.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by DEMILOVATO at 0:00:51 on 2011-08-04
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3583.2713 [GMT 2:00]
.
AV: BitDefender Antivirus *Enabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Prio\prio_svc.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Tunngle\TnglCtrl.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\program files\unlocker\unlockerassistant.exe
C:\Program Files\CleanMem\Mini_Monitor.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\DEMILOVATO\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mStart Page = about:blank
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2010\IEToolbar.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
uRun: [Google Update] "c:\documents and settings\demilovato\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2010\bdagent.exe"
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2010\IEShow.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [UnlockerAssistant] "c:\program files\unlocker\unlockerassistant.exe"
mRun: [CleanMem Mini Monitor] c:\program files\cleanmem\Mini_Monitor.exe /startup
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: safelinking.net
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242293823812
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} - hxxp://www.netgame.com/mplugin/mglaunch_USAv1005.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{6C0999CC-54DF-4E35-95F5-FCD570673EB2} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{E6FD9529-A8B5-491F-A2A4-00D09359E894} : NameServer = 195.29.150.3,195.29.150.4
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\Skype4COM.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: prio.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\demilovato\application data\mozilla\firefox\profiles\gxsargnq.default\
FF - prefs.js: browser.startup.homepage - www.google.hr
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\demilovato\local settings\application data\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npWebLaunch.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\windows\system32\npOGPPlugin.dll
FF - plugin: c:\windows\system32\npptools.dll
FF - plugin: c:\windows\system32\npwmsdrm.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-7-19 123264]
R2 BDVEDISK;BDVEDISK;c:\program files\bitdefender\bitdefender 2010\bdvedisk.sys [2010-1-19 85128]
R2 Htsysm;Htsysm;c:\windows\system32\HtsysmNT.sys [2011-1-30 2304]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-5-14 304464]
R2 prio_svc;Prio Service;c:\program files\prio\prio_svc.exe [2010-7-28 5120]
R2 TunngleService;TunngleService;c:\program files\tunngle\TnglCtrl.exe [2011-3-21 718072]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-2-3 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2010-1-4 111312]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2011-1-25 44368]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-5-14 20952]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [2009-11-13 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-11-24 1691480]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2009-10-19 183880]
S3 CEDRIVER55;CEDRIVER55;\??\c:\program files\cheat engine\dbk32.sys --> c:\program files\cheat engine\dbk32.sys [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\demilo~1\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\demilo~1\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 ESLvnic1;ESLvnic Virtual Network 32 Bit;c:\windows\system32\drivers\ESLvnic.sys [2010-9-1 24504]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena\safedrv.sys --> c:\program files\garena\safedrv.sys [?]
S3 iatmunin;iatmunin;c:\docume~1\demilo~1\locals~1\temp\iatmunin.sys [2006-1-6 29696]
S3 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2006-2-28 14336]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\36.tmp --> c:\windows\system32\36.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-4-13 27064]
S3 wip0204;Wippien Network Adapter 2.4;c:\windows\system32\drivers\wip0204.sys [2010-12-14 23480]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 XDva248;XDva248;\??\c:\windows\system32\xdva248.sys --> c:\windows\system32\XDva248.sys [?]
S3 XDva285;XDva285;\??\c:\windows\system32\xdva285.sys --> c:\windows\system32\XDva285.sys [?]
S3 XDva337;XDva337;\??\c:\windows\system32\xdva337.sys --> c:\windows\system32\XDva337.sys [?]
S3 XDva344;XDva344;\??\c:\windows\system32\xdva344.sys --> c:\windows\system32\XDva344.sys [?]
.
=============== Created Last 30 ================
.
