DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.16674
Run by X at 18:34:23 on 2014-09-08
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2217 [GMT 4.5:30]
.
AV: Bitdefender Antivirus *Enabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *Enabled*
.
============== Running Processes ================
.
C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\HitmanPro\hmpsched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bitdefender\Bitdefender 2015\bdagent.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe
C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxapps.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\THEKMP~1\KMPlayer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\osk.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
BHO: IDM integration (IDMIEHlprObj Class): {0055C089-8582-441B-A0BF-17B458C2A3A8} - c:\program files\internet download manager\IDMIECC.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
uRun: [Bitdefender Wallet Agent] "c:\program files\bitdefender\bitdefender 2015\bdwtxag.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [Bdagent] "c:\program files\bitdefender\bitdefender 2015\bdagent.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [NUSB3MON] "c:\program files\nec electronics\usb 3.0 host controller driver\application\nusb3mon.exe"
dRunOnce: [nltide_2] regsvr32 /s /n /I:U shell32
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{CF609D1E-97DD-4B77-AF6C-24905EF17D10} : DHCPNameServer = 192.168.1.1
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 141.0.174.38 xvideos.com
Hosts: 141.0.174.39
www.xvideos.com
Hosts: 141.0.173.209 static.xvideos.com
Hosts: 199.16.156.198 twitter.com
Hosts: 69.55.53.7 forum.xnxx.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\x\application data\mozilla\firefox\profiles\l83mi5s4.default\
FF - plugin: c:\documents and settings\all users\application data\nexoneu\ngm\npNxGameeu.dll
FF - plugin: c:\documents and settings\x\application data\mozilla\firefox\profiles\l83mi5s4.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_14_0_0_179.dll
.
============= SERVICES / DRIVERS ===============
.
R0 avc3;avc3;c:\windows\system32\drivers\avc3.sys [2014-9-5 1060312]
R0 gzflt;gzflt;c:\windows\system32\drivers\gzflt.sys [2014-9-5 165744]
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\eek\bin\a2ddax86.sys [2014-9-6 22056]
R1 BDVEDISK;BDVEDISK;c:\windows\system32\drivers\bdvedisk.sys [2014-9-5 72704]
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2012-8-31 109768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-13 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2014-7-23 142648]
R2 HitmanProScheduler;HitmanPro Scheduler;c:\program files\hitmanpro\hmpsched.exe [2014-9-5 106248]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes anti-malware\mbamscheduler.exe [2014-9-5 1809720]
R2 MBAMService;MBAMService;c:\program files\malwarebytes anti-malware\mbamservice.exe [2014-9-5 860472]
R2 UPDATESRV;Bitdefender Desktop Update Service;c:\program files\bitdefender\bitdefender 2015\updatesrv.exe [2014-9-5 54424]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2014-9-5 99856]
R3 avckf;avckf;c:\windows\system32\drivers\avckf.sys [2014-9-5 528248]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf.sys [2014-9-5 116688]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2014-9-5 23256]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2014-9-5 110296]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2014-9-5 1691480]
S3 avchv;avchv Function Driver;c:\windows\system32\drivers\avchv.sys [2014-9-5 242504]
S3 BdDesktopParental;Bitdefender Desktop Parental Control;c:\program files\bitdefender\bitdefender 2015\bdparentalservice.exe [2014-9-5 69880]
S3 BDSandBox;BDSandBox;c:\windows\system32\drivers\bdsandbox.sys [2014-9-5 66832]
S3 cleanhlp;cleanhlp;c:\eek\bin\cleanhlp32.sys [2014-9-6 50200]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\eaglexnt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
.
=============== Created Last 30 ================
.
