View Single Post
Old 12-16-2008, 07:52 PM   #23 (permalink)
tanger
Registered User
 
Join Date: Aug 2007
Posts: 62
OS: XP SP3


Re: Does this HJT log look suspicious?

I ran dds.com in safe mode...here are the logs



DDS (Version 1.0.1) - NTFSx86 MINIMAL
Run by Warren at 21:49:44.64 on 16/12/2008
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.2047.1774 [GMT -5:00]

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Warren\Desktop\dds.com

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
BHO: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [EPSON Stylus CX4800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [combofix] c:\windows\system32\cf30058.exe /c c:\combofix\Combobatch.bat
mRunOnce: [combofix] c:\windows\system32\cf30058.exe /c c:\combofix\Combobatch.bat
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\asus wifi-ap solo.lnk - c:\program files\asus wifi-ap solo\RtWLan.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
uPolicies-explorer: NoInstrumentation = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\microsoft office\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\microsoft office\office11\REFIEBAR.DLL
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Notify: klogon - c:\windows\system32\klogon.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\warren\applic~1\mozilla\firefox\profiles\po1w7agd.default\
FF - prefs.js: browser.startup.homepage - www.tsn.ca

============= SERVICES / DRIVERS ===============

S0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-4-16 112144]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 32784]
S1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2008-7-16 213008]
S2 AVP;Kaspersky Internet Security;"c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" -r [2008-4-25 201992]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-3-25 24592]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2008-11-26 176128]
S3 SjyPkt;SjyPkt;\??\c:\windows\system32\drivers\SjyPkt.sys [2008-11-26 13532]

=============== Created Last 30 ================

2008-12-16 09:02 4,444 a------- c:\windows\system32\pid.PNF
2008-12-16 08:54 <DIR> a-dshr-- C:\autorun.inf
2008-12-16 07:37 <DIR> a-dshr-- C:\cmdcons
2008-12-16 07:35 <DIR> --d----- C:\ComboFix
2008-12-13 01:06 <DIR> --d----- c:\program files\Nobilis
2008-12-12 11:52 <DIR> --d----- c:\program files\MathType
2008-12-11 16:02 453,152 a------- c:\windows\system32\nvudisp.exe
2008-12-11 16:02 203,520 a------- c:\windows\system32\nvapps.xml
2008-12-11 16:02 18,537 a------- c:\windows\system32\nvdisp.nvu
2008-12-11 16:02 <DIR> --d----- c:\windows\nview
2008-12-11 16:02 453,152 a------- c:\windows\system32\NVUNINST.EXE
2008-12-11 16:01 <DIR> --d----- C:\NVIDIA
2008-12-11 14:05 <DIR> --d----- c:\windows\SHELLNEW
2008-12-11 13:43 <DIR> --d----- c:\windows\Downloaded Installations
2008-12-10 14:03 <DIR> --d----- c:\windows\SxsCaPendDel
2008-12-04 02:25 161,792 a------- c:\windows\SWREG.exe
2008-12-04 02:25 98,816 a------- c:\windows\sed.exe
2008-12-04 00:47 250 a------- c:\windows\gmer.ini
2008-12-02 22:50 79 a------- c:\windows\wininit.ini
2008-12-02 14:34 <DIR> --d----- c:\program files\Foxit Software
2008-12-02 11:15 <DIR> --d----- c:\docume~1\warren\applic~1\Kaspersky_Key_Finder_(KKF
2008-11-28 00:34 <DIR> --d----- c:\docume~1\warren\applic~1\Design Science
2008-11-28 00:22 <DIR> --d----- c:\docume~1\warren\applic~1\Inkscape
2008-11-28 00:21 <DIR> --d----- c:\program files\Inkscape
2008-11-27 19:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Alias
2008-11-26 21:24 21,035 a------- c:\windows\system32\drivers\AegisP.sys
2008-11-26 21:23 176,128 a------- c:\windows\system32\drivers\RTL8187.sys
2008-11-26 21:23 13,532 a------- c:\windows\system32\drivers\SjyPkt.sys
2008-11-26 21:23 <DIR> --d----- c:\program files\ASUS WiFi-AP Solo
2008-11-26 17:35 28 a------- c:\windows\pdf995.ini
2008-11-26 17:34 59 a------- c:\windows\wpd99.drv
2008-11-26 17:34 <DIR> --d----- c:\docume~1\alluse~1\applic~1\pdf995
2008-11-26 17:34 249,856 a------- c:\windows\system32\pdfmona.dll
2008-11-26 17:34 51,716 a------- c:\windows\system32\pdf995mon.dll
2008-11-26 17:34 <DIR> --d----- c:\program files\pdf995
2008-11-21 23:08 410,984 a------- c:\windows\system32\deploytk.dll
2008-11-21 23:08 73,728 a------- c:\windows\system32\javacpl.cpl

==================== Find3M ====================

2008-12-16 20:34 3,784,736 ac-sh--- c:\windows\system32\drivers\fidbox.dat
2008-12-16 20:34 712,736 ac-sh--- c:\windows\system32\drivers\fidbox2.dat
2008-12-16 20:34 33,792 ac-sh--- c:\windows\system32\drivers\fidbox.idx
2008-12-16 20:34 5,612 ac-sh--- c:\windows\system32\drivers\fidbox2.idx
2008-10-24 06:21 455,296 a------- c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 15:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2008-10-13 09:56 70,936 a------- c:\windows\system32\PhysXLoader.dll
2008-10-07 09:13 288,024 a------- c:\windows\system32\PhysXCplUI.exe
2008-10-07 09:13 23,320 a------- c:\windows\system32\PhysXDevice.dll
2008-10-07 09:13 288,024 a------- c:\windows\system32\PhysXCompatCplUI.exe
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelTraditionalChinese.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelSwedish.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelSpanish.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelSimplifiedChinese.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelPortugese.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelKorean.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelJapanese.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelGerman.dll
2008-10-07 09:13 58,648 a------- c:\windows\system32\AgCPanelFrench.dll
2008-10-03 05:02 247,326 a------- c:\windows\system32\strmdll.dll
2008-07-18 13:06 47,360 ac------ c:\docume~1\warren\applic~1\pcouffin.sys
2006-06-23 13:48 32,768 ac------ c:\windows\inf\UpdateUSB.exe
2004-08-04 07:00 73,728 ac-sh--- c:\windows\registeredpackages\{dd90d410-1823-43eb-9a16-a2331bf08799}$backup$\system\wmplayer.exe

============= FINISH: 21:50:02.73 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Version 1.0)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 02/05/2008 2:58:43 AM
System Uptime: 16/12/2008 8:34:45 PM (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5K-E
Processor: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz | LGA775 | 2671/333mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 233 GiB total, 164.976 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 466 GiB total, 44.037 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E96A-E325-11CE-BFC1-08002BE10318}
Description: Standard Dual Channel PCI IDE Controller
Device ID: PCI\VEN_197B&DEV_2363&SUBSYS_824F1043&REV_03\4&332B0EE8&0&00E4
Manufacturer: (Standard IDE ATA/ATAPI controllers)
Name: Standard Dual Channel PCI IDE Controller
PNP Device ID: PCI\VEN_197B&DEV_2363&SUBSYS_824F1043&REV_03\4&332B0EE8&0&00E4
Service: pciide

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4364&SUBSYS_81F81043&REV_12\4&625283&0&00E5
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_11AB&DEV_4364&SUBSYS_81F81043&REV_12\4&625283&0&00E5
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:

Class GUID: {4D36E978-E325-11CE-BFC1-08002BE10318}
Description: Communications Port
Device ID: ACPI\PNP0501\1
Manufacturer: (Standard port types)
Name: Communications Port (COM1)
PNP Device ID: ACPI\PNP0501\1
Service: Serial

Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Keyboard
Device ID: ACPI\PNP0303\4&B6AFFD&0
Manufacturer: Logitech
Name: PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&B6AFFD&0
Service: i8042prt

Class GUID: {4D36E96A-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) ICH9 2 port Serial ATA Storage Controller 2 - 2926
Device ID: PCI\VEN_8086&DEV_2926&SUBSYS_82771043&REV_02\3&11583659&0&FD
Manufacturer: Intel
Name: Intel(R) ICH9 2 port Serial ATA Storage Controller 2 - 2926
PNP Device ID: PCI\VEN_8086&DEV_2926&SUBSYS_82771043&REV_02\3&11583659&0&FD
Service: pciide

Class GUID: {4D36E97B-E325-11CE-BFC1-08002BE10318}
Description: SCSI/RAID Host Controller
Device ID: ACPI\PNPA000\4&5D18F2DF&0
Manufacturer: (Standard mass storage controllers)
Name: SCSI/RAID Host Controller
PNP Device ID: ACPI\PNPA000\4&5D18F2DF&0
Service: aqsx7ul7

==== System Restore Points ===================

RP1: 04/12/2008 2:25:33 AM - System Checkpoint
RP2: 04/12/2008 2:27:48 AM - ComboFix created restore point
RP3: 05/12/2008 5:58:48 AM - System Checkpoint
RP4: 06/12/2008 6:29:27 AM - System Checkpoint
RP5: 07/12/2008 8:32:05 AM - System Checkpoint
RP6: 08/12/2008 8:34:56 AM - System Checkpoint
RP7: 09/12/2008 10:12:43 AM - System Checkpoint
RP8: 10/12/2008 1:58:53 PM - Removed Microsoft Silverlight
RP9: 10/12/2008 2:00:50 PM - Removed Microsoft Office Enterprise 2007
RP10: 11/12/2008 1:43:50 PM - Installed GiPo@FileUtilities 3.2
RP11: 11/12/2008 1:54:15 PM - Revo Uninstaller's restore point - GiPo@FileUtilities 3.2
RP12: 11/12/2008 1:54:29 PM - Removed GiPo@FileUtilities 3.2
RP13: 11/12/2008 1:58:11 PM - Installed Microsoft Office Enterprise 2007
RP14: 11/12/2008 2:10:02 PM - Printer Driver Send To Microsoft OneNote Driver Installed
RP15: 11/12/2008 3:04:07 PM - Configured Microsoft Office Enterprise 2007
RP16: 11/12/2008 11:43:50 PM - Software Distribution Service 3.0
RP17: 12/12/2008 6:33:55 PM - Revo Uninstaller's restore point - Disciples 2 Gold Gallean
RP18: 13/12/2008 1:11:48 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP19: 14/12/2008 11:25:48 AM - Software Distribution Service 3.0
RP20: 15/12/2008 11:27:36 AM - System Checkpoint
RP21: 15/12/2008 4:43:38 PM - ComboFix created restore point
RP22: 16/12/2008 7:36:11 AM - ComboFix created restore point
RP23: 16/12/2008 4:30:18 PM - Software Distribution Service 3.0

==== Installed Programs ======================


*edited to save space*

==== Event Viewer Messages ===================

11/12/2008 1:39:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
11/12/2008 1:37:42 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
11/12/2008 1:37:36 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
11/12/2008 1:19:29 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips i8042prt intelppm IPSec kl1 klbg KLIF MRxSmb NetBIOS NetBT RasAcd Rdbss SCDEmu Tcpip
11/12/2008 1:19:29 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/12/2008 1:19:29 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
11/12/2008 1:19:29 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

==== End Of File ===========================
Attached Files
File Type: txt DDS.txt (8.3 KB, 1 views)
File Type: txt Attach.txt (11.6 KB, 1 views)

Last edited by Ried; 12-16-2008 at 08:02 PM.
tanger is offline