Hi there,
I suspect a virus infection but the symptoms until recently have been subtle - a rogue pop-up tab window opening once in a while using Firefox, and a svchost.exe process running occasionally and taking up most of the processor power. AVG scans and Spybot scans do not show anything suspicious, although if I leave the PC for a while sometimes the AVG resident shield will fire up a warning about a Trojan. 2 days ago the PC suddenly rebooted and would not complete a boot-up sequence, rebooting once again before the desktop was complete. I was able to restart by pressing F8 and choosing 'Select Last Known Working Configuration' However the problem seems to be getting worse today and it has been difficult to restart successfully. As requested in your FAQs please find attached the DDS and attach logs. I see from your FAQ that you ask us to post the logs but the program says zip and attach the attach.txt ??
Regards,
Keith
DDS (Ver_10-03-17.01) - NTFSx86
Run by keith at 13:32:49.95 on 26/07/2010
Internet Explorer: 6.0.2900.2149
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.383.56 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe 4
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe 4
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
C:\Program Files\Netdrive\ndsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\keith\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
mSearch Page =
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [{95C5721D-2FA0-4EA2-8C50-ADF841EF840B}] "c:\documents and settings\keith\application data\loar\guled.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9e.exe
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
mPolicies-explorer: UseDesktopIniCache = 1 (0x1)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program
files\java\jre1.6.0_04\bin\ssv.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
IFEO: RapportMgmtService.exe - ZASRAKOMONDOHUI31338.EXE
IFEO: RapportService.exe - ZASRAKOMONDOHUI31338.EXE
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\keith\applic~1\mozilla\firefox\profiles\8f26ffzs.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.co.uk/|http://uk.mc867.mail.yahoo.com/mc/welcome?.partner=bt-1&.gx=1&.tm=1264517933&.rand=4iu43c05tk8lv#_pg
=welcome&&.rand=121126838&clean&.jsrand=1109760|http://www.metoffice.gov.uk/weather/uk/radar/|http://www.sat24.com/gb|http://
www.westwind.ch/?link=ukmb,http://w...ell+24,bracknell+36,bracknell+48,bracknell+60,
bracknell+72,bracknell+84,bracknell+96,bracknell+120
FF - plugin: c:\documents and settings\keith\application
data\mozilla\firefox\profiles\8f26ffzs.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-27 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-6 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-5-6 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-6 108552]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-3-7 394952]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-6 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-6 297752]
R2 ndsvc;NetDrive Service;c:\program files\netdrive\ndsvc.exe [2008-11-7 2566144]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service -->
c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 iadusb;BT Voyager 205 ADSL Router;c:\windows\system32\drivers\glauiad.sys [2008-3-5 30371]
S1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2008-8-4 127768]
S2 assert update;assert update;c:\windows\system32\wildday.exe --> c:\windows\system32\wildday.exe [?]
S2 RDSessMgrSCardSvr;Remote Desktop Help Session Manager RDSessMgrSCardSvr;c:\windows\system32\acluic.exe srv -->
c:\windows\system32\acluic.exe srv [?]
S2 RpcSsMSDTC;Remote Procedure Call (RPC) RpcSsMSDTC;c:\windows\system32\advapi32z.exe srv -->
c:\windows\system32\advapi32z.exe srv [?]
S2 WmiApSrvwscsvc;WMI Performance Adapter WmiApSrvwscsvc;c:\windows\system32\accesso.exe srv -->
c:\windows\system32\accesso.exe srv [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1263728]
S3 ndfs;ndfs;c:\program files\netdrive\ndfs.sys [2008-7-3 70400]
=============== Created Last 30 ================
2010-07-24 19:19:09 308782 ----a-w- C:\attachments_2010_07_24.zip
==================== Find3M ====================
============= FINISH: 13:34:19.46 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 26/02/2008 08:29:35
System Uptime: 26/07/2010 13:06:14 (0 hours ago)
Motherboard: ASUSTek Computer INC. | | P4R800-VM
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | CPU 1 | 2793/100mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 149 GiB total, 87.361 GiB free.
