Scan saved at 04:24:53 AM, on 1/1/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
c:Program FilesMicrosoft Security EssentialsMsMpEng.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32hkcmd.exe
C:PROGRA~1SBCSEL~1SMARTB~1MotiveSB.exe
C:Program FilesJavajre1.6.0_06binjusched.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32rundll32.exe
C:Program FilesMicrosoft Security Essentialsmsseces.exe
c:PROGRA~1COMMON~1MICROS~1DWDW20.EXE
C:WINDOWSsystem32rundll32.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:WINDOWSsystem32rundll32.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:WINDOWSpchealthhelpctrbinarieshelpctr.exe
C:WINDOWSPCHealthHelpCtrBinariesHelpSvc.exe
C:Documents and SettingsOwnerDesktopHiJackThis2HijackThis.exe
C:WINDOWSsystem32spider.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_06binssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:Program FilesYahoo!CompanionInstallscpnYTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:Program FilesYahoo!CompanionInstallscpnyt.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM..Run: [IgfxTray] C:WINDOWSSystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSSystem32hkcmd.exe
O4 - HKLM..Run: [Motive SmartBridge] C:PROGRA~1SBCSEL~1SMARTB~1MotiveSB.exe
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_06binjusched.exe"
O4 - HKLM..Run: [MSSE] "c:Program FilesMicrosoft Security Essentialsmsseces.exe" -hide
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_06binssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe (file missing)
O15 - Trusted Zone: *.att.net
O15 - Trusted Zone: http://*.att.net
O15 - Trusted Zone: www.ebay.com
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: *.sbcglobal.net
O15 - Trusted Zone: http://*.sbcglobal.net
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} -
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1211409827093
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:Program FilesCommon FilesInstallShieldDriver1150Intel 32IDriverT.exe
O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:Program FilesMicrosoft Windows OneCare Livewinss.exe (file missing)
--
End of file - 4756 bytes
DDS (Ver_09-12-01.01) - NTFSx86
Run by Owner at 23:54:39.78 on Fri 01/01/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.126.21 [GMT -5:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:WINDOWSsystem32svchost -k DcomLaunch
svchost.exe
c:Program FilesMicrosoft Security EssentialsMsMpEng.exe
C:WINDOWSSystem32svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:WINDOWSsystem32spoolsv.exe
svchost.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1SBCSEL~1SMARTB~1MotiveSB.exe
C:Program FilesJavajre1.6.0_06binjusched.exe
C:Program FilesMicrosoft Security Essentialsmsseces.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32taskmgr.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:Documents and SettingsOwnerDesktopdds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:program filesyahoo!companioninstallscpnyt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:program filesyahoo!companioninstallscpnyt.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:program filesjavajre1.6.0_06binssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:program filesyahoo!companioninstallscpnYTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:program filesyahoo!companioninstallscpnyt.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [SUPERAntiSpyware] c:program filessuperantispywareSUPERAntiSpyware.exe
mRun: [IgfxTray] c:windowssystem32igfxtray.exe
mRun: [HotKeysCmds] c:windowssystem32hkcmd.exe
mRun: [Motive SmartBridge] c:progra~1sbcsel~1smartb~1MotiveSB.exe
mRun: [SunJavaUpdateSched] "c:program filesjavajre1.6.0_06binjusched.exe"
mRun: [MSSE] "c:program filesmicrosoft security essentialsmsseces.exe" -hide
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:program filesjavajre1.6.0_06binssv.dll
Trusted Zone: att.net
Trusted Zone: ebay.comwww
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com
Trusted Zone: yahoo.compn1.adserver
DPF: DirectAnimation Java Classes - file://c:windowsjavaclassesdajava.cab
DPF: Microsoft XML Parser for Java - file://c:windowsjavaclassesxmldso.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/swdir8d196a.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211409827093
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: !SASWinLogon - c:program filessuperantispywareSASWINLO.dll
Notify: igfxcui - igfxsrvc.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:program filessuperantispywareSASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 MpFilter;Microsoft Malware Protection Driver;c:windowssystem32driversMpFilter.sys [2009-6-18 142832]
R1 SASKUTIL;SASKUTIL;c:program filessuperantispywareSASKUTIL.SYS [2009-11-23 74480]
R3 SASENUM;SASENUM;c:program filessuperantispywareSASENUM.SYS [2009-11-23 7408]
=============== Created Last 30 ================
2010-01-01 22:21:19 0 d-----w- c:program filescommon filesWise Installation Wizard
2010-01-01 22:10:40 0 d-----w- c:program filesMalwarebytes' Anti-Malware
2010-01-01 06:53:06 0 d-s---w- c:documents and settingsowner%USERPROFILE%
2009-12-29 13:20:24 274288 ----a-w- c:windowssystem32mucltui.dll
2009-12-29 13:20:24 215920 ----a-w- c:windowssystem32muweb.dll
2009-12-29 13:20:24 16736 ----a-w- c:windowssystem32mucltui.dll.mui
2009-12-29 09:43:37 0 d-----w- C:8d1f879bc5941325460c55907fa7
2009-12-29 09:34:09 195456 ------w- c:windowssystem32MpSigStub.exe
2009-12-29 09:28:25 0 d-----w- c:program filesMicrosoft Security Essentials
2009-12-29 05:06:31 25992 ----a-w- c:windowssystem32pgdfgsvc.exe
2009-12-29 04:55:52 8832 -c--a-w- c:windowssystem32dllcachewmiacpi.sys
2009-12-29 04:54:55 98304 -c--a-w- c:windowssystem32dllcacheverifier.exe
2009-12-29 04:53:57 149376 -c--a-w- c:windowssystem32dllcachetffsport.sys
2009-12-29 04:52:29 58368 -c--a-w- c:windowssystem32dllcachesmiminib.sys
2009-12-29 04:51:51 18400 -c--a-w- c:windowssystem32dllcachesgsmld.sys
2009-12-29 04:50:57 20992 -c--a-w- c:windowssystem32dllcachertl8139.sys
2009-12-29 04:50:57 19017 -c--a-w- c:windowssystem32dllcachertl8029.sys
2009-12-29 04:50:56 30720 -c--a-w- c:windowssystem32dllcacherthwcls.sys
2009-12-29 04:50:54 132608 -c--a-w- c:windowssystem32dllcachersvp.exe
2009-12-29 04:50:53 9216 -c--a-w- c:windowssystem32dllcachersmgrstr.dll
2009-12-29 04:50:52 3840 -c--a-w- c:windowssystem32dllcacherpfun.sys
2009-12-29 04:50:48 79104 -c--a-w- c:windowssystem32dllcacherocket.sys
2009-12-29 04:50:47 37563 -c--a-w- c:windowssystem32dllcacherlnet5.sys
2009-12-29 04:50:46 9728 -c--a-w- c:windowssystem32dllcachereset.exe
2009-12-29 04:50:46 86097 -c--a-w- c:windowssystem32dllcachereslog32.dll
2009-12-29 04:50:02 19584 -c--a-w- c:windowssystem32dllcacherasirda.sys
2009-12-29 04:50:00 899146 -c--a-w- c:windowssystem32dllcacher2mdkxga.sys
2009-12-29 04:50:00 714762 -c--a-w- c:windowssystem32dllcacher2mdmkxx.sys
2009-12-29 04:48:59 39424 -c--a-w- c:windowssystem32dllcacheovcoms.exe
2009-12-29 04:47:59 91488 -c--a-w- c:windowssystem32dllcachen9i3disp.dll
2009-12-29 04:46:56 6528 -c--a-w- c:windowssystem32dllcacheminiqic.sys
2009-12-29 04:45:55 37376 -c--a-w- c:windowssystem32dllcachekousd.dll
2009-12-29 04:45:52 253952 -c--a-w- c:windowssystem32dllcachekdsusd.dll
2009-12-29 04:45:51 48640 -c--a-w- c:windowssystem32dllcachekdsui.dll
2009-12-29 04:44:50 8192 -c--a-w- c:windowssystem32dllcachekbdkor.dll
2009-12-29 04:44:49 8704 -c--a-w- c:windowssystem32dllcachekbdjpn.dll
2009-12-29 04:44:10 14592 -c--a-w- c:windowssystem32dllcachekbdhid.sys
2009-12-29 04:44:00 6144 -c--a-w- c:windowssystem32dllcachekbd106.dll
2009-12-29 04:44:00 5632 -c--a-w- c:windowssystem32dllcachekbd103.dll
2009-12-29 04:42:52 102463 -c--a-w- c:windowssystem32dllcacheimepadsm.dll
2009-12-29 04:41:55 10129408 -c--a-w- c:windowssystem32dllcachehwxkor.dll
2009-12-29 04:40:59 322432 -c--a-w- c:windowssystem32dllcacheg400m.sys
2009-12-29 04:39:11 24618 -c--a-w- c:windowssystem32dllcachefa410nd5.sys
2009-12-29 04:39:10 16074 -c--a-w- c:windowssystem32dllcachefa312nd5.sys
2009-12-29 04:39:08 12362 -c--a-w- c:windowssystem32dllcachef3ab18xi.sys
2009-12-29 04:39:08 11850 -c--a-w- c:windowssystem32dllcachef3ab18xj.sys
2009-12-29 04:39:01 7040 -c--a-w- c:windowssystem32dllcacheexabyte2.sys
