.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Colin at 12:04:38 on 2011-10-10
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1023.393 [GMT 1:00]
.
AV: Sophos Anti-Virus *Enabled/Outdated* {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
C:\Program Files\Kaseya\KSAASP42944940446000\AgentMon.exe
C:\Program Files\Common Files\Sage SData\Sage.SData.Service.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Kaseya\KSAASP42944940446000\KaUsrTsk.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Documents and Settings\Colin\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFIE.EXE
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.co.uk/
uDefault_Page_URL = hxxp://companyweb
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
uRun: [SansaDispatch] c:\documents and settings\colin\application data\sandisk\sansa updater\SansaDispatch.exe
uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot
uRun: [\\BELLSERVER\EPSON SX510W Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifie.exe /fu "c:\docume~1\colin\locals~1\temp\E_S2A3.tmp" /EF "HKCU"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [Rqimop] rundll32.exe "c:\windows\idinegifo.dll",Startup
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe
mRun: [KASHKSAASP42944940446000] "c:\program files\kaseya\ksaasp42944940446000\KaUsrTsk.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\colin\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sophos~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {7B43048F-DA7A-458F-AF35-D825BDBB6816} - hxxp://192.168.2.23/codebase/NetVideoOCX.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.2.2
TCP: Interfaces\{F5699187-B514-4DEC-B0AE-425BAC374A01} : DhcpNameServer = 192.168.2.2
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: LMIinit - LMIinit.dll
AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Notification Packages = scecli imefsc32.dll
mASetup: {F0173905-8498-4452-A4BD-EC689AFA6B3A} - "%ProgramFiles%\Common Files\Sage SBD\ForceEIRRegistration.exe"
.
============= SERVICES / DRIVERS ===============
.
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2010-6-16 152192]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2010-6-16 24064]
R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-9-16 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-9-16 234888]
R2 KAKSAASP42944940446000;Kaseya IT Toolkit;c:\program files\kaseya\ksaasp42944940446000\AgentMon.exe [2010-6-22 835584]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-4-7 47640]
R2 Sage SData Service;Sage SData Service;c:\program files\common files\sage sdata\Sage.SData.Service.exe [2009-12-16 49152]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2010-6-16 104488]
R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2010-6-16 93736]
R2 Sophos Agent;Sophos Agent;c:\program files\sophos\remote management system\ManagementAgentNT.exe [2010-6-22 278528]
R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2010-2-3 175144]
R2 Sophos Message Router;Sophos Message Router;c:\program files\sophos\remote management system\RouterNT.exe [2010-6-22 802816]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 KAPFA;KAPFA;c:\windows\system32\drivers\KAPFA.sys [2010-6-22 17920]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c9bd037d4c1d48;Google Update Service (gupdate1c9bd037d4c1d48);c:\program files\google\update\GoogleUpdate.exe [2009-4-14 133104]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\logmein\x86\rainfo.sys --> c:\program files\logmein\x86\RaInfo.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-4-14 133104]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-3-29 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-3-29 8320]
S3 sdcfilter;sdcfilter;c:\windows\system32\drivers\sdcfilter.sys [2010-6-16 23928]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2010-6-16 14976]
.
=============== Created Last 30 ================
.
2011-09-13 11:02:33 -------- d-----w- c:\documents and settings\all users\application data\Fronius
2011-09-13 10:51:18 -------- d-----w- c:\documents and settings\colin\local settings\application data\FRONIUS_International_Gmb
2011-09-13 10:51:12 -------- d-----w- c:\documents and settings\all users\Fronius International
2011-09-13 09:47:00 -------- d-----w- c:\program files\common files\Fronius
2011-09-13 09:35:09 -------- d-----w- c:\documents and settings\colin\local settings\application data\Fronius Konfigurator
2011-09-13 09:34:38 -------- d-----w- c:\program files\Fronius Austria
.
==================== Find3M ====================
.
