Regards,
MattS
DDS (Ver_2011-07-14.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by MattS at 13:05:25 on 2011-07-14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.434 [GMT 10:00]
.
AV: Sophos Anti-Virus *Enabled/Updated* {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
============== Running Processes ================
.
E:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Sophos\AutoUpdate\almon.exe
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\PROGRESS\bin\AdmSrvc.exe
E:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
E:\PROGRA~1\MICROS~4\rapimgr.exe
E:\WINDOWS\system32\cisvc.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
E:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\PROGRESS\jre\bin\java.exe
E:\Program Files\Sophos\AutoUpdate\ALsvc.exe
E:\Program Files\Sophos\Remote Management System\RouterNT.exe
E:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
E:\WINDOWS\system32\SearchIndexer.exe
E:\WINDOWS\System32\alg.exe
C:\Program Files\PROGRESS\jre\bin\java.exe
E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
E:\PROGRA~1\COMPON~1\CS-RCS\System\csrcssrv.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\WINDOWS\system32\SearchFilterHost.exe
E:\WINDOWS\system32\SearchProtocolHost.exe
E:\WINDOWS\system32\wbem\wmiprvse.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
E:\WINDOWS\system32\svchost.exe -k NetworkService
E:\WINDOWS\system32\svchost.exe -k LocalService
E:\WINDOWS\system32\svchost.exe -k LocalService
E:\WINDOWS\System32\svchost.exe -k Akamai
E:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://image.bizit.com.au/images/AusBrkBulk/login.asp
uInternet Connection Wizard,ShellNext = iexplore
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Sophos Web Content Scanner: {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - e:\program files\sophos\sophos anti-virus\SophosBHO.dll
BHO: AcroIEToolbarHelper Class: {AE7CD045-E861-484f-8273-0445EE161910} - e:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - e:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - e:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - e:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - e:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - e:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] e:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "e:\program files\messenger\msmsgs.exe" /background
uRun: [H/PC Connection Agent] "e:\program files\microsoft activesync\Wcescomm.exe"
mRun: [Sophos AutoUpdate Monitor] e:\program files\sophos\autoupdate\almon.exe
mRun: [SunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] e:\windows\system32\CTFMON.EXE
StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - e:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - e:\program files\microsoft office\office\OSA9.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Web Capture - e:\program files\smarthru office\WebCapture.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - e:\program files\microsoft activesync\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - e:\program files\microsoft activesync\INetRepl.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe
DPF: {106E49CF-797A-11D2-81A2-00E02C015623} - hxxp://www.alternatiff.com/install-ie/alttiff.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxps://a248.e.akamai.net/f/248/14778/2h/dlmanager.download.akamai.com/14778/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245127871225
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1245634852839
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.208.14 203.8.183.1
TCP: Interfaces\{132931AB-F7BE-490E-8CF2-7BB01DC970D2} : DHCPNameServer = 192.168.208.14 203.8.183.1
Handler: ipp - <Clsid value has no data>
Handler: msdaipp - <Clsid value has no data>
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - e:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "e:\program files\outlook express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
mASetup: {7790769C-0471-11d2-AF11-00C04FA35D02} - "e:\program files\outlook express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
IFEO: Your Image File Name Here without a path - ntsd -d
.
================= FIREFOX ===================
.
FF - ProfilePath - e:\documents and settings\matts\application data\mozilla\firefox\profiles\awiz02g4.default\
FF - prefs.js: browser.startup.homepage - hxxp://image.bizit.com.au/images/AusBrkBulk/login.asp
FF - plugin: e:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: e:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: e:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: e:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: e:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - e:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - e:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - e:\program files\java\jre6\lib\deploy\jqs\ff
.
============= SERVICES / DRIVERS ===============
.
