DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.1.0
Run by Owner at 2:51:15 on 2011-11-05
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.678 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TightVNC\tvnserver.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Documents and Settings\Owner\Local Settings\Application Data\YouGov\PanelApp\PanelApp.exe
C:\WAREHOUSE\threat-1.0.3\threat.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TightVNC\tvnserver.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Documents and Settings\Owner\Application Data\Moonchild Productions\Pale Moon\Profiles\dau0qezm.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe
C:\Program Files\Pale Moon\palemoon.exe
C:\WINDOWS\system32\osk.exe
C:\WINDOWS\system32\MSSWCHX.EXE
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.spiritdaily.com/
uURLSearchHooks: Streaming Internet Radio Toolbar: {10853dc2-7a27-4e4f-a444-1518b76ab2ec} - c:\program files\streaming_internet_radio\tbStre.dll
BHO: DAPHelper Class: {0000cc75-acf3-4cac-a0a9-dd3868e06852} - c:\program files\dap\DAPBHO.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: GhosteryBHO Class: {237eb6da-3fea-4dd2-8a61-a901b5c489d7} - c:\program files\ghosteryieplugin\GhosteryBrowserHelperObjec.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: SimpleAdblock Class: {ffcb3198-32f3-4e8b-9539-4324694ed664} - c:\program files\common files\simple adblock\SimpleAdblock.dll
TB: Streaming Internet Radio Toolbar: {10853dc2-7a27-4e4f-a444-1518b76ab2ec} - c:\program files\streaming_internet_radio\tbStre.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [PanelApp] c:\documents and settings\owner\local settings\application data\yougov\panelapp\PanelApp.exe
mRun: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
mRun: [tvncontrol] "c:\program files\tightvnc\tvnserver.exe" -controlservice -slave
mRun: [SoundMan] SOUNDMAN.EXE
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\threat.lnk - c:\warehouse\threat-1.0.3\threat.exe
uPolicies-explorer: DisallowRun = 0 (0x0)
uPolicies-explorer: MaxRecentDocs = 3 (0x3)
IE: &Download with &DAP - c:\progra~1\dap\dapextie.htm
IE: Download &all with DAP - c:\progra~1\dap\dapextie2.htm
IE: Download all with Download Commander - C:/Program Files/Heitmeijer/Download Commander version 3.0/IE\DownloadCommander.html
IE: Download with Download Commander - C:/Program Files/Heitmeijer/Download Commander version 3.0/IE\DownloadCommander2.html
IE: {669695BC-A811-4A9D-8CDF-BA8C795F261C} - c:\progra~1\dap\DAP.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - {237EB6DA-3FEA-4DD2-8A61-A901B5C489D7} - c:\program files\ghosteryieplugin\GhosteryBrowserHelperObjec.dll
Trusted Zone: gwrs.com\www
Trusted Zone: youtube.com\www
DPF: {10000000-1000-1000-1000-100000000000} - hxxp://cdn.betteradvertising.com/ghostery/addons/ie/WebInstall/ghostery.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1293670686359
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263927953031
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {96695E54-ECE5-437B-81BF-D45FA9F878A0} - hxxp://www.s3graphics.com.cn/S3DisplayAct/active/S3DispayAct.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.254.254 192.168.1.3
TCP: Interfaces\{A494A91A-2C2C-4D69-BC84-CFF4547FC876} : DhcpNameServer = 192.168.254.254 192.168.1.3
Filter: text/html - {4459DC76-1FDE-4B16-BAD0-E4F8E7647555} - c:\program files\ghosteryieplugin\GhosteryMimeFilter.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\dau0qezm.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.spiritdaily.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\common files\parallelgraphics\cortona\npCortona.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin9.dll
FF - plugin: c:\program files\quicktime\plugins\npqtplugin8.dll
FF - plugin: c:\program files\quicktime\plugins\npqtplugin9.dll
FF - plugin: c:\program files\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlchromebrowserrecordext.dll
FF - plugin: c:\program files\realnetworks\realdownloader\browserplugins\mozillaplugins\nprndlhtml5videoshim.dll
.
============= SERVICES / DRIVERS ===============
.
R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2010-8-4 9344]
R2 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2010-8-4 462464]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2010-1-19 14336]
R2 tvnserver;TightVNC Server;c:\program files\tightvnc\tvnserver.exe [2010-7-8 828944]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 cpudrv;cpudrv;c:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336]
S3 D100IB;D100IB;c:\windows\system32\drivers\D100IB5.SYS [2010-1-19 117760]
S3 dsnpfd;DeskSoft Service;c:\windows\system32\drivers\dsnpfd.sys --> c:\windows\system32\drivers\dsnpfd.sys [?]
