You are on page 1of 4

Log created by WinPatrol PLUS version 25.6.2012.1:25.6.2012.

1 Scan saved at 8:07:08 PM, on 12/26/2012 Platform: Windows XP SP3 Service Pack 3 (Build 2600) MSIE: Internet Explorer (7.00.6000.20772) Boot mode: Normal Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ctfmon.exe D:\IBM\TC\TOTALCMD.EXE D:\IBM\WinPatrol 2012 PLUS v25.6.2012.1 with Key [h33t][iahq76]\WinPatrol\WinPat rol.exe D:\IBM\WinPatrol 2012 PLUS v25.6.2012.1 with Key [h33t][iahq76]\WinPatrol\WinPat rolEx.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.micro soft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go .microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.micro soft.com/fwlink/?LinkId=69157 O4 - HKCU\..\Run: [ctfmon.exe]C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIC ROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir% \Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2b a38496583} - %windir%\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Progr am Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F 795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [] O14 - IERESET.INF: START_PAGE_URL = http://www.microsoft.com/isapi/redir.dll?prd =ie&pver=6&ar=msnhome O14 - IERESET.INF: SEARCH_PAGE_URL = http://www.microsoft.com/isapi/redir.dll?pr d=ie&ar=iesearch O14 - IERESET.INF:HKCU, Start Page = %START_PAGE_URL% O14 - IERESET.INF:HKLM, Default_Page_URL = %START_PAGE_URL% O14 - IERESET.INF:HKLM, Default_Search_URL = %SEARCH_PAGE_URL% O14 - IERESET.INF:HKLM, Search Page = %SEARCH_PAGE_URL% O14 - IERESET.INF:HKCU, Search Page = %SEARCH_PAGE_URL% O21 - WPDShServiceObj - WPDShServiceObj Class - {AAA288BA-9A4C-45B0-95D7-94D5248 69DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe Flash Player Update Service - Adobe Systems Incorporated C:\WINDOWS\system32\Macromed\Flash\FLASHPLAYERUPDATESERVICE.EXE O23 - Service: Google Update Service (gupdate) - Google Inc. - C:\PROGRAM FILES\ Google\Update\GOOGLEUPDATE.EXE O23 - Service: Google Update Service (gupdatem) - Google Inc. - C:\PROGRAM FILES \Google\Update\GOOGLEUPDATE.EXE O23 - Service: Human Interface Device Access - - C:\WINDOWS\SYSTEM32\HIDSERV.DL L --- Additional WinPatrol Info ---

Default Browser: Windows Internet Explorer - Internet Explorer version 7.00.6000. 20772 MSIE: Internet Explorer (7.00.6000.20772) 55 IE Cookies in Folder: C:\Documents and Settings\DEUS\Cookies\ 17 Mozilla Cookies in Folder: C:\Documents and Settings\DEUS\Application Data\Mo zilla\FireFox\Profiles\iog1ksat.default WP00 WP00 WP00 WP02 HKLM\CS1: HKLM\CCS: HKLM\CS2: HKLM\CCS: BootExecute = autocheck autochk * BootExecute = autocheck autochk * BootExecute = autocheck autochk * Command = C:\WINDOWS\system32\cmd.exe

WP03 - Windows Automatic Update = 1:Turn off Automatic Updates. WP08 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix: Default = http:// WP08 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes: www = http:/ / WP31 - Scheduled Tasks: [Adobe Flash Player Updater.job]C:\WINDOWS\system32\Macr omed\Flash\FlashPlayerUpdateService.exe 12/26/2012 7:11 PM WP31 - Scheduled Tasks: [GoogleUpdateTaskMachineUA.job]C:\Program Files\Google\U pdate\GoogleUpdate.exe 12/26/2012 7:23 PM WP31 - Scheduled Tasks: [GoogleUpdateTaskMachineCore.job]C:\Program Files\Google \Update\GoogleUpdate.exe 12/26/2012 5:27 PM WP16 - ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} [Shockwave Flash Object] C:\WINDOWS\system32\Macromed\Flash\FLASH32_11_2_202_235.OCX 11,2,202,235 WP16 - ActiveX: {0002E541-0000-0000-C000-000000000046} [Microsoft Office Spreads heet 10.0] C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC1 0.DLL 10.0.6765 WP16 - ActiveX: {0002E542-0000-0000-C000-000000000046} [Microsoft Office PivotTa ble 10.0] C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10 .DLL 10.0.6765 WP16 - ActiveX: {0002E543-0000-0000-C000-000000000046} [Microsoft Office Data So urce Control 10.0] C:\Program Files\Common Files\Microsoft Shared\Web Components \10\OWC10.DLL 10.0.6765 WP16 - ActiveX: {0002E546-0000-0000-C000-000000000046} [Microsoft Office Chart 1 0.0] C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL 10.0.6765 WP16 - ActiveX: {05589fa1-c356-11ce-bf01-00aa0055595a} [ActiveMovieControl Objec t] C:\WINDOWS\system32\wmpdxm.dll 11.0.5721.5145 WP16 - ActiveX: {1D2B4F40-1F10-11D1-9E88-00C04FDCAB92} [ThumbCtl Class] C:\WINDO WS\system32\webvw.dll 6.00.2900.5512 WP16 - ActiveX: {52A2AAAE-085D-4187-97EA-8C30DB990436} [HHCtrl Object] C:\WINDOW S\system32\hhctrl.ocx 5.2.3790.4110 WP16 - ActiveX: {8856F961-340A-11D0-A96B-00C04FD705A2} [Microsoft Web Browser] C :\WINDOWS\system32\ieframe.dll 7.00.6000.20772 WP16 - ActiveX: {8BD21D50-EC42-11CE-9E0D-00AA006002F3} [Microsoft Forms 2.0 Opti onButton] C:\WINDOWS\system32\FM20.DLL 11.0.6550 WP16 - ActiveX: {AE24FDAE-03C6-11D1-8B76-0080C744F389} [Microsoft Scriptlet Comp onent] C:\WINDOWS\system32\mshtml.dll 7.00.6000.20772 WP16 - ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} [Shockwave Flash Object] C:\WINDOWS\system32\Macromed\Flash\FLASH32_11_2_202_235.OCX 11,2,202,235 WP16 - ActiveX: {D27CDB70-AE6D-11cf-96B8-444553540000} [Macromedia Flash Factory Object] C:\WINDOWS\system32\Macromed\Flash\FLASH32_11_2_202_235.OCX 11,2,202,23 5 WP16 - ActiveX: {E5DF9D10-3B52-11D1-83E8-00A0C90DC849} [WebViewFolderIcon Class] C:\WINDOWS\system32\webvw.dll 6.00.2900.5512

WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden WP32 - Hidden ndex.dat WP32 - Hidden 32e.tmp WP32 - Hidden 9d8.tmp WP32 - Hidden c7c.tmp WP32 - Hidden 99a.tmp WP32 - Hidden a26.tmp WP32 - Hidden ab8.tmp WP32 - Hidden 630.tmp WP32 - Hidden 544.tmp

File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File: File:

C:\PAGEFILE.SYS C:\ntldr C:\NTDETECT.COM C:\boot.ini C:\IO.SYS C:\MSDOS.SYS C:\WINDOWS\winstart.bat C:\WINDOWS\winnt.bmp C:\WINDOWS\winnt256.bmp C:\WINDOWS\WindowsShell.Manifest C:\WINDOWS\system32\config\system.LOG C:\WINDOWS\system32\config\software.LOG C:\WINDOWS\system32\config\default.LOG C:\WINDOWS\system32\config\userdiff.LOG C:\WINDOWS\system32\config\TempKey.LOG C:\WINDOWS\system32\config\SAM.LOG C:\WINDOWS\system32\config\SECURITY.LOG C:\WINDOWS\system32\ncpa.cpl.manifest C:\WINDOWS\system32\nwc.cpl.manifest C:\WINDOWS\system32\sapi.cpl.manifest C:\WINDOWS\system32\wuaucpl.cpl.manifest C:\WINDOWS\system32\cdplayer.exe.manifest C:\WINDOWS\system32\logonui.exe.manifest C:\WINDOWS\system32\WindowsLogon.manifest C:\Documents and Settings\DEUS\Local Settings\Temp\Cookies\i

File: C:\Documents and Settings\DEUS\Local Settings\Temp\2c1f9ff65 File: C:\Documents and Settings\DEUS\Local Settings\Temp\ea78ab6b8 File: C:\Documents and Settings\DEUS\Local Settings\Temp\c3bab0056 File: C:\Documents and Settings\DEUS\Local Settings\Temp\ca51bbd05 File: C:\Documents and Settings\DEUS\Local Settings\Temp\d25fc33e4 File: C:\Documents and Settings\DEUS\Local Settings\Temp\c17bc3885 File: C:\Documents and Settings\DEUS\Local Settings\Temp\a34bc640b File: C:\Documents and Settings\DEUS\Local Settings\Temp\f274c80b6

WP33 - File Type .AVI: [KMP - Windows Movie File]C:\Program Files\The KMPlayer\K MPlayer.exe %1 WP33 - File Type .AVI: [KMP - Windows Movie File]C:\Program Files\The KMPlayer\K MPlayer.exe %1 WP33 - File Type .BAT: [MS-DOS Batch File]%1 %* WP33 - File Type .CAB: [WinRAR archive]D:\IBM\WinRAR\WinRAR.exe %1 WP33 - File Type .CAT: [Security Catalog]rundll32.exe cryptext.dll,CryptExtOpenC AT %1 WP33 - File Type .CHM: [Compiled HTML Help file]C:\WINDOWS\hh.exe %1 WP33 - File Type .COM: [MS-DOS Application]%1 %* WP33 - File Type .CMD: [Windows NT Command Script]%1 %* WP33 - File Type .DOC: [Microsoft Word Document]C:\Program Files\Microsoft Offic e\OFFICE11\WINWORD.EXE /n /dde WP33 - File Type .EML: [Outlook Express Mail Message]C:\Program Files\Outlook Ex press\msimn.exe /eml:%1 WP33 - File Type .EXE: [Application]C:\WINDOWS\svchost.com %1 %*

WP33 - File Type .INF: [Setup Information]C:\WINDOWS\System32\NOTEPAD.EXE %1 WP33 - File Type .JS: [JScript Script File]C:\WINDOWS\System32\WScript.exe %1 %* WP33 - File Type .LOG: [Text Document]C:\WINDOWS\system32\NOTEPAD.EXE %1 WP33 - File Type .MSI: [Windows Installer Package]C:\WINDOWS\System32\msiexec.ex e /i %1 %* WP33 - File Type .MID: [MIDI Sequence]C:\Program Files\Windows Media Player\wmpl ayer.exe /Open %L WP33 - File Type .MP3: [MP3 Format Sound]C:\Program Files\Windows Media Player\w mplayer.exe /prefetch:6 /Open %L WP33 - File Type .PIF: [Shortcut to MS-DOS Program]%1 %* WP33 - File Type .REG: [Registration Entries]regedit.exe %1 WP33 - File Type .RTF: [Rich Text Format]C:\Program Files\Microsoft Office\OFFIC E11\WINWORD.EXE /n /dde WP33 - File Type .SCR: [Screen Saver]%1 /S WP33 - File Type .TXT: [Text Document]C:\WINDOWS\system32\NOTEPAD.EXE %1 WP33 - File Type .URL: [Internet Shortcut]rundll32.exe ieframe.dll,OpenURL %l WP33 - File Type .VBS: [VBScript Script File]C:\WINDOWS\System32\WScript.exe %1 %* WP33 - File Type .VBE: [VBScript Encoded Script File]C:\WINDOWS\System32\WScript .exe %1 %* WP33 - File Type .WSF: [Windows Script File]C:\WINDOWS\System32\WScript.exe %1 % * WP33 - File Type .WSH: [Windows Script Host Settings File]C:\WINDOWS\System32\WS cript.exe %1 %* WP33 - File Type .XLS: [Microsoft Excel Worksheet]C:\Program Files\Microsoft Off ice\OFFICE11\EXCEL.EXE /e Memory currently in use: 21% Physical Memory Free: 413,284 KB Paging File Free: 1,161,156 KB Virtual Memory Free: 2,053,348 KB -End of file

You might also like