Hi jmw3
Many thanks for the reply. The dds program seemed to run ok but a message was displayed saying "sort utility encounted a problem and needs to close". The log files are below.
The gmer application refuses to execute so no log files.
Hope to hear from you soon.
Bill
DDS (Ver_09-05-14.01) - NTFSx86
Run by Graham Else at 12:04:08.85 on 26/05/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.676 [GMT 1:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Documents and Settings\Graham Else\My Documents\Web downloads\keys\MacroMaker.exe
C:\Program Files\Outlook Express\msimn.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Graham Else\Desktop\dds.scr
============== Pseudo HJT Report ===============
uLocal Page = c:\program files\common files\microsoft shared\stationery\Blank.htm
uStart Page =
http://www.google.co.uk/uSearch Page =
hxxp://www.google.comuInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
TB: {71AAABE5-1F0F-11D7-BD6F-004854603DCE} - No File
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [EPSON Stylus Photo R300 Series] c:\windows\system32\spool\drivers\w32x86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\graham~1\startm~1\programs\startup\chkdisk.lnk - c:\windows\system32\rundll32.exe
StartupFolder: c:\docume~1\graham~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\HOTSYNC.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\MSOFFICE.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
uPolicies-system: DisableRegistryTools = 0
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: mcafee.com
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
hxxp://download.mcafee.com/molbin/share ... cgdmgr.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload.macromedia.com/get/fl ... wflash.cab============= SERVICES / DRIVERS ===============
R0 VOBID;VOBID;c:\windows\system32\drivers\vobid.sys [2003-8-1 29239]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-9 214024]
R1 vobiw;vobiw;c:\windows\system32\drivers\vobIW.sys [2004-9-1 188416]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-2-19 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-2-19 144704]
R3 cdrdrv;Cdrdrv;c:\windows\system32\drivers\Cdrdrv.sys [2004-8-3 62976]
R3 DCamUSBVideoLogic;HomeC@m;c:\windows\system32\drivers\p35u.sys [2005-11-19 90144]
R3 HSFHWCD2;HSFHWCD2;c:\windows\system32\drivers\HSFHWCD2.sys [2006-11-2 201728]
R3 kbdcap;kbdcap;c:\windows\system32\drivers\KbdCap.sys [2006-9-21 109440]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-2-19 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-2-19 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-2-19 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-2-19 40552]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-2-12 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-2-12 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-2-12 81288]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-2-19 34216]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-12 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-2-12 1079176]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [2005-12-1 224960]
=============== Created Last 30 ================
2009-05-24 12:28 <DIR> --d----- c:\program files\Trend Micro
2009-05-22 14:42 <DIR> --d----- c:\documents and settings\graham else\DoctorWeb
2009-05-20 14:39 <DIR> --d----- c:\program files\common files\ParetoLogic
2009-05-20 14:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ParetoLogic
2009-05-19 15:57 192 a------- c:\docume~1\graham~1\applic~1\asd.bat
==================== Find3M ====================
2009-05-21 20:03 2,707,744 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-05-21 20:03 37,340 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-05-21 20:03 1,100 a--sh--- c:\windows\system32\drivers\fidbox2.idx
2009-05-21 20:03 288 a--sh--- c:\windows\system32\drivers\fidbox2.dat
2009-04-11 16:08 167 a------- C:\gprologvars.bat
2009-03-06 15:22 284,160 a------- c:\windows\system32\pdh.dll
2008-04-07 11:38 61,224 a------- c:\documents and settings\graham else\GoToAssistDownloadHelper.exe
============= FINISH: 12:05:58.06 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 01/01/2003 16:48:04
