Hi my Google chrome is redirecting to http://xxx.searchnu.com/406 and I cannot remove it or restore computer to a previous safe point.
I have attached DDS logs as requested. I hope I have done it right as never had to do this before. Please can someone help with this? Many thanks.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by [removed] at 21:00:21 on 2012-05-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.224 [GMT 1:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uSearch Page =
uSearch Bar =
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&c ... channel=uk
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: cnet.com\download
Trusted Zone: download.com
Trusted Zone: facebook.com\apps
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/softwareupdate/ ... TSUEng.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/200 ... oader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://homebase.2020.net/Core/Player/20 ... _Win32.cab
DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/uk/uk/importe ... loader.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {36C17E9B-3354-11D1-95CF-0000B4530F04} - hxxp://85.189.44.185/Baxi/Plugins/GFXVIEW.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.snapfish.co.uk/SnapfishUKActivia.cab
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex ... 0-3-48.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by121fd.bay121.hotmail.msn.com/r ... nPUpld.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.tescophoto.com/wpp/tescophot ... oader5.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resourc ... oscan8.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/ ... TSUEng.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/200 ... ader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/softwa ... Plugin.cab
DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} - hxxp://www.bootsdigitalphotocentre.com/ ... loader.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/Me ... b56907.cab
DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} - hxxp://help.broadbandassist.com/prequal ... reQual.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} - hxxp://static.photobox.co.uk/sg/common/uploader_uni.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/ ... /CTPID.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{080A986A-0035-43D7-9415-7F9A2C015E7E} : DhcpNameServer = 192.168.0.1
AppInit_DLLs:
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 http://www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-5-10 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-5-10 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-5-10 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-5-10 66616]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-16 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-16 136176]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-12-1 16968]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-5-2 40776]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2006-11-20 182784]
.
=============== Created Last 30 ================
.
2012-05-02 14:44:08 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-05-01 19:15:17 -------- d-----w- c:\documents and settings\all users\application data\boost_interprocess
2012-05-01 18:23:50 -------- d-----w- c:\documents and settings\stephanie\local settings\application data\Ilivid Player
2012-04-25 14:55:15 -------- d-----w- c:\documents and settings\all users\application data\DivX
.
==================== Find3M ====================
.
2012-04-04 14:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-01 01:25:04 832512 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 01:25:03 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-03-01 01:25:03 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-01 01:25:03 17408 ----a-w- c:\windows\system32\corpol.dll
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-03 09:22:18 1860096 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 21:02:17.75 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 02/06/2006 15:41:23
System Uptime: 02/05/2012 20:47:20 (1 hours ago)
.
Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 70 GiB total, 7.608 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP385: 17/02/2012 08:07:18 - System Checkpoint
RP386: 18/02/2012 09:23:09 - System Checkpoint
RP387: 19/02/2012 09:46:06 - System Checkpoint
RP388: 20/02/2012 13:46:01 - System Checkpoint
RP389: 21/02/2012 08:00:42 - Software Distribution Service 3.0
RP390: 22/02/2012 09:07:12 - System Checkpoint
RP391: 23/02/2012 13:37:25 - System Checkpoint
RP392: 24/02/2012 16:46:38 - System Checkpoint
RP393: 25/02/2012 22:02:19 - System Checkpoint
RP394: 27/02/2012 08:02:15 - System Checkpoint