D: is CDROM ()
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Multimedia Controller
Device ID: PCI\VEN_1131&DEV_7134&SUBSYS_48421043&REV_01\4&264A3649&0&38A4
Manufacturer:
Name: Multimedia Controller
PNP Device ID: PCI\VEN_1131&DEV_7134&SUBSYS_48421043&REV_01\4&264A3649&0&38A4
Service:
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Realtek AC'97 Audio
Device ID: PCI\VEN_1002&DEV_4341&SUBSYS_E00D1631&REV_00\3&267A616A&0&A5
Manufacturer: Realtek
Name: Realtek AC'97 Audio
PNP Device ID: PCI\VEN_1002&DEV_4341&SUBSYS_E00D1631&REV_00\3&267A616A&0&A5
Service: ALCXWDM
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_1002&DEV_434D&SUBSYS_30541631&REV_01\3&267A616A&0&A6
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_1002&DEV_434D&SUBSYS_30541631&REV_01\3&267A616A&0&A6
Service:
==== System Restore Points ===================
RP312: 26/04/2010 15:52:59 - System Checkpoint
RP313: 27/04/2010 19:14:58 - System Checkpoint
RP314: 29/04/2010 19:11:22 - System Checkpoint
RP315: 03/05/2010 18:48:23 - System Checkpoint
RP316: 06/05/2010 18:01:40 - System Checkpoint
RP317: 10/05/2010 07:58:58 - System Checkpoint
RP318: 11/05/2010 20:15:57 - System Checkpoint
RP319: 15/05/2010 10:40:15 - Installed ACSI Camp Site Guide Europe 2010
RP320: 15/05/2010 14:36:16 - Configured ACSI Camp Site Guide Europe 2010
RP321: 15/05/2010 14:37:41 - Configured ACSI Camp Site Guide Europe 2010
RP322: 16/05/2010 14:40:41 - System Checkpoint
RP323: 18/05/2010 11:49:15 - System Checkpoint
RP324: 20/05/2010 16:44:47 - System Checkpoint
RP325: 21/05/2010 23:15:18 - System Checkpoint
RP326: 23/05/2010 21:05:48 - System Checkpoint
RP327: 24/05/2010 21:43:27 - System Checkpoint
RP328: 26/05/2010 18:13:42 - System Checkpoint
RP329: 28/05/2010 13:51:02 - System Checkpoint
RP330: 01/06/2010 14:19:18 - System Checkpoint
RP331: 03/06/2010 22:02:15 - System Checkpoint
RP332: 10/06/2010 17:53:44 - System Checkpoint
RP333: 11/06/2010 20:48:58 - System Checkpoint
RP334: 13/06/2010 12:52:49 - System Checkpoint
RP335: 16/06/2010 14:47:12 - System Checkpoint
RP336: 20/06/2010 21:24:04 - System Checkpoint
RP337: 22/06/2010 18:41:36 - Avg8 Update
RP338: 26/06/2010 22:16:54 - System Checkpoint
RP339: 29/06/2010 13:46:16 - System Checkpoint
RP340: 01/07/2010 09:01:09 - System Checkpoint
RP341: 02/07/2010 18:16:03 - System Checkpoint
RP342: 17/07/2010 21:11:46 - Avg8 Update
RP343: 18/07/2010 12:36:42 - Avg8 Update
RP344: 21/07/2010 18:28:25 - System Checkpoint
RP345: 25/07/2010 11:02:23 - System Checkpoint
RP346: 26/07/2010 12:36:25 - Restore Operation
==== Installed Programs ======================
ACSI Camp Site Guide Europe 2010
Ad-Aware
Ad-Aware Email Scanner for Outlook
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Amazon MP3 Downloader 1.0.9
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AVG Free 8.5
Broadband Desktop Help
BT Voyager 205 ADSL Router
CCleaner (remove only)
Cobian Backup 10
Compatibility Pack for the 2007 Office system
Creative Jukebox Driver
ERUNT 1.1j
FLV Player 2.0, build 24
Harry Potter and the Prisoner of Azkaban(TM)
HijackThis 2.0.2
hp instant support
iTunes
Java(TM) 6 Update 4
Malwarebytes' Anti-Malware
Memory-Map OS Edition Version 5
Microsoft .NET Framework 2.0
Microsoft Bootvis
Microsoft Office Excel Viewer 2003
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Word Viewer 2003
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.11)
MP3 Player Recovery Tool
Mr Smooth v1.0
MrSmooth
MySQL Server 5.1
Netdrive
OpenOffice.org 2.4
QuickTime
Realtek AC'97 Audio
Skype™ 3.8
Smart Defrag 1.20
Spybot - Search & Destroy
SpywareBlaster 4.3
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VNC Free Edition 4.1.3
WebFldrs XP
WINGRIDDS
Winmail Reader 1.1.12
ZoneAlarm
==== Event Viewer Messages From Past Week ========
26/07/2010 12:59:16, error: Service Control Manager [7000] - The SSDP Discovery Service service failed to start due to the following error: The system cannot find the path specified.
