slynk
Topic Starter
Hey there.
I haven't noticed a strange error which appears once on startup of my machine which only says..
RUNDLL ERROR
Error running C:/Documents
I assume there is more to the path but it does not show.
I have also notinced some occasional redirections to ads when im searching for something on google and click a link. I have AVG free which I update and scan regularly but have found nothing.
Any help would be much appreciated!
Here is the results of the DDS scan.
DDS.txt posted below and attach.txt attached as stated in the rules. Thank you guys in advance!
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 1:16:36.82 on Tue 22/06/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.3326.2388 [GMT 10:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Everything\Everything.exe
C:\WINDOWS\system32\DeltaIITray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\SteamWatch\SteamWatchTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\INTERN~2\mum.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Slynk\Application Data\regsdkrl32\regsdkrl29.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\SteamWatch\SteamWatch.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe
C:\WINDOWS\system32\mousenh32.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Program Files\Razer\Tarantula\razertra.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Slynk\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe"
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [SteamWatchTray] c:\program files\steamwatch\SteamWatchTray.exe
uRun: [InternodeUsage] c:\progra~1\intern~2\mum.exe
uRun: [Desktop Cleanup Wizard] rundll32.exe "c:\documents and settings\slynk\local settings\application data\desktop cleanup wizard\dskclean.dll", StartProt
uRun: [regsdkrl32] c:\documents and settings\slynk\application data\regsdkrl32\regsdkrl29.exe
mRun: [LClock] c:\program files\lclock\LClock.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [M-Audio Taskbar Icon] c:\windows\system32\DeltaIITray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Tarantula] c:\program files\razer\tarantula\razerhid.exe
mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Acronis Toolbar Helper] rundll32.exe c:\documents and settings\slynk\local settings\application data\desktop cleanup wizard\dskclean.dll, StartProt
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{af0fa6d7-96f3-468a-abb7-28be006ea8e9}\IcoUltraMon.ico
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\windows\system32\syspol32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\slynk\applic~1\mozilla\firefox\profiles\yug45wtd.default\
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 amdide1;amdide1;c:\windows\system32\drivers\amdide1.sys [2010-1-17 9096]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-6-21 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-6-21 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-6-21 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-21 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-21 308064]
R2 SteamWatch;SteamWatch;c:\program files\steamwatch\SteamWatch.exe [2010-6-21 18944]
R2 ToolTipFixer;ToolTipFixer;c:\program files\neosmart technologies\tooltipfixer\ToolTipFixer.exe [2008-10-15 61952]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2006-9-24 11776]
R2 winbackupdumper-id19T5e6l2szc-;Windows System Backup Dumper;c:\windows\system32\mousenh32.exe [2010-6-22 11776]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2010-6-21 22784]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\drivers\MAudioDelta.sys [2010-6-21 302472]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [2010-6-21 45440]
R3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\UltraMonMirror.sys [2006-9-24 3584]
S2 acrosysbackup_exT5e6l2szc-;Acronis System Backup;c:\windows\system32\wirepots.exe [2010-6-22 8704]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-6-21 1684736]
=============== Created Last 30 ================