RP395: 28/02/2012 08:28:59 - System Checkpoint
RP396: 29/02/2012 09:04:56 - System Checkpoint
RP397: 01/03/2012 16:50:15 - System Checkpoint
RP398: 02/03/2012 18:13:58 - System Checkpoint
RP399: 03/03/2012 21:10:20 - System Checkpoint
RP400: 05/03/2012 09:01:58 - System Checkpoint
RP401: 06/03/2012 17:32:34 - System Checkpoint
RP402: 07/03/2012 20:33:11 - System Checkpoint
RP403: 09/03/2012 12:15:48 - System Checkpoint
RP404: 10/03/2012 14:20:03 - System Checkpoint
RP405: 11/03/2012 14:40:11 - System Checkpoint
RP406: 13/03/2012 08:43:57 - System Checkpoint
RP407: 14/03/2012 08:00:26 - Software Distribution Service 3.0
RP408: 15/03/2012 08:40:47 - System Checkpoint
RP409: 16/03/2012 08:52:28 - System Checkpoint
RP410: 17/03/2012 11:55:11 - System Checkpoint
RP411: 18/03/2012 15:59:56 - System Checkpoint
RP412: 20/03/2012 07:02:30 - System Checkpoint
RP413: 21/03/2012 09:51:58 - System Checkpoint
RP414: 22/03/2012 13:02:18 - System Checkpoint
RP415: 23/03/2012 13:06:01 - System Checkpoint
RP416: 24/03/2012 15:57:42 - System Checkpoint
RP417: 25/03/2012 21:51:22 - System Checkpoint
RP418: 27/03/2012 09:27:58 - System Checkpoint
RP419: 28/03/2012 13:41:30 - System Checkpoint
RP420: 29/03/2012 16:06:01 - System Checkpoint
RP421: 30/03/2012 19:24:33 - System Checkpoint
RP422: 31/03/2012 21:07:38 - System Checkpoint
RP423: 01/04/2012 21:21:36 - System Checkpoint
RP424: 03/04/2012 10:15:26 - System Checkpoint
RP425: 04/04/2012 15:35:02 - System Checkpoint
RP426: 09/04/2012 17:11:22 - System Checkpoint
RP427: 10/04/2012 22:18:18 - System Checkpoint
RP428: 12/04/2012 08:24:05 - System Checkpoint
RP429: 12/04/2012 23:33:58 - Software Distribution Service 3.0
RP430: 14/04/2012 10:23:28 - System Checkpoint
RP431: 15/04/2012 14:37:01 - System Checkpoint
RP432: 16/04/2012 21:07:05 - System Checkpoint
RP433: 18/04/2012 09:21:59 - System Checkpoint
RP434: 19/04/2012 09:23:39 - System Checkpoint
RP435: 20/04/2012 13:40:26 - System Checkpoint
RP436: 21/04/2012 15:18:24 - System Checkpoint
RP437: 22/04/2012 20:38:04 - System Checkpoint
RP438: 23/04/2012 21:09:43 - System Checkpoint
RP439: 25/04/2012 10:15:45 - System Checkpoint
RP440: 26/04/2012 16:21:32 - System Checkpoint
RP441: 27/04/2012 21:17:44 - System Checkpoint
RP442: 29/04/2012 09:44:42 - System Checkpoint
RP443: 01/05/2012 07:26:15 - System Checkpoint
RP444: 02/05/2012 12:57:32 - System Checkpoint
RP445: 02/05/2012 20:48:54 - Restore Operation
.
==== Installed Programs ======================
.
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.1
Adobe Shockwave Player 11.5
Amazon MP3 Downloader 1.0.8
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ARTEuro
Avira AntiVir Personal - Free Antivirus
Bonjour
BroadJump Client Foundation
BurnPlugin for Audible
CCleaner
Compatibility Pack for the 2007 Office system
Dell CinePlayer
Dell Driver Reset Tool
Dell System Restore
Dropbox
EPSON Printer Software
FinePixViewer Ver.4.0
FUJIFILM USB Driver
Google Chrome
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImageMixer VCD for FinePix
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet for Wired Connections
iTunes
Java Auto Updater
Java(TM) 6 Update 29
Learn2 Player (Uninstall Only)
Malwarebytes Anti-Malware version 1.61.0.1400
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Professional
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.9
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft WinUsb 1.0
MobileMe Control Panel
MSVC80_x86
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML4 Parser
NETGEAR WG111v2 wireless USB 2.0 adapter
QuickTime
RAW FILE CONVERTER LE
RealPlayer
Roxio DLA
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB2482017)
Security Update for Windows Internet Explorer 7 (KB2544521)
Security Update for Windows Internet Explorer 7 (KB2618444)
Security Update for Windows Internet Explorer 7 (KB2647516)
Security Update for Windows Internet Explorer 7 (KB2675157)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Segoe UI
Sibelius Scorch (ActiveX Only)
Sky Go Desktop
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Spotify
Spybot - Search & Destroy
SUPERAntiSpyware
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Service Pack 3
.
==== Event Viewer Messages From Past Week ========
.
30/04/2012 19:48:34, error: Dhcp [1002] - The IP address lease 192.168.0.2 for the Network Card with network address 001676292AB4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
30/04/2012 07:43:36, error: WPDMTPDriver [15300] -
28/04/2012 19:46:48, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.
27/04/2012 22:24:15, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.0.2 with the system having network hardware address F0:B4:79:6B:D7:9D. Network operations on this system may be disrupted as a result.
