.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_25
Run by Eli at 1:35:19 on 2011-05-31
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.734.105 [GMT 8:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\AVAST Software\Avast\avastUI.exe
D:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
D:\Program Files\uTorrent\uTorrent.exe
D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
D:\Program Files\IVT Corporation\BlueSoleil\BsMobileCS.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\WINDOWS\system32\imapi.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\mIRC\mirc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
D:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Eli\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mWinlogon: Taskman=c:\recycler\r-1-5-21-1482476501-1644491937-682003330-1013\acleaner.exe
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - d:\program files\avast software\avast\aswWebRepIE.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - d:\program files\avast software\avast\aswWebRepIE.dll
uRun: [uTorrent] "d:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [Messenger (Yahoo!)] "d:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [avast] "d:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [BtTray] "d:\program files\ivt corporation\bluesoleil\BtTray.exe"
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mirc.lnk - d:\program files\mirc\mirc.exe
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
uPolicies-explorer: MemCheckBoxInRunDlg = 1 (0x1)
mPolicies-explorer: MemCheckBoxInRunDlg = 1 (0x1)
mPolicies-explorer: StartMenuFavorites = 0 (0x0)
mPolicies-explorer: Start_ShowMyComputer = 1 (0x1)
mPolicies-explorer: Start_ShowMyDocs = 1 (0x1)
mPolicies-explorer: Start_ShowMyMusic = 0 (0x0)
mPolicies-explorer: Start_ShowRun = 1 (0x1)
mPolicies-explorer: Start_ShowSearch = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
dPolicies-explorer: MemCheckBoxInRunDlg = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: Send by Bluetooth - d:\program files\ivt corporation\bluesoleil\transsend\ie\tsinfo.htm
IE: Send via &Message... - d:\program files\ivt corporation\bluesoleil\transsend\ie\tssms.htm
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\windows\system32\skype4com.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\eli\application data\mozilla\firefox\profiles\xutztpmi.default\
FF - plugin: c:\program files\windows media player\npdrmv2.dll
FF - plugin: c:\program files\windows media player\npdsplay.dll
FF - plugin: c:\program files\windows media player\npwmsdrm.dll
FF - plugin: d:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2010-4-6 20744]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2007-3-26 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2007-3-26 52224]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-11 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-11 307928]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-11 19544]
R2 avast! Antivirus;avast! Antivirus;d:\program files\avast software\avast\AvastSvc.exe [2011-4-11 42184]
R2 BsMobileCS;BsMobileCS;d:\program files\ivt corporation\bluesoleil\BsMobileCS.exe [2009-2-27 143467]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2010-4-6 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2010-4-6 26248]
S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\drivers\btcomport.sys --> c:\windows\system32\drivers\btcomport.sys [?]
S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\drivers\btcombus.sys --> c:\windows\system32\drivers\btcombus.sys [?]
.
=============== File Associations ===============
.
.txt=Notepad++_file
.
=============== Created Last 30 ================
.
