Thanks for your last reply greyknight,
Here is the log from the DSS ,
Also i have found i cannot get into Device Manager and i cant turn on the firewall when i click on the firewall it says the device is not running when i choose to start it i cannot switch on the firewall its permenanly off.
Please Help
Deckard's System Scanner v20071014.68
Run by J B on 2008-01-30 19:38:35
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 511 MiB (512 MiB recommended).
-- HijackThis (run as J B.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:38:45, on 30/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\odbcconf.exe
C:\WINDOWS\odbconf32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SCARDS32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\J B\My Documents\win tools\dss.exe
C:\DOCUME~1\JB0176~1\MYDOCU~1\HIJACK~1\JBB813~1.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2K0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.euro.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) -
http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/clien...uweb_si
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DirMS_Defragmentation - Unknown owner - C:\Program Files\MATCO\DirmsService.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: odbcconf - Unknown owner - C:\WINDOWS\odbcconf.exe
O23 - Service: odbconf32 - Unknown owner - C:\WINDOWS\odbconf32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SIM Manager SCARD Service (TWKSCARDSRV) - TOWITOKO - German Technology - C:\WINDOWS\SCARDS32.EXE
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 4914 bytes
-- Files created between 2007-12-30 and 2008-01-30 -----------------------------
2008-01-27 13:15:49 849920 --a------ C:\sdf.exe
2008-01-27 02:27:08 849920 -r-hs---- C:\WINDOWS\odbconf32.exe
2008-01-26 22:13:45 0 d-------- C:\Program Files\Data Doctor Recovery - SIM Card
2008-01-26 11:13:01 135168 --a------ C:\WINDOWS\u39v22.exe <Not Verified; ; rm2303 Application>
2008-01-26 11:13:01 34332 --a------ C:\WINDOWS\system\SER9PL.sys <Not Verified; Prolific Technology Inc.; USB-Serial Bridge Cable>
2008-01-26 11:13:01 0 d-------- C:\sim_scan
2008-01-26 11:12:55 0 d-------- C:\Program Files\GSM SIM Utility
2008-01-19 10:32:13 0 d-------- C:\Program Files\Bytescout XLS Viewer
2008-01-18 20:29:06 0 d-------- C:\Program Files\BreakPoint Software
2008-01-18 20:05:18 820736 -r-hs---- C:\WINDOWS\odbcconf.exe
2008-01-18 11:35:24 0 d-------- C:\Documents and Settings\J B\Application Data\Nero
2008-01-18 11:31:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-01-15 13:53:17 0 d-------- C:\Program Files\Data Doctor Recovery NTFS
2008-01-15 12:57:18 0 d-------- C:\Program Files\Registrar Registry Manager
2008-01-15 10:50:00 1107 --a------ C:\WINDOWS\system32\HexStudio.dll
2008-01-15 10:50:00 1068 --a------ C:\WINDOWS\system32\HexData.dll
2008-01-13 12:23:27 0 d-------- C:\Program Files\xStarter
2008-01-13 12:22:52 0 d-------- C:\Program Files\VAG-COM
2008-01-09 11:58:04 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus>
2008-01-09 11:49:57 0 d-------- C:\WINDOWS\SxsCaPendDel
2008-01-07 14:02:03 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-01-05 16:15:01 0 d-------- C:\Program Files\MATCO
2008-01-03 17:50:27 0 d-------- C:\Documents and Settings\LocalService\Application Data\Identities
2008-01-03 17:47:45 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-03 17:47:45 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-01-03 17:47:45 81920 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-01-03 17:47:44 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-01-03 17:47:44 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-01-03 17:47:44 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-03 17:13:18 1694 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-03 12:51:27 0 d-------- C:\Program Files\Common Files\BitDefender
2007-12-31 15:59:04 0 d-------- C:\WINDOWS\BDOSCAN8
-- Find3M Report ---------------------------------------------------------------
2008-01-27 12:26:14 0 d-------- C:\Documents and Settings\J B\Application Data\Azureus
2008-01-26 11:12:55 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-20 10:38:32 0 d-------- C:\Documents and Settings\J B\Application Data\Adobe
2008-01-18 11:33:50 0 d-------- C:\Program Files\Common Files\Nero
