Anda di halaman 1dari 3

.

DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL


Internet Explorer: 8.0.6001.19088
Run by Katy at 20:02:52 on 2012-07-26
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Explorer.EXE
C:\Windows\helppane.exe
C:\Users\Katy\Desktop\dds.scr
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0809&m=aspire_5332&r=2v
350709c105l0304zq45t47i2x236
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c
:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae0
64} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program
files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~
1\mcafee\msk\mskapbho.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcaf
ee\virusscan\scriptsn.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\pr
ogram files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program
files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\pr
ogram files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~
1\mcafee\sitead~1\mcieplg.dll
BHO: LimeWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files
\ask.com\GenericAskToolbar.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\prog
ra~1\mcafee\sitead~1\mcieplg.dll
TB: LimeWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\
ask.com\GenericAskToolbar.dll
TB: {8dcb7100-df86-4384-8842-8fa844297b3f} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\go
ogle\google toolbar\GoogleToolbar_32.dll
mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malwar
e\mbamgui.exe /install /silent
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\programdata\mal
warebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33A

EC} - c:\program files\windows live\writer\WriterBrowserExtension.dll


IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E348
6C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D655
03} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: o2.co.uk\*.broadband
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub
/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub
/shockwave/cabs/director/sw.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/control
s/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/j
install-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/j
install-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/j
install-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/ge
tPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{8E754B43-A926-4192-B09F-AE0A89555BE5} : DhcpNameServer = 192.16
8.1.254
TCP: Interfaces\{A156ED08-84FA-4128-BBBC-4F79EC76EB10} : DhcpNameServer = 192.16
8.1.254
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafe
e\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\si
tead~1\McIEPlg.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\prog
ram files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1
www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R? BBSvc;Bing Bar Update Service
R? CLHNService;CLHNService
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? DPMemGridVista;Physical Memory I/O for GridVista
R? ePowerSvc;Acer ePower Service
R? GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller
R? MBAMProtector;MBAMProtector
R? MBAMService;MBAMService
R? McAfee SiteAdvisor Service;McAfee SiteAdvisor Service
R? McComponentHostService;McAfee Security Scan Component Host Service
R? McProxy;McAfee Proxy Service
R? McShield;McAfee Real-time Scanner
R? McSysmon;McAfee SystemGuards
R? mfeavfk;McAfee Inc. mfeavfk
R? mfebopk;McAfee Inc. mfebopk
R? mfehidk;McAfee Inc. mfehidk
R? mferkdk;McAfee Inc. mferkdk
R? mfesmfk;McAfee Inc. mfesmfk
R? mwlPSDFilter;mwlPSDFilter

R? mwlPSDNServ;mwlPSDNServ
R? mwlPSDVDisk;mwlPSDVDisk
R? MWLService;MyWinLocker Service
R? NTIBackupSvc;NTI Backup Now 5 Backup Service
R? NTISchedulerSvc;NTI Backup Now 5 Scheduler Service
R? PAC207;PC Camer@
R? SASDIFSV;SASDIFSV
R? SASKUTIL;SASKUTIL
R? SBSDWSCService;SBSD Security Center Service
R? sprtsvc_O2;SupportSoft Sprocket Service (O2)
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
.
=============== Created Last 30 ================
.
2012-07-26 00:00:33
-------d-----wC:\TDSSKiller_Quarantine
2012-07-25 23:52:52
-------d-----wc:\users\katy\appdata\lo
cal\temp
2012-07-25 23:52:09
-------d-sh--wC:\$RECYCLE.BIN
2012-07-25 23:11:38
-------d-----wc:\program files\VS Revo
Group
2012-07-25 18:14:18
98816 ----a-wc:\windows\sed.exe
2012-07-25 18:14:18
518144 ----a-wc:\windows\SWREG.exe
2012-07-25 18:14:18
256000 ----a-wc:\windows\PEV.exe
2012-07-25 18:14:18
208896 ----a-wc:\windows\MBR.exe
2012-07-25 18:12:06
-------d-----wC:\FRST
2012-07-24 23:18:24
-------d-----wc:\programdata\Spybot Search & Destroy
2012-07-24 23:18:24
-------d-----wc:\program files\Spybot
- Search & Destroy
2012-07-24 21:53:32
-------d-----wc:\windows\pss
2012-07-24 19:16:04
-------d-----wc:\users\katy\appdata\ro
aming\Malwarebytes
2012-07-24 19:15:28
-------d-----wc:\programdata\Malwareby
tes
2012-07-24 19:15:27
22344 ----a-wc:\windows\system32\drivers\mbam
.sys
2012-07-24 19:15:27
-------d-----wc:\program files\Malware
bytes' Anti-Malware
2012-07-24 17:56:35
-------d-----wc:\users\katy\appdata\ro
aming\SUPERAntiSpyware.com
2012-07-24 17:56:27
-------d-----wc:\program files\SUPERAn
tiSpyware
2012-07-24 17:56:26
-------d-----wc:\programdata\SUPERAnti
Spyware.com
.
==================== Find3M ====================
.
.
============= FINISH: 20:04:52.54 ===============

Anda mungkin juga menyukai