I was referred to here from http://www.bleepingcomputer.com/forums/topic233747.html
I did not backup, not knowing if problem would also be on my SanDisk Cruzer Micra 8GB (U3) & don't know if it will work on my computer, (confused me & sales person) and don't know about the script stuff to turn off.
Thank you for helping me
-Deb
- Edit: Hope I did this right
DDS (Ver_09-05-14.01) - NTFSx86
Run by Owner at 23:17:37.57 on Thu 06/18/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.64 [GMT -6:00]
AV: CA Anti-Virus *On-access scanning enabled* (Updated)
{17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svcprs32.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\cfgmng32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
C:\WINDOWS\system32\mdmcls32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://homepage.bresnan.net/default.aspx?newZip=59715
uInternet Settings,ProxyOverride = ;<local>
uURLSearchHooks: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} -
c:\program files\macrogaming\sweetimbarforie\toolbar.dll
mURLSearchHooks: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} -
c:\program files\macrogaming\sweetimbarforie\toolbar.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program
files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SWEETIE Class: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} -
c:\progra~1\macrog~1\sweeti~1\toolbar.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search
enhancement pack\search helper\SEPsearchhelperie.dll
BHO: del.icio.us Toolbar Helper: {7aa07ae6-01ef-44ec-93ca-9d7cd41ccdb6} - c:\program
files\del.icio.us\internet explorer buttons\dlcsIE.dll
BHO: ALToolbarBho Class: {7f1a79f9-78d1-4186-9f60-ee0b63df042a} - c:\program
files\estsoft\altoolbar\ALToolBand_114_25.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program
files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program
files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: &Google Notebook: {ccccccd3-666f-4f81-8b69-745de9f6d897} - c:\program files\google\google
notebook\gnotes1.0.2.19--752316462.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program
files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program
files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: CA Toolbar Helper: {fbf2401b-7447-4727-be5d-c19b2075ca84} - c:\program files\ca\ca internet
security suite\ca website inspector\toolbar\CallingIDIE.dll
TB: Google Notebook: {ccccccdb-4ddb-4703-95d4-dd2c526397bf} - c:\program files\google\google
notebook\gnotes1.0.2.19--752316462.dll
TB: del.icio.us: {981fe6a8-260c-4930-960f-c3bc82746cb0} - c:\program files\del.icio.us\internet
explorer buttons\dlcsIE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program
files\google\googletoolbar1.dll
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program
files\macrogaming\sweetimbarforie\toolbar.dll
TB: ALToolBar: {38fbe93d-4ca1-4414-af6a-94920c5bd8da} - c:\program
files\estsoft\altoolbar\ALToolBand_114_25.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows
live\toolbar\wltcore.dll
TB: {C17590D2-ECB4-4B15-8820-F58798DCC118} - No File
TB: CA Toolbar: {10134636-e7af-4ac5-a1dc-c7c44bb97d81} - c:\program files\ca\ca internet security
suite\ca website inspector\toolbar\CallingIDIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [dvHighMem] c:\windows\cfgmng32.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [VetStart] "c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe" -r
mRun: [QOELOADER] "c:\program files\ca\ca internet security suite\ca
anti-spam\qsp-6.0.1.33\QOELoader.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\launch~1.lnk -
c:\windows\installer\{d8e363a7-88b7-446d-b2c0-e26ce4dc8e54}\_294823.exe
uPolicies-explorer: NoCommonGroups = 0 (0x0)
uPolicies-explorer: NoFileSharing = 0 (0x0)
uPolicies-explorer: NoPrintSharing = 0 (0x0)
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
IE: &Add animation to IncrediMail Style Box - c:\program
files\incredimail\bin\resources\WebMenuImg.htm
IE: &Search
IE: ALToolBar &Search - c:\program files\estsoft\altoolbar\ALToolBandRes.dll/23/SEARCH.HTML
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} -
c:\program files\windows live\writer\WriterBrowserExtension.dll
LSP: c:\windows\system32\winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} -
hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} -
hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGACo
ntrol.cab
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -
hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?11760
65949484
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} -
hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program
files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} -
c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program
files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath -
============= SERVICES / DRIVERS ===============
R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-6-3 28544]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2007-4-10
3968]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-5-21 26352]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-5-21
21104]
R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2008-2-26 880560]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2009-5-21
21488]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-5-21 161008]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-2-26
144696]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-30 55152]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2008-9-19 54960]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe
[2008-2-26 185584]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2008-2-26 108368]
S4 dlci_device;dlci_device;c:\windows\system32\dlcicoms.exe -service -->
c:\windows\system32\dlcicoms.exe -service [?]
S4 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe
[2009-2-6 533360]
S4 gupdate1c9a3c35b602e70;Google Update Service (gupdate1c9a3c35b602e70);c:\program
files\google\update\GoogleUpdate.exe [2009-3-13 133104]
S4 NG;NG;c:\docume~1\owner\locals~1\temp\ng.exe -->
c:\docume~1\owner\locals~1\temp\NG.exe [?]
=============== Created Last 30 ================
2009-06-17 19:12 <DIR> -cd----- c:\docume~1\owner\applic~1\SUPERAntiSpyware.com
2009-06-15 20:05 102,664 a------- c:\windows\system32\drivers\tmcomm.sys
2009-06-15 20:03 <DIR> -cd----- c:\documents and settings\owner\.housecall6.6
2009-06-11 12:33 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-06-11 12:33 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-06-11 12:13 73,728 a------- c:\windows\system32\javacpl.cpl
2009-06-03 01:20 28,544 a------- c:\windows\system32\drivers\pavboot.sys
2009-06-03 00:25 9,135 a------- c:\windows\DNAPrinters.ini
2009-05-26 18:18 664 a------- c:\windows\system32\d3d9caps.dat
2009-05-21 21:54 161,008 a------- c:\windows\system32\drivers\vetmonnt.sys
2009-05-21 21:54 21,488 a------- c:\windows\system32\drivers\vetfddnt.sys
2009-05-21 21:54 26,352 a------- c:\windows\system32\drivers\vet-filt.sys
2009-05-21 21:54 21,104 a------- c:\windows\system32\drivers\vet-rec.sys
==================== Find3M ====================
2009-05-26 13:20 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 13:19 19,096 ac------ c:\windows\system32\drivers\mbam.sys
2009-05-25 00:24 350,208 -------- c:\windows\system32\mssph.dll
2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-12 23:15 915,456 a------- c:\windows\system32\wininet.dll
2009-05-12 15:12 26,144 a------- c:\windows\system32\spupdsvc.exe
2009-05-07 09:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-17 06:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 08:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-03-27 08:45 676,224 a------- c:\windows\system32\OGACheckControl.DLL
2008-08-29 12:35 1,377,872 ac------
c:\docume~1\alluse~1\applic~1\pswi_preloaded.exe
2007-08-15 17:11 774,144 ac------ c:\program files\RngInterstitial.dll
2008-02-26 14:59 30,720 a--sh--- c:\windows\rnapxs\rnapxs.dat
2008-09-14 23:10 88 ---shr-- c:\windows\system32\868EC7B823.sys
2008-09-15 00:37 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-06-14 21:57 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local
settings\history\history.ie5\mshist012008061420080615\index.dat
============= FINISH: 23:18:47.28 ===============
Attached File(s)
-
Attach.txt (7.09K)
Number of downloads: 0
This post has been edited by MontanaDeb: 19 June 2009 - 03:23 AM

Help
This topic is locked

Back to top











