.
DDS (Ver_11-03-05.01) - NTFSx86
Run by David at 21:16:01.64 on Tue 05/10/2011
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Starter 6.1.7600.0.1252.1.1033.18.1012.228 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
AV: Norton Internet Security Netbook Edition *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: avast! Antivirus *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security Netbook Edition *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Internet Security Netbook Edition *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5576240ee6baaa25\STacSV.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5576240ee6baaa25\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\SPLASH.SYS\config\DVMExportService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS\A5E82D02\17.0.0.136\InstStub.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Hewlett-Packard\HP QuickSync\QuickSync.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP QuickSync\jre\bin\javaw.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Hewlett-Packard\HP CloudDrive\zumodrive.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Users\David\AppData\Roaming\cacaoweb\cacaoweb.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\David\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\David\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\17.0.0.136\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\17.0.0.136\IPSBHO.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0566.0\msneshellx.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0566.0\msneshellx.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\17.0.0.136\coIEPlg.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [Simplify Media] "c:\program files\hp\hp mediastream\HPMediaStream.exe" -splash
uRun: [Google Update] "c:\users\david\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [cacaoweb] "c:\users\david\appdata\roaming\cacaoweb\cacaoweb.exe" -noplayer
uRun: [GHWAUC6NNZ] c:\users\david\appdata\local\temp\Ahl.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [HP] c:\program files\hewlett-packard\hp quicksync\QuickSync.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [ZumoDrive] "c:\program files\hewlett-packard\hp clouddrive\ZumoLauncher.lnk"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-12-2 165584]
R1 DVMIO;DVMIO;c:\splash.sys\config\dvmio.sys [2009-9-29 17624]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-12-2 17744]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-12-2 50768]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2010-3-25 174592]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-3-25 204288]
.
=============== File Associations ===============
.
regfile="regedit.exe" "%1"
.
=============== Created Last 30 ================
.
2011-05-11 03:44:45 20 ----a-w- c:\windows\system32\drivers\SMR162.dat
2011-05-11 03:44:31 76920 ----a-w- c:\windows\system32\drivers\SMR162.SYS
2011-05-11 01:02:51 -------- d-----w- c:\users\david\appdata\local\{F8755F71-451D-4A65-A936-77FB877A9CF2}
2011-05-09 18:34:23 -------- d-----w- c:\users\david\appdata\local\jagexlauncher
2011-05-07 17:33:05 -------- d-----w- c:\users\david\appdata\local\{CA2EB6E9-CB9C-4FD5-8849-393C692423FD}
2011-05-07 02:55:37 -------- d-----w- c:\users\david\appdata\local\{E6FDFCD6-E20C-4F55-83D4-F1B46D8C8F83}
2011-05-04 18:03:35 -------- d-----w- c:\users\david\appdata\local\{2E470572-9579-4052-9494-2DD549965CE4}
2011-05-02 17:49:56 -------- d-----w- c:\users\david\appdata\local\{86840695-3F73-4B22-AA4B-5C139BFF079A}
2011-05-02 17:08:29 -------- d-----w- c:\users\david\appdata\local\{2EFA383F-3029-4FD3-B92B-2677FE490BBC}
2011-04-30 23:53:25 -------- d-----w- c:\users\david\appdata\local\{5E7824C8-239B-43AA-BAE6-F377E42FB143}
2011-04-30 08:07:12 -------- d-----w- c:\users\david\appdata\local\{66BE47AD-9A52-495B-869A-7F46416DF143}
2011-04-28 17:17:44 -------- d-----w- c:\users\david\appdata\local\{D189B722-4E22-490D-BA05-85A8926AA43F}
2011-04-28 17:04:24 -------- d-----w- c:\users\david\appdata\local\{77FA33D0-EFE2-4910-8F24-6B966F094848}
2011-04-28 05:03:50 -------- d-----w- c:\users\david\appdata\local\{A11E34F3-BC85-4EFC-A308-704538E432A1}
2011-04-27 16:20:24 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-04-27 16:20:06 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-04-27 16:20:05 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-04-27 16:20:04 1686016 ----a-w- c:\windows\system32\esent.dll