27/04/2012 22:24:07, error: Dhcp [1002] - The IP address lease 192.168.0.7 for the Network Card with network address 001676292AB4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
27/04/2012 20:01:40, error: Dhcp [1002] - The IP address lease 192.168.0.6 for the Network Card with network address 001676292AB4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
I have attached DDS logs as requested. I hope I have done it right as never had to do this before. Please can someone help with this? Many thanks.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by [removed] at 21:00:21 on 2012-05-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.224 [GMT 1:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uSearch Page =
uSearch Bar =
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&c ... channel=uk
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant =
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\netgea~1.lnk - c:\program files\netgear\wg111v2\WG111v2.exe
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: cnet.com\download
Trusted Zone: download.com
Trusted Zone: facebook.com\apps
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/softwareupdate/ ... TSUEng.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/200 ... oader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://homebase.2020.net/Core/Player/20 ... _Win32.cab
DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} - hxxp://www.mypixmania.com/uk/uk/importe ... loader.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {36C17E9B-3354-11D1-95CF-0000B4530F04} - hxxp://85.189.44.185/Baxi/Plugins/GFXVIEW.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.snapfish.co.uk/SnapfishUKActivia.cab
DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} - hxxp://tools.ebayimg.com/eps/wl/activex ... 0-3-48.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by121fd.bay121.hotmail.msn.com/r ... nPUpld.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.tescophoto.com/wpp/tescophot ... oader5.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resourc ... oscan8.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/ ... TSUEng.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/200 ... ader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/softwa ... Plugin.cab
DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} - hxxp://www.bootsdigitalphotocentre.com/ ... loader.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/Me ... b56907.cab
DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} - hxxp://help.broadbandassist.com/prequal ... reQual.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} - hxxp://static.photobox.co.uk/sg/common/uploader_uni.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/ ... /CTPID.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{080A986A-0035-43D7-9415-7F9A2C015E7E} : DhcpNameServer = 192.168.0.1
AppInit_DLLs:
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 http://www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-5-10 11608]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-5-10 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-5-10 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-5-10 66616]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-16 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-16 136176]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [2010-12-1 16968]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-5-2 40776]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2006-11-20 182784]
.
=============== Created Last 30 ================
.
2012-05-02 14:44:08 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-05-01 19:15:17 -------- d-----w- c:\documents and settings\all users\application data\boost_interprocess
2012-05-01 18:23:50 -------- d-----w- c:\documents and settings\stephanie\local settings\application data\Ilivid Player
2012-04-25 14:55:15 -------- d-----w- c:\documents and settings\all users\application data\DivX
.
==================== Find3M ====================
.
2012-04-04 14:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-01 01:25:04 832512 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 01:25:03 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-03-01 01:25:03 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-01 01:25:03 17408 ----a-w- c:\windows\system32\corpol.dll
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-03 09:22:18 1860096 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 21:02:17.75 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 02/06/2006 15:41:23
System Uptime: 02/05/2012 20:47:20 (1 hours ago)
.
Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 70 GiB total, 7.608 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP385: 17/02/2012 08:07:18 - System Checkpoint
RP386: 18/02/2012 09:23:09 - System Checkpoint
RP387: 19/02/2012 09:46:06 - System Checkpoint
RP388: 20/02/2012 13:46:01 - System Checkpoint
RP389: 21/02/2012 08:00:42 - Software Distribution Service 3.0
RP390: 22/02/2012 09:07:12 - System Checkpoint
RP391: 23/02/2012 13:37:25 - System Checkpoint
RP392: 24/02/2012 16:46:38 - System Checkpoint
RP393: 25/02/2012 22:02:19 - System Checkpoint
RP394: 27/02/2012 08:02:15 - System Checkpoint