2011-05-30 17:12:34 28672 -c--a-w- c:\windows\system32\01.exe
2011-05-30 16:58:41 28672 -c--a-w- c:\windows\system32\16.exe
2011-05-30 16:55:33 28672 -c--a-w- c:\windows\system32\30.exe
2011-05-30 16:53:39 28672 -c--a-w- c:\windows\system32\14.exe
2011-05-30 16:15:00 98816 -c--a-w- c:\windows\sed.exe
2011-05-30 16:15:00 518144 -c--a-w- c:\windows\SWREG.exe
2011-05-30 16:15:00 256512 -c--a-w- c:\windows\PEV.exe
2011-05-30 16:15:00 208896 -c--a-w- c:\windows\MBR.exe
2011-05-30 16:14:52 -------- dcs---w- C:\ComboFix
2011-05-30 14:44:41 0 -c--a-r- C:\logwmemory.bin
2011-05-30 12:32:18 -------- dc----w- c:\windows\system32\wbem\snmp
2011-05-30 12:32:18 -------- dc----w- c:\windows\system32\oobe
2011-05-30 12:32:17 -------- dc----w- d:\program files\windows nt
2011-05-30 12:32:17 -------- dc----w- d:\program files\msn gaming zone
2011-05-30 12:32:17 -------- dc----w- c:\windows\system32\xircom
2011-05-30 12:32:17 -------- dc----w- c:\windows\srchasst
2011-05-30 12:32:14 -------- dc----w- c:\windows\system32\inetsrv
2011-05-30 12:12:49 -------- dcsha-r- C:\cmdcons
2011-05-30 07:56:53 -------- dc----w- c:\documents and settings\eli\application data\Malwarebytes
2011-05-30 07:56:13 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-30 07:56:12 -------- dc----w- c:\documents and settings\all users\application data\Malwarebytes
2011-05-30 07:56:09 20952 -c--a-w- c:\windows\system32\drivers\mbam.sys
2011-05-30 07:56:09 -------- dc----w- d:\program files\Malwarebytes' Anti-Malware
2011-05-19 09:48:28 -------- dc----w- c:\documents and settings\eli\local settings\application data\Help
2011-05-19 09:05:31 -------- dc----w- c:\documents and settings\eli\local settings\application data\Easy CD-DA Extractor
2011-05-19 09:05:21 -------- dc----w- c:\documents and settings\all users\application data\Easy CD-DA Extractor
2011-05-19 09:05:15 -------- dc----w- d:\program files\Easy CD-DA Extractor 12
2011-05-19 09:05:15 -------- dc----w- c:\windows\Easy CD-DA Extractor 12
2011-05-09 13:25:36 290304 -c--a-w- c:\windows\upx.exe
2011-05-09 12:38:40 73728 -c--a-w- c:\windows\system32\javacpl.cpl
2011-05-09 11:52:06 -------- dc----w- c:\documents and settings\eli\local settings\application data\uTorrent
2011-05-09 11:28:28 -------- dc----w- d:\program files\Resource Kit
2011-05-06 08:48:40 -------- dc----w- c:\documents and settings\eli\application data\.minecraft
2011-05-04 06:57:57 -------- dc----w- d:\program files\PopCap Games
2011-05-03 12:20:52 -------- dc----w- d:\program files\GameHouse
2011-05-03 11:58:54 -------- dc----w- c:\windows\.jagex_cache_32
2011-05-01 07:38:51 12160 -c--a-w- c:\windows\system32\drivers\mouhid.sys
2011-05-01 07:37:30 10368 -c--a-w- c:\windows\system32\drivers\hidusb.sys
.
==================== Find3M ====================
.
2011-05-10 12:10:59 40112 -c--a-w- c:\windows\avastSS.scr
2011-05-10 12:03:54 441176 -c--a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-09 12:38:09 472808 -c--a-w- c:\windows\system32\deployJava1.dll
2011-04-16 16:15:31 106557 -c--a-w- c:\windows\system32\btw_ci.dll
2011-04-11 15:00:41 401408 -c--a-w- c:\windows\system32\wget.exe
2011-04-11 06:28:15 404640 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-03-04 19:44:14 59888 -c----w- c:\windows\system32\pxwma.dll
2011-03-04 19:44:14 45648 -c----w- c:\windows\system32\drivers\PxHelp20.sys
2011-03-04 19:44:14 133616 -c----w- c:\windows\system32\pxafs.dll
2011-03-04 19:44:12 9200 -c----w- c:\windows\system32\drivers\cdralw2k.sys
2011-03-04 19:44:12 9072 -c----w- c:\windows\system32\drivers\cdr4_xp.sys
2011-03-04 19:44:12 126448 -c----w- c:\windows\system32\pxinsi64.exe
2011-03-04 19:44:12 123888 -c----w- c:\windows\system32\pxcpyi64.exe
.
============= FINISH: 1:39:51.04 ===============
Attached File(s)
-
attach.txt (14.38K)
Number of downloads: 1

Help
This topic is locked

Back to top
button.