26/07/2010 00:42:35, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect.
26/07/2010 00:42:35, error: Service Control Manager [7000] - The TrueVector Internet Monitor service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
25/07/2010 18:38:11, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
25/07/2010 16:35:19, error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 1 time(s).
25/07/2010 16:35:19, error: Service Control Manager [7031] - The Help and Support service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
25/07/2010 11:54:00, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
25/07/2010 11:54:00, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
25/07/2010 01:04:48, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG8 E-mail Scanner service to connect.
25/07/2010 01:04:48, error: Service Control Manager [7000] - The AVG8 E-mail Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
23/07/2010 15:52:17, error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 2 time(s).
23/07/2010 15:52:17, error: Service Control Manager [7034] - The COM+ Event System service terminated unexpectedly. It has done this 2 time(s).
23/07/2010 15:52:17, error: Service Control Manager [7031] - The Help and Support service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Wireless Zero Configuration service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Windows Time service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The System Restore Service service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The System Event Notification service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Security Center service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Network Location Awareness (NLA) service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
23/07/2010 14:36:46, error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
23/07/2010 14:36:46, error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 6000 milliseconds: Restart the service.
23/07/2010 14:21:16, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
23/07/2010 14:21:16, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
==== End Of File ===========================
I suspect a virus infection but the symptoms until recently have been subtle - a rogue pop-up tab window opening once in a while using Firefox, and a svchost.exe process running occasionally and taking up most of the processor power. AVG scans and Spybot scans do not show anything suspicious, although if I leave the PC for a while sometimes the AVG resident shield will fire up a warning about a Trojan. 2 days ago the PC suddenly rebooted and would not complete a boot-up sequence, rebooting once again before the desktop was complete. I was able to restart by pressing F8 and choosing 'Select Last Known Working Configuration' However the problem seems to be getting worse today and it has been difficult to restart successfully. As requested in your FAQs please find attached the DDS and attach logs. I see from your FAQ that you ask us to post the logs but the program says zip and attach the attach.txt ??
Regards,
Keith
DDS (Ver_10-03-17.01) - NTFSx86
Run by keith at 13:32:49.95 on 26/07/2010
Internet Explorer: 6.0.2900.2149
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.383.56 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe 4
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe 4
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
C:\Program Files\Netdrive\ndsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\keith\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
mSearch Page =
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [{95C5721D-2FA0-4EA2-8C50-ADF841EF840B}] "c:\documents and settings\keith\application data\loar\guled.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9e.exe
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
mPolicies-explorer: UseDesktopIniCache = 1 (0x1)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program
files\java\jre1.6.0_04\bin\ssv.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
IFEO: RapportMgmtService.exe - ZASRAKOMONDOHUI31338.EXE
IFEO: RapportService.exe - ZASRAKOMONDOHUI31338.EXE
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\keith\applic~1\mozilla\firefox\profiles\8f26ffzs.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.co.uk/|http://uk.mc867.mail.yahoo.com/mc/welcome?.partner=bt-1&.gx=1&.tm=1264517933&.rand=4iu43c05tk8lv#_pg
=welcome&&.rand=121126838&clean&.jsrand=1109760|http://www.metoffice.gov.uk/weather/uk/radar/|http://www.sat24.com/gb|http://
www.westwind.ch/?link=ukmb,http://w...ell+24,bracknell+36,bracknell+48,bracknell+60,
bracknell+72,bracknell+84,bracknell+96,bracknell+120
FF - plugin: c:\documents and settings\keith\application
data\mozilla\firefox\profiles\8f26ffzs.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js -
pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-27 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-6 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-5-6 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-6 108552]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-3-7 394952]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-6 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-6 297752]
R2 ndsvc;NetDrive Service;c:\program files\netdrive\ndsvc.exe [2008-11-7 2566144]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service -->
c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 iadusb;BT Voyager 205 ADSL Router;c:\windows\system32\drivers\glauiad.sys [2008-3-5 30371]
S1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2008-8-4 127768]
S2 assert update;assert update;c:\windows\system32\wildday.exe --> c:\windows\system32\wildday.exe [?]
