DDS:
.
DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22
Run by lorraine hobson at 21:13:31 on 2011-06-04
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1022.507 [GMT 1:00]
.
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwbarebytes' brilliant virus removal\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\program files\lxbmaesm\tesykeca.exe
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\documents and settings\lorraine hobson\start menu\programs\startup\tesykeca.exe
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\
www.msi
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\aatp.dll
WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll
Hosts: 127.0.0.1
www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\lorraine hobson\application data\mozilla\firefox\profiles\bs3czrpn.default\
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
============= SERVICES / DRIVERS ===============
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2011-4-28 53816]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-6-4 11608]
R1 RapportCerberus_26169;RapportCerberus_26169;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\26169\RapportCerberus_26169.sys [2011-5-2 57144]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2011-4-28 158904]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-6-4 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-6-4 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-6-4 61960]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2008-11-26 66048]
R2 MBAMService;MBAMService;c:\program files\malwbarebytes' brilliant virus removal\mbamservice.exe [2011-6-3 366640]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 3xHybrid;Philips SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2006-7-10 882688]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2011-3-15 57440]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-6-3 22712]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [2006-7-10 7040]
S1 MpKsl0b05d477;MpKsl0b05d477;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3f392024-a7a8-4a02-ac08-b1d7a85fc6a6}\mpksl0b05d477.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3f392024-a7a8-4a02-ac08-b1d7a85fc6a6}\MpKsl0b05d477.sys [?]
S1 MpKsl35231091;MpKsl35231091;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32028339-1dc9-4323-ac79-3e178affe807}\mpksl35231091.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32028339-1dc9-4323-ac79-3e178affe807}\MpKsl35231091.sys [?]
S1 MpKslae24dca0;MpKslae24dca0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32028339-1dc9-4323-ac79-3e178affe807}\mpkslae24dca0.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{32028339-1dc9-4323-ac79-3e178affe807}\MpKslae24dca0.sys [?]
S1 MpKslb9bbebb4;MpKslb9bbebb4;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{48696746-f734-4d1d-91aa-cb7eb40d032d}\mpkslb9bbebb4.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{48696746-f734-4d1d-91aa-cb7eb40d032d}\MpKslb9bbebb4.sys [?]
S1 MpKsld3ad200c;MpKsld3ad200c; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-3 136176]
S3 AR9271;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2011-3-15 1723840]
S3 DUBE100;D-LINK DUB-E100 USB 2.0 to Fast Ethernet Adapter;c:\windows\system32\drivers\DUBE100.sys [2009-1-16 11935]
S3 esgiguard;esgiguard;\??\c:\program files\enigma software group\spyhunter\esgiguard.sys --> c:\program files\enigma software group\spyhunter\esgiguard.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-8-3 136176]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files\netgear\wna1100\jswpsapi.exe [2011-3-15 360529]
S3 Micorsoft Windows Service;Micorsoft Windows Service;\??\c:\windows\temp\bptgnbum.sys --> c:\windows\temp\bptgnbum.sys [?]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [2008-11-26 167808]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2008-11-26 13532]
S4 WSWNA1100;WSWNA1100;c:\program files\netgear\wna1100\WifiSvc.exe [2011-3-15 268768]
.
=============== Created Last 30 ================
.
2011-06-04 20:03:29 -------- d-----w- c:\documents and settings\lorraine hobson\application data\Avira
2011-06-04 19:53:35 179631 ----a-w- c:\program files\internet explorer\iexploremgr.exe
2011-06-04 18:26:09 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-06-04 18:26:09 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-04 00:53:50 -------- d-sha-w- c:\windows\Repair
2011-06-04 00:40:56 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-04 00:40:54 -------- d-----w- c:\program files\Avira
2011-06-04 00:40:54 -------- d-----w- c:\documents and settings\all users\application data\Avira
2011-06-04 00:12:14 -------- d-----w- c:\program files\Trend Micro
2011-06-03 21:34:54 -------- d-----w- c:\program files\Spybot - Search & Destroy brilliant
2011-06-03 18:55:56 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-03 18:55:50 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-03 18:55:50 -------- d-----w- c:\program files\Malwbarebytes' brilliant virus removal
2011-06-03 18:31:33 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-06-03 18:24:18 179631 --s---w- C:\tesykeca.exe
2011-05-28 22:49:28 -------- d-----w- c:\program files\lxbmaesm
.
==================== Find3M ====================
.
2011-04-28 13:34:50 53816 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2003-08-27 22:19:18 36963 ----a-r- c:\program files\common files\SM1updtr.dll
.
============= FINISH: 21:17:56.50 ===============