ladyixnay
Topic Starter
Have been having problems mostly with being slow, boot up is slow and doing anything else also slowed down. Avast found a trojan 2 days ago and we had it delete it, but I have a feeling it probably left behind some bad things lol Scan follows, and thank you.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 15:19:22 on 2011-08-30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.521 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://amyost.homestead.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft
shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program
files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -
hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233743462062
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.137.1
TCP: Interfaces\{D180834B-5532-4BE3-B57F-F1D96D89A84B} : DhcpNameServer = 192.168.137.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program
files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\dad\application data\mozilla\firefox\profiles\3zqtl4ny.default\
FF - prefs.js: browser.startup.homepage - hxxp://amyost.homestead.com/
FF - plugin: c:\documents and settings\dad\local settings\application
data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: d:\bryan\itunes\mozilla plugins\npitunes.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-13 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-11-26 309848]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-11-26 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-26 42184]
R2 LANPkt;Realtek LANPkt Protocol;c:\windows\system32\drivers\LANPkt.sys [2003-9-17 8440]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia
updatus\daemonu.exe [2011-7-17 2214504]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-3 136176]
S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [2003-8-15 11237]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-3 136176]
S3 jfdcd;jfdcd;\??\c:\docume~1\dad\locals~1\temp\jfdcd.sys –> c:\docume~1\dad\locals~1\temp\jfdcd.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys –>
c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
S3 samhid;samhid;c:\windows\system32\drivers\samhid.sys –> c:\windows\system32\drivers\samhid.sys [?]
S3 XDva226;XDva226;\??\c:\windows\system32\xdva226.sys –> c:\windows\system32\XDva226.sys [?]
.
=============== Created Last 30 ================
.
2011-08-28 06:04:58 2106216 -c–a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll
2011-08-28 06:04:55 1998168 -c–a-w- c:\program files\mozilla firefox\d3dx9_43.dll
2011-08-10 15:24:29 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
.
==================== Find3M ====================
.
2011-08-11 01:23:29 404640 -c–a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-18 19:29:54 273344 —-a-w- c:\windows\system32\nvdrsdb1.bin
2011-07-18 19:29:54 1 —-a-w- c:\windows\system32\nvdrssel.bin
2011-07-18 19:25:12 273344 -c–a-w- c:\windows\system32\nvdrsdb0.bin
2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 -c–a-w- c:\windows\system32\drivers\mbam.sys
2011-07-04 11:43:53 40112 —-a-w- c:\windows\avastSS.scr
2011-07-04 11:36:43 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-06-24 14:10:36 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36:30 43520 -c–a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36:30 1469440 -c–a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05:13 385024 -c–a-w- c:\windows\system32\html.iec
2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 15:21:00.56 ===============