System Uptime: 26/05/2009 11:52:36 (0 hours ago)
Motherboard: ASUSTeK Computer INC. | | A8N-E
Processor: AMD Athlon(tm) 64 Processor 3200+ | Socket 939 | 2010/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 69.114 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
7-Zip 4.57
Adobe Flash Player 10 ActiveX
Adobe Photoshop Elements 2.0
Adobe Reader 7.0.8
Apple Software Update
Athlon 64 Processor Driver
AutoUpdate
Avi2Dvd 0.4.5 beta
AVIcodec (remove only)
AviSynth 2.5
AVS Video Converter 6
AVS4YOU Software Navigator 1.3
BBC iPlayer Download Manager
Before You Know It 3.5 Lite
Brother HL-1430
Compatibility Pack for the 2007 Office system
DesignPro 5.0 Limited Edition
DivX Codec
DivX Converter
DivX Player
DVD Shrink 3.2
EPSON CardMonitor
EPSON Copy Utility
EPSON Photo Print
EPSON PhotoQuicker3.5
EPSON PhotoStarter3.1
EPSON Print CD
EPSON PRINT Image Framer Tool2.1
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
ESPR300 Reference Guide
ESPR300 Software Guide
ESPR300 Standalone Guide
EZY Prolog Suite
FinePix Studio
FinePixViewer Resource
FinePixViewer Ver.5.4
FUJIFILM USB Driver
GNU Prolog version 1.3.1
HijackThis 2.0.2
HomeC@m
Hotfix for Windows XP (KB952287)
ImgBurn (Remove Only)
Logitech SetPoint
MacroMaker
Max-FTP
McAfee SecurityCenter
MetaFrame Presentation Server Web Client for Win32
Microsoft Office 97, Professional Edition
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
NVIDIA Drivers
P2400P Reference Guide
Palm Desktop
Photo Viewer V208G2
PIF DESIGNER2.1
Pinnacle InstantCD/DVD Suite
Pinnacle InstantCD/DVD Suite Update
PowerDVD
QuickTime
Realtek AC'97 Audio
Registry Healer 4.0.1 uninstall
ScanToWeb
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
Skype 2.5
SoftV92 Data Fax Modem with SmartCP
Spyware Doctor 6.0
SWI-Prolog (remove only)
Trellian Dictionary v1.0
Trellian LiveUpgrade v2.0
Trellian WebPage
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Visual Prolog 7.2 Personal Edition
Visual Prolog Examples
Web Design Group CSS Reference
Web Design Group HTML Reference
WebFldrs XP
WinAVIVideoConverter
Windows Backup Utility
Windows Genuine Advantage Validation Tool (KB892130)
Windows XP Service Pack 3
Xvid 1.1.2 final uninstall
==== Event Viewer Messages From Past Week ========
26/05/2009 12:04:11, error: Service Control Manager [7016] - The SmartLinkService service has reported an invalid current state 0.
26/05/2009 12:04:10, error: Service Control Manager [7016] - The BrSplService service has reported an invalid current state 0.
22/05/2009 13:34:10, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.
22/05/2009 12:26:38, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is Graham Else.
22/05/2009 12:16:55, information: Windows File Protection [64016] - Windows File Protection file scan was started.
22/05/2009 11:12:26, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
22/05/2009 11:12:02, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
22/05/2009 11:11:45, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Fips IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
22/05/2009 11:11:45, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
22/05/2009 11:11:45, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
22/05/2009 11:11:45, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
22/05/2009 11:11:45, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
22/05/2009 11:10:42, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
22/05/2009 11:10:37, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
21/05/2009 16:56:47, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
20/05/2009 17:38:43, error: System Error [1003] - Error code 100000d1, parameter1 e1d2a000, parameter2 00000002, parameter3 00000000, parameter4 eed67b00.
20/05/2009 14:09:36, error: System Error [1003] - Error code 1000000a, parameter1 eb00004f, parameter2 00000002, parameter3 00000001, parameter4 8051eefd.
19/05/2009 16:19:22, error: Service Control Manager [7022] - The KService service hung on starting.
19/05/2009 16:04:12, error: Service Control Manager [7034] - The McAfee Scanner service terminated unexpectedly. It has done this 1 time(s).
==== End Of File ===========================