alturtle
2011-06-10, 22:09
I dropped the ball when posting this before, got some input from you, then was away from my computer.
http://forums.spybot.info/showthread.php?t=62803
Problem occurs on one of my four computers. Spybot works find on the others.
Having been away, I reran everything today. Erunt ran fine. DDS ran in Safe Mode only.
DDS.Txt is below. Attach.txt is zipped and attached.
******************************************************************************
.
DDS (Ver_2011-06-03.01) - NTFSx86 MINIMAL
Internet Explorer: 8.0.6001.18702
Run by ALTURTLE at 11:30:53 on 2011-06-10
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.382.196 [GMT -7:00]
.
AV: Sunbelt VIPRE *Enabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://news.google.com/
uSearch Page = hxxp://www.google.com
mSearch Page = hxxp://news.google.com
uInternet Settings,ProxyServer = http=192.168.0.1:87
uInternet Settings,ProxyOverride = 127.0.0.1;www.direcwaysupport.com;www.systemcontrolcenter.com;192.168.0.*;<local>;*.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: NXIECatcher Class: {83b80a9c-d91a-4f22-8dcf-ea7204039f79} - c:\program files\xi\netxfer\NXIEHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: NetXfer: {c16cbaac-a75c-4db5-a0dd-cdf5cafcdd3a} - c:\program files\xi\netxfer\NXToolBar.dll
uRun: [GoodSync] "c:\program files\siber systems\goodsync\goodsync.exe" /min
uRun: [Google Update] "c:\documents and settings\alturtle\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [EZ Macros] c:\program files\american systems\ez macros\EZMacros.exe /m
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [basicsmssmenu] c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
mRun: [SBAMTray] "c:\program files\sunbelt software\vipre\SBAMTray.exe"
StartupFolder: c:\docume~1\alturtle\startm~1\programs\startup\hughes~1.lnk - c:\program files\hughesnetstatusmeter\hughesnetstatusmeter\HughesNetStatusMeter.exe
IE: Download all by NetXfer - c:\program files\xi\netxfer\NXAddList.html
IE: Download by NetXfer - c:\program files\xi\netxfer\NXAddLink.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {44C1E3A2-B594-401C-B27A-D1B4476E4797} - hxxps://gfavpn.goandfish.com/XTSAC.cab
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://software-dl.real.com/3081e459c92466e3fb21/netzip/RdxIE601.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: DhcpNameServer = 66.82.4.8
TCP: Interfaces\{9805983E-E48D-4942-85DF-A1069E72AB7E} : NameServer = 208.67.220.220,208.67.222.222
TCP: Interfaces\{9805983E-E48D-4942-85DF-A1069E72AB7E} : DhcpNameServer = 66.82.4.8
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {08B0E5C0-4FCB-11CF-AAX5-10401C608512} - c:\recycler\s-1-5-21-1482476501-1644491937-682003330-1013\update.exe
IFEO: taskmgr.exe - "c:\program files\processexplorer\PROCEXP.EXE"
.
============= SERVICES / DRIVERS ===============
.
R3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-4-29 101720]
S1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2010-8-29 21592]
S1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2010-8-29 212568]
S2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2010-10-9 10448]
S2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2010-8-29 74968]
S3 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2010-3-15 401920]
S3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [2009-1-1 33808]
.
=============== Created Last 30 ================
.
2011-06-10 16:32:36 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-06-08 18:08:47 -------- d-----w- c:\program files\iPod
2011-06-08 18:07:43 -------- d-----w- c:\program files\iTunes
2011-05-20 16:01:57 -------- d-----w- c:\program files\TweetDeck
2011-05-11 23:55:16 42832 ----a-w- c:\windows\system32\sbbd.exe
.
==================== Find3M ====================
.
2011-05-11 23:26:04 74968 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2011-05-11 23:26:04 21592 ----a-w- c:\windows\system32\drivers\sbaphd.sys
2011-04-29 21:15:42 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-06 23:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20:16 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 23:20:16 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 23:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 00:35:20 212568 ----a-w- c:\windows\system32\drivers\sbtis.sys
.
============= FINISH: 11:33:01.14 ===============
http://forums.spybot.info/showthread.php?t=62803
Problem occurs on one of my four computers. Spybot works find on the others.
