moodyblu67
Topic Starter
This PC is going off my 18th floor balcony soon if I don't get it back to normal! No viruses, etc., come up in security program's results, so I have no idea what's going on.
It's experiencing far too many crashes, and when it's not crashing, it's either freezing (alot) or running like carp**. Below is my DDS text results and I've attached the "Attach ZIP file" as it said to do on your "Are you infected" page. I hope I done it properly for you guys. Please advise if you get a chance. Thanx so much, Victoria
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 16:58:31.76 on Tue 06/15/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.107 [GMT -4:00]
AV: Rogers Online Protection Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: Rogers Online Protection Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
============== Running Processes ===============
C:\WINDOWS\NEWEST\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\NEWEST\System32\svchost.exe -k netsvcs
C:\WINDOWS\NEWEST\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exe
svchost.exe
C:\WINDOWS\NEWEST\system32\spoolsv.exe
C:\WINDOWS\NEWEST\Explorer.EXE
C:\WINDOWS\NEWEST\System32\svchost.exe -k HTTPFilter
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\NEWEST\system32\svchost.exe -k imgsvc
C:\WINDOWS\NEWEST\System32\vssvc.exe
C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Bin\SanaAgent.exe
C:\WINDOWS\NEWEST\system32\LVComsX.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Bin\SanaMonitor.exe
C:\Program Files\Rogers Online Protection\Rogers Online Protection\RPS.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe
C:\Program Files\Rogers Online Protection\Rogers Online Protection\PrtlAgt.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Documents and Settings\Vicky\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://facebook.com/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://ieaddons.com/en/students
uSearch Bar = hxxp://www.google.com/ie
uWindow Title = DONT HOG THE COMPUTER
mDefault_Page_URL = hxxp://rogers.yahoo.com
mDefault_Search_URL = hxxp://ca.red.clientapps.yahoo.com/customize/rogers/defaults/su/*http://www.yahoo.com
mSearch Page = hxxp://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sp/*http://www.yahoo.com
mStart Page = hxxp://rogers.yahoo.com
mWindow Title = DONT HOG THE COMPUTER
mSearch Bar = hxxp://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sb/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyOverride = localhost;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Download Guard for Internet Explorer: {20c1a7f0-528e-444f-bac5-5804a61cca7f} - c:\program files\lavasoft\download guard for internet explorer\DownloadGuardBHO.dll
BHO: PopKill Class: {3c060ea2-e6a9-4e49-a530-d4657b8c449a} - c:\program files\rogers online protection\rogers online protection\pkR.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
EB: {D86FA331-DF95-46C8-8978-4C00D084C9A1} - No File
EB: {E360B15E-21A7-4FAB-944E-9DC4F092818E} - No File
uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m
uRunOnce: [IndexCleaner] "c:\program files\rogers online protection\rogers online protection\IdxClnR.exe"
mRun: [Rogers SHS] c:\program files\rogers\selfhealing\shs.exe
mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\newest\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
mRunOnce: [IndexCleaner] "c:\program files\rogers online protection\rogers online protection\IdxClnR.exe"
uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
IE: Add to Google Photos Screensa&ver - c:\windows\newest\system32\GPhotos.scr/200
IE: Save Page As PDF …
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\newest\system32\WPDShServiceObj.dll
SEH: WinFax PRO IShellExecuteHook: {a213b520-c6c2-11d0-af9d-008029e1027e} - c:\program files\symantec\winfax\WfxSeh32.Dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\vicky\applic~1\mozilla\firefox\profiles\u5d487yl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://familywatchdog.us/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll
FF - plugin: c:\documents and settings\vicky\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\vicky\application data\mozilla\firefox\profiles\u5d487yl.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\progra~1\meadco~1\npmeadax.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\newest\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\newest\system32\drivers\Lbd.sys [2010-4-17 64288]
R1 KLIF;KLIF;c:\windows\newest\system32\drivers\klif.sys [2010-4-17 179984]
R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\rogers online protection\rogers online protection\safeconnect\driver\platform_xp\SafeConnectDriver.sys [2008-11-14 161304]
R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\rogers online protection\rogers online protection\safeconnect\driver\platform_xp\SafeConnectFilter.sys [2008-11-14 29720]
R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\rogers online protection\rogers online protection\safeconnect\driver\platform_xp\SafeConnectShim.sys [2008-11-14 27376]
S2 gupdate1ca640167659b5c;Google Update Service (gupdate1ca640167659b5c);c:\program files\google\update\GoogleUpdate.exe [2009-11-12 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1285864]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\newest\system32\drivers\npf.sys [2005-8-2 32512]
S3 TMPassthruMP;TMPassthruMP;c:\windows\newest\system32\drivers\tmpassthru.sys –> c:\windows\newest\system32\drivers\TMPassthru.sys [?]