R1 SAVOnAccessControl;SAVOnAccessControl;e:\windows\system32\drivers\savonaccesscontrol.sys [2009-6-16 153344]
R1 SAVOnAccessFilter;SAVOnAccessFilter;e:\windows\system32\drivers\savonaccessfilter.sys [2009-6-16 24064]
R2 AdminService9.1D;AdminService for PROGRESS 9.1D;c:\program files\progress\bin\admsrvc.exe [2005-7-6 20480]
R2 Akamai;Akamai NetSession Interface;e:\windows\system32\svchost.exe -k Akamai [2007-7-27 14336]
R2 SAVAdminService;Sophos Anti-Virus status reporter;e:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2011-3-25 163056]
R2 SAVService;Sophos Anti-Virus;e:\program files\sophos\sophos anti-virus\SavService.exe [2011-3-25 97520]
R2 Sophos Agent;Sophos Agent;e:\program files\sophos\remote management system\ManagementAgentNT.exe [2011-3-29 282624]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;e:\program files\sophos\autoupdate\ALsvc.exe [2010-9-30 230640]
R2 Sophos Message Router;Sophos Message Router;e:\program files\sophos\remote management system\RouterNT.exe [2011-3-29 806912]
R2 swi_service;Sophos Web Intelligence Service;e:\program files\sophos\sophos anti-virus\web intelligence\swi_service.exe [2011-3-25 1541360]
R3 es1969;ESS 1969 Audio Driver (WDM);e:\windows\system32\drivers\es1969.sys [2009-6-17 72704]
R3 xcpip;TCP/IP Protocol Driver;e:\windows\system32\drivers\xcpip.sys --> e:\windows\system32\drivers\xcpip.sys [?]
R3 xpsec;IPSEC driver;e:\windows\system32\drivers\xpsec.sys --> e:\windows\system32\drivers\xpsec.sys [?]
S2 gupdate;Google Update Service (gupdate);e:\program files\google\update\GoogleUpdate.exe [2010-10-18 136176]
S2 SSPORT;SSPORT;\??\e:\windows\system32\drivers\ssport.sys --> e:\windows\system32\drivers\SSPORT.sys [?]
S3 B-Service;B-Service;e:\documents and settings\matts\local settings\temporary internet files\content.ie5\fbom80h4\b-service.exe --> e:\documents and settings\matts\local settings\temporary internet files\content.ie5\fbom80h4\B-Service.exe [?]
S3 gupdatem;Google Update Service (gupdatem);e:\program files\google\update\GoogleUpdate.exe [2010-10-18 136176]
S3 ProService9.1D;ProService for 9.1D;c:\program files\progress\bin\prosrvc.exe [2005-7-6 126976]
S3 sdcfilter;sdcfilter;e:\windows\system32\drivers\sdcfilter.sys [2011-3-25 23928]
S4 SophosBootDriver;SophosBootDriver;e:\windows\system32\drivers\SophosBootDriver.sys [2009-6-16 14976]
.
=============== Created Last 30 ================
.
2011-07-13 02:22:07 -------- d-----w- e:\windows\system32\NtmsData
2011-07-11 00:54:26 462848 ----a-w- e:\windows\system32\providorduaqhn.dll
2011-06-21 05:18:24 73728 ----a-w- e:\windows\system32\javacpl.cpl
2011-06-21 05:18:24 476904 ----a-w- e:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-06-21 05:18:24 472808 ----a-w- e:\windows\system32\deployJava1.dll
2011-06-21 01:10:00 -------- d-----w- E:\OE102b
2011-06-17 02:01:31 105472 -c----w- e:\windows\system32\dllcache\mup.sys
.
==================== Find3M ====================
.
2011-06-23 02:39:32 404640 ----a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02:05 1858944 ----a-w- e:\windows\system32\win32k.sys
2011-05-02 15:31:52 692736 ----a-w- e:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- e:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- e:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07:50 33280 ----a-w- e:\windows\system32\csrsrv.dll
2011-04-26 11:07:50 293376 ----a-w- e:\windows\system32\winsrv.dll
2011-04-25 16:11:12 916480 ----a-w- e:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ----a-w- e:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ----a-w- e:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ----a-w- e:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- e:\windows\system32\drivers\mup.sys
.
============= FINISH: 13:06:31.84 ===============
Attached File(s)
-
attach.txt (12.55K)
Number of downloads: 0 -
ark.txt (32.58K)
Number of downloads: 0

Help
This topic is locked

Back to top











