-----------
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_20
Run by emperador at 19:53:41 on 2011-09-17
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2047.1625 [GMT -6:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Archivos de programa\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Archivos de programa\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
A:\8ttfqd6m.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://www.ixquick.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - AcroIEHlprObj Class
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\archivos de programa\java\jre6\bin\jp2ssv.dll
BHO: {e5a1691b-d188-4419-ad02-90002030b8ee} - FlashFXP Helper for Internet Explorer
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\archivos de programa\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [DAEMON Tools Lite] "c:\archivos de programa\daemon tools lite\DTLite.exe" -autorun
dRun: [DWQueuedReporting] "c:\archiv~1\archiv~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\archivos de programa\messenger\msmsgs.exe
TCP: Interfaces\{C29FD719-342B-4864-BFA3-6E23246F2E46} : NameServer = 68.87.85.102,68.87.69.150
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\archivos de programa\archivos comunes\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\archiv~1\archiv~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\archivos de programa\getright\xx2gr.dll
Name-Space Handler: http\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} - c:\archivos de programa\getright\xx2gr.dll
Notify: !SASWinLogon - h:\archivos de programa\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - h:\archivos de programa\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrador\datos de programa\mozilla\firefox\profiles\hrc436z7.default\
FF - plugin: c:\archivos de programa\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\archivos de programa\opera\program\plugins\NPDocBox.dll
FF - plugin: c:\archivos de programa\opera\program\plugins\nppdf32.dll
FF - plugin: c:\documents and settings\all users\datos de programa\zylom\zylomgamesplayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpjplug.dll
FF - plugin: h:\archivos de programa\divx\divx web player\npdivx32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\archivos de programa\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\archivos de programa\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - h:\archivos de programa\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
============= SERVICES / DRIVERS ===============
.
R0 d344bus6;d344bus6;c:\windows\system32\drivers\d344bus6.sys [2007-10-31 137216]
R0 d344prt6;d344prt6;c:\windows\system32\drivers\d344prt6.sys [2007-10-31 5248]
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2010-8-14 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2010-8-14 5248]
R0 SI3114;SiI-3114 SATALink Controller;c:\windows\system32\drivers\SI3114.sys [2011-9-16 73768]
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2004-8-10 19240]
R1 SASDIFSV;SASDIFSV;h:\archivos de programa\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;h:\archivos de programa\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-11-19 116560]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-11-19 41424]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;c:\windows\system32\drivers\3xHybrid.sys [2009-11-13 1121536]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]
R3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2011-9-16 232512]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-9-11 20952]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-11-10 104016]
S0 d344bus;d344bus;c:\windows\system32\drivers\d344bus.sys --> c:\windows\system32\drivers\d344bus.sys [?]
S0 d344prt;d344prt;c:\windows\system32\drivers\d344prt.sys --> c:\windows\system32\drivers\d344prt.sys [?]
S1 mirrorv3;mirrorv3;c:\windows\system32\drivers\rminiv3.sys [2006-11-1 3328]
S2 MBAMService;MBAMService;h:\archivos de programa\malwarebytes' anti-malware\mbamservice.exe [2010-9-11 304464]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416]
S3 COMMPR;CommView/WiFi Driver by TamoSoft;c:\windows\system32\drivers\commpr.sys [2004-4-1 15104]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\archivos de programa\archivos comunes\creative labs shared\service\CTAELicensing.exe [2010-9-22 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360]
S3 ddsxeiservice;ddsxeiservice2;\??\c:\archivos de programa\sxe injected\ddsxei.sys --> c:\archivos de programa\sxe injected\ddsxei.sys [?]
S3 IPN2120;Wireless-B PCI Adapter Driver;c:\windows\system32\drivers\lsipnds.sys --> c:\windows\system32\drivers\LSIPNDS.sys [?]
S3 ISLNDIS5;ISLNDIS5 Protocol Driver;\??\c:\windows\system32\islndis5.sys --> c:\windows\system32\ISLNDIS5.SYS [?]
S3 jgameenp;jgameenp;\??\c:\docume~1\compgeek\config~1\temp\jgameenp.sys --> c:\docume~1\compgeek\config~1\temp\jgameenp.sys [?]
S3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\drivers\ma311n51.sys [2007-2-23 54784]
S3 RTCore;RTCore;\??\c:\documents and settings\compgeek\escritorio\rightmark memory analyzer v3.43_rmma343bin_fix\rtcore.sys --> c:\documents and settings\compgeek\escritorio\rightmark memory analyzer v3.43_rmma343bin_fix\RTCore.sys [?]
S3 SASENUM;SASENUM;\??\c:\archivos de programa\superantispyware\sasenum.sys --> c:\archivos de programa\superantispyware\SASENUM.SYS [?]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-11-19 95568]
S3 XDva359;XDva359;\??\c:\windows\system32\xdva359.sys --> c:\windows\system32\XDva359.sys [?]
S3 XIRLINK;Dsc Pro Digital 640 Camera;c:\windows\system32\drivers\C-itNT.sys [2010-1-18 447245]
S4 ppa;Controlador de filtro de puerto paralelo Iomega Parallel;c:\windows\system32\drivers\ppa.sys [2007-3-31 17792]
.
=============== Created Last 30 ================
.
2011-09-17 20:05:52 114 ----a-w- c:\windows\Printdir.bat
2011-09-17 04:59:22 73768 ----a-w- c:\windows\system32\drivers\SI3114.sys
2011-09-17 04:59:22 119848 ----a-w- c:\windows\system32\SilSupp.dll
2011-09-17 01:29:48 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-09-17 01:09:20 102160 ----a-w- c:\windows\system32\drivers\nbf.sys
2011-09-17 00:21:08 -------- d-----w- c:\windows\ime
2011-09-10 20:22:23 -------- d-sha-r- C:\cmdcons
2011-09-10 20:22:21 -------- d-----w- c:\windows\setup.pss
2011-09-03 18:29:11 -------- d-----w- c:\archivos de programa\DAEMON Tools Lite
2011-09-03 18:28:53 -------- d-----w- c:\documents and settings\administrador\datos de programa\DAEMON Tools Lite
2011-09-03 18:28:49 -------- d-----w- c:\documents and settings\all users\datos de programa\DAEMON Tools Lite
.
==================== Find3M ====================
.
2011-06-26 06:45:56 256000 ----a-w- c:\windows\PEV.exe
2002-11-11 18:19:04 2274816 ----a-w- c:\archivos de programa\archivos comunes\Monopoly.exe
1999-12-09 19:17:14 172032 ----a-w- c:\archivos de programa\archivos comunes\binkw32.dll
1999-12-09 19:17:12 411648 ----a-w- c:\archivos de programa\archivos comunes\boarded.exe
.
============= FINISH: 19:54:01.15 ===============
AND NOW THE ATTACHED LOGS from DDS and GMER.
I have Gmer still running in case I need to delete a service, so I would appreciate a relatively fast help. Thank you and good night@<
Attached File(s)
-
attach.txt (7.54K)
Number of downloads: 1 -
Ark.txt (23.56K)
Number of downloads: 1

Help
This topic is locked


Back to top












