[======================] AnalyzerXP by TurcoLoco [======================]
21/12/2006
12:31
The files listed below could be safe and valid, so before you do anything, research further.
You could also submit this log on
www.iamnotageek.com - HijackThis forum for help.
Microsoft (R) Windows (R) XP Operating System Group Policy Result tool v2.0
Copyright (C) Microsoft Corp. 1981-2001
Created On 21/12/2006 at 12:28:12
RSOP results for DILAN\Dilan Shah on DILAN : Logging Mode
----------------------------------------------------------
OS Type: Microsoft Windows XP Professional
OS Configuration: Standalone Workstation
OS Version: 5.1.2600
Domain Name: DILAN
Domain Type: N/A<Local Computer>
Site Name: N/A
Roaming Profile:
Local Profile: C:\Documents and Settings\Dilan Shah
Connected over a slow link?: Yes
COMPUTER SETTINGS
------------------
Last time Group Policy was applied: 21/12/2006 at 11:57:28
Group Policy was applied from: N/A
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
-----------------------------
N/A
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Local Group Policy
Filtering: Not Applied (Empty)
The computer is a part of the following security groups:
--------------------------------------------------------
BUILTIN\Administrators
Everyone
NT AUTHORITY\Authenticated Users
USER SETTINGS
--------------
Last time Group Policy was applied: 21/12/2006 at 11:57:28
Group Policy was applied from: N/A
Group Policy slow link threshold: 500 kbps
Applied Group Policy Objects
-----------------------------
N/A
The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Local Group Policy
Filtering: Not Applied (Empty)
The user is a part of the following security groups:
----------------------------------------------------
None
Everyone
Debugger Users
BUILTIN\Administrators
BUILTIN\Users
LOCAL
NT AUTHORITY\INTERACTIVE
NT AUTHORITY\Authenticated Users
Volume in drive C has no label.
Volume Serial Number is 20E8-C18D
Directory of C:\WINDOWS\Tasks
04/12/2006 23:34 284 AppleSoftwareUpdate.job
1 File(s) 284 bytes
0 Dir(s) 4,031,694,848 bytes free
TaskName Next Run Time Status
==================================== ======================== ===============
AppleSoftwareUpdate 16:26:00, 22/12/2006
MP Scheduled Scan 01:52:00, 22/12/2006
INFO: No event triggers found.
=====] Examining the executables in INTERNET EXPLORER folder:
W32i APP ENU 9.0.3790.2428 shp 33,792 11-07-2006 c:\program files\internet explorer\custsat.dll
W32i DLL ENU 7.0.5730.11 shp 60,416 10-17-2006 c:\program files\internet explorer\hmmapi.dll
W32i APP ENU 5.50.4134.100 shp 143,360 06-08-2000 c:\program files\internet explorer\ie4.dll
W32i APP ENU 5.50.4134.100 shp 32,768 06-08-2000 c:\program files\internet explorer\iedetect.dll
W32i APP ENU 7.0.5730.11 shp 69,120 10-17-2006 c:\program files\internet explorer\iedw.exe
W32i DLL ENU 7.0.5730.11 shp 287,744 11-07-2006 c:\program files\internet explorer\ieproxy.dll
W32i APP ENU 7.0.5730.11 shp 622,080 10-17-2006 c:\program files\internet explorer\iexplore.exe
{ If listed above, please ignore hmmapi.dll, iedw.exe and iexplore.exe }
=====] Looking for suspicious file types in WINDOWS folder:
W32i - - - - 53,248 09-15-2003 c:\windows\apprun.exe
W32i - - - - 129,536 07-23-1999 c:\windows\auhccup1.dll
W32i - - - - 224,256 03-31-1999 c:\windows\comctl32.oca
W32i - - - - 71,749 10-28-2005 c:\windows\hcextoutput.dll
W32i - - - - 12,288 09-28-2004 c:\windows\impborl.dll
W32i - - - - 43,520 03-31-1999 c:\windows\msmapi32.oca
W32i - - - - 36,864 10-19-2003 c:\windows\restart.exe
Volume in drive C has no label.
Volume Serial Number is 20E8-C18D
Directory of C:\WINDOWS
05/12/2002 17:23 19,274 001299_.tmp
02/04/2006 12:37 19,528 003920_.tmp
10/12/2002 16:15 69,632 DUMP478c.tmp
10/12/2002 16:15 69,632 DUMP4b39.tmp
10/12/2002 16:15 69,632 DUMP4c0b.tmp
10/12/2002 16:15 69,632 DUMP4fc3.tmp
10/12/2002 16:15 69,632 DUMP546b.tmp
10/12/2002 16:15 69,632 DUMP57d2.tmp
10/12/2002 16:15 69,632 DUMP59c7.tmp
10/12/2002 16:15 69,632 DUMP60c7.tmp
10/12/2002 16:15 69,632 DUMP6121.tmp
10/12/2002 16:15 69,632 DUMP6199.tmp
10/12/2002 16:15 69,632 DUMP6515.tmp
10/12/2002 16:15 69,632 DUMP66d7.tmp
10/12/2002 16:15 69,632 DUMP6c29.tmp
10/12/2002 16:15 69,632 DUMP6d6a.tmp
10/12/2002 16:15 69,632 DUMP6eb4.tmp
19 File(s) 2,182,803 bytes
0 Dir(s) 4,031,625,216 bytes free
DOS - - - - 12,498 08-23-2001 c:\windows\system32\append.exe
W32i - - - - 262,416 10-17-1999 c:\windows\system32\asfv2.dll
W32i - - - - 2,067,140 11-29-2005 c:\windows\system32\avcodec.dll
W32i - - - - 24,576 08-15-2003 c:\windows\system32\coinst.dll
W32i - - - - 23,040 09-18-2000 c:\windows\system32\cssms_in.dll
DOS - - - - 9,833 09-03-2001 c:\windows\system32\ddmi.vxd
DOS - - - - 20,634 08-23-2001 c:\windows\system32\debug.exe
DOS - - - - 9,321 11-11-2001 c:\windows\system32\dlpt.vxd
DOS - - - - 53,840 08-03-2004 c:\windows\system32\dosx.exe
DOS - - - - 69,886 08-23-2001 c:\windows\system32\edit.com
DOS - - - - 12,642 08-23-2001 c:\windows\system32\edlin.exe
DOS - - - - 8,424 08-23-2001 c:\windows\system32\exe2bin.exe
DOS - - - - 882 08-23-2001 c:\windows\system32\fastopen.exe
DOS - - - - 7,315 02-28-2003 c:\windows\system32\javasup.vxd
DOS - - - - 39,274 08-23-2001 c:\windows\system32\mem.exe
W32i - - - - 20,480 07-01-2002 c:\windows\system32\mpfapi.dll
DOS - - - - 25,225 11-27-2002 c:\windows\system32\mpfirewl.vxd
DOS - - - - 817 08-23-2001 c:\windows\system32\mscdexnt.exe
W32i - - - - 45,056 09-24-2001 c:\windows\system32\navlogon.dll
W16 - - - - 2,656 08-23-2001 c:\windows\system32\netware.drv
DOS - - - - 7,052 08-23-2001 c:\windows\system32\nlsfunc.exe
DOS - - - - 3,252 08-23-2001 c:\windows\system32\nw16.exe
DOS - - - - 5,672 08-17-1998 c:\windows\system32\quartz.vxd
DOS - - - - 3,338 08-03-2004 c:\windows\system32\redir.exe
DOS - - - - 11,753 08-23-2001 c:\windows\system32\setver.exe
DOS - - - - 882 08-23-2001 c:\windows\system32\share.exe
DOS - - - - 120,379 09-24-2001 c:\windows\system32\symevnt.386
W16 - - - - 10,240 08-17-1998 c:\windows\system32\vidx16.dll
DOS - - - - 1,129 08-23-2001 c:\windows\system32\vwipxspx.exe
W16 - - - - 13,312 08-23-2001 c:\windows\system32\win87em.dll
W16 - - - - 11,776 03-25-2003 c:\windows\system32\zport4as.dll
{ If listed above, please ignore append.exe, chcfg.exe, choice.exe, debug.exe, dosx.exe, edit.com, edlin.exe, exe2bin.exe, fastopen.exe, javasup.vxd, mem.exe, mscdexnt.exe, netware.drv, nlsfunc.exe, nw16.exe, redir.exe, setver.exe, share.exe, vwipxspx.exe, win87em.dll }
