DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 6.0.2900.2180
Run by Administrator at 23:21:35 on 2012-01-20
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1661 [GMT -6:00]
.
AV: Norton Internet Security 2006 *Enabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security 2006 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NETGEAR\WG111T\wlan111t.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\notepad.exe
.
============== Pseudo HJT Report ===============
.
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: CNavExtBho Class: {a8f38d8d-e480-4d52-b7a2-731bb6995fdd} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Norton AntiVirus: {c4069e3a-68f1-403e-b40e-20066696354b} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_05\bin\jusched.exe
mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [HPHUPD08] c:\program files\hp\digital imaging\{33d6cc28-9f75-4d1b-a11d-98895b3a3729}\hphupd08.exe
mRun: [PinInit] c:\hp\bin\cloaker.exe c:\hp\bin\PinToStart.bat
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [DISCover] c:\program files\disc\DISCover.exe
mRun: [DiscUpdateManager] c:\program files\disc\DiscUpdateMgr.exe
mRun: [DMAScheduler] c:\program files\sonic\digitalmedia plus\digitalmedia archive\DMAScheduler.exe
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [<NO NAME>]
mRun: [PCDrProfiler] "c:\program files\pc-doctor 5 for windows\RunProfiler.exe" -r
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [IS CfgWiz] c:\program files\norton internet security\cfgwiz.exe /GUID {F073BDC9-0D67-4ff0-879E-27241C843828} /MODE CfgWiz /CMDLINE "REBOOT"
mRun: [SSC_UserPrompt] "c:\program files\common files\symantec shared\security center\UsrPrmpt.exe"
mRun: [SetDefaultPrinter] c:\hp\bin\cloaker.exe c:\windows\system32\cmd.exe /c c:\hp\bin\defaultprinter\SetDefaultPrinter.cmd
mRun: [HPBootOp] c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe /run
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
mRun: [IcoSet] c:\hp\bin\cloaker.exe c:\hp\bin\icoset\adjust.bat seticon
mRun: [PMLreset] c:\hp\bin\cloaker.exe cmd /c c:\hp\drivers\pmlreset.bat
mRun: [HPSUreset] c:\hp\bin\cloaker.exe cmd /c c:\hp\drivers\hpsu\HPSULastRunReset.bat
mRun: [RBreset] c:\hp\bin\cloaker.exe cmd /c c:\hp\drivers\hpsu\RBLastRunReset.bat
mRun: [Reminder] "c:\windows\creator\Remind_XP.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRunOnce: [licfix] c:\hp\bin\cloaker c:\hp\bin\drm\lgstub.bat
mRunOnce: [regcmdcons] c:\windows\regedit.exe /s c:\hp\bin\cmdcons3.reg
mRunOnce: [SetHibernate] c:\hp\bin\cloaker.exe c:\hp\bin\commands /ww /c c:\hp\bin\hibernate\install.cmd doit
mRunOnce: [no_show] c:\hp\bin\cloaker.exe c:\hp\bin\kbd_bar\KBD_Bar.bat
mRunOnce: [Icon] c:\hp\bin\cloaker.exe c:\hp\bin\volume\delandr.bat
mRunOnce: [OCA_MRK] c:\hp\bin\cloaker.exe c:\windows\system32\cmd.exe /c c:\hp\bin\oca\install.cmd
mRunOnce: [pwr] c:\hp\bin\cloaker.exe c:\hp\bin\energystar\pwrmgt.exe
mRunOnce: [USB] c:\hp\bin\cloaker.exe c:\hp\bin\energystar\usbpwrmgmt.exe
mRunOnce: [Engy] c:\hp\bin\cloaker.exe c:\hp\bin\energystar\EnergyStar.bat
mRunOnce: [WG111T] c:\windows\system32\AegisI5.exe -silent -install -vendor wg111t
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\documents and settings\all users\application data\malwarebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\casup.lnk - c:\hp\region\CustAtStartUp.wsf
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111t\wlan111t.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\resche~1.lnk - c:\hp\bin\CLOAKER.EXE
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_05\bin\npjpi150_05.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
Trusted Zone: trymedia.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
Notify: AtiExtEvent - Ati2evxx.dll
.
============= SERVICES / DRIVERS ===============
.
S0 hxvwfo;hxvwfo;c:\windows\system32\drivers\dgcb.sys --> c:\windows\system32\drivers\dgcb.sys [?]
S2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-9-17 192112]
S2 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\ccProxy.exe [2005-9-17 202352]
S2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-9-17 169584]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 navapsvc;Norton AntiVirus Auto-Protect Service;c:\program files\norton internet security\norton antivirus\navapsvc.exe [2005-10-7 133744]
S2 SAVRTPEL;SAVRTPEL;c:\program files\norton internet security\norton antivirus\Savrtpel.sys [2005-8-26 53896]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2012-1-20 17149]
S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20060104.006\NAVENG.Sys [2006-3-12 77864]
S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20060104.006\NavEx15.Sys [2006-3-12 750952]
S3 SAVRT;SAVRT;c:\program files\norton internet security\norton antivirus\savrt.sys [2005-8-26 334984]
S3 SAVScan;Symantec AVScan;c:\program files\norton internet security\norton antivirus\SAVScan.exe [2005-8-26 198368]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-3-12 1119888]
.
=============== Created Last 30 ================
.
2012-01-21 04:33:08 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-21 04:33:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-20 23:18:13 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes
2012-01-20 23:18:07 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-01-20 23:18:00 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Adobe
2012-01-20 23:09:16 -------- d-----w- c:\windows\LastGood.Tmp
2012-01-20 23:09:15 94208 ----a-w- c:\windows\system32\DNIN50.dll
2012-01-20 23:09:15 651264 ----a-w- c:\windows\system32\libeay32.dll
2012-01-20 23:09:15 362944 ----a-w- c:\windows\system32\drivers\WG11TND5.sys
2012-01-20 23:09:15 192512 ----a-r- c:\windows\system32\AegisI5.exe
2012-01-20 23:09:15 17149 ----a-w- c:\windows\system32\DNINDIS5.sys
2012-01-20 23:09:15 15941 ----a-w- c:\windows\system32\DNINDIS3.VXD
2012-01-20 23:09:15 149392 ----a-w- c:\windows\system32\drivers\ar5523.bin
2012-01-20 23:09:15 147456 ----a-w- c:\windows\system32\ssleay32.dll
2012-01-20 23:09:15 -------- d-----w- c:\program files\NETGEAR
2012-01-18 06:47:19 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-01-18 06:47:16 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-01-18 06:47:15 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2012-01-18 06:47:13 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-01-18 06:47:11 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-01-18 05:21:53 -------- d-sh--r- c:\windows\system32\dllcache
2012-01-18 04:04:27 -------- d-----w- C:\USERDATA
2012-01-18 02:20:26 -------- d-----r- c:\documents and settings\all users\Documents
2012-01-18 02:18:44 -------- d-----r- c:\windows\Offline Web Pages
.
==================== Find3M ====================
.
.
============= FINISH: 23:21:58.84 ===============
Attached File(s)
-
attach.txt (6.73K)
Number of downloads: 0 -
ark.log (1.73K)
Number of downloads: 1

Help
This topic is locked

Back to top









