Tech Support Forum banner
Status
Not open for further replies.
1 - 3 of 3 Posts

·
Registered
Joined
·
7 Posts
hi
i run your tool in my computer and i attach to see u
thanks



DDS (Ver_09-03-16.01) - NTFSx86
Run by hq6873 at 9:47:17.94 on Sun 05/03/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2527.1876 [GMT 5.5:30]

AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS.0\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS.0\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS.0\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS.0\system32\igfxtray.exe
C:\WINDOWS.0\system32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS.0\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\WINDOWS.0\system32\svchost.exe -k imgsvc
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Documents and Settings\HQ6873.ICL\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS.0\system32\wuauclt.exe
C:\PROGRA~1\MICROS~1\Office12\OUTLOOK.EXE
C:\WINDOWS.0\system32\mstsc.exe
C:\Documents and Settings\HQ6873.ICL\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uWindow Title = gods must be creazy!!!!
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = 192.168.0.5:8080
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
mWinlogon: Userinit=c:\windows.0\system32\userinit.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: SBCONVERT Class: {a1056498-d09a-41e4-864b-505edd640d9e} - c:\program files\speedbit video downloader\toolbar\SpeedBitVideoDownloader.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
BHO: GrabberObj Class: {ff7c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\speedb~2\toolbar\grabber.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
TB: SpeedBit Video Downloader: {0329e7d6-6f54-462d-93f6-f5c3118badf2} - c:\program files\speedbit video downloader\toolbar\SpeedBitVideoDownloader.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows.0\system32\ctfmon.exe
uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMBgMonitor.exe"
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Google Update] "c:\documents and settings\hq6873.icl\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [igfxtray] c:\windows.0\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows.0\system32\hkcmd.exe
mRun: [igfxpers] c:\windows.0\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
mRun: [EPSON Stylus C59 Series] c:\windows.0\system32\spool\drivers\w32x86\3\e_fatibhp.exe /fu "c:\windows.0\temp\E_S720.tmp" /EF "HKLM"
mRun: [ToolBoxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:eek:n /alerts:eek:n /notifications:eek:n /systrayIcon:eek:n /fl:eek:n /fr:eek:n /appData:eek:n
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [winlogon] c:\windows.0\winlogon.exe
mRun: [WinampAgent] c:\program files\winamp\winampa.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [PAC207_Monitor] c:\windows.0\pixart\pac207\Monitor.exe
mRun: [Monitor] c:\windows.0\pixart\pac207\Monitor.exe
mExplorerRun: [lsass] c:\windows.0\lsass.exe
StartupFolder: c:\docume~1\alluse~1.0\startm~1\programs\startup\adobea~1.lnk - c:\windows.0\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1.0\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1.0\startm~1\programs\startup\sinhal~2.lnk - c:\program files\sinhalatamil kit\SinhalaKit.exe
StartupFolder: c:\docume~1\alluse~1.0\startm~1\programs\startup\sinhal~1.lnk - c:\program files\sinhalatamil kit\TamilKit.exe
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/F/D/9/FD9E437D-5BC8-4264-A093-DFA2C39D197E/LegitCheckControl.cab
DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} - hxxp://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1232963821555
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1232963788425
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\dap\dapie.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows.0\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows.0\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\hq6873.icl\applic~1\mozilla\firefox\profiles\a9abvdlm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.ftp - 192.168.0.5
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 192.168.0.5
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - 192.168.0.5
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 192.168.0.5
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 192.168.0.5
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\documents and settings\hq6873.icl\local settings\application data\google\update\1.2.141.5\npGoogleOneClick7.dll

============= SERVICES / DRIVERS ===============

R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-9-27 116464]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-9-27 1813232]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~1\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~1\VideoAcceleratorService.exe -start -scm [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-11 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090430.018\naveng.sys [2009-5-1 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090430.018\navex15.sys [2009-5-1 876144]
S3 a4wnetMgrService;Sage Accpac .NET Remoting Service;c:\program files\common files\sage\sage accpac\a4wnetMgrService.exe [2006-5-28 20480]
S3 EraserUtilDrv10910;EraserUtilDrv10910;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10910.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10910.sys [?]
S3 EraserUtilDrvI7;EraserUtilDrvI7;\??\c:\program files\common files\symantec shared\eengine\eraserutildrvi7.sys --> c:\program files\common files\symantec shared\eengine\EraserUtilDrvI7.sys [?]

