Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

DDS/attach/ark

$
0
0
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702
Run by Owner at 12:18:42 on 2012-12-19
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.894.376 [GMT -6:00]
.
AV: BullGuard Antivirus *Enabled/Updated* {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913}
FW: BullGuard Firewall *Disabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardScanner.exe
C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\SvcHost.exe -k BullGuard_Main
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\SvcHost.exe -k BullGuard_Backup
C:\WINDOWS\System32\SvcHost.exe -k BullGuard
C:\WINDOWS\System32\SvcHost.exe -k BullGuard_Proxy
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
mSearchAssistant = hxxp://www.google.com/ie
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [CHotkey] zHotkey.exe
mRun: [ShowWnd] ShowWnd.exe
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [BullGuard] "c:\program files\bullguard ltd\bullguard\BullGuard.exe" -boot
StartupFolder: c:\documents and settings\owner\start menu\programs\startup\CurseClientStartup.ccip
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - c:\program files\bullguard ltd\bullguard\antiphishing\ie\BGAntiphishingIE.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: c:\windows\system32\BGLsp.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1344927058023
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{6C20FB66-5137-46DA-954C-7EBC63C1B194} : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
.
============= SERVICES / DRIVERS ===============
.
R1 BdSpy;BdSpy;c:\windows\system32\drivers\BdSpy.sys [2012-7-3 64608]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\drivers\NSKernel.sys [2012-7-3 789960]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\drivers\NSNetmon.sys [2012-7-3 19272]
R2 BsBackup;BullGuard backup service;c:\windows\system32\SvcHost.exe -k BullGuard_Backup [2005-4-13 14336]
R2 BsBhvScan;BullGuard behavioural detection service;c:\program files\bullguard ltd\bullguard\BullGuardBhvScanner.exe [2012-8-20 321376]
R2 BsFileScan;BullGuard on-access service;c:\windows\system32\SvcHost.exe -k BullGuard [2005-4-13 14336]
R2 BsFire;BullGuard firewall service;c:\windows\system32\SvcHost.exe -k BullGuard [2005-4-13 14336]
R2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\system32\SvcHost.exe -k BullGuard_Proxy [2005-4-13 14336]
R2 BsMain;BullGuard main service;c:\windows\system32\SvcHost.exe -k BullGuard_Main [2005-4-13 14336]
R2 BsScanner;BullGuard scanning service;c:\program files\bullguard ltd\bullguard\BullGuardScanner.exe [2012-8-20 178528]
R2 BsUpdate;BullGuard update service;c:\program files\bullguard ltd\bullguard\BullGuardUpdate.exe [2012-8-20 304480]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [2012-7-3 32512]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2012-7-3 284928]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-11-9 160944]
.
=============== Created Last 30 ================
.
2012-12-19 17:07:25 -------- d-----w- c:\documents and settings\owner\application data\FportPackages
2012-12-19 16:48:23 -------- d-----w- c:\program files\OI App Manager
2012-12-19 16:47:32 -------- d-----w- c:\documents and settings\owner\local settings\application data\Wajam
2012-12-19 16:41:46 -------- d-----w- c:\program files\CCleaner
2012-12-19 03:41:44 -------- d-----w- c:\documents and settings\owner\application data\BullGuard
2012-12-19 03:39:11 -------- d-----w- c:\documents and settings\all users\application data\BullGuard
2012-12-19 03:38:51 -------- d-----w- c:\program files\common files\BullGuard Ltd
2012-12-19 03:38:41 -------- d-----w- c:\program files\BullGuard Ltd
2012-12-19 02:55:12 -------- d-----w- c:\windows\pss
2012-11-27 08:58:13 -------- d-----r- c:\program files\Skype
2012-11-27 08:39:30 -------- d-----w- c:\documents and settings\owner\local settings\application data\ATI
2012-11-27 08:38:57 0 ----a-w- c:\windows\ativpsrm.bin
2012-11-27 08:37:19 -------- d-----w- c:\documents and settings\owner\local settings\application data\realtech_VR
2012-11-27 08:32:09 593920 ------w- c:\windows\system32\ati2sgag.exe
2012-11-27 08:28:38 -------- d--h--w- c:\windows\msdownld.tmp
2012-11-27 08:18:45 -------- d-----w- C:\ATI
2012-11-27 08:11:42 -------- d-----w- c:\documents and settings\all users\application data\realtech VR
2012-11-27 08:09:18 -------- d-----w- c:\program files\realtech VR
2012-11-27 06:20:01 -------- d-----w- c:\documents and settings\owner\application data\PriceGong
2012-11-27 06:19:54 -------- d-----w- c:\program files\Conduit
2012-11-27 06:19:51 -------- d-----w- c:\documents and settings\owner\local settings\application data\Conduit
2012-11-27 06:19:43 -------- d-----w- c:\documents and settings\owner\local settings\application data\Temp
2012-11-27 06:09:50 -------- d-----w- c:\documents and settings\owner\local settings\application data\SCE
2012-11-27 06:09:50 -------- d-----w- C:\Crash
2012-11-27 06:09:49 -------- d-----w- c:\documents and settings\owner\application data\Sony Online Entertainment
2012-11-27 06:07:44 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
.
==================== Find3M ====================
.
2012-12-12 10:51:10 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-12 10:51:09 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-24 20:01:49 74703 ----a-w- c:\windows\system32\mfc45.dat
2012-09-24 21:32:24 477168 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-09-24 21:32:20 473072 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-24 19:51:47 73728 ----a-w- c:\windows\system32\javacpl.cpl
.
============= FINISH: 12:19:25.39 ===============

I am noticing severe latency with my web browsing, and my gameplay (World of Warcraft) is slow. I had a friend tell me to download leatrix, and this initially solved some of my World of Warcraft latency, but it since has returned. I think my I.E. 8 is bugged, and is causing the root of my problems, perhaps, from websites while my avp wasn't active. I currently have BullGuard three months free activated, however, a resent scan showed no malicious activity. Lastly, when I go to 'Start,' my I.E. icon is a white page, and not the blue 'e.' My friend said I was hijacked so I researched that, and attempted to download fport. Mcafee, and brosoft, I think was the name, didn't seem to active after I open/downloaded.
The computer I'm using is an Emachines desktop. The name is Windows XP Media Center Edition 2005.
I hope this has provided you with enough information to make corrections to my computer. I also did try to reset my I.E browser.

Attached Files
File Type: zip attach.zip (4.0 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles