DDS (Ver_09-02-01.01) - NTFSx86
Run by Administrator at 18:26:30,26 on 03/02/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.456 [GMT 1:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Documents and Settings\Administrator.CHAOSCOMP\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\documents and settings\administrator.chaoscomp\lackf.exe \s
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [services] c:\windows\services.exe
dRun: [ctfmon.exe] c:\windows\system32\CTFMON.EXE
dRun: [lfwffqrf.exe] c:\windows\lfwffqrf.exe
dRun: [services] c:\windows\services.exe
mExplorerRun: [services] c:\windows\services.exe
dExplorerRun: [services] c:\windows\services.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-system: DisableRegistryTools = 1 (0x1)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
============= SERVICES / DRIVERS ===============
S3 CSNPD51;CSNPD51 NDIS Protocol Driver;c:\windows\system32\drivers\CSNPD51.sys [2009-1-31 27800]
S3 FrwDriver;Frw Virtual Audio Device (WDM);c:\windows\system32\drivers\FrwDriver.sys [2009-1-15 33152]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
=============== Created Last 30 ================
2009-02-03 18:17 21,803,560 a------- C:\sav32sfx.exe
2009-02-03 17:54 138,496 a------- c:\windows\system32\drivers\ethkliyu.sys
2009-02-03 17:54 3,584 a------- c:\windows\lfwffqrf.exe
2009-02-03 17:49 32,768 a---h--- c:\documents and settings\administrator.chaoscomp\lackf.exe
2009-02-03 17:49 53,248 a------- c:\windows\system32\drivers\ndisio.sys
2009-02-03 17:49 66,560 ----h--- c:\windows\system32\secupdat.dat
2009-02-03 17:49 163,844 a------- c:\windows\system32\4.tmp
2009-02-03 14:56 537,088 a------- C:\rmvirut.exe
2009-02-03 14:56 495,104 a------- C:\rmvirut.nt
2009-02-03 11:50 4,622,076 a------- c:\temp\WINDOWSXP-KB310994-SP2-PRO-BOOTDISK-FRA.EXE
2009-02-03 11:27 168,960 a------- c:\temp\JavaRa.exe
2009-02-03 11:25 69,512 a------- c:\temp\JavaRa.zip
2009-02-03 10:54
--d----- c:\docume~1\admini~1.cha\applic~1\Malwarebytes
2009-02-03 10:54 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-03 10:54 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-03 10:54 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-03 10:54 --d----- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-02-03 01:11 9,728 -------- c:\windows\system32\rwnh.dll
2009-02-03 01:11 10,752 -------- c:\windows\system32\smtpapi.dll
2009-02-03 01:04 --d----- c:\docume~1\admini~1.cha\applic~1\iWin
2009-02-03 00:46 --d----- c:\windows\system32\appmgmt
2009-02-02 23:58 19,569 a------- c:\windows\000001_.tmp
2009-02-02 22:57 142,592 a------- c:\windows\system32\drivers\aec.sys
2009-02-02 22:36 37,376 a------- c:\windows\services.exe
2009-02-02 20:49 4 a------- c:\windows\_id.dat
2009-02-02 20:49 130 a------- c:\windows\adobe.bat
2009-02-02 20:15 --d----- c:\program files\Trend Micro
2009-02-02 20:06 59,904 a------- c:\windows\system32\drivers\atmarpc.sys.bak
2009-02-02 19:44 --d----- c:\windows\Jewel Match 2
2009-02-02 18:52 0 a------- c:\windows\system32\3C.tmp
2009-02-02 18:15 0 a----r-- c:\windows\vxrikaff.exe
2009-02-02 18:11 0 a------- c:\windows\system32\2C.tmp
2009-02-02 17:36 --d-h--- C:\$AVG8.VAULT$