2011-07-16 06:41:31 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-07-16 06:41:31 53632 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll
2011-07-16 06:41:30 87424 ----a-w- c:\windows\system32\LMIinit.dll
2011-07-16 06:41:30 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-11-10 11:10:54 1105920 ------w- c:\program files\sg50Doctor.dll
2010-11-10 11:04:14 696320 ------w- c:\program files\sg50Nominal.dll
2010-10-07 14:49:06 1130496 ------w- c:\program files\sg50Bank.dll
2010-10-04 10:40:54 2232320 ------w- c:\program files\sg50Convert.dll
2010-10-04 10:22:28 958464 ------w- c:\program files\Sage.Integration.Accounts50.SDO.Adapter.GCRM.Feeds.dll
2010-10-04 10:15:02 5685248 ------w- c:\program files\sg50BusinessObjects.dll
2010-09-10 08:38:28 225280 ------w- c:\program files\sg50File.dll
2010-08-19 10:08:16 32768 ------w- c:\program files\Sage.Expressions.Line50.dll
2010-08-18 15:27:22 3346432 ------w- c:\program files\sg50Wizards.dll
2010-08-18 15:19:02 180224 ------w- c:\program files\sg50AccountantsLink.dll
2010-07-13 10:40:30 40984 ----a-w- c:\program files\SGScrnPop.exe
2010-07-13 10:40:28 323608 ----a-w- c:\program files\Sage.exe
2010-07-13 10:39:42 81920 ----a-w- c:\program files\ACCREP.DLL.Conversion.dll
2010-07-13 10:39:38 98304 ----a-w- c:\program files\Sage.Query.Engine.DataProvider.Line50.dll
2010-07-13 10:39:28 364544 ----a-w- c:\program files\sg50ProjectCosting.dll
2010-07-13 10:39:16 212992 ----a-w- c:\program files\sg50PurchaseOrders.dll
2010-07-13 10:37:44 479232 ----a-w- c:\program files\sg50Stock.dll
2010-07-13 10:37:32 118784 ----a-w- c:\program files\sg50Modal.dll
2010-07-13 10:37:24 57344 ----a-w- c:\program files\sg50Memorised.dll
2010-07-13 10:37:20 200704 ----a-w- c:\program files\sg50SalesOrders.dll
2010-07-13 10:37:10 98304 ----a-w- c:\program files\sg50User.dll
2010-07-13 10:36:52 110592 ----a-w- c:\program files\sg50Launcher.exe
2010-07-13 10:36:48 110592 ----a-w- c:\program files\sg50TaskLauncher2011.dll
2010-07-13 10:36:42 692224 ----a-w- c:\program files\sg50Invoicing.dll
2010-07-13 10:36:24 126976 ----a-w- c:\program files\sg50Intrastat.dll
2010-07-13 10:36:18 118784 ----a-w- c:\program files\sg50FixedAssets.dll
2010-07-13 10:31:38 4767744 ----a-w- c:\program files\sg50Application.dll
2010-07-13 10:30:24 610304 ----a-w- c:\program files\sg50Tasks.dll
2010-07-13 10:30:08 131072 ----a-w- c:\program files\sg50Departments.dll
2010-07-13 10:30:00 167936 ----a-w- c:\program files\sg50Budgets.dll
2010-07-13 10:29:48 512000 ----a-w- c:\program files\sg50Financials.dll
2010-07-13 10:29:22 270336 ----a-w- c:\program files\sg50End.dll
2010-07-13 10:29:08 217088 ----a-w- c:\program files\sg50ConfigEditor.dll
2010-07-13 10:28:58 151552 ----a-w- c:\program files\sg50Data.dll
2010-07-13 10:28:20 196608 ----a-w- c:\program files\sg50Import.dll
2010-07-13 10:28:12 86016 ----a-w- c:\program files\sg50EBankingRecordNotify.dll
