
here with Highjackthis logs. OK , so I have now & I hope someone can help me on this because it's driving me nuts
with my Windows XP with SP3.

My previous post & Highjackthis log can be found here
http://www.bleepingcomputer.com/forums/ind...p;#entry1237143

***************************************************************************
Under Device Manager / Sound, Video and game controllers
-------------------------------------------------------------------------------------------------------
Under Audio Codecs
When I right-click properties , I get only 3 options
Disable & Uninstal Options do not show.
Update Driver : When I try this option it says can not find a better driver than what I have.
Scan for hardware change : Nothing happens with this option.
Properties :
On General tab it says
Audio Codecs
Device Type : Sound,Video and game controllers
Maufacturer : (Standard System Devices)
Location : Unknown
This devise is working properly
Devise usage is blank & I can not access it.
----------------------------------------------------------------------------------
Legacy Audio Drivers
same problem
----------------------------------------------------------------------------------
Legacy Video Capture Devices
same problem
---------------------------------------------------------------------------------
Media Control Devices
same problem
--------------------------------------------------------------------------------
Video Codecs
same problem
-------------------------------------------------------------------------
The only one that is working fine is Realtek High Definition Audio
Location
65535 (Internal High Definition Audio)
************************************************************************
I tried also unistalling & re-installing Realtek High Definition Audio from the Control Panel but I have the same
problem.
********************************************************************

DDS (Ver_09-03-16.01) - NTFSx86
Run by Owner at 15:36:01.21 on Fri 04/24/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.895.307 [GMT -7:00]
AV: StopSign Antivirus *On-access scanning enabled* (Updated)
FW: StopSign Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\eAcceleration\OnAccess\onaccess.exe
C:\PROGRA~1\StopSign\POPUPB~1\sspopupblockerctrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\eAcceleration\Firewall\FWService.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T6426
mWinlogon: Userinit=c:\windows\system32\Userinit.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: {b753c7c5-0942-4b7f-bc27-942b52bdac66} - c:\progra~1\stopsign\popupb~1\sspopupblocker.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Uniblue SpyEraser] "c:\program files\uniblue\spyeraser\SpyEraser.exe" -m
uRunOnce: [ Privacy Eraser Pro] c:\program files\privacyeraser computing\privacy eraser pro\PrivacyEraser.exe /ErIEIndex
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [readericon] c:\program files\digital media reader\readericon45G.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
mRun: [SoftwareStation] "c:\program files\eacceleration\station\station.exe" /b Startup
mRun: [webscan] "c:\program files\acceleration software\anti-virus\stopsignav.exe" -k
mRun: [OnAccess] "c:\program files\eacceleration\onaccess\onaccess.exe" -erk
mRun: [StopSignPopupBlocker] c:\progra~1\stopsign\popupb~1\sspopupblockerctrl.exe /Startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRunOnce: [ Privacy Eraser Pro] c:\program files\privacyeraser computing\privacy eraser pro\PrivacyEraser.exe /ErIEIndex
dRun: [Power2GoExpress] NA
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {24BE56F9-F0B6-4ac7-97F1-8CACEDA9A427} - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - c:\progra~1\stopsign\popupb~1\sspopupblocker.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: google.com\www
Trusted Zone: metacafe.com\www
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\www
Trusted Zone: yahoo.com\www
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: ExecuteMonitorShellHook Class: {42dd0873-5fa9-465d-90de-0826020416a5} - c:\program files\eacceleration\onaccess\onaccess_hk32.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
============= SERVICES / DRIVERS ===============
R0 fwcore;Fwcore Filter;c:\windows\system32\drivers\fwcore.sys [2009-4-23 109536]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944]
R2 eac_notifysvc;eAcceleration Notification Service;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2009-4-23 111952]
R2 eac_productsvc;eAcceleration Product Manager Service;c:\progra~1\eaccel~1\framew~1\eac_productsvc.exe [2009-4-23 263504]
R2 FWService;FWService;c:\program files\eacceleration\firewall\fwservice.exe -service --> c:\program files\eacceleration\firewall\FWService.exe -Service [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-23 210216]
R2 ssfwmonsvc;StopSign Firewall Security Center Provider;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2009-4-23 111952]
R2 sstsmonsvc;StopSign Antivirus Security Center Provider;c:\progra~1\eaccel~1\framew~1\eac_svc.exe [2009-4-23 111952]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-4-23 38496]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\ambfilt.sys --> c:\windows\system32\drivers\Ambfilt.sys [?]
