 14:59 <DIR> --dsh--- c:\documents and settings\ed\UserData 2009-04-19 14:58 <DIR> --ds---- c:\windows\system32\Microsoft 2009-04-19 14:55 316,640 a------- c:\windows\WMSysPr9.prx 2009-04-19 14:53 2,897,920 -------- c:\windows\system32\xpsp2res.dll 2009-04-19 14:53 19,528 a------- c:\windows\002238_.tmp 2009-04-19 14:53 <DIR> --d----- c:\windows\system32\ReinstallBackups 2009-04-19 14:52 26,144 a------- c:\windows\system32\spupdsvc.exe 2009-04-19 14:52 <DIR> --d----- c:\windows\EHome 2009-04-19 14:48 <DIR> --dsh--- c:\windows\Installer 2009-04-19 14:48 <DIR> --d----- c:\documents and settings\ed 2009-04-19 14:47 8,192 a------- c:\windows\REGLOCS.OLD 2009-04-19 14:45 143,422 ac------ c:\windows\system32\dllcache\softkey.dll 2009-04-19 14:44 <DIR> --dsh--- c:\documents and settings\all users\DRM 2009-04-19 14:43 <DIR> --d----- c:\program files\common files\MSSoap 2009-04-19 14:42 <DIR> --d-h--- c:\program files\WindowsUpdate 2009-04-19 14:42 <DIR> --d----- c:\program files\Online Services 2009-04-19 14:42 <DIR> --d----- c:\program files\MSN Gaming Zone 2009-04-19 14:42 <DIR> --d----- c:\program files\Windows NT 2009-04-19 07:38 <DIR> --d----- c:\program files\common files\ODBC 2009-04-19 07:38 <DIR> --d----- c:\program files\common files\SpeechEngines 2009-04-19 07:38 <DIR> --d--r-- c:\documents and settings\all users\Documents ==================== Find3M ==================== 2009-04-19 15:14 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-04-19 14:42 21,640 a------- c:\windows\system32\emptyregdb.dat 2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll 2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll 2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll 2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll 2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll 2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll 2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll 2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll 2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe 2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll 2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll 2009-02-25 21:59 1,316,096 a------- c:\windows\system32\ooscrsav.scr 2009-02-25 21:59 730,368 a------- c:\windows\system32\oodsvct.exe 2009-02-25 21:59 1,352,960 a------- c:\windows\system32\oodag.exe 2009-02-25 21:58 2,553,088 a------- c:\windows\system32\oodtray.exe 2009-02-25 21:57 194,816 a------- c:\windows\system32\oodbs.exe 2009-02-25 21:53 951,552 a------- c:\windows\system32\oodtrrs.dll 2009-02-25 21:53 541,952 a------- c:\windows\system32\oodssrs.dll 2009-02-25 21:53 9,984 a------- c:\windows\system32\oodbsrs.dll 2009-02-25 21:53 8,448 a------- c:\windows\system32\OODAGRS.DLL 2009-02-25 21:52 15,616 a------- c:\windows\system32\OODAGMG.DLL 2009-02-23 20:03 15,104 a------- c:\windows\system32\ootmapi.dll ============= FINISH: 16:16:01.59 =============== sorry forgot to post GMER and attach ... Attach.zip sdf ark.txt |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#3 (permalink) |
|
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
Join Date: Oct 2007
Location: Georgia
Posts: 10,540
OS: XP SP3
|
Re: malware issues
Thanks for letting us know. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:
IMPORTANT - Read This Before Posting For Malware Removal Help ------------------------------------------------------ |
|
|
![]() |
| Thread Tools | |
|
|