=============== Created Last 30 ================

2009-05-01 11:41 <DIR> --d----- c:\windows.0\system32\appmgmt
2009-05-01 11:17 243,197 a--shr-- c:\windows.0\lsass.exe
2009-04-29 20:15 0 a------- c:\windows.0\VPC32.INI
2009-04-24 12:36 352 a------- c:\windows.0\st6unst.000
2009-04-24 12:29 <DIR> --d----- c:\docume~1\alluse~1.0\applic~1\Sage
2009-04-24 12:29 <DIR> --d----- c:\docume~1\alluse~1.0\applic~1\SageInstalls
2009-04-24 12:28 <DIR> --d----- c:\program files\Business Objects
2009-04-24 12:27 <DIR> --d----- c:\program files\Seagate Software
2009-04-24 12:27 <DIR> --d----- c:\program files\common files\Sage
2009-04-24 12:27 <DIR> --d----- c:\program files\common files\Business Objects
2009-04-24 12:26 <DIR> --d----- C:\Sage Accpac
2009-04-24 10:12 <DIR> --d----- c:\docume~1\hq6873.icl\applic~1\Peachtree
2009-04-24 10:12 7,358 -------- c:\windows.0\support.ICO
2009-04-24 10:12 7,358 -------- c:\windows.0\forms.ICO
2009-04-24 10:12 5,222 -------- c:\windows.0\ADOBE.ICO
2009-04-24 10:12 766 -------- c:\windows.0\ACTGPR2.ICO
2009-04-24 10:11 <DIR> --d----- c:\windows.0\Crystal
2009-04-24 10:10 <DIR> --d----- c:\program files\Crystal Decisions
2009-04-24 10:10 <DIR> --d----- c:\program files\common files\Crystal Decisions
2009-04-24 10:09 <DIR> --d----- c:\program files\Sage Software
2009-04-23 08:26 <DIR> --d----- c:\windows.0\system32\KB905474
2009-04-17 09:14 401,408 -c------ c:\windows.0\system32\dllcache\rpcss.dll
2009-04-17 09:14 284,160 -c------ c:\windows.0\system32\dllcache\pdh.dll
2009-04-17 09:14 110,592 -c------ c:\windows.0\system32\dllcache\services.exe
2009-04-17 09:14 60,416 -c------ c:\windows.0\system32\dllcache\colbact.dll
2009-04-17 09:14 35,328 -c------ c:\windows.0\system32\dllcache\sc.exe
2009-04-17 09:14 728,576 -c------ c:\windows.0\system32\dllcache\lsasrv.dll
2009-04-17 09:14 715,264 -c------ c:\windows.0\system32\dllcache\ntdll.dll
2009-04-17 09:14 617,984 -c------ c:\windows.0\system32\dllcache\advapi32.dll
2009-04-17 09:14 473,088 -c------ c:\windows.0\system32\dllcache\fastprox.dll
2009-04-17 09:14 227,840 -c------ c:\windows.0\system32\dllcache\wmiprvse.exe
2009-04-17 09:11 215,552 -c------ c:\windows.0\system32\dllcache\wordpad.exe

==================== Find3M ====================

2009-04-02 14:56 304,160 a------- C:\PA207.DAT
2009-03-11 08:29 124,928 ---shr-- c:\windows.0\system32\kavo0.dll
2009-03-06 19:30 284,160 a------- c:\windows.0\system32\pdh.dll
2009-03-03 05:48 826,368 a------- c:\windows.0\system32\wininet.dll
2009-02-20 23:39 78,336 a------- c:\windows.0\system32\ieencode.dll
2009-02-09 15:50 1,847,424 a------- c:\windows.0\system32\win32k.sys
2009-02-09 15:31 728,576 a------- c:\windows.0\system32\lsasrv.dll
2009-02-09 15:31 617,984 a------- c:\windows.0\system32\advapi32.dll
2009-02-09 15:31 401,408 a------- c:\windows.0\system32\rpcss.dll
2009-02-09 15:31 715,264 a------- c:\windows.0\system32\ntdll.dll
2009-02-06 15:59 2,142,720 a------- c:\windows.0\system32\ntoskrnl.exe
2009-02-06 15:52 110,592 a------- c:\windows.0\system32\services.exe
2009-02-06 15:24 35,328 a------- c:\windows.0\system32\sc.exe
2009-02-06 15:19 2,020,864 a------- c:\windows.0\system32\ntkrnlpa.exe
2009-02-04 01:22 56,320 a------- c:\windows.0\system32\secur32.dll
2009-02-03 09:17 50,688 a------- c:\windows.0\system32\wbhelp2.dll
2009-01-20 01:44 243,197 a--shr-- c:\windows.0\lsass.exe

============= FINISH: 9:47:45.12 ===============
 

Attachments

·
TSF-Emeritus
Joined
·
15,384 Posts
Hello and welcome to TSF.

Apologies for the late response. If you still need help, please post a fresh DDS.txt as it has been a while since you posted.

Your internet explorer is set to use a proxy. Is that an intentional setting?

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Please note that the forum is very busy and if I don’t hear from you in three days this thread will be closed.
 
1 - 3 of 3 Posts
Status
Not open for further replies.
Top