.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by Luis Enrique at 9:25:07 on 2011-12-22
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.416 [GMT 0:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Documents and Settings\Luis Enrique\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Luis Enrique\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Luis Enrique\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Luis Enrique\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = plimus.com;www.plimus.com;regnow.com;www.regnow.com
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\winlogon.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: ChromeFrame BHO: {ecb3c477-1a0a-44bd-bb57-78f9efe34fa7} - c:\program files\google\chrome frame\application\16.0.912.63\npchrome_frame.dll
BHO: SimpleAdblock Class: {ffcb3198-32f3-4e8b-9539-4324694ed664} - c:\program files\common files\simple adblock\SimpleAdblock.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
uPolicies-explorer: NoInstrumentation = 1 (0x1)
uPolicies-explorer: NoRun = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxp://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.127.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
TCP: DhcpNameServer = 208.67.222.222 208.67.220.220
TCP: Interfaces\{0A92049F-B7D9-4173-9F85-E02F6E1DC7B5} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{0A92049F-B7D9-4173-9F85-E02F6E1DC7B5} : DhcpNameServer = 208.67.222.222 208.67.220.220
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - c:\program files\google\chrome frame\application\16.0.912.63\npchrome_frame.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\luis enrique\application data\mozilla\firefox\profiles\ei63u9uk.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/home
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - prefs.js: network.proxy.gopher -
FF - prefs.js: network.proxy.gopher_port - 0
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\all users\application data\nexoneu\ngm\npNxGameeu.dll
FF - plugin: c:\documents and settings\luis enrique\application data\mozilla\firefox\profiles\ei63u9uk.default\extensions\battlefieldheroespatcher@ea.com\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\luis enrique\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\tencent\qqmusic\npQzoneMusic.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2011-8-19 51984]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2011-8-19 69392]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-12-12 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-12-12 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-12-12 20568]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-12-12 44768]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-8-13 21992]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2011-10-18 38608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-10 136176]
S3 cpuz130;cpuz130;\??\c:\docume~1\luisen~1\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\luisen~1\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-10 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys --> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2011-8-19 33552]
S3 ThreatFire;ThreatFire;c:\program files\pc tools security\tfengine\tfservice.exe service --> c:\program files\pc tools security\tfengine\TFService.exe service [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
chm.file="hh.exe" %1
txtfile=c:\windows\notepad.exe %1
.
=============== Created Last 30 ================
.
2011-12-19 17:53:00 -------- d-----w- c:\program files\Activision
2011-12-19 17:49:34 -------- d-sh--w- c:\windows\ftpcache
2011-12-18 16:04:10 839752 ----a-w- c:\windows\system32\pbsvc.exe
2011-12-16 20:33:19 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2011-12-16 20:33:18 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\ctor.dll
2011-12-16 20:33:18 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iscript.dll
2011-12-16 20:33:18 180224 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iuser.dll
2011-12-16 20:33:17 749568 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iKernel.dll
2011-12-16 20:33:17 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\DotNetInstaller.exe
2011-12-16 20:07:24 192644 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\iGdi.dll
2011-12-16 20:07:19 323716 ----a-w- c:\program files\common files\installshield\professional\runtime\10\50\intel32\setup.dll
2011-12-15 18:00:46 -------- d-----w- c:\program files\GameSpy Arcade
2011-12-14 19:34:54 -------- d-----w- c:\documents and settings\all users\application data\Trymedia
2011-12-14 17:52:25 268048 ----a-w- c:\windows\system32\dxtmeta2.dll
2011-12-12 21:41:33 425984 ----a-w- c:\program files\microsoft games\flight simulator 9\modules\ContrailsProFS9.dll
2011-12-12 21:40:16 -------- d-----w- c:\program files\FlightSimTools.com
2011-12-12 21:37:53 -------- d-----w- c:\program files\Driver Reviver
2011-12-12 21:30:32 -------- d-----w- c:\program files\Reviversoft
2011-12-12 20:30:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-12 20:26:25 41184 ----a-w- c:\windows\avastSS.scr
2011-12-11 19:38:09 -------- d--h--w- c:\documents and settings\all users\application data\Common Files
2011-12-11 19:30:03 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2011-12-11 19:27:22 179206 ----a-w- c:\documents and settings\all users\application data\1323631361.bdinstall.bin
2011-12-11 19:20:44 105327 ----a-w- c:\documents and settings\all users\application data\1323631026.bdinstall.bin
2011-12-11 19:17:05 29322 ----a-w- c:\documents and settings\all users\application data\1323631023.bdinstall.bin
2011-12-11 19:07:54 -------- d-----w- c:\program files\BandiMPEG1
2011-12-11 18:32:21 -------- d-----w- C:\SG Interactive
2011-12-09 21:25:19 -------- d-----w- c:\program files\common files\Steam
2011-12-09 21:25:10 -------- d-----w- c:\program files\Steam
2011-12-09 19:53:54 -------- d-----w- C:\aef29ac035d9dc64f0e47decdc25a3
2011-12-08 19:25:09 -------- d-----w- c:\documents and settings\luis enrique\application data\liQeNSoft
2011-12-08 19:19:18 242828 ----a-w- c:\documents and settings\all users\application data\1323370950.bdinstall.bin
2011-12-08 19:09:22 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2011-12-08 19:03:49 -------- d-----w- c:\program files\Bitdefender
2011-12-08 18:08:54 2600 ----a-w- c:\windows\system32\xp_exe_fix.reg
2011-12-05 17:17:01 -------- d-----w- c:\program files\RAR Password Unlocker
2011-12-04 22:05:45 -------- d-----w- c:\documents and settings\luis enrique\application data\Malwarebytes
2011-12-04 22:05:15 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-02 20:03:57 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-12-02 17:48:32 22328 ----a-w- c:\documents and settings\luis enrique\application data\PnkBstrK.sys
2011-12-02 17:48:07 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-12-02 17:48:07 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-12-02 17:48:05 76888 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-11-26 19:11:20 -------- d-----w- c:\documents and settings\luis enrique\jagexcache
.
==================== Find3M ====================
.
2011-12-21 14:04:53 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-12-09 20:42:20 240184 ----a-w- c:\windows\system32\drivers\avchv.sys
2011-12-09 20:42:01 454960 ----a-w- c:\windows\system32\drivers\avckf.sys
2011-11-19 20:38:36 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-11-14 15:57:21 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-31 20:12:52 2608 ----a-w- c:\windows\system32\ASOROSet.bin
2011-10-23 15:35:20 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-10-22 11:05:08 65536 ----a-w- c:\windows\system32\frapsvid.dll
2011-10-05 15:34:26 724992 ----a-w- c:\windows\iun6002.exe
2011-10-04 09:16:08 1034232 ----a-w- c:\windows\system32\drivers\vbcorent.sys
2008-04-14 04:42:40 507904 --sh--w- c:\windows\system32\winlogon.exe
.
============= FINISH: 9:32:12.68 ===============
Attached File(s)
-
attach.txt (11.16K)
Number of downloads: 0

Help
This topic is locked

Back to top









