DDS--------------------------------------------------
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Administrator at 19:00:18 on 2011-06-24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1271.291 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Cherry\CDI\CDI.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Fore! Reservations\PMSHOST.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Fore! Reservations\4MCServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Cherry\KeyMan\KeyMan.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
C:\Documents and Settings\Administrator.MCGOLF\Local Settings\Apps\2.0\6OP74KL6.TK0\CZZX665B.GOV\goog...app_f84b370c827b5c7a_0001.0003_5cbb67db0893f7c4\GoogleUpdateSetup.exe
C:\DOCUME~1\ADMINI~1.MCG\LOCALS~1\Temp\GUM15.tmp\GoogleUpdate.exe
C:\Documents and Settings\Administrator.MCGOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Administrator.MCGOLF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\Administrator.MCGOLF\Local Settings\Temporary Internet Files\Content.IE5\0ARHDS4U\prpfsfyd[1].exe
C:\DOCUME~1\ADMINI~1.MCG\LOCALS~1\Temp\SSUPDATE.EXE
C:\Documents and Settings\Administrator.MCGOLF\Local Settings\Application Data\Google\Update\Install\{A17EA3C3-F67C-4F71-B922-27D597FC8135}\chrome_installer.exe
C:\DOCUME~1\ADMINI~1.MCG\LOCALS~1\Temp\CR_2FF05.tmp\setup.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uSearch Bar = hxxp://go.compaq.com/1Q00CDT/0409/bl8.asp
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [UnHackMe Monitor] c:\program files\unhackme\hackmon.exe
uRun: [Google Update] "c:\documents and settings\administrator.mcgolf\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [srmclean] c:\cpqs\scom\srmclean.exe
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [CherryKeyMan] "c:\program files\cherry\keyman\KeyMan.exe"
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
mPolicies-system: LogonType = 0 (0x0)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142976313356
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1142979571656
DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} - hxxp://www.gamehouse.com/games/tumblebugs/axhost.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://www.gamehouse.com/games/SproutLauncher.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v10.cab
TCP: Interfaces\{43160C12-5AAB-44C2-9ED1-80DBCAEFA1AE} : NameServer = 8.8.8.8,8.8.4.4
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl903fe4a3;MpKsl903fe4a3;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae175374-6e51-45f9-95df-2449e94ee0dc}\MpKsl903fe4a3.sys [2011-6-24 28752]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 4Internet;Fore! Internet;c:\program files\fore! reservations\4Internet.exe [2010-2-23 352544]
R2 4MCServe;Fore! Reservations PMS Remoting Server;c:\program files\fore! reservations\4MCServ.exe [2007-8-29 50296]
R2 Cherry Device Interface;Cherry Device Interface;c:\program files\cherry\cdi\CDI.exe [2005-8-3 569390]
R2 PMSHost;Fore! PMS Host;c:\program files\fore! reservations\PMSHOST.EXE [2007-6-10 83336]
R3 Ch2kPS2;Cherry PS/2 Keyboard Driver (CDI);c:\windows\system32\drivers\Ch2kPS2.sys [2005-4-29 134254]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2011-6-23 35816]
S1 MpKslead83d7e;MpKslead83d7e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae175374-6e51-45f9-95df-2449e94ee0dc}\MpKslead83d7e.sys [2011-6-24 28752]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-6-12 366640]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [2011-6-23 24416]
.
=============== Created Last 30 ================
.
2011-06-24 23:49:36 -------- d-----w- c:\documents and settings\administrator.mcgolf\local settings\application data\Deployment
2011-06-24 22:19:31 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae175374-6e51-45f9-95df-2449e94ee0dc}\MpKsl903fe4a3.sys
2011-06-24 19:44:39 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae175374-6e51-45f9-95df-2449e94ee0dc}\MpKslead83d7e.sys
2011-06-23 23:06:32 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ae175374-6e51-45f9-95df-2449e94ee0dc}\mpengine.dll
2011-06-23 18:57:55 20552 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-06-23 18:52:42 24416 ----a-w- c:\windows\system32\drivers\regguard.sys
2011-06-23 18:48:53 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
2011-06-23 18:48:52 39192 ----a-w- c:\windows\system32\Partizan.exe
2011-06-23 18:48:40 2 --shatr- c:\windows\winstart.bat
2011-06-23 18:48:34 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-06-23 18:48:15 12808 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2011-06-23 18:47:40 -------- d-----w- c:\program files\UnHackMe
2011-06-23 18:47:23 -------- d-----w- c:\documents and settings\all users\application data\Hitman Pro
2011-06-17 04:57:47 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-13 17:19:06 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-06-13 17:12:49 -------- d-----w- c:\program files\CCleaner
2011-06-13 15:45:58 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-06-13 15:45:58 -------- d-----w- c:\documents and settings\administrator.mcgolf\application data\SUPERAntiSpyware.com
2011-06-13 15:45:42 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-12 15:16:27 -------- d-----w- c:\program files\Microsoft Security Client
2011-06-12 13:22:28 -------- d-----w- c:\documents and settings\administrator.mcgolf\application data\Malwarebytes
2011-06-12 13:22:17 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-12 13:22:16 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-06-12 13:22:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-12 11:54:04 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-12 11:44:12 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-06-12 11:44:12 -------- d-----w- c:\windows\system32\wbem\Repository
.
==================== Find3M ====================
.
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
============= FINISH: 19:04:58.93 ===============
EDIT: Posts merged ~Budapest
This post has been edited by Budapest: 26 June 2011 - 06:15 PM

Help
This topic is locked

Back to top