2008-01-18 11:31:24 0 d-------- C:\Program Files\Nero
2008-01-18 11:25:13 0 d-------- C:\Program Files\Common Files\Ahead
2008-01-14 14:34:39 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-11 10:59:58 0 d-------- C:\Program Files\Java
2008-01-09 21:12:39 0 d-------- C:\Program Files\eBay
2008-01-09 12:37:14 0 d-------- C:\Program Files\WS_FTP Pro
2008-01-09 12:27:24 0 d-------- C:\Program Files\Common Files\LightScribe
2008-01-06 18:29:30 0 d-a------ C:\Program Files\Common Files
2008-01-03 12:30:32 0 d-------- C:\Documents and Settings\J B\Application Data\AVG7
2008-01-02 18:43:17 0 d-------- C:\Documents and Settings\J B\Application Data\Vso
2007-12-28 14:45:56 0 d-------- C:\Documents and Settings\J B\Application Data\Grisoft
2007-12-28 00:12:28 0 d-------- C:\Program Files\QuickTime
2007-12-27 19:13:26 90112 --a------ C:\WINDOWS\VMSnap23 .exe
2007-12-27 19:13:22 778318 --a------ C:\WINDOWS\system32\wltray .exe <Not Verified; Belkin Corporation; Belkin 802.11 Network Adapter Wireless Network Tray Applet>
2007-12-27 19:13:18 0 d-------- C:\Program Files\PowerISO
2007-12-27 18:34:31 0 d-------- C:\Program Files\Common Files\SWF Studio
2007-12-24 22:30:03 0 d-------- C:\Documents and Settings\J B\Application Data\NeroDCTemplates
2007-12-24 13:04:02 0 d-------- C:\Program Files\Azureus
2007-12-21 12:07:08 0 d-------- C:\Program Files\Blaze Media Pro
2007-12-21 11:23:39 0 d-------- C:\Program Files\MagicISO
2007-12-20 21:07:40 0 d-------- C:\Program Files\Alcohol Soft
2007-12-20 20:27:09 0 d-------- C:\Program Files\Elaborate Bytes
2007-12-20 20:26:28 0 d-------- C:\Program Files\SlySoft
2007-12-19 14:19:18 38400 --a------ C:\WINDOWS\wl.exe <Not Verified; AMF; WinLock>
2007-12-19 14:13:52 73216 --a------ C:\WINDOWS\WinLockDll.dll <Not Verified; AMF; WinLock>
2007-12-19 11:58:07 0 d-------- C:\Program Files\EPSON Print CD
2007-12-12 22:23:54 0 d-------- C:\Documents and Settings\J B\Application Data\WinRAR
2007-12-09 19:54:48 0 d-------- C:\Documents and Settings\J B\Application Data\CyberLink
2007-12-09 19:54:45 0 d-------- C:\Program Files\CyberLink
2007-12-07 18:23:56 0 d-------- C:\Program Files\acar
2007-12-07 17:56:00 0 d-------- C:\Program Files\WMA To MP3 Encoder
2007-11-20 17:36:32 5248 --a------ C:\WINDOWS\system32\giveio.sys
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [01/06/2006 16:22]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 09:25]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [01/03/2007 14:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [03/12/2007 14:21]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 07:56]
C:\Documents and Settings\J B\Start Menu\Programs\Startup\
DESKTOP.INI [03/09/2002 09:00:00]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [03/09/2002 09:00:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRun"=0 (0x0)
"NoClose"=0 (0x0)
"NoLogOff"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 8.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\AOL 8.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check 2.lnk]
backup=C:\WINDOWS\pss\EPSON Status Monitor 3 Environment Check 2.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Trend Micro Anti-Spyware.lnk]
backup=C:\WINDOWS\pss\Trend Micro Anti-Spyware.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^J B^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath323Domino]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath323VMSnap]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDefender Antiphishing Helper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DBOX2_Announcer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eyeBeam SIP Client]
"C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RunDLL32.exe NvMCTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCKeyRecorder]
C:\PKRb\PCKEYR~1 .exe /run
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCLEPCI]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask .exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wltray.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{969B3B70-8765-11D5-9809-0050BACBF861}]
rundll32.exe advpack.dll,LaunchINFSection C:\Program Files\CyberLink\MP3PowerEncoder\Cyber.inf,PerUserStub
-- End of Deckard's System Scanner: finished at 2008-01-30 19:39:07 ------------