2010-07-13 10:27:42 274432 ----a-w- c:\program files\sg50CashFlow.dll
2010-07-13 10:27:12 184320 ----a-w- c:\program files\sg50Assistance.dll
2010-07-13 10:27:04 397312 ----a-w- c:\program files\sg50Customers.dll
2010-07-13 10:26:52 356352 ----a-w- c:\program files\sg50PriceLists.dll
2010-07-13 10:26:36 24064 ----a-w- c:\program files\sg50MFCLibrary.dll
2010-07-13 10:26:32 573440 ----a-w- c:\program files\sg50Suppliers.dll
2010-07-13 10:26:16 233472 ----a-w- c:\program files\sg50Calendar.dll
2010-07-13 10:25:52 454656 ----a-w- c:\program files\sg50HMRCSubmission.dll
2010-07-13 10:25:28 200704 ----a-w- c:\program files\sg50AccountsReporting.dll
2010-07-13 10:25:28 200704 ----a-w- c:\program files\accrep32.dll
2010-07-13 10:25:12 712704 ----a-w- c:\program files\sg50Accounts.dll
2010-07-13 10:24:56 151552 ----a-w- c:\program files\sg50Addresses.dll
2010-07-13 10:24:50 184320 ----a-w- c:\program files\sg50RecurringInvoices.dll
2010-07-13 10:24:40 802816 ----a-w- c:\program files\sg50Dialog.dll
2010-07-13 10:24:10 135168 ----a-w- c:\program files\sg50CompanyLimit.dll
2010-07-13 10:24:06 184320 ----a-w- c:\program files\sg50Reporting.dll
2010-07-13 10:23:50 507904 ----a-w- c:\program files\sg50Filter.dll
2010-07-13 10:23:42 229376 ----a-w- c:\program files\sg50Sync.dll
2010-07-13 10:23:34 303104 ----a-w- c:\program files\sg50Outlook.dll
2010-07-13 10:23:26 565248 ----a-w- c:\program files\sg50Common.dll
2010-07-13 10:22:52 344064 ----a-w- c:\program files\sg50DEntry.dll
2010-07-13 10:22:38 126976 ----a-w- c:\program files\sg50Grid.dll
2010-07-13 10:22:34 696320 ----a-w- c:\program files\sg50Bitmaps.dll
2010-07-13 10:22:30 163840 ----a-w- c:\program files\sg50Controls.dll
2010-07-13 10:19:28 3174400 ----a-w- c:\program files\sg50DataObjects.dll
2010-07-13 10:19:10 10752 ----a-w- c:\program files\sg50Globvar.dll
2010-07-13 10:19:08 196608 ----a-w- c:\program files\sg50Excel.dll
2010-07-13 10:19:02 18944 ----a-w- c:\program files\sg50Network.dll
2010-07-13 10:19:00 339968 ----a-w- c:\program files\sg50DataFramework.dll
2010-07-13 10:18:42 253952 ----a-w- c:\program files\sg50Registration.dll
2010-07-13 10:18:20 151552 ----a-w- c:\program files\sg50Utils.dll
2010-07-13 10:18:00 335872 ----a-w- c:\program files\Sage.SBD.Utils.dll
2010-06-28 11:51:52 651264 ----a-w- c:\program files\Convertreports.exe
2008-08-19 15:34:38 1961984 ----a-w- c:\program files\Calendar1122vc80.dll
2007-04-23 13:46:12 90112 ----a-r- c:\program files\Sage.Accounts.InstallHelper.dll
2006-08-29 20:14:16 5556616 ----a-w- c:\program files\mdac_typ.exe
2006-05-12 17:02:02 118784 ----a-w- c:\program files\implodelib.dll
2005-01-20 14:58:44 36864 ----a-w- c:\program files\CrypKeys.exe
1999-07-13 14:26:50 70656 ----a-w- c:\program files\polspell.dll
.
============= FINISH: 12:06:03.80 ===============
Attached File(s)
-
attach.txt (17.19K)
Number of downloads: 2 -
ark.txt (133.72K)
Number of downloads: 2

Help
This topic is locked

Back to top













