| thanks for a quick reply. I had carried out the instructions to run SDfix. However the problem seems to stay. although logged as administrator the admin rights were not run for SD fix programme.
The report of SD fix is as under
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
driver loading error disk not found C:\
please note that you need administrator rights to perform deep scan
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "E:\\ROADRASH\\ROADRASH.EXE"="E:\\ROADRASH\\ROADRASH.EXE:*:Enabled:Road Rash for Windows 95 Executable"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[b]Remaining Files [/b]:
[b]Files with Hidden Attributes [/b]:
Wed 4 Aug 2004 93,184 A.SH. --- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" Wed 4 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe" Wed 4 Aug 2004 4,639 A.SH. --- "C:\Program Files\Windows Media Player\mplayer2.exe" Wed 4 Aug 2004 73,728 A.SH. --- "C:\Program Files\Windows Media Player\wmplayer.exe" Wed 8 Jan 2003 38,400 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0001.tmp" Wed 8 Jan 2003 21,504 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0003.tmp" Wed 8 Jan 2003 30,720 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0004.tmp" Wed 8 Jan 2003 22,016 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0005.tmp" Wed 8 Jan 2003 38,912 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0006.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0291.tmp" Wed 8 Jan 2003 26,112 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0414.tmp" Wed 8 Jan 2003 35,328 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0487.tmp" Wed 8 Jan 2003 58,368 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0741.tmp" Wed 8 Jan 2003 56,832 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL0762.tmp" Wed 8 Jan 2003 44,544 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1318.tmp" Wed 8 Jan 2003 40,960 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1509.tmp" Wed 8 Jan 2003 54,784 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1593.tmp" Wed 8 Jan 2003 38,912 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1610.tmp" Wed 8 Jan 2003 55,808 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1640.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1829.tmp" Wed 8 Jan 2003 28,160 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1923.tmp" Wed 8 Jan 2003 45,568 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL1928.tmp" Wed 8 Jan 2003 30,720 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2040.tmp" Wed 8 Jan 2003 30,720 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2048.tmp" Wed 8 Jan 2003 47,616 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2110.tmp" Wed 8 Jan 2003 52,224 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2387.tmp" Wed 8 Jan 2003 46,080 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2468.tmp" Wed 8 Jan 2003 46,592 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2506.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2619.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2739.tmp" Wed 8 Jan 2003 31,744 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2757.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2783.tmp" Wed 8 Jan 2003 23,552 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2829.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL2841.tmp" Wed 8 Jan 2003 58,368 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3001.tmp" Wed 8 Jan 2003 26,624 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3135.tmp" Wed 8 Jan 2003 29,184 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3240.tmp" Wed 8 Jan 2003 27,648 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3276.tmp" Wed 8 Jan 2003 45,568 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3478.tmp" Wed 8 Jan 2003 58,368 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3514.tmp" Wed 8 Jan 2003 57,344 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3560.tmp" Fri 17 Jan 2003 23,040 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3586.tmp" Wed 8 Jan 2003 57,856 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3878.tmp" Fri 17 Jan 2003 22,016 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL3893.tmp" Wed 8 Jan 2003 23,040 ...H. --- "C:\Documents and Settings\Administrator\Desktop\~WRL4040.tmp" Thu 18 Nov 2004 94,458 ...H. --- "C:\Program Files\Nero\data\Nero PhotoShow Express.exe" Wed 8 Jan 2003 109,056 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\~WRL3107.tmp" Thu 9 Jan 2003 110,592 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\~WRL4011.tmp" Wed 8 Jan 2003 27,648 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL0049.tmp" Thu 9 Jan 2003 101,888 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL0459.tmp" Thu 9 Jan 2003 41,472 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL0568.tmp" Thu 9 Jan 2003 47,104 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL0843.tmp" Thu 9 Jan 2003 49,152 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1013.tmp" Thu 9 Jan 2003 81,920 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1074.tmp" Thu 9 Jan 2003 40,448 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1093.tmp" Thu 9 Jan 2003 49,664 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1225.tmp" Thu 9 Jan 2003 54,784 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1584.tmp" Thu 9 Jan 2003 116,224 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1716.tmp" Thu 9 Jan 2003 86,016 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1806.tmp" Wed 8 Jan 2003 37,376 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL1896.tmp" Wed 8 Jan 2003 24,576 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL2217.tmp" Thu 9 Jan 2003 93,696 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL2298.tmp" Thu 9 Jan 2003 112,640 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL2637.tmp" Thu 9 Jan 2003 95,744 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL2877.tmp" Wed 8 Jan 2003 26,624 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL2932.tmp" Thu 9 Jan 2003 73,728 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL3161.tmp" Wed 8 Jan 2003 26,624 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL3693.tmp" Thu 9 Jan 2003 65,024 ...H. --- "C:\Documents and Settings\Administrator\Desktop\word docs\ICP\~WRL4027.tmp"
[b]Finished![/b]
the log of hijack this is as under
Running processes: C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\notepad.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F2 - REG:system.ini: UserInit=userinit.exe,New Folder.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{00CA385E-2EE9-414D-AB7E-0BDA534EE0F0}: NameServer = 218.248.240.24 218.248.240.23 O17 - HKLM\System\CS1\Services\Tcpip\..\{00CA385E-2EE9-414D-AB7E-0BDA534EE0F0}: NameServer = 218.248.240.24 218.248.240.23 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
|