2011-04-27 16:20:04 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-04-27 16:20:03 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-04-27 16:20:03 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2011-04-27 16:20:02 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-04-27 16:20:02 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-04-27 16:20:01 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-04-27 16:19:22 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-27 16:19:08 2614784 ----a-w- c:\windows\explorer.exe
2011-04-27 05:44:09 122880 --sha-r- c:\windows\system32\wmidx5.dll
2011-04-27 03:24:38 -------- d-----w- c:\users\david\appdata\local\{1DF367EE-AF79-43CA-AAA5-6A83ED548909}
2011-04-24 18:12:21 -------- d-----w- c:\users\david\appdata\local\{16234E6B-09EC-4F35-81B6-A898E7DF221B}
2011-04-23 04:02:36 7071056 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{806a385f-c7b4-4e9b-8002-ddd6884a4458}\mpengine.dll
2011-04-19 16:49:50 -------- d-----w- c:\users\david\appdata\local\{79212E52-88F0-4E56-8A3E-289A1A10AD94}
2011-04-18 15:44:38 -------- d-----w- c:\users\david\appdata\local\{C5A35AA2-5B41-4D73-A3CA-37A58BB9C961}
2011-04-17 08:58:39 -------- d-----w- c:\users\david\appdata\local\{4F730B2D-9588-4996-9D42-8838B9A178DF}
2011-04-15 16:27:15 -------- d-----w- c:\program files\VirtualDJ
2011-04-15 16:18:38 -------- d-----w- c:\users\david\appdata\local\{FC01D874-CD6A-45FA-84C4-205F5A7F0A18}
2011-04-14 16:07:57 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-14 16:07:57 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-14 16:07:57 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-14 16:07:52 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-14 16:07:52 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-14 16:07:48 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-04-14 16:07:47 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-14 16:07:00 2331136 ----a-w- c:\windows\system32\win32k.sys
2011-04-14 16:06:58 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-14 16:06:57 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-14 16:06:55 740864 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-14 16:06:53 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-14 16:06:53 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-14 16:06:51 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-14 16:06:51 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-14 16:06:51 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-14 16:06:51 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-12 06:34:40 -------- d-----w- c:\users\david\appdata\local\{27C40AE9-7DD5-4314-9164-4FCD5117FD6B}
2011-04-12 05:17:05 -------- d-----w- c:\users\david\appdata\local\ElevatedDiagnostics
.
==================== Find3M ====================
.
2011-05-04 15:31:10 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-04 15:31:09 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-04 15:31:09 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-04 15:31:07 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-04 15:31:06 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-04 15:31:06 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-04 15:31:06 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-04 15:31:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-04 15:31:03 367104 ----a-w- c:\windows\system32\html.iec
2011-05-04 15:31:00 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-04 15:31:00 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-04 15:30:59 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-04 15:30:59 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-04 15:30:59 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-04 15:30:58 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-04 15:30:55 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-05-04 15:30:55 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-04 15:30:54 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-04 15:30:54 101888 ----a-w- c:\windows\system32\admparse.dll
2011-05-04 15:30:51 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-04 15:30:51 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-04-03 07:50:18 203776 --sh--w- c:\progra~2\unrar.exe
2011-04-03 07:49:14 198656 ----a-w- c:\windows\system32\browcli32.exe
2011-02-19 05:33:11 802304 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 05:32:48 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 05:32:35 739840 ----a-w- c:\windows\system32\d2d1.dll
.
============= FINISH: 21:18:32.91 ===============
Attached File(s)
-
ark.txt (15.82K)
Number of downloads: 1 -
Attach.txt (7.52K)
Number of downloads: 0

Help
This topic is locked

Back to top