=============== Created Last 30 ================
2010-06-15 17:32:36 10 —-a-w- c:\windows\newest\WININIT.INI
2010-06-15 17:03:57 73728 —-a-w- c:\windows\newest\system32\javacpl.cpl
2010-06-15 17:03:57 411368 —-a-w- c:\windows\newest\system32\deployJava1.dll
2010-06-15 16:34:57 0 d—–w- c:\windows\newest\system32\drivers\NSS
2010-06-15 16:34:57 0 d—–w- c:\program files\Norton Security Scan
2010-06-15 16:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\Symantec
2010-06-15 16:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\Norton
2010-06-15 16:34:52 0 d—–w- c:\program files\NortonInstaller
2010-06-15 16:34:52 0 d—–w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-06-15 15:59:30 0 d—–w- c:\program files\Bonjour
2010-06-11 06:00:46 743424 -c—-w- c:\windows\newest\system32\dllcache\iedvtool.dll
2010-06-08 00:25:26 5632 —-a-w- c:\windows\newest\system32\ptpusb.dll
2010-06-08 00:25:21 15104 -c–a-w- c:\windows\newest\system32\dllcache\usbscan.sys
2010-06-08 00:25:21 15104 —-a-w- c:\windows\newest\system32\drivers\usbscan.sys
2010-06-08 00:25:14 159232 —-a-w- c:\windows\newest\system32\ptpusd.dll
2010-05-31 10:54:04 0 d—–w- c:\docume~1\vicky\applic~1\com.adobe.px.Uploader.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1
2010-05-31 10:53:34 0 d—–w- c:\program files\Adobe Photoshop.com Uploader
2010-05-31 03:10:11 0 d—–w- c:\program files\Speccy
2010-05-31 03:10:02 0 d—–w- c:\program files\Defraggler
2010-05-29 23:47:36 161296 —-a-w- c:\windows\newest\system32\drivers\tmcomm.sys
==================== Find3M ====================
2010-06-15 20:58:27 24541472 –sha-w- c:\windows\newest\system32\drivers\fidbox.dat
2010-06-11 23:44:59 52124 –sha-w- c:\windows\newest\system32\drivers\fidbox2.idx
2010-06-11 23:44:58 679456 –sha-w- c:\windows\newest\system32\drivers\fidbox2.dat
2010-06-11 23:44:58 291644 –sha-w- c:\windows\newest\system32\drivers\fidbox.idx
2010-05-10 06:08:41 95024 —-a-w- c:\windows\newest\system32\drivers\SBREDrv.sys
2010-05-10 06:08:35 15880 —-a-w- c:\windows\newest\system32\lsdelete.exe
2010-05-06 10:41:53 916480 —-a-w- c:\windows\newest\system32\wininet.dll
2010-05-02 05:22:50 1851264 —-a-w- c:\windows\newest\system32\win32k.sys
2010-04-29 18:47:18 3600384 -c–a-w- c:\windows\newest\system32\GPhotos.scr
2010-04-20 19:13:06 3168 -c–a-w- c:\docume~1\vicky\applic~1\wklnhst.dat
2010-04-20 05:30:08 285696 —-a-w- c:\windows\newest\system32\atmfd.dll
2010-04-08 17:20:02 91424 —-a-w- c:\windows\newest\system32\dnssd.dll
2010-04-08 17:20:02 107808 —-a-w- c:\windows\newest\system32\dns-sd.exe
2009-12-13 16:51:28 2147 -c–a-w- c:\program files\INSTALL.LOG
2009-08-31 17:22:26 32768 -csha-w- c:\windows\newest\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082420090831\index.dat
2009-08-31 17:22:26 32768 -csha-w- c:\windows\newest\system32\config\systemprofile\local settings\history\history.ie5\mshist012009083120090901\index.dat
============= FINISH: 17:03:17.73 ===============