S2 RDSessMgrSCardSvr;Remote Desktop Help Session Manager RDSessMgrSCardSvr;c:\windows\system32\acluic.exe srv -->
c:\windows\system32\acluic.exe srv [?]
S2 RpcSsMSDTC;Remote Procedure Call (RPC) RpcSsMSDTC;c:\windows\system32\advapi32z.exe srv -->
c:\windows\system32\advapi32z.exe srv [?]
S2 WmiApSrvwscsvc;WMI Performance Adapter WmiApSrvwscsvc;c:\windows\system32\accesso.exe srv -->
c:\windows\system32\accesso.exe srv [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1263728]
S3 ndfs;ndfs;c:\program files\netdrive\ndfs.sys [2008-7-3 70400]
=============== Created Last 30 ================
2010-07-24 19:19:09 308782 ----a-w- C:\attachments_2010_07_24.zip
==================== Find3M ====================
============= FINISH: 13:34:19.46 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 26/02/2008 08:29:35
System Uptime: 26/07/2010 13:06:14 (0 hours ago)
Motherboard: ASUSTek Computer INC. | | P4R800-VM
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | CPU 1 | 2793/100mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 149 GiB total, 87.361 GiB free.
D: is CDROM ()
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Multimedia Controller
Device ID: PCI\VEN_1131&DEV_7134&SUBSYS_48421043&REV_01\4&264A3649&0&38A4
Manufacturer:
Name: Multimedia Controller
PNP Device ID: PCI\VEN_1131&DEV_7134&SUBSYS_48421043&REV_01\4&264A3649&0&38A4
Service:
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: Realtek AC'97 Audio
Device ID: PCI\VEN_1002&DEV_4341&SUBSYS_E00D1631&REV_00\3&267A616A&0&A5
Manufacturer: Realtek
Name: Realtek AC'97 Audio
PNP Device ID: PCI\VEN_1002&DEV_4341&SUBSYS_E00D1631&REV_00\3&267A616A&0&A5
Service: ALCXWDM
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_1002&DEV_434D&SUBSYS_30541631&REV_01\3&267A616A&0&A6
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_1002&DEV_434D&SUBSYS_30541631&REV_01\3&267A616A&0&A6
Service:
==== System Restore Points ===================
RP312: 26/04/2010 15:52:59 - System Checkpoint
RP313: 27/04/2010 19:14:58 - System Checkpoint
RP314: 29/04/2010 19:11:22 - System Checkpoint
RP315: 03/05/2010 18:48:23 - System Checkpoint
RP316: 06/05/2010 18:01:40 - System Checkpoint
RP317: 10/05/2010 07:58:58 - System Checkpoint
RP318: 11/05/2010 20:15:57 - System Checkpoint
RP319: 15/05/2010 10:40:15 - Installed ACSI Camp Site Guide Europe 2010
RP320: 15/05/2010 14:36:16 - Configured ACSI Camp Site Guide Europe 2010
RP321: 15/05/2010 14:37:41 - Configured ACSI Camp Site Guide Europe 2010
RP322: 16/05/2010 14:40:41 - System Checkpoint
RP323: 18/05/2010 11:49:15 - System Checkpoint
RP324: 20/05/2010 16:44:47 - System Checkpoint
RP325: 21/05/2010 23:15:18 - System Checkpoint
RP326: 23/05/2010 21:05:48 - System Checkpoint
RP327: 24/05/2010 21:43:27 - System Checkpoint
RP328: 26/05/2010 18:13:42 - System Checkpoint
RP329: 28/05/2010 13:51:02 - System Checkpoint
RP330: 01/06/2010 14:19:18 - System Checkpoint
RP331: 03/06/2010 22:02:15 - System Checkpoint
RP332: 10/06/2010 17:53:44 - System Checkpoint
RP333: 11/06/2010 20:48:58 - System Checkpoint
RP334: 13/06/2010 12:52:49 - System Checkpoint
RP335: 16/06/2010 14:47:12 - System Checkpoint
RP336: 20/06/2010 21:24:04 - System Checkpoint
RP337: 22/06/2010 18:41:36 - Avg8 Update
RP338: 26/06/2010 22:16:54 - System Checkpoint
RP339: 29/06/2010 13:46:16 - System Checkpoint
RP340: 01/07/2010 09:01:09 - System Checkpoint
RP341: 02/07/2010 18:16:03 - System Checkpoint
RP342: 17/07/2010 21:11:46 - Avg8 Update
RP343: 18/07/2010 12:36:42 - Avg8 Update
RP344: 21/07/2010 18:28:25 - System Checkpoint
RP345: 25/07/2010 11:02:23 - System Checkpoint
RP346: 26/07/2010 12:36:25 - Restore Operation
==== Installed Programs ======================
ACSI Camp Site Guide Europe 2010
Ad-Aware
Ad-Aware Email Scanner for Outlook
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Amazon MP3 Downloader 1.0.9
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AVG Free 8.5
Broadband Desktop Help
BT Voyager 205 ADSL Router
CCleaner (remove only)
Cobian Backup 10
Compatibility Pack for the 2007 Office system
Creative Jukebox Driver
ERUNT 1.1j
FLV Player 2.0, build 24
Harry Potter and the Prisoner of Azkaban(TM)
HijackThis 2.0.2
hp instant support
iTunes
Java(TM) 6 Update 4
Malwarebytes' Anti-Malware
Memory-Map OS Edition Version 5
Microsoft .NET Framework 2.0
Microsoft Bootvis
Microsoft Office Excel Viewer 2003
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Word Viewer 2003
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.11)
MP3 Player Recovery Tool
Mr Smooth v1.0
MrSmooth
MySQL Server 5.1
Netdrive
OpenOffice.org 2.4
QuickTime
Realtek AC'97 Audio
Skype™ 3.8
Smart Defrag 1.20
Spybot - Search & Destroy
SpywareBlaster 4.3
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VNC Free Edition 4.1.3
WebFldrs XP
WINGRIDDS
Winmail Reader 1.1.12
ZoneAlarm
==== Event Viewer Messages From Past Week ========
26/07/2010 12:59:16, error: Service Control Manager [7000] - The SSDP Discovery Service service failed to start due to the following error: The system cannot find the path specified.
26/07/2010 00:42:35, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect.
26/07/2010 00:42:35, error: Service Control Manager [7000] - The TrueVector Internet Monitor service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
25/07/2010 18:38:11, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
25/07/2010 16:35:19, error: Service Control Manager [7034] - The Server service terminated unexpectedly. It has done this 1 time(s).
25/07/2010 16:35:19, error: Service Control Manager [7031] - The Help and Support service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
25/07/2010 11:54:00, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
25/07/2010 11:54:00, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
25/07/2010 01:04:48, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG8 E-mail Scanner service to connect.
25/07/2010 01:04:48, error: Service Control Manager [7000] - The AVG8 E-mail Scanner service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
23/07/2010 15:52:17, error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 2 time(s).
23/07/2010 15:52:17, error: Service Control Manager [7034] - The COM+ Event System service terminated unexpectedly. It has done this 2 time(s).
23/07/2010 15:52:17, error: Service Control Manager [7031] - The Help and Support service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Wireless Zero Configuration service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Windows Time service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The System Restore Service service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The System Event Notification service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Security Center service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Network Location Awareness (NLA) service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7034] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 1 time(s).
23/07/2010 14:36:46, error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
23/07/2010 14:36:46, error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
23/07/2010 14:36:46, error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 6000 milliseconds: Restart the service.
23/07/2010 14:21:16, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
23/07/2010 14:21:16, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
==== End Of File ===========================