RP395: 28/02/2012 08:28:59 - System Checkpoint
RP396: 29/02/2012 09:04:56 - System Checkpoint
RP397: 01/03/2012 16:50:15 - System Checkpoint
RP398: 02/03/2012 18:13:58 - System Checkpoint
RP399: 03/03/2012 21:10:20 - System Checkpoint
RP400: 05/03/2012 09:01:58 - System Checkpoint
RP401: 06/03/2012 17:32:34 - System Checkpoint
RP402: 07/03/2012 20:33:11 - System Checkpoint
RP403: 09/03/2012 12:15:48 - System Checkpoint
RP404: 10/03/2012 14:20:03 - System Checkpoint
RP405: 11/03/2012 14:40:11 - System Checkpoint
RP406: 13/03/2012 08:43:57 - System Checkpoint
RP407: 14/03/2012 08:00:26 - Software Distribution Service 3.0
RP408: 15/03/2012 08:40:47 - System Checkpoint
RP409: 16/03/2012 08:52:28 - System Checkpoint
RP410: 17/03/2012 11:55:11 - System Checkpoint
RP411: 18/03/2012 15:59:56 - System Checkpoint
RP412: 20/03/2012 07:02:30 - System Checkpoint
RP413: 21/03/2012 09:51:58 - System Checkpoint
RP414: 22/03/2012 13:02:18 - System Checkpoint
RP415: 23/03/2012 13:06:01 - System Checkpoint
RP416: 24/03/2012 15:57:42 - System Checkpoint
RP417: 25/03/2012 21:51:22 - System Checkpoint
RP418: 27/03/2012 09:27:58 - System Checkpoint
RP419: 28/03/2012 13:41:30 - System Checkpoint
RP420: 29/03/2012 16:06:01 - System Checkpoint
RP421: 30/03/2012 19:24:33 - System Checkpoint
RP422: 31/03/2012 21:07:38 - System Checkpoint
RP423: 01/04/2012 21:21:36 - System Checkpoint
RP424: 03/04/2012 10:15:26 - System Checkpoint
RP425: 04/04/2012 15:35:02 - System Checkpoint
RP426: 09/04/2012 17:11:22 - System Checkpoint
RP427: 10/04/2012 22:18:18 - System Checkpoint
RP428: 12/04/2012 08:24:05 - System Checkpoint
RP429: 12/04/2012 23:33:58 - Software Distribution Service 3.0
RP430: 14/04/2012 10:23:28 - System Checkpoint
RP431: 15/04/2012 14:37:01 - System Checkpoint
RP432: 16/04/2012 21:07:05 - System Checkpoint
RP433: 18/04/2012 09:21:59 - System Checkpoint
RP434: 19/04/2012 09:23:39 - System Checkpoint
RP435: 20/04/2012 13:40:26 - System Checkpoint
RP436: 21/04/2012 15:18:24 - System Checkpoint
RP437: 22/04/2012 20:38:04 - System Checkpoint
RP438: 23/04/2012 21:09:43 - System Checkpoint
RP439: 25/04/2012 10:15:45 - System Checkpoint
RP440: 26/04/2012 16:21:32 - System Checkpoint
RP441: 27/04/2012 21:17:44 - System Checkpoint
RP442: 29/04/2012 09:44:42 - System Checkpoint
RP443: 01/05/2012 07:26:15 - System Checkpoint
RP444: 02/05/2012 12:57:32 - System Checkpoint
RP445: 02/05/2012 20:48:54 - Restore Operation
.
==== Installed Programs ======================
.
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.1
Adobe Shockwave Player 11.5
Amazon MP3 Downloader 1.0.8
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ARTEuro
Avira AntiVir Personal - Free Antivirus
Bonjour
BroadJump Client Foundation
BurnPlugin for Audible
CCleaner
Compatibility Pack for the 2007 Office system
Dell CinePlayer
Dell Driver Reset Tool
Dell System Restore
Dropbox
EPSON Printer Software
FinePixViewer Ver.4.0
FUJIFILM USB Driver
Google Chrome
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImageMixer VCD for FinePix
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
Intel(R) PROSet for Wired Connections
iTunes
Java Auto Updater
Java(TM) 6 Update 29
Learn2 Player (Uninstall Only)
Malwarebytes Anti-Malware version 1.61.0.1400
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Professional
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.9
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft WinUsb 1.0
MobileMe Control Panel
MSVC80_x86
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML4 Parser
NETGEAR WG111v2 wireless USB 2.0 adapter
QuickTime
RAW FILE CONVERTER LE
RealPlayer
Roxio DLA
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB2482017)
Security Update for Windows Internet Explorer 7 (KB2544521)
Security Update for Windows Internet Explorer 7 (KB2618444)
Security Update for Windows Internet Explorer 7 (KB2647516)
Security Update for Windows Internet Explorer 7 (KB2675157)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Segoe UI
Sibelius Scorch (ActiveX Only)
Sky Go Desktop
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
Spotify
Spybot - Search & Destroy
SUPERAntiSpyware
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows XP Service Pack 3
.
==== Event Viewer Messages From Past Week ========
.
30/04/2012 19:48:34, error: Dhcp [1002] - The IP address lease 192.168.0.2 for the Network Card with network address 001676292AB4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
30/04/2012 07:43:36, error: WPDMTPDriver [15300] -
28/04/2012 19:46:48, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.
27/04/2012 22:24:15, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.0.2 with the system having network hardware address F0:B4:79:6B:D7:9D. Network operations on this system may be disrupted as a result.
27/04/2012 22:24:07, error: Dhcp [1002] - The IP address lease 192.168.0.7 for the Network Card with network address 001676292AB4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
27/04/2012 20:01:40, error: Dhcp [1002] - The IP address lease 192.168.0.6 for the Network Card with network address 001676292AB4 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
textbox. Do not include the word Code
.