2009-12-29 04:39:01 16998 -c--a-w- c:windowssystem32dllcacheex10.sys
2009-12-29 04:37:59 334208 -c--a-w- c:windowssystem32dllcacheds1wdm.sys
2009-12-29 04:36:55 91305 -c--a-w- c:windowssystem32dllcachedimaint.sys
2009-12-29 04:35:55 49792 -c--a-w- c:windowssystem32dllcachecyzport.sys
2009-12-29 04:34:59 49182 -c--a-w- c:windowssystem32dllcachecem56n5.sys
2009-12-29 04:33:57 54271 -c--a-w- c:windowssystem32dllcachebcm42xx5.sys
2009-12-29 04:29:55 101888 -c--a-w- c:windowssystem32dllcacheadpu160m.sys
2009-12-29 04:28:59 66048 -c--a-w- c:windowssystem32dllcaches3legacy.dll
2009-12-24 19:52:13 0 d-sh--w- c:documents and settingsownerIECompatCache
2009-12-24 18:39:53 0 d-sh--w- c:documents and settingsownerPrivacIE
2009-12-24 18:26:31 0 d-sh--w- c:documents and settingsownerIETldCache
2009-12-24 17:54:52 12800 -c----w- c:windowssystem32dllcachexpshims.dll
2009-12-24 17:54:49 55296 -c----w- c:windowssystem32dllcachemsfeedsbs.dll
2009-12-24 17:54:48 594432 -c----w- c:windowssystem32dllcachemsfeeds.dll
2009-12-24 17:54:48 246272 -c----w- c:windowssystem32dllcacheieproxy.dll
2009-12-24 17:54:48 1985536 -c----w- c:windowssystem32dllcacheiertutil.dll
2009-12-24 17:54:45 11069952 -c----w- c:windowssystem32dllcacheieframe.dll
2009-12-24 17:54:14 0 d-----w- c:windowsie8updates
2009-12-24 17:53:24 92160 -c----w- c:windowssystem32dllcacheiecompat.dll
2009-12-24 17:49:59 0 dc-h--w- c:windowsie8
2009-12-24 09:39:55 1089593 -c----w- c:windowssystem32dllcachentprint.cat
2009-12-14 14:34:39 0 ----a-w- c:windowsCyoyoxo.bin
2009-12-14 14:34:36 120 ----a-w- c:windowsLyeseburi.dat
2009-12-14 14:27:23 0 ----a-w- c:windowssystem32driversbvszpf.sys
2009-12-13 22:50:36 0 d-----w- c:docume~1alluse~1applic~1McAfee Security Scan
2009-12-10 00:44:41 0 d-----w- c:docume~1alluse~1applic~1SUPERAntiSpyware.com
2009-12-10 00:43:29 0 d-----w- c:program filesSUPERAntiSpyware
2009-12-10 00:43:28 0 d-----w- c:docume~1ownerapplic~1SUPERAntiSpyware.com
2009-12-10 00:29:13 0 d-----w- c:docume~1ownerapplic~1Malwarebytes
2009-12-10 00:28:54 0 d-----w- c:docume~1alluse~1applic~1Malwarebytes
2009-12-06 07:21:37 235520 ----a-w- c:documents and settingsownersysdump.tar
==================== Find3M ====================
2009-11-30 05:45:03 61224 ----a-w- c:documents and settingsownerGoToAssistDownloadHelper.exe
2009-10-29 07:45:38 916480 ----a-w- c:windowssystem32wininet.dll
2009-10-29 04:48:52 499712 ----a-w- c:windowssystem32msvcp71.dll
2009-10-29 04:48:52 348160 ----a-w- c:windowssystem32msvcr71.dll
2009-10-21 05:38:36 75776 ----a-w- c:windowssystem32strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:windowssystem32httpapi.dll
2009-10-13 10:30:16 270336 ----a-w- c:windowssystem32oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:windowssystem32rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:windowssystem32raschap.dll
============= FINISH: 23:55:51.98 ===============
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/01/01 23:44
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:WINDOWSSystem32Driversdump_atapi.sys
Address: 0xF3A2A000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:WINDOWSSystem32Driversdump_WMILIB.SYS
Address: 0xFCA6B000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:WINDOWSsystem32driversrootrepeal.sys
Address: 0xF3378000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: c:documents and settingsall usersapplication datamicrosoftmicrosoft antimalwaresupportmpwpptracing.bin
Status: Allocation size mismatch (API: 1048576, Raw: 65536)
SSDT
-------------------
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:Program FilesSUPERAntiSpywareSASKUTIL.sys" at address 0xf30510b0
==EOF==
here is the other scan!
also, just so you know i came across a file citrix online go to assist. i'm not sure if thats a windows thing or what?? but i don't have a wireless router and i never added that. i was debating deleting it but i'll wait til i hear back from you!
Attached File(s)
-
Attach.txt (69.84K)
Number of downloads: 18
This post has been edited by garmanma: 06 January 2010 - 11:50 AM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top