02/03/2006 11:17 0 02.tmp
{ If listed above, please ignore CONFIG.TMP, OLDx.tmp and setbX.tmp files }
10/12/2006 19:50 1,744 d3d9caps.dat
05/09/2006 23:01 2,451,824 ieapfltr.dat
{ If listed above, please ignore emptyreg.dat, emptyregdb.dat and FNTCACHE.DAT }
W32i DLL ENU 58.6.0.0 shp 141,424 08-24-2006 c:\windows\downloaded program files\asinst.dll
W32i DLL ENU 6.5.2.7 shp 357,376 02-02-2006 c:\windows\downloaded program files\housecall_activex.dll
W32i DLL ENU 1.0.0.2 shp 113,152 03-17-2005 c:\windows\downloaded program files\msnmessengersetupdownloader.ocx
W32i DLL ENU 2004.3.0.20 shp 124,072 12-22-2004 c:\windows\downloaded program files\naveng32.dll
W32i DLL ENU 2004.3.0.20 shp 685,224 12-22-2004 c:\windows\downloaded program files\navex32a.dll
W32i DLL ENU 5.70.0.1088 shp 435,712 10-03-2005 c:\windows\downloaded program files\xscan53.ocx
=====] List of files located at the root of the C Drive:
Volume in drive C has no label.
Volume Serial Number is 20E8-C18D
Directory of C:\
21/09/2006 08:49 9,820 2EF.tmp
01/12/2002 11:21 245,792 CLASSES.1ST
01/12/2002 11:38 0 CONFIG.BAK
01/12/2002 11:38 0 CONFIG.SYS
20/12/2006 00:29 0 conmgr.log
02/12/2002 00:09 16 CTJINI.INI
20/12/2006 16:01 189,354 hpfr5550.log
26/12/2004 15:43 348 install.log
02/12/2002 00:10 82 OUT1.TXT
01/12/2002 11:10 3,833 RECOVERY.LOG
01/12/2002 15:04 470 SCANDISK.LOG
26/12/2004 15:59 3,723 _NavCClt.Log
29 File(s) 467,381 bytes
0 Dir(s) 4,031,501,312 bytes free
{ If listed above, please ignore CONFIG.SYS and AUTOEXEC.BAT }
=====] Directory Analysis - PROGRAM FILES:
03/04/2006 12:30 <DIR> Ahead
29/07/2006 14:46 <DIR> AOL 9.0b
04/12/2006 23:34 <DIR> Apple Software Update
24/04/2006 09:23 <DIR> ArcSoft
17/08/2006 15:46 <DIR> Driving Test Success 2006-2007
01/04/2006 09:38 <DIR> Elaborate Bytes
30/03/2006 18:03 <DIR> FileZilla
04/12/2006 23:37 <DIR> iPod
04/12/2006 23:37 <DIR> iTunes
02/04/2006 12:56 <DIR> messenger
04/04/2006 22:19 <DIR> Microsoft ActiveSync
02/04/2006 15:49 <DIR> Microsoft Device Emulator
02/04/2006 15:51 <DIR> Microsoft SQL Server
04/04/2006 22:15 <DIR> Microsoft Visual Studio
02/04/2006 15:05 <DIR> Microsoft Visual Studio 8
02/04/2006 15:11 <DIR> Microsoft.NET
20/11/2006 00:01 <DIR> MSXML 4.0
04/12/2006 23:35 <DIR> QuickTime
01/04/2006 15:59 <DIR> SAMSUNG
21/08/2006 14:46 <DIR> Windows Defender
16/03/2006 22:41 <DIR> WinRAR
(The above folders were created in 2006, ignore the ones you know of)
=====] Directory Analysis - COMMON FILES (subfolder of Program Files folder):
03/04/2006 12:31 <DIR> Ahead
04/04/2006 22:21 <DIR> L&H
03/04/2006 12:32 <DIR> Nero
{ if listed above, please ignore Adobe, Microsoft Shared, MSSoap, ODBC, Services, SpeechEngines, System and others you recognize)
=====] Directory Analysis - WINDOWS folder:
Volume in drive C has no label.
Volume Serial Number is 20E8-C18D
Directory of C:\WINDOWS
01/12/2002 19:02 <DIR> .
01/12/2002 19:02 <DIR> ..
01/12/2002 19:02 <DIR> addins
01/12/2002 19:02 <DIR> AppPatch
24/08/2005 19:24 <DIR> AU_Backup
24/08/2005 19:20 <DIR> AU_Log
28/10/2005 19:44 <DIR> AU_Temp
01/12/2002 19:02 <DIR> Config
01/12/2002 19:02 <DIR> Connection Wizard
01/12/2002 19:02 <DIR> Cursors
01/12/2002 19:02 <DIR> Debug
09/05/2005 17:05 <DIR> Downloaded Installations
01/12/2002 19:02 <DIR> Driver Cache
05/12/2002 20:51 <DIR> ehome
01/12/2002 19:02 <DIR> Help
31/03/2004 20:55 <DIR> henry screensaver dir
09/12/2006 11:58 <DIR> ie7
05/12/2002 11:31 <DIR> IIS Temporary Compressed Files
01/12/2002 19:02 <DIR> ime
03/04/2006 12:33 <DIR> InCD
01/12/2002 19:02 <DIR> inf
01/12/2002 19:02 <DIR> java
01/12/2002 19:02 <DIR> Media
05/12/2002 21:26 <DIR> Microsoft.NET
04/12/2002 23:48 <DIR> Minidump
04/12/2002 09:59 <DIR> Modio
15/12/2004 11:25 <DIR> Motive
01/12/2002 19:02 <DIR> msagent
01/12/2002 19:02 <DIR> msapps
01/12/2002 19:02 <DIR> mui
10/10/2004 18:21 <DIR> occache
01/12/2002 19:16 <DIR> Offline Web Pages
01/12/2002 19:14 <DIR> PCHEALTH
02/04/2006 12:54 <DIR> peernet
03/12/2002 13:34 <DIR> PIF
02/04/2006 14:26 <DIR> Prefetch
02/04/2006 12:54 <DIR> provisioning
01/04/2006 12:44 <DIR> pss
01/12/2002 19:12 <DIR> Registration
01/12/2002 19:02 <DIR> repair
24/08/2005 19:24 <DIR> report
01/12/2002 19:02 <DIR> Resources
01/12/2002 19:02 <DIR> security
05/12/2002 20:51 <DIR> ServicePackFiles
04/04/2006 22:14 <DIR> SHELLNEW
01/09/2005 10:33 <DIR> SoftwareDistribution
01/12/2002 19:15 <DIR> srchasst
01/12/2002 19:02 <DIR> system
01/12/2002 19:02 <DIR> system32
01/12/2002 19:02 <DIR> Temp
01/12/2002 19:02 <DIR> twain_32
09/12/2006 12:00 <DIR> WBEM
01/12/2002 19:02 <DIR> Web
01/12/2002 19:02 <DIR> WinSxS
0 File(s) 0 bytes
188 Dir(s) 4,031,488,512 bytes free
{ If listed above, please ignore addins, AppPatch, assembly, Config, Connection Wizard, Cursors, Debug, Downloaded Program Files, Driver Cache, EHome, ERDNT, Fonts, Help, ime, inf, Installer, java, LastGood, Media, Microsoft.NET, msagent, msapps, mui, Offiline Web Pages, PCHealth, peernet, Prefetch, Profiles, provisioning, RegisteredPackages, Registration, repair, Resources, security, ServicePackFiles, SoftwareDistribution, srchasst, system, system32, Tasks, Temp, twain_32, Web and WinSxs folders }
=====] Process Analysis - User-based processes with their Services:
Image Name PID Services
========================= ====== =============================================
WebClient
explorer.exe 1720 N/A
sqlservr.exe 232 MSSQL$SQLEXPRESS
AOLDial.exe 1348 N/A
AOLSP Scheduler.exe 1468 N/A
dslstat.exe 1516 N/A
dslagent.exe 1536 N/A
fts.exe 1556 N/A
MpfTray.exe 1504 N/A
MSASCui.exe 2096 N/A
ctfmon.exe 2116 N/A
MpfAgent.exe 2212 N/A
alg.exe 3208 ALG
MpCmdRun.exe 2232 N/A
cmd.exe 2192 N/A
tasklist.exe 936 N/A
find.exe 3644 N/A
wmiprvse.exe 3224 N/A
{ If listed above, please ignore CMD.EXE, EXPLORER.EXE, FIND.EXE and TASKLIST.EXE }
=====] Process Analysis - Currently running Service based Processes:
Image Name PID Services
========================= ====== =============================================
System Idle Process 0 N/A
System 4 N/A
smss.exe 624 N/A
csrss.exe 676 N/A
winlogon.exe 700 N/A
services.exe 744 Eventlog, PlugPlay
lsass.exe 756 PolicyAgent, ProtectedStorage, SamSs
svchost.exe 916 DcomLaunch, TermService
svchost.exe 960 RpcSs
MsMpEng.exe 1056 WinDefend
svchost.exe 1100 AudioSrv, BITS, CryptSvc, Dhcp, dmserver,
ERSvc, EventSystem,
FastUserSwitchingCompatibility, helpsvc,
lanmanserver, lanmanworkstation, Netman,
Nla, RasMan, Schedule, seclogon, SENS,
SharedAccess, ShellHWDetection, TapiSrv,
Themes, TrkWks, W32Time, winmgmt, wscsvc,
wuauserv, WZCSVC
InCDsrv.exe 1120 InCDsrvR
svchost.exe 1220 Dnscache
svchost.exe 1372 Alerter, LmHosts, RemoteRegistry, SSDPSRV,
WebClient
spoolsv.exe 1604 Spooler
explorer.exe 1720 N/A
AOLacsd.exe 1780 AOL ACS
defwatch.exe 1824 DefWatch
ewidoctrl.exe 1856 ewido security suite control
inetinfo.exe 1876 IISADMIN, SMTPSVC, W3SVC
mdm.exe 1940 MDM
MpfService.exe 1996 MpfService
sqlservr.exe 232 MSSQL$SQLEXPRESS
AOLDial.exe 1348 N/A
AOLSP Scheduler.exe 1468 N/A
dslstat.exe 1516 N/A
dslagent.exe 1536 N/A
fts.exe 1556 N/A
MpfTray.exe 1504 N/A
MSASCui.exe 2096 N/A
ctfmon.exe 2116 N/A
MpfAgent.exe 2212 N/A
alg.exe 3208 ALG
wmiprvse.exe 3568 N/A
wuauclt.exe 2444 N/A
MpCmdRun.exe 2232 N/A
cmd.exe 2192 N/A
wmiprvse.exe 3224 N/A
tasklist.exe 2836 N/A
[======================] End of Log [======================]