Immediately upon logging on this pops up. WINDOWS RECOVERY [CRITICAL ERROR Damaged hard drive clusters detected]
Here is the DDS and attach file zip. please help!
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Mama at 17:08:21.88 on Thu 04/21/2011
Internet Explorer: 6.0.2800.1106
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.246.55 [GMT 8:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\lexpps.exe
C:\Documents and Settings\All Users\Application Data\SQYJBiKnjSxs.exe
C:\WINDOWS\System32\attrib.exe
C:\Documents and Settings\All Users\Application Data\17227572.exe
C:\Documents and Settings\Mama\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
uInternet Settings,ProxyServer = 10.34.50.6:8080
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: CPrintEnhancer Object: {ae84a6aa-a333-4b92-b276-c11e2212e4fe} - c:\program files\hp\smart web printing\SmartWebPrinting.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [SQYJBiKnjSxs] c:\documents and settings\all users\application data\SQYJBiKnjSxs.exe
mRun: [avgnt] "c:\program files\antivir personaledition classic\avgnt.exe" /min
dRun: [CTFMON.EXE] $$
StartupFolder: c:\docume~1\mama\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\microt~1.lnk - c:\program files\microtek\scanwizard 5\ScannerFinder.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
mPolicies-system: DisableTaskMgr = 1 (0x1)
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - c:\program files\lenovo\pkgmgr\\PkgMgr.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
Notify: igfxcui - igfxsrvc.dll
SEH: {05041043-0C5F-46A4-A959-58D2A1F73262} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\mama\applic~1\mozilla\firefox\profiles\tbl1cs9g.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com/
FF - prefs.js: network.proxy.ftp - 10.34.50.6
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 10.34.50.6
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - 10.34.50.6
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 10.34.50.6
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 10.34.50.6
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
============= SERVICES / DRIVERS ===============
.
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [2011-3-15 14848]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [2011-3-15 32768]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-7-6 561152]
R2 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;c:\program files\antivir personaledition classic\sched.exe [2011-3-15 34344]
R2 AntiVirService;AntiVir PersonalEdition Classic Guard;c:\program files\antivir personaledition classic\avguard.exe [2011-3-15 191016]
S0 IFP300;iRiver Internet Audio Player IFP-300;c:\windows\system32\drivers\ifp300.sys --> c:\windows\system32\drivers\ifp300.sys [?]
S4 Remote Auther Service;Remote Auther Service;"c:\windows\system32\svshost.exe" --> c:\windows\system32\svshost.exe [?]
.
=============== Created Last 30 ================
.
2011-04-16 06:34:17 487424 ---ha-w- c:\docume~1\alluse~1\applic~1\17227572.exe
2011-04-16 06:25:08 569344 ---ha-w- c:\docume~1\alluse~1\applic~1\SQYJBiKnjSxs.exe
.
==================== Find3M ====================
.
.
============= FINISH: 17:10:54.06 ===============
Here is the DDS and attach file zip. please help!
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Mama at 17:08:21.88 on Thu 04/21/2011
Internet Explorer: 6.0.2800.1106
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.246.55 [GMT 8:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\lexpps.exe
C:\Documents and Settings\All Users\Application Data\SQYJBiKnjSxs.exe
C:\WINDOWS\System32\attrib.exe
C:\Documents and Settings\All Users\Application Data\17227572.exe
C:\Documents and Settings\Mama\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
uInternet Settings,ProxyServer = 10.34.50.6:8080
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: CPrintEnhancer Object: {ae84a6aa-a333-4b92-b276-c11e2212e4fe} - c:\program files\hp\smart web printing\SmartWebPrinting.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [SQYJBiKnjSxs] c:\documents and settings\all users\application data\SQYJBiKnjSxs.exe
mRun: [avgnt] "c:\program files\antivir personaledition classic\avgnt.exe" /min
dRun: [CTFMON.EXE] $$
StartupFolder: c:\docume~1\mama\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\microt~1.lnk - c:\program files\microtek\scanwizard 5\ScannerFinder.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
mPolicies-system: DisableTaskMgr = 1 (0x1)
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - c:\program files\lenovo\pkgmgr\\PkgMgr.exe
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
Notify: igfxcui - igfxsrvc.dll
SEH: {05041043-0C5F-46A4-A959-58D2A1F73262} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\mama\applic~1\mozilla\firefox\profiles\tbl1cs9g.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com/
FF - prefs.js: network.proxy.ftp - 10.34.50.6
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - 10.34.50.6
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - 10.34.50.6
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - 10.34.50.6
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - 10.34.50.6
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
============= SERVICES / DRIVERS ===============
.
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [2011-3-15 14848]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [2011-3-15 32768]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-7-6 561152]
R2 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;c:\program files\antivir personaledition classic\sched.exe [2011-3-15 34344]
R2 AntiVirService;AntiVir PersonalEdition Classic Guard;c:\program files\antivir personaledition classic\avguard.exe [2011-3-15 191016]
S0 IFP300;iRiver Internet Audio Player IFP-300;c:\windows\system32\drivers\ifp300.sys --> c:\windows\system32\drivers\ifp300.sys [?]
S4 Remote Auther Service;Remote Auther Service;"c:\windows\system32\svshost.exe" --> c:\windows\system32\svshost.exe [?]
.
=============== Created Last 30 ================
.
2011-04-16 06:34:17 487424 ---ha-w- c:\docume~1\alluse~1\applic~1\17227572.exe
2011-04-16 06:25:08 569344 ---ha-w- c:\docume~1\alluse~1\applic~1\SQYJBiKnjSxs.exe
.
==================== Find3M ====================
.
.
============= FINISH: 17:10:54.06 ===============