Having been away, I reran everything today. Erunt ran fine. DDS ran in Safe Mode only.
DDS.Txt is below. Attach.txt is zipped and attached.
******************************************************************************
.
DDS (Ver_2011-06-03.01) - NTFSx86 MINIMAL
Internet Explorer: 8.0.6001.18702
Run by ALTURTLE at 11:30:53 on 2011-06-10
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.382.196 [GMT -7:00]
.
AV: Sunbelt VIPRE *Enabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://news.google.com/
uSearch Page = hxxp://www.google.com
mSearch Page = hxxp://news.google.com
uInternet Settings,ProxyServer = http=192.168.0.1:87
uInternet Settings,ProxyOverride = 127.0.0.1;www.direcwaysupport.com;www.systemcontrolcenter.com;192.168.0.*;<local>;*.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: NXIECatcher Class: {83b80a9c-d91a-4f22-8dcf-ea7204039f79} - c:\program files\xi\netxfer\NXIEHelper.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: NetXfer: {c16cbaac-a75c-4db5-a0dd-cdf5cafcdd3a} - c:\program files\xi\netxfer\NXToolBar.dll
uRun: [GoodSync] "c:\program files\siber systems\goodsync\goodsync.exe" /min
uRun: [Google Update] "c:\documents and settings\alturtle\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [EZ Macros] c:\program files\american systems\ez macros\EZMacros.exe /m
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [basicsmssmenu] c:\program files\seagate\basics\basics status\MaxMenuMgrBasics.exe
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
mRun: [SBAMTray] "c:\program files\sunbelt software\vipre\SBAMTray.exe"
StartupFolder: c:\docume~1\alturtle\startm~1\programs\startup\hughes~1.lnk - c:\program files\hughesnetstatusmeter\hughesnetstatusmeter\HughesNetStatusMeter.exe
IE: Download all by NetXfer - c:\program files\xi\netxfer\NXAddList.html
IE: Download by NetXfer - c:\program files\xi\netxfer\NXAddLink.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {44C1E3A2-B594-401C-B27A-D1B4476E4797} - hxxps://gfavpn.goandfish.com/XTSAC.cab
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://software-dl.real.com/3081e459c92466e3fb21/netzip/RdxIE601.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://fb.familylink.com/we_are_related/stream/core/lib/AurigmaImageUploader/ImageUploader5.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: DhcpNameServer = 66.82.4.8
TCP: Interfaces\{9805983E-E48D-4942-85DF-A1069E72AB7E} : NameServer = 208.67.220.220,208.67.222.222
TCP: Interfaces\{9805983E-E48D-4942-85DF-A1069E72AB7E} : DhcpNameServer = 66.82.4.8
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {08B0E5C0-4FCB-11CF-AAX5-10401C608512} - c:\recycler\s-1-5-21-1482476501-1644491937-682003330-1013\update.exe
IFEO: taskmgr.exe - "c:\program files\processexplorer\PROCEXP.EXE"
.
============= SERVICES / DRIVERS ===============
.
R3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-4-29 101720]
S1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2010-8-29 21592]
S1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2010-8-29 212568]
S2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2010-10-9 10448]
S2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2010-8-29 74968]
S3 Amazon Download Agent;Amazon Download Agent;c:\program files\amazon\amazon games & software downloader\AmazonGSDownloaderService.exe [2010-3-15 401920]
S3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [2009-1-1 33808]
.
=============== Created Last 30 ================
.
2011-06-10 16:32:36 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-06-08 18:08:47 -------- d-----w- c:\program files\iPod
2011-06-08 18:07:43 -------- d-----w- c:\program files\iTunes
2011-05-20 16:01:57 -------- d-----w- c:\program files\TweetDeck
2011-05-11 23:55:16 42832 ----a-w- c:\windows\system32\sbbd.exe
.
==================== Find3M ====================
.
2011-05-11 23:26:04 74968 ----a-w- c:\windows\system32\drivers\sbapifs.sys
2011-05-11 23:26:04 21592 ----a-w- c:\windows\system32\drivers\sbaphd.sys
2011-04-29 21:15:42 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-06 23:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20:16 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 23:20:16 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 23:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-06 00:35:20 212568 ----a-w- c:\windows\system32\drivers\sbtis.sys
.
============= FINISH: 11:33:01.14 ===============