.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by Landulph at 19:41:42 on 2011-12-09
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.349 [GMT -5:00]
.
AV: Panda Antivirus Pro 2011 *Enabled/Updated* {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}
FW: Panda Personal Firewall 2011 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\TPSrv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\PROGRAM FILES\PANDA SECURITY\PANDA ANTIVIRUS PRO 2011\WebProxy.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\PavFnSvr.exe
C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\Firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\PsImSvc.exe
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\PskSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\pavsrvx86.exe
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Security\Panda Antivirus Pro 2011\ApVxdWin.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\svchost.exe -k netsvc
C:\WINDOWS\System32\ping.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APVXDWIN] "c:\program files\panda security\panda antivirus pro 2011\APVXDWIN.EXE" /s
mRun: [SCANINICIO] "c:\program files\panda security\panda antivirus pro 2011\Inicio.exe"
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{DF633078-3384-470F-86BB-99B4970B1A66} : DhcpNameServer = 209.18.47.61 209.18.47.62
Notify: avldr - avldr.dll
Notify: igfxcui - igfxdev.dll
Notify: TPSvc - TPSvc.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\landulph\application data\mozilla\firefox\profiles\pon2x1m6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npaudio.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npavi32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npdsplay.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npnul32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPOFFICE.DLL
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppl3260.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprfxins.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprjplug.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nprpjplug.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npwmsdrm.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
.
============= SERVICES / DRIVERS ===============
.
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [2011-10-3 26696]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-12-9 207280]
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2011-9-26 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2011-8-16 59080]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-12-9 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-12-9 59664]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [2011-10-3 76296]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [2011-10-3 53256]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [2011-10-3 22024]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [2011-10-3 193800]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [2011-10-3 159112]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2011-12-9 233136]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [2011-10-3 37896]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [2011-10-3 46856]
R2 AmFSM;AmFSM;c:\windows\system32\drivers\amm8651.sys [2011-10-3 59080]
R2 Panda Software Controller;Panda Software Controller;c:\program files\panda security\panda antivirus pro 2011\PsCtrlS.exe [2011-10-3 173312]
R2 PAVFNSVR;Panda Function Service;c:\program files\panda security\panda antivirus pro 2011\PavFnSvr.exe [2011-10-3 202048]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [2011-10-3 163336]
R2 PavPrSrv;Panda Process Protection Service;c:\program files\common files\panda security\pavshld\PavPrSrv.exe [2011-10-3 62768]
R2 PAVSRV;Panda On-Access Anti-Malware Service;c:\program files\panda security\panda antivirus pro 2011\pavsrvx86.exe [2011-10-3 314176]
R2 PskSvcRetail;Panda PSK service;c:\program files\panda security\panda antivirus pro 2011\psksvc.exe [2011-10-3 28992]
R2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2004-8-4 14336]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
R3 NETIMFLT01060042;PANDA NDIS IM Filter Miniport v1.6.0.42;c:\windows\system32\drivers\neti1642.sys [2011-10-3 199688]
R3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\pavsrk.sys --> c:\windows\system32\PavSRK.sys [?]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\pavtpk.sys --> c:\windows\system32\PavTPK.sys [?]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2011-9-26 61328]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2011-12-9 70408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2011-12-9 365280]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2011-12-9 1141712]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-12-9 33552]
S3 ThreatFire;ThreatFire;c:\program files\spyware doctor\tfengine\tfservice.exe service --> c:\program files\spyware doctor\tfengine\TFService.exe service [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== File Associations ===============
.
JSEFile=c:\progra~1\pandas~1\pandaa~1\PavScrip.exe "%1" %*
VBEFile=c:\progra~1\pandas~1\pandaa~1\PavScrip.exe "%1" %*
VBSFile=c:\progra~1\pandas~1\pandaa~1\PavScrip.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-12-09 21:10:17 -------- d-----w- c:\program files\STOPzilla!
2011-12-09 21:10:13 -------- d-----w- c:\program files\common files\iS3
2011-12-09 21:10:12 -------- d-----w- c:\documents and settings\all users\application data\STOPzilla!
2011-12-09 20:32:32 -------- d--h--w- c:\windows\PIF
2011-12-09 20:21:03 59664 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2011-12-09 20:21:03 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2011-12-09 20:21:02 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2011-12-09 20:13:15 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-12-09 20:13:11 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-12-09 20:13:11 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-12-09 20:13:06 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-12-09 20:12:57 -------- d-----w- c:\program files\Spyware Doctor
2011-12-09 20:12:57 -------- d-----w- c:\program files\common files\PC Tools
2011-12-09 20:12:57 -------- d-----w- c:\documents and settings\landulph\application data\PC Tools
2011-12-09 20:12:57 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-12-09 20:10:12 -------- d-----w- c:\documents and settings\landulph\application data\GetRightToGo
2011-12-09 19:33:15 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-12-09 19:33:15 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-07 22:12:22 68648 ----a-r- c:\windows\system32\IS3Hks5.dll
2011-12-07 22:12:22 547880 ----a-r- c:\windows\system32\SZComp5.dll
2011-12-07 22:12:22 482344 ----a-r- c:\windows\system32\SZBase5.dll
2011-12-07 22:12:22 457768 ----a-r- c:\windows\system32\IS3DBA5.dll
2011-12-07 22:12:22 30248 ----a-r- c:\windows\system32\IS3XDat5.dll
2011-12-07 22:12:22 24616 ----a-r- c:\windows\system32\SZIO5.dll
2011-12-07 22:12:22 134184 ----a-r- c:\windows\system32\IS3HTUI5.dll
2011-12-07 22:12:20 740392 ----a-r- c:\windows\system32\IS3Base5.dll
2011-12-07 22:12:20 392232 ----a-r- c:\windows\system32\IS3UI5.dll
2011-12-07 22:12:20 232488 ----a-r- c:\windows\system32\IS3Win325.dll
2011-12-07 22:12:20 105512 ----a-r- c:\windows\system32\IS3Inet5.dll
2011-12-07 22:12:20 101416 ----a-r- c:\windows\system32\IS3Svc5.dll
2011-11-23 20:04:39 -------- d-----w- c:\windows\system32\LogFiles
.
==================== Find3M ====================
.
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 19:45:05 9727564 ----a-w- c:\windows\system32\Shakespeare Picture Book.scr
2011-10-03 19:30:29 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 18:41:42 28276 ----a-w- c:\windows\system32\drivers\MxlW2k.sys
2011-10-03 18:25:55 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-10-03 18:25:55 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 16:19:13 319488 ----a-w- c:\windows\system32\AegisI5Installer.exe
2011-10-03 16:19:13 21425 ----a-w- c:\windows\system32\drivers\AegisP.sys
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:21:00 61328 ----a-r- c:\windows\system32\drivers\SZKG.sys
2011-09-26 16:21:00 61328 ----a-r- c:\windows\system32\drivers\is3srv.sys
2011-09-26 15:41:20 611328 ------w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 19:43:59.28 ===============
GMER finished, but this form is telling me my 368K ark log is too big to be posted here, so I have attached a "mini-Ark"--everything except the user code sections, which are taking up the bulk of the space--let me know if you want these as well, and how to post them.
Attached File(s)
-
attach.txt (13.43K)
Number of downloads: 1 -
ark.txt (20.92K)
Number of downloads: 1
This post has been edited by Landulph: 10 December 2011 - 02:50 AM

Help
This topic is locked


Back to top