=============== Created Last 30 ================
2009-04-24 11:10
2009-04-24 10:55
2009-04-24 10:55 201,050 a------- c:\windows\system32\nvapps.nvb
2009-04-24 10:53
2009-04-24 10:53
2009-04-24 10:52 192,000 -c------ c:\windows\system32\dllcache\offfilt.dll
2009-04-24 10:52 98,304 -c------ c:\windows\system32\dllcache\nlhtml.dll
2009-04-24 10:52 29,696 -c------ c:\windows\system32\dllcache\mimefilt.dll
2009-04-24 10:52
2009-04-24 10:51
2009-04-24 10:50
2009-04-24 09:40
2009-04-23 21:44 410,984 a------- c:\windows\system32\deploytk.dll
2009-04-23 21:44 73,728 a------- c:\windows\system32\javacpl.cpl
2009-04-23 21:40
2009-04-23 21:33
2009-04-23 21:12
2009-04-23 21:11
2009-04-23 21:11
2009-04-23 21:11
2009-04-23 20:21
2009-04-23 20:21 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-23 20:21 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-23 20:21
2009-04-23 20:21
2009-04-23 19:19 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-04-23 19:06
2009-04-23 19:06 20,232 a------- c:\windows\system32\AntiSpyNative64.exe
2009-04-23 19:06 16,648 a------- c:\windows\system32\AntiSpyNative32.exe
2009-04-23 18:57
2009-04-23 18:47 36,352 a------- c:\windows\system32\RtkCoInstXP.dll
2009-04-23 16:18
2009-04-23 16:18
2009-04-23 16:18
2009-04-23 16:18
2009-04-23 16:14
2009-04-23 16:11
2009-04-23 16:10
2009-04-23 16:10
2009-04-23 16:07
2009-04-23 16:03 14,820,864 a------- c:\windows\SET41A.tmp
2009-04-23 15:55 7,680 a------- c:\windows\system32\spdwnwxp.exe
2009-04-23 15:54 650,752 -------- c:\windows\system32\dot3ui.dll
2009-04-23 15:20
2009-04-23 15:19 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-04-23 15:19 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-23 15:19 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-23 15:19 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-23 15:19
2009-04-23 15:19 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-04-23 15:19 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-04-23 15:19 117,760 -------- c:\windows\system32\prntvpt.dll
2009-04-23 15:17
2009-04-23 13:08
2009-04-23 12:13 109,536 a------- c:\windows\system32\drivers\fwcore.sys
2009-04-23 12:13
2009-04-23 12:12
2009-04-23 12:12
2009-04-23 12:12
2009-04-23 12:12
2009-04-23 12:01 2 a------- c:\windows\msoffice.ini
2009-04-23 11:57
2009-04-23 11:50
2009-04-23 11:35 146,650 a------- c:\windows\system32\BuzzingBee.wav
2009-04-23 11:35 940,794 a------- c:\windows\system32\LoopyMusic.wav
2009-04-23 11:35
2009-04-23 10:45 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-04-23 10:45 272,128 -------- c:\windows\system32\drivers\bthport.sys
2009-04-23 10:41 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-23 10:41 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-23 10:40
2009-04-23 10:38 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2009-04-23 10:38 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-04-23 10:37 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-04-23 10:37 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-04-23 10:36 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-04-23 10:36
2009-04-23 10:34 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-04-23 10:34 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-23 10:33
2009-04-23 10:27
2009-04-23 10:23
2009-04-23 10:21 2,752 a------- c:\windows\system32\Status.MPF
2009-04-23 10:19
2009-04-23 10:08
2009-04-23 10:07
2009-04-23 10:07
2009-04-23 10:06
2009-04-23 10:06 221,184 a------- c:\windows\system32\wmpns.dll
2009-04-23 10:06
2009-04-23 10:06 67,072 a------- c:\windows\POWERCFG.EXE
2009-04-23 10:05
2009-04-23 10:04
2009-04-23 10:04
2009-04-23 10:04
2009-04-23 10:04
2009-04-23 10:04
2009-04-23 10:03 1,115 a---h--- C:\IPH.PH
2009-04-23 10:03
2009-04-23 10:03 10,280 a------- c:\windows\BigFixClientOverride.dll
2009-04-23 10:03
2009-04-23 10:03
2009-04-23 10:02
2009-04-23 10:02
2009-04-23 10:02 89,088 a------- c:\windows\system32\atl71.dll
2009-04-23 10:02 6,272 a------- c:\windows\system32\drivers\splitter.sys
2009-04-23 10:02 83,072 a------- c:\windows\system32\drivers\wdmaud.sys
2009-04-23 10:02 52,864 a------- c:\windows\system32\drivers\dmusic.sys