2011-08-03 21:36:15 -------- d-----w- c:\documents and settings\demilovato\application data\SUPERAntiSpyware.com
2011-08-03 21:35:58 -------- d-----w- c:\windows\system32\AppLogs
2011-08-03 21:35:57 -------- d-----w- c:\documents and settings\all users\application data\!SASCORE
2011-08-03 21:35:50 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-08-03 17:08:00 -------- d-----w- c:\program files\Sierra
2011-08-03 14:46:55 -------- d-----w- c:\program files\LIMBO
2011-08-03 10:58:22 -------- d-----w- c:\documents and settings\all users\application data\GamesCampus
2011-08-03 09:34:15 -------- d-----w- C:\GamesCampus
2011-08-02 17:54:39 -------- d-----w- c:\windows\Kudos 2-in-1
2011-08-02 13:50:49 -------- d-----w- c:\program files\Darkstar One
2011-08-02 07:53:15 -------- d-----w- c:\documents and settings\demilovato\application data\Mumble
2011-08-02 07:52:56 -------- d-----w- c:\program files\Mumble
2011-07-26 00:25:28 -------- d-----w- c:\documents and settings\demilovato\VirtualBox VMs
2011-07-26 00:21:53 -------- d-----w- c:\documents and settings\demilovato\.VirtualBox
2011-07-26 00:21:45 158000 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-07-26 00:21:38 93488 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-07-17 16:34:07 -------- d-----w- C:\ATI
2011-07-17 15:45:13 -------- d-----w- c:\program files\Combined Community Codec Pack
2011-07-07 14:59:01 -------- d-----w- c:\program files\Mount&Blade Warband
.
==================== Find3M ====================
.
2011-08-03 19:00:51 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2011-07-17 23:07:49 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-07-17 23:07:49 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-07-17 16:35:51 0 ----a-w- c:\windows\ativpsrm.bin
2011-07-10 17:55:51 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-07-10 17:55:37 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-07-03 08:13:53 138056 ----a-w- c:\documents and settings\demilovato\application data\PnkBstrK.sys
2011-07-03 08:13:32 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2011-06-30 23:31:36 249856 ------w- c:\windows\Setup1.exe
2011-06-30 23:31:31 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-06-28 00:19:10 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-06-02 19:43:59 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-25 04:21:44 6554624 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-05-25 04:15:14 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2011-05-25 03:53:14 57344 ----a-w- c:\windows\system32\aticalrt.dll
2011-05-25 03:53:06 53248 ----a-w- c:\windows\system32\aticalcl.dll
2011-05-25 03:47:42 17989632 ----a-w- c:\windows\system32\atioglxx.dll
2011-05-25 03:42:42 5922816 ----a-w- c:\windows\system32\aticaldd.dll
2011-05-25 03:14:06 4059328 ----a-w- c:\windows\system32\ati3duag.dll
2011-05-25 03:07:40 956160 ----a-w- c:\windows\system32\ativvamv.dll
2011-05-25 03:05:18 503808 ----a-w- c:\windows\system32\atiok3x2.dll
2011-05-25 02:58:28 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-05-25 02:56:58 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-05-25 02:55:58 302592 ----a-w- c:\windows\system32\ati2dvag.dll
2011-05-25 02:54:56 3152384 ----a-w- c:\windows\system32\ativvaxx.dll
2011-05-25 02:39:28 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2011-05-25 02:39:16 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2011-05-25 02:39:08 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2011-05-25 02:39:00 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-05-25 02:38:52 64512 ----a-w- c:\windows\system32\atimpc32.dll
2011-05-25 02:38:52 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2011-05-25 02:38:50 188416 ----a-w- c:\windows\system32\ati2evxx.dll
2011-05-25 02:37:34 643072 ----a-w- c:\windows\system32\ati2evxx.exe
2011-05-25 02:36:10 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2011-05-25 02:34:52 151552 ----a-w- c:\windows\system32\atiapfxx.exe
2011-05-25 02:31:28 651264 ----a-w- c:\windows\system32\atikvmag.dll
2011-05-25 02:27:52 200704 ----a-w- c:\windows\system32\atiadlxx.dll
2011-05-25 02:27:36 17408 ----a-w- c:\windows\system32\atitvo32.dll
2011-05-25 02:22:34 856064 ----a-w- c:\windows\system32\ati2cqag.dll
2011-05-21 07:54:17 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-05-21 07:42:10 837192 ----a-w- c:\windows\system32\pbsvc.exe
.
============= FINISH: 0:01:26,83 ===============
Attached File(s)
-
attach.txt (11K)
Number of downloads: 1 -
ark.txt (127.99K)
Number of downloads: 1
This post has been edited by Demi<3: 04 August 2011 - 06:17 AM

Help

Back to top