2010-06-21 14:51:27 0 d—–w- c:\docume~1\slynk\applic~1\Waves Audio
2010-06-21 14:50:06 0 d—–w- c:\program files\Waves
2010-06-21 14:48:59 0 d—–w- c:\program files\Image-Line
2010-06-21 14:47:51 2 —-a-w- c:\documents and settings\slynk\tenmy.ini
2010-06-21 14:47:51 0 d—–w- c:\docume~1\slynk\applic~1\regsdkrl32
2010-06-21 14:47:46 38912 —-a-w- c:\windows\system32\b_syspol32.dll
2010-06-21 14:47:46 140288 —-a-w- c:\windows\system32\pcre3.dll
2010-06-21 14:47:45 8704 —-a-w- c:\windows\system32\wirepots.exe
2010-06-21 14:47:45 717671 —-a-w- c:\documents and settings\slynk\regsdkrl29.exe
2010-06-21 14:47:45 38912 —-a-w- c:\windows\system32\wirepots.dll
2010-06-21 14:47:45 38912 —-a-w- c:\windows\system32\syspol32.dll
2010-06-21 14:47:45 11776 —-a-w- c:\windows\system32\mousenh32.exe
2010-06-21 14:47:27 86016 —-a-w- c:\windows\unvise32.exe
2010-06-21 14:47:09 0 d—–w- c:\program files\GForce
2010-06-21 14:33:33 0 d—–w- C:\VST
2010-06-21 14:30:32 0 d—–w- c:\program files\Spectrasonics
2010-06-21 14:29:44 0 d–h–w- C:\$AVG
2010-06-21 14:23:53 0 d—–w- c:\docume~1\slynk\applic~1\Ableton
2010-06-21 14:23:43 368640 —-a-w- c:\windows\system32\ReWire.dll
2010-06-21 14:23:43 233472 —-a-w- c:\windows\system32\REX Shared Library.dll
2010-06-21 14:23:32 0 d—–w- c:\program files\Ableton
2010-06-21 04:46:51 0 d—–w- c:\program files\common files\ODBC
2010-06-21 04:46:48 0 d—–w- c:\program files\common files\SpeechEngines
2010-06-21 04:46:25 0 d—–r- c:\documents and settings\all users\Documents
2010-06-20 22:22:56 0 d—–w- c:\docume~1\slynk\applic~1\Internode
2010-06-20 22:22:36 0 d—–w- c:\program files\Internode
2010-06-20 22:15:52 0 d—–w- c:\program files\SteamWatch
2010-06-20 22:14:56 0 d—–w- c:\program files\Steam
2010-06-20 21:09:22 0 d—–w- c:\docume~1\slynk\applic~1\Office Genuine Advantage
2010-06-20 20:40:28 0 d—–w- c:\docume~1\alluse~1\applic~1\avg9
2010-06-20 20:19:23 0 d—–w- c:\docume~1\slynk\applic~1\Realtime Soft
2010-06-20 20:19:18 0 d—–w- c:\program files\UltraMon
2010-06-20 20:19:18 0 d—–w- c:\program files\common files\Realtime Soft
2010-06-20 20:19:18 0 d—–w- c:\docume~1\alluse~1\applic~1\Realtime Soft
2010-06-20 19:43:05 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro
2010-06-20 19:42:41 0 d—–w- c:\docume~1\slynk\applic~1\DAEMON Tools Pro
2010-06-20 19:41:47 0 d—–w- c:\program files\DAEMON Tools Pro
2010-06-20 19:37:36 0 d—–w- c:\program files\AVG
2010-06-20 19:28:36 0 d—–w- c:\program files\M-Audio
2010-06-20 19:17:21 0 d—–w- c:\program files\ATI Technologies
2010-06-20 19:17:19 0 d—–w- c:\program files\ATI
2010-06-20 19:16:10 0 d—–w- c:\program files\Everything
2010-06-20 19:13:08 0 d—–w- c:\program files\AMD
2010-06-20 19:10:33 0 d—–w- c:\program files\Realtek
2010-06-20 18:58:37 0 d—–w- c:\program files\VideoLAN
2010-06-20 18:58:26 0 d—–w- c:\program files\NeoSmart Technologies
2010-06-20 18:56:28 0 d-sh–w- c:\documents and settings\all users\DRM
2010-06-20 18:56:16 0 d–h–w- c:\program files\WindowsUpdate
2010-06-20 18:56:13 0 d—–w- c:\program files\Online Services
2010-06-20 18:56:06 0 d—–w- c:\program files\Windows Media Connect 2
2010-06-20 18:55:37 0 d—–w- c:\program files\common files\MSSoap
2010-06-20 18:53:56 0 d—–w- c:\program files\LClock
2010-06-20 18:53:52 0 d—–w- c:\program files\MSN Gaming Zone
2010-06-20 18:53:33 0 d—–w- c:\program files\Windows NT
==================== Find3M ====================
2010-06-20 23:32:33 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-20 20:42:25 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-06-20 20:42:19 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-20 19:40:27 685816 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-20 19:35:45 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-20 18:54:32 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-06 10:36:27 919040 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 02:04:16 1860352 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30:08 285696 —-a-w- c:\windows\system32\atmfd.dll
============= FINISH: 1:16:48.65 ===============