2009-02-02 17:25 --d----- c:\docume~1\alluse~1.win\applic~1\Downloaded Installations
2009-02-02 17:24 --d----- c:\program files\AVG
2009-02-02 17:24 --d----- c:\docume~1\alluse~1.win\applic~1\avg8
2009-02-02 17:20 --d-h--- c:\windows\PIF
2009-02-02 16:44 --d----- c:\program files\Advanced Registry Fix
2009-02-02 16:22 0 a------- c:\windows\system32\B5.tmp
2009-02-02 16:05 0 a------- c:\windows\system32\8D.tmp
2009-02-02 15:45 0 a----r-- c:\windows\system32\drivers\803ff150.sys
2009-02-02 15:08 194 a------- c:\windows\workshop.ini
2009-02-02 15:06 --d----- C:\Boulot
2009-02-02 14:30 --d----- c:\docume~1\admini~1.cha\applic~1\JewelMatch2
2009-02-02 02:40 1,341 a------- C:\regtools.vbs
2009-02-02 02:30 --d-h--- c:\windows\system32\GroupPolicy
2009-02-02 02:21 0 a------- c:\windows\mqcd.dbt
2009-02-02 02:20 28,672 a------- c:\windows\system32\do8d.sr
2009-02-02 02:20 32,768 a------- c:\windows\system32\rer.wa
2009-02-02 02:20 32,768 a------- c:\windows\system32\qzhr1.ant
2009-02-02 02:20 28,672 a------- c:\windows\system32\dedwf.lp
2009-02-02 02:20 77,312 a------- c:\windows\system32\re3d.pf
2009-02-02 02:18 --d----- c:\program files\ReflexiveArcade
2009-02-01 10:36 --d----- c:\program files\Nmap
2009-02-01 01:56 --d----- c:\program files\SQLPowerInjector
2009-02-01 01:37 --d----- c:\program files\0x90.org
2009-01-31 20:01 --d----- c:\docume~1\admini~1.cha\applic~1\Colasoft Packet Builder
2009-01-31 20:01 --d----- c:\program files\common files\Colasoft Shared
2009-01-31 20:01 --d----- c:\program files\Colasoft Packet Builder 1.0
2009-01-31 11:36 4,096 a------- c:\windows\d3dx.dat
2009-01-31 00:17 186,407 a------- c:\windows\system32\nvapps.nvb
2009-01-31 00:16 --d----- C:\NVIDIA
2009-01-31 00:13 221,184 a------- c:\windows\system32\wmpns.dll
2009-01-31 00:12 --d----- c:\windows\system32\xircom
2009-01-31 00:05 --d----- c:\windows\ServicePackFiles
2009-01-30 12:56 --d----- c:\windows\system32\DirectX
2009-01-29 23:13 --d----- c:\docume~1\alluse~1.win\applic~1\2DBoy
2009-01-29 17:51 59 a------- c:\windows\go.bat
2009-01-27 16:54 --d----- c:\documents and settings\administrator.chaoscomp\.thumbnails
2009-01-27 16:53 --d----- c:\documents and settings\administrator.chaoscomp\.gimp-2.6
2009-01-27 16:53 --d----- c:\documents and settings\administrator.chaoscomp\.gegl-0.0
2009-01-27 16:48 --d----- c:\program files\GIMP-2.0
2009-01-27 16:45 3,639,412 a------- c:\temp\GREYCstoration-2.9.zip
2009-01-27 16:30 --d----- c:\program files\VirtuallTek
2009-01-25 16:21 --d----- c:\docume~1\admini~1.cha\applic~1\Wireshark
2009-01-25 16:09 --d----- c:\program files\WinPcap
2009-01-25 16:08 --d----- c:\program files\Wireshark
2009-01-25 13:51 --d----- c:\docume~1\alluse~1.win\applic~1\Trymedia
2009-01-24 00:55 --d----- c:\temp\Word
2009-01-24 00:53 --d----- c:\program files\MSECache
2009-01-22 21:54 74 a------- c:\windows\CFF Explorer.INI
2009-01-22 21:09 1,869 a------- c:\windows\TSearch.INI
2009-01-22 20:33 1,764,044 a------- C:\TestSound2.wav
2009-01-22 19:04 196,652 a------- C:\Ramp3.wav
2009-01-22 18:54 524,324 a------- C:\Ramp2.wav
2009-01-22 18:50 524,324 a------- C:\Ramp.wav
2009-01-20 00:13 32,768 a------- c:\windows\ReBirth RB-338 2.prf
2009-01-20 00:11 41,216 a---h--- C:\rb20crk.dat