S3 dsnpfdMP;dsnpfdMP;c:\windows\system32\drivers\dsnpfd.sys --> c:\windows\system32\drivers\dsnpfd.sys [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-10-9 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-10-9 8456]
S3 PanelSvc;PanelSvc;c:\program files\yougov\panelapp\PanelSvc.exe [2009-12-30 91136]
S3 WefiEngSvc;WeFi Engine Service;c:\program files\wefi\WefiEngSvc.exe [2010-11-3 120152]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2010-1-19 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2011-7-8 31424]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2011-4-22 92592]
S4 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedbit video accelerator\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedbit video accelerator\VideoAcceleratorService.exe -start -scm [?]
.
=============== File Associations ===============
.
vbefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
vbsfile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
jsefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
.
=============== Created Last 30 ================
.
2011-11-04 08:37:54 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-04 08:37:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-04 07:49:03 -------- d-----w- c:\program files\AVAST Software
2011-11-04 07:49:03 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-11-04 07:29:36 -------- d-----w- c:\documents and settings\owner\local settings\application data\Threat Expert
2011-11-04 07:14:46 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2011-11-04 07:14:46 -------- d-----w- c:\program files\common files\PC Tools
2011-11-04 07:14:45 -------- d-----w- c:\program files\PC Tools
2011-11-04 07:13:12 -------- d-----w- c:\documents and settings\owner\application data\TestApp
2011-11-04 07:13:12 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-11-03 09:12:52 388096 ----a-r- c:\documents and settings\owner\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-11-03 09:07:22 -------- d-----w- c:\program files\Trend Micro
2011-11-01 09:02:58 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
2011-11-01 09:01:11 -------- d-----w- C:\cabs
2011-10-30 03:16:45 -------- d-----w- c:\program files\Your Company Name, Inc
2011-10-28 07:55:56 -------- d-----w- c:\program files\FM Software Studio
2011-10-28 07:55:53 -------- d-----w- c:\program files\GSLite
2011-10-24 05:47:44 -------- d-----w- c:\program files\SSuiteAdvance
2011-10-23 04:51:33 48992996 ----a-w- c:\documents and settings\owner\TRACE_BOOT+DRIVERS_1_1.BIN
2011-10-22 07:34:59 -------- d-----w- c:\documents and settings\owner\application data\Ketarin
2011-10-20 08:45:53 -------- d-----w- c:\program files\MemoryOptimization
2011-10-19 08:54:19 -------- d-----w- c:\program files\AppCleaner
2011-10-16 06:48:49 -------- d-----w- c:\documents and settings\owner\local settings\application data\Sun
2011-10-11 08:32:03 40960 ----a-r- c:\documents and settings\owner\application data\microsoft\installer\{ade3cacc-ec31-480c-83a0-587ee60ce8df}\Rambooster.exe1_ADE3CACCEC31480C83A0587EE60CE8DF_1.exe
2011-10-11 08:32:03 40960 ----a-r- c:\documents and settings\owner\application data\microsoft\installer\{ade3cacc-ec31-480c-83a0-587ee60ce8df}\NewShortcut2_ADE3CACCEC31480C83A0587EE60CE8DF.exe
2011-10-11 08:32:02 -------- d-----w- c:\program files\RamBooster 2.0
2011-10-11 08:31:43 53248 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\msihook.dll
2011-10-11 08:31:43 126976 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\knlwrap.exe
2011-10-11 08:31:42 114688 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\scpthdlr.dll
2011-10-10 05:11:44 -------- d-----w- c:\program files\NirSoft
2011-10-10 04:26:47 -------- d-----w- c:\program files\BATSLOT
2011-10-10 01:13:30 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2011-10-10 01:13:30 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys
2011-10-10 01:13:30 2469760 ----a-w- c:\windows\system32\BootMan.exe
2011-10-10 01:13:30 19840 ----a-w- c:\windows\system32\EuEpmGdi.dll
2011-10-10 01:13:30 13192 ----a-w- c:\windows\system32\epmntdrv.sys
2011-10-10 01:06:19 -------- d-----w- c:\program files\EASEUS
.
==================== Find3M ====================
.
2011-10-30 03:31:10 24576 ----a-w- c:\windows\system32\FoolishEventLogMsgHelper.dll
2011-10-09 04:36:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 06:50:34 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 06:45:22 128000 ----a-w- c:\windows\system32\javacpl.cpl
2011-10-01 14:42:32 323624 ----a-w- c:\windows\system32\wiaaut.dll
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 00:54:53 42286 ----a-w- c:\windows\system32\uninstall.exe
2011-09-09 09:12:13 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-06 04:15:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec
2011-08-22 04:04:17 17408 ----a-w- C:\psapi.dll
2011-08-17 13:49:54 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
============= FINISH: 2:51:50.09 ===============
Attached File(s)
-
attach.txt (10.6K)
Number of downloads: 0 -
Gmer.log (1.81K)
Number of downloads: 1

Help
This topic is locked

Back to top










