Here's my DDS log:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by John at 19:18:50.59 on Fri 05/13/2011
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_23
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2046.887 [GMT -4:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\OEM02Mon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
C:\Users\John\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Nfole] rundll32.exe "c:\users\john\appdata\local\ebeputehobekeyoj.dll",Startup
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
StartupFolder: c:\users\john\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {DC656D0F-7731-4DD2-B5CF-6D87DC02AAF2} = 10.42.40.1
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\john\appdata\roaming\mozilla\firefox\profiles\k9eifd8r.default\
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mozilla firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-2-1 64288]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsladc91cff;MpKsladc91cff;c:\programdata\microsoft\microsoft antimalware\definition updates\{2c5c5b91-c497-4fce-89c8-cff59518a249}\MpKsladc91cff.sys [2011-5-13 28752]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [2011-5-13 18816]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-12-3 2146496]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-1-7 378984]
R3 BTHprint;Microsoft Bluetooth Printer Class;c:\windows\system32\drivers\BTHPRINT.SYS [2009-7-13 50688]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-14 45736]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-1 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-12-3 15232]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-29 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-2-2 1343400]
.
=============== Created Last 30 ================
.
2011-05-13 23:08:27 28752 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{2c5c5b91-c497-4fce-89c8-cff59518a249}\MpKsladc91cff.sys
2011-05-13 23:08:26 7071056 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-05-13 23:08:19 7071056 ----a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{2c5c5b91-c497-4fce-89c8-cff59518a249}\mpengine.dll
2011-05-13 23:01:25 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2011-05-13 22:20:25 -------- d-----w- c:\program files\Sophos
2011-05-13 00:36:19 -------- d-----w- c:\users\john\appdata\roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2011-05-13 00:35:28 -------- d-----w- c:\program files\Adobe Download Assistant
2011-05-12 23:44:44 439632 ------w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{0d24f736-4f7c-4ae7-9f35-ff7bbc803736}\gapaengine.dll
2011-05-12 23:42:07 -------- d-----w- c:\program files\Microsoft Security Client
2011-05-12 20:44:25 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-05-12 19:51:38 -------- d-----w- c:\users\john\appdata\local\{5AF5C220-6E33-4FD9-B8FD-6E87440030DD}
2011-05-12 02:12:37 0 ----a-w- c:\users\john\appdata\local\eruwipiqowaliyun.dll
2011-05-11 01:12:04 0 ----a-w- c:\users\john\appdata\local\Htemadu.bin
2011-05-10 03:03:12 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2011-05-10 03:03:12 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2011-05-10 03:03:12 -------- d-----w- c:\program files\OpenAL
2011-05-10 00:52:00 -------- d--h--w- c:\program files\InstallJammer Registry
2011-05-10 00:28:50 -------- d-----w- c:\users\john\appdata\roaming\LogMate
2011-05-02 01:27:20 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-04-30 20:42:11 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-04-30 20:42:11 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-04-30 20:42:11 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-04-30 20:42:10 89048 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-04-30 20:42:10 465880 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-04-30 20:42:10 1974616 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-04-30 20:42:10 1892184 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-04-30 20:42:10 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-30 00:16:34 -------- d-----w- c:\windows\system32\SPReview
2011-04-30 00:15:37 -------- d-----w- c:\windows\system32\EventProviders
2011-04-30 00:15:13 7071056 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{baa0297c-6cdf-4024-bea0-e2df4c40b640}\mpengine.dll
2011-04-29 23:08:59 941568 ----a-w- c:\windows\system32\mblctr.exe
2011-04-29 23:07:58 189952 ----a-w- c:\windows\system32\wdscore.dll
2011-04-29 23:07:57 209920 ----a-w- c:\windows\system32\PkgMgr.exe
2011-04-29 23:07:39 323072 ----a-w- c:\windows\system32\drvstore.dll
2011-04-29 23:07:39 257024 ----a-w- c:\windows\system32\dpx.dll
2011-04-29 22:05:11 219136 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-04-29 22:05:11 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-28 13:41:19 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-04-28 13:40:40 1699328 ----a-w- c:\windows\system32\esent.dll
2011-04-28 13:40:39 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-04-28 13:40:39 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-04-28 13:40:39 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-04-28 13:40:39 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-04-28 13:40:39 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-04-28 13:40:39 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-04-28 13:40:39 1211264 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-04-28 13:40:39 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-04-28 13:40:05 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-28 13:39:09 2616320 ----a-w- c:\windows\explorer.exe
2011-04-19 22:29:02 53248 ------w- c:\windows\system32\mwgfxvb.dll
2011-04-19 22:29:02 49152 ------w- c:\windows\system32\mwddsvb.dll
2011-04-19 22:29:02 28672 ------w- c:\windows\system32\mwgfxcopy.exe
2011-04-19 22:29:02 256512 ------w- c:\windows\system32\mwdlg.dll
2011-04-19 22:29:02 237056 ------w- c:\windows\system32\mwgfx24.dll
2011-04-19 22:29:02 191488 ------w- c:\windows\system32\mwgfx.dll
2011-04-19 22:29:02 104960 ------w- c:\windows\system32\mwdds.dll
2011-04-19 22:29:01 56832 ------w- c:\windows\system32\mwace.dll
2011-04-19 22:29:01 27136 ------w- c:\windows\system32\mwacevb.dll
2011-04-19 22:28:36 -------- d-----w- c:\program files\RW_Tools
2011-04-17 00:24:44 -------- d-----w- c:\program files\RailWorks
2011-04-15 21:35:16 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-15 21:35:16 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-15 21:35:12 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-15 21:35:12 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-15 21:35:12 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-15 21:35:09 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-15 21:35:09 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-04-15 21:34:48 2333184 ----a-w- c:\windows\system32\win32k.sys
2011-04-15 21:34:46 802304 ----a-w- c:\windows\system32\WFS.exe
2011-04-15 21:34:46 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-15 21:34:44 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-15 21:34:42 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-15 21:34:41 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-15 21:34:41 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-15 21:34:39 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-15 21:34:39 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-15 21:34:39 223232 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-15 21:34:39 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
==================== Find3M ====================
.
2011-04-30 00:42:28 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-03-29 07:30:14 86016 ----a-w- c:\windows\system32\frapsvid.dll
2011-02-19 06:30:54 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:30:51 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:30:50 739840 ----a-w- c:\windows\system32\d2d1.dll
.
============= FINISH: 19:19:33.70 ===============
Attached File(s)
-
Attach.txt (7.31K)
Number of downloads: 0 -
ark.txt (7K)
Number of downloads: 3

Help
This topic is locked

Back to top