2009-04-23 10:02 142,592 a------- c:\windows\system32\drivers\aec.sys
2009-04-23 10:02 56,576 a------- c:\windows\system32\drivers\swmidi.sys
2009-04-23 10:02 172,416 a------- c:\windows\system32\drivers\kmixer.sys
2009-04-23 10:02 2,944 a------- c:\windows\system32\drivers\drmkaud.sys
2009-04-23 10:02 60,800 a------- c:\windows\system32\drivers\sysaudio.sys
2009-04-23 10:02 7,552 a------- c:\windows\system32\drivers\mskssrv.sys
2009-04-23 10:02 4,992 a------- c:\windows\system32\drivers\mspqm.sys
2009-04-23 10:02 5,376 a------- c:\windows\system32\drivers\mspclock.sys
2009-04-23 10:01 4,096 ac------ c:\windows\system32\dllcache\ksuser.dll
2009-04-23 10:01 4,096 a------- c:\windows\system32\ksuser.dll
2009-04-23 10:01 129,536 ac------ c:\windows\system32\dllcache\ksproxy.ax
2009-04-23 10:01 60,160 ac------ c:\windows\system32\dllcache\drmk.sys
2009-04-23 10:01 129,536 a------- c:\windows\system32\ksproxy.ax
2009-04-23 10:01 60,160 a------- c:\windows\system32\drivers\drmk.sys
2009-04-23 10:01 26,488 a------- c:\windows\system32\spupdsvc.exe
2009-04-23 10:01 192,954 a------- c:\windows\system32\nvapps.xml
2009-04-23 10:00 453,152 a------- c:\windows\system32\nvudisp.exe
2009-04-23 10:00 18,394 a------- c:\windows\system32\nvdisp.nvu
2009-04-23 10:00
2009-04-23 10:00 4 a------- c:\windows\Pix11.dat
2009-04-23 10:00
2009-04-23 10:00 20,480 a------- c:\windows\system32\Marker32.exe
2009-04-23 09:59 2,238 a------- c:\windows\system32\32-aol.ico
2009-04-23 09:59 1,406 a------- c:\windows\system32\16-aol.ico
2009-04-23 09:57 471,300 a------- c:\windows\wallpe.exe
2009-04-23 09:57 94,208 a------- c:\windows\system32\bae.dll
2009-04-23 09:57 30,056 a------- c:\windows\system32\oemlogo.bmp
2009-04-23 09:56
2009-04-23 09:56
2009-04-23 09:56 2 a------- C:\AUDIT_INSTALL_IN_PROGRESS
2009-04-23 09:54 376 a------- c:\windows\ODBC.INI
2009-04-23 09:54 17,920 a------- c:\windows\system32\mdimon.dll
2009-04-23 09:54
2009-04-23 09:54
2009-04-23 09:50 176,128 a------- c:\windows\system32\nvunrm.exe
2009-04-23 09:50 100,480 a------- c:\windows\system32\drivers\nvtcp.sys
2009-04-23 09:50 3,632 a------- c:\windows\system32\nvnrm.nvu
2009-04-23 09:50 176,128 a------- c:\windows\system32\nvusmb.exe
2009-04-23 09:50 1,391 a------- c:\windows\system32\nvsmb.nvu
2009-04-23 09:50
2009-04-23 09:50 453,152 a------- c:\windows\system32\NVUNINST.EXE
2009-04-23 09:48
2009-04-23 09:48
2009-04-23 09:46 0 a------- C:\REQUEST_OEMRESET_ENDUSER
2009-04-23 09:45 17,152 a------- c:\windows\system32\drivers\usbohci.sys
2009-04-23 09:45 30,208 a------- c:\windows\system32\drivers\usbehci.sys
2009-04-23 09:45 7,168 a------- c:\windows\system32\hccoin.dll
2009-04-23 09:41
2009-04-23 09:40 1,204,128 a------- c:\windows\system32\drivers\AGRSM.sys
2009-04-23 09:40 55,816 a------- c:\windows\agrsmdel.exe
2009-04-23 09:40
2009-04-23 09:40
2009-04-23 09:38 77,890 a------- c:\windows\system32\usrdpa.dll
2009-04-23 09:37 25,600 a------- c:\windows\system32\drivers\usbcamd.sys
2009-04-23 09:36 47,104 a------- c:\windows\system32\cnbjmon.dll
==================== Find3M ====================
2009-04-23 16:22 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-23 10:04 8,552 a------- c:\windows\system32\drivers\asctrm.sys
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 17:18 826,368 a------- c:\windows\system32\wininet.dll
2009-02-20 11:09 78,336 a------- c:\windows\system32\ieencode.dll
2009-02-09 05:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 05:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 05:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 05:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 04:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-07 19:02 2,066,048 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-06 04:11 110,592 a------- c:\windows\system32\services.exe
2009-02-06 04:08 2,189,056 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 03:39 35,328 a------- c:\windows\system32\sc.exe
2009-02-03 12:59 56,832 a------- c:\windows\system32\secur32.dll
============= FINISH: 15:37:26.93 ===============
I think my computer is infected .
I also uploaded my Atach file.

Attached Files
Edited by koolkat, 24 April 2009 - 11:59 PM.