2009-01-20 00:11 --d----- C:\audio
2009-01-18 20:01 82,583 a------- c:\temp\in_mpc.exe
2009-01-18 20:00 51,600 a------- c:\windows\system32\RadLightMPCUninstall.exe
2009-01-18 18:44 176,444 a------- C:\TestSound.wav
2009-01-16 14:57 423,424 a------- C:\HdErazer.exe
2009-01-15 22:06 11,008 a------- c:\windows\system32\drivers\KSMON.SYS
2009-01-15 20:56 3,154,009 a------- c:\temp\audacity-win-1.2.6.zip
2009-01-15 14:09 33,152 a------- c:\windows\system32\drivers\FrwDriver.sys
2009-01-15 13:38 156,910 a------- c:\windows\WMSysPr8.prx
2009-01-15 13:38 665,424 a------- c:\windows\system32\wmv8dmoe.dll
2009-01-15 13:38 572,752 a------- c:\windows\system32\wmvdmoe.dll
2009-01-15 13:38 438,608 a------- c:\windows\system32\wmv8dmod.dll
2009-01-15 13:38 1,683,792 a------- c:\windows\system32\wmvcore2.dll
2009-01-15 13:38 285,184 a------- c:\windows\system32\wmidx2.ocx
2009-01-15 11:44 14,275,882 a------- c:\temp\pidgin-2.5.4.exe
2009-01-14 20:24 --d----- c:\documents and settings\administrator.chaoscomp\VSWebCache
2009-01-11 21:23 17,408 a------- c:\windows\system32\drivers\vadsimpl.sys
2009-01-11 20:49 0 a------- c:\windows\graphedt.INI
2009-01-11 20:16 321 a------- c:\windows\ksstudio.ini
2009-01-11 20:03 --d----- C:\WINDDK
2009-01-10 17:36 --d----- c:\temp\aspell
2009-01-09 22:17 8,192 a------- c:\windows\REGLOCS.OLD
2009-01-09 22:15 --d----- c:\program files\Peer2Me
2009-01-09 22:07 3,217,072 a------- c:\temp\Peer2Me - setup.exe
2009-01-09 18:02 --d----- c:\docume~1\admini~1.cha\applic~1\ChaosPro
2009-01-09 18:02 --d----- c:\program files\ChaosPro3.3
2009-01-08 22:54 --d----- c:\program files\ionCube Package Foundry Evaluation
2009-01-08 22:53 86,016 a------- c:\windows\system32\ionenshi.dll
2009-01-08 22:53 --d----- c:\program files\ionCubePHPEncoder6.5
2009-01-08 22:10 --d----- c:\docume~1\admini~1.cha\applic~1\Subversion
2009-01-08 22:08 --d----- c:\program files\TortoiseSVN
2009-01-08 20:54 22,148,280 a------- c:\temp\antivir_workstation_winu_fr_h.exe
2009-01-07 18:55 --d----- c:\temp\Fractals
2009-01-06 19:30 --d----- c:\temp\idaplugs
2009-01-06 18:47 --d----- c:\program files\Delphi Files
2009-01-06 14:27 --d----- c:\docume~1\admini~1.cha\applic~1\Dev-Cpp
2009-01-06 14:27 --d----- C:\Dev-Cpp
2009-01-05 20:22 --d----- c:\program files\ShareAPicUploader
2009-01-05 20:22 --d----- c:\temp\SAPuploader30
2009-01-05 19:38 --d----- c:\temp\crackjob
2009-01-05 13:31 --d----- c:\docume~1\admini~1.cha\applic~1\Datarescue
2009-01-05 13:30 --d----- c:\program files\Photo N-Gine
2009-01-04 20:08 --d----- c:\windows\system32\oodag
==================== Find3M ====================
2009-01-02 19:13 159 a------- c:\windows\fonts\INSTALL.LOG
2009-01-02 11:12 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-27 20:15 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-27 20:10 21,640 a------- c:\windows\system32\emptyregdb.dat
2008-12-08 12:53 57,344 a------- c:\windows\system32\ff_vfw.dll
2008-12-07 19:08 795,648 a------- c:\windows\system32\xvidcore.dll
2008-12-07 19:08 130,048 a------- c:\windows\system32\xvidvfw.dll
2004-08-22 17:05 102,400 a------- c:\program files\daemon.exe
2002-05-23 11:55 167,936 a------- c:\program files\pfctoc.dll
============= FINISH: 18:26:52,94 ===============