2014-09-08 00:35:09 -------- d-----w- c:\documents and settings\x\local settings\application data\Identities
2014-09-07 23:08:30 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2014-09-07 23:03:25 -------- d-----w- c:\program files\NEC Electronics
2014-09-07 13:08:08 -------- d-----w- c:\documents and settings\all users\application data\Nexon
2014-09-07 12:50:46 -------- d-----w- c:\documents and settings\all users\application data\NexonEU
2014-09-07 11:48:06 -------- d-----w- c:\documents and settings\x\application data\SUPERAntiSpyware.com
2014-09-07 11:47:28 -------- d-----w- c:\program files\SUPERAntiSpyware
2014-09-07 11:47:28 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2014-09-07 10:54:37 12872 ----a-w- c:\windows\system32\bootdelete.exe
2014-09-07 10:41:51 -------- d-----w- c:\documents and settings\x\local settings\application data\Google
2014-09-06 19:04:00 -------- d-----w- C:\FRST
2014-09-05 23:30:10 -------- d-----w- c:\documents and settings\x\local settings\application data\ATI
2014-09-05 21:02:14 -------- d-----w- C:\EEK
2014-09-05 13:41:08 -------- d-----w- c:\program files\ESET
2014-09-05 13:34:43 -------- d-----w- c:\windows\ERUNT
2014-09-05 13:27:28 -------- d-----w- C:\AdwCleaner
2014-09-05 13:21:12 33512 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-09-05 13:21:10 -------- d-----w- c:\documents and settings\all users\application data\RogueKiller
2014-09-05 13:19:01 -------- d-----w- c:\program files\HitmanPro
2014-09-05 13:18:33 -------- d-----w- c:\documents and settings\all users\application data\HitmanPro
2014-09-05 13:12:04 110296 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-09-05 13:11:51 53208 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-09-05 13:11:51 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-09-05 13:11:51 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2014-09-05 12:44:34 -------- d-----w- c:\windows\system32\ReinstallBackups
2014-09-05 12:44:27 99856 ----a-w- c:\windows\system32\drivers\AtihdXP3.sys
2014-09-05 12:44:18 0 ----a-w- c:\windows\ativpsrm.bin
2014-09-05 12:39:35 -------- d-----w- c:\program files\ATI Technologies
2014-09-05 12:39:34 -------- d-----w- c:\program files\ATI
2014-09-05 12:38:33 -------- d-----w- C:\AMD
2014-09-05 12:27:38 -------- d-----w- c:\windows\system32\Lang
2014-09-05 12:23:58 -------- d-----w- c:\windows\system32\RTCOM
2014-09-05 12:20:11 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-09-05 12:20:11 699568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-09-05 12:19:50 -------- d-----w- c:\program files\GIGABYTE
2014-09-05 12:19:48 327168 ----a-w- c:\windows\IsUninst.exe
2014-09-05 12:19:10 1531268 ----a-w- c:\documents and settings\all users\application data\1409916657.bdinstall.bin
2014-09-05 12:17:37 -------- d-----w- c:\documents and settings\x\local settings\application data\Adobe
2014-09-05 12:08:56 -------- d-----w- c:\documents and settings\all users\application data\BDLogging
2014-09-05 12:08:09 72704 ----a-w- c:\windows\system32\drivers\bdvedisk.sys
2014-09-05 12:07:21 511328 ----a-w- c:\windows\capicom.dll
2014-09-05 12:07:21 116688 ----a-w- c:\windows\system32\drivers\bdfndisf.sys
2014-09-05 12:07:20 74512 ----a-w- c:\windows\system32\bdsandboxuiskin.dll
2014-09-05 12:07:20 66832 ----a-w- c:\windows\system32\drivers\bdsandbox.sys
2014-09-05 12:07:20 27168 ----a-w- c:\windows\system32\bdsandboxuh.dll
2014-09-05 12:07:20 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2014-09-05 12:06:46 528248 ----a-w- c:\windows\system32\drivers\avckf.sys
2014-09-05 12:06:46 242504 ----a-w- c:\windows\system32\drivers\avchv.sys
2014-09-05 12:06:46 1060312 ----a-w- c:\windows\system32\drivers\avc3.sys
2014-09-05 12:00:58 -------- d-----w- c:\documents and settings\x\application data\IDM
2014-09-05 12:00:57 -------- d-----w- c:\documents and settings\x\application data\DMCache
2014-09-05 12:00:49 -------- d-----w- c:\program files\Internet Download Manager
.
==================== Find3M ====================
.
2014-09-05 11:19:55 17488 ----a-w- c:\windows\gdrv.sys
2014-07-02 13:17:10 385096 ----a-w- c:\windows\system32\drivers\trufos.sys
.
============= FINISH: 18:36:24.75 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 9/5/2014 3:43:56 PM
System Uptime: 9/8/2014 4:29:20 PM (2 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | P41T-D3P
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Socket 775 | 2999/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 50 GiB total, 42.505 GiB free.
D: is FIXED (NTFS) - 50 GiB total, 49.575 GiB free.
E: is FIXED (NTFS) - 147 GiB total, 14.375 GiB free.
F: is FIXED (NTFS) - 147 GiB total, 1.356 GiB free.
G: is FIXED (NTFS) - 147 GiB total, 6.856 GiB free.
H: is FIXED (NTFS) - 147 GiB total, 43.133 GiB free.
I: is FIXED (NTFS) - 243 GiB total, 33.674 GiB free.
J: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_14F1&DEV_2F30&SUBSYS_205D14F1&REV_01\4&BC67B8D&0&08F0
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_14F1&DEV_2F30&SUBSYS_205D14F1&REV_01\4&BC67B8D&0&08F0
Service:
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_50011458&REV_01\3&13C0B0C5&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_50011458&REV_01\3&13C0B0C5&0&FB
Service:
.
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: BitDefender AVC HV
Device ID: ROOT\SYSTEM\0003
Manufacturer: (Standard system devices)
Name: BitDefender AVC HV
PNP Device ID: ROOT\SYSTEM\0003
Service: avchv
.
==== System Restore Points ===================
.
RP1: 9/5/2014 3:46:50 PM - System Checkpoint
RP2: 9/5/2014 3:54:39 PM - Installed REALTEK GbE & FE Ethernet PCI-E NIC Driver
RP3: 9/5/2014 4:53:33 PM - Installed Realtek High Definition Audio Driver
RP4: 9/7/2014 3:24:01 PM - Checkpoint by HitmanPro
RP5: 9/7/2014 3:24:34 PM - Checkpoint by HitmanPro
RP6: 9/7/2014 3:43:43 PM - Checkpoint by HitmanPro
RP7: 9/8/2014 3:33:20 AM - Installed NEC Electronics USB 3.0 Host Controller Driver
.
==== Hosts File Hijack ======================
.
Hosts: 141.0.174.38 xvideos.com
Hosts: 141.0.174.39
www.xvideos.com
Hosts: 141.0.173.209 static.xvideos.com
Hosts: 199.16.156.198 twitter.com
Hosts: 69.55.53.7 forum.xnxx.com
Hosts: 69.55.52.190 multi.xnxx.com
Hosts: 69.55.53.77 upload.xvideos.com
Hosts: 141.0.173.148 trafficfactory.biz
Hosts: 192.150.16.117 adobe.com
Hosts: 95.211.170.250 ant.com
Hosts: 69.50.139.162 rtalabel.org
Hosts: 141.0.173.27 info.xvideos.com
Hosts: 208.111.161.254 img100.xvideos.com
Hosts: 208.111.160.6 img.xnxx.com
Hosts: 69.55.53.238 jp.xvideos.com
.
==== Installed Programs ======================
.
Adobe Flash Player 14 Plugin
AMD Catalyst Install Manager
Bitdefender Total Security 2015
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Combat Arms EU
DriverCD
ESET Online Scanner v3
HitmanPro 3.7
Internet Download Manager
Malwarebytes Anti-Malware version 2.0.2.1012
Microsoft .NET Framework 2.0
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 32.0 (x86 en-US)
Mozilla Maintenance Service
NEC Electronics USB 3.0 Host Controller Driver
Nexon Game Manager
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek HDMI Audio Driver for ATI
Realtek High Definition Audio Driver
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB950760)
SUPERAntiSpyware
The KMPlayer (remove only)
Update for Windows XP (KB898461)
WebFldrs XP
WinRAR 4.20 (32-bit)
.
==== Event Viewer Messages From Past Week ========
.
9/7/2014 5:20:31 PM, error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
9/7/2014 5:19:30 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 806373f1, parameter3 a9184b74, parameter4 00000000.
9/7/2014 4:10:21 AM, error: System Error [1003] - Error code 1000000a, parameter1 00000016, parameter2 0000001c, parameter3 00000000, parameter4 804fa266.
9/7/2014 3:51:19 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.
9/7/2014 3:50:29 AM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 1C6F65C42783 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
9/6/2014 3:57:20 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/6/2014 2:31:06 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avc3 bdselfpr BDVEDISK Fips intelppm trufos
9/5/2014 4:22:27 PM, error: Service Control Manager [7034] - The MBAMScheduler service terminated unexpectedly. It has done this 1 time(s).
9/5/2014 3:55:36 PM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -122474 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|192.168.1.2:123->64.4.10.33:123) is working properly.
.
==== End Of File ===========================