.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Andy at 18:02:54 on 2011-07-07
Microsoft Windows 7 Professional 6.1.7601.1.1252.44.1033.18.3067.1802 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\EgisTec\VITAKEY\CompPtcVUI.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\EgisTec\VITAKEY\BASVC.exe
C:\Program Files\Realtek Semiconductor Corp\Realtek USB 2.0 Card Reader\reset.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\EgisTec\VITAKEY\PdtWzd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\EgisTec\VITAKEY\PwdBank.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskhost.exe
C:\Users\Andy\Downloads\gmer\gmer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\andy\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [VitaKeyPdtWzd] c:\program files\egistec\vitakey\PdtWzd.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {10954C80-4F0F-11d3-B17C-00C0DFE39736} - c:\program files\egistec\vitakey\PwdBank.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8D9563A9-8D5F-459B-87F2-BA842255CB9A} - hxxps://snap.ofqual.gov.uk/InternalSite/WhlCompMgr.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://www.vexcast.com/download/vexcast.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C2091AFF-E242-498B-B890-6D0576386222} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C2091AFF-E242-498B-B890-6D0576386222}\2456C6B696E6F5E4B2F5143434134434 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{C2091AFF-E242-498B-B890-6D0576386222}\350756564645F6573686730383441373 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{C2091AFF-E242-498B-B890-6D0576386222}\6596277696E6F52427F616462616E646 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C2091AFF-E242-498B-B890-6D0576386222}\6796277696E6022627F616462616E646 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C2091AFF-E242-498B-B890-6D0576386222}\C496675626F687D224347383 : DhcpNameServer = 192.168.1.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = c:\program files\egistec\vitakey\PwdFilter
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\andy\appdata\roaming\mozilla\firefox\profiles\rsaxqmod.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/webhp?hl=en
FF - component: c:\users\andy\appdata\roaming\mozilla\firefox\profiles\rsaxqmod.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\users\andy\appdata\roaming\mozilla\firefox\profiles\rsaxqmod.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - plugin: c:\users\andy\appdata\local\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\users\andy\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - Ext: Update Service: updater@foxstart.com - c:\program files\mozilla firefox\extensions\updater@foxstart.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Forecastfox Weather: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3} - %profile%\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
FF - Ext: InvisibleHand: canitbecheaper@trafficbroker.co.uk - %profile%\extensions\canitbecheaper@trafficbroker.co.uk
.
============= SERVICES / DRIVERS ===============
.
R0 FPWinIo;FPWinIo;c:\windows\system32\drivers\FPWinIo.sys [2009-11-6 66856]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 165264]
R1 MpKsl80ec1be2;MpKsl80ec1be2;c:\programdata\microsoft\microsoft antimalware\definition updates\{35895193-04ca-46a6-aa98-2c753ef0bed2}\MpKsl80ec1be2.sys [2011-7-7 28752]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-4-27 61440]
R2 FPSensor;EgisTec-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\drivers\FPSensor.sys [2009-8-28 29744]
R2 IGBASVC;EgisTec Service;c:\program files\egistec\vitakey\BASVC.exe [2008-8-29 2187048]
R2 resetWinService;Reset Reader;c:\program files\realtek semiconductor corp\realtek usb 2.0 card reader\reset.exe [2009-11-6 70656]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-5-6 1153368]
R2 uagqecsvc;Microsoft Forefront UAG Quarantine Enforcement Client;c:\program files\microsoft forefront uag\endpoint components\3.1.0\uagqecsvc.exe [2010-7-16 150928]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-14 45736]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-8-21 66592]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-3-21 362600]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [2009-11-6 13976]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-10 135664]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 DMService;Microsoft Forefront UAG Endpoint Component Manager;c:\windows\downloaded program files\dm.0\DMService.exe [2010-12-12 468368]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-5-2 39272]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-10 135664]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 43392]
S3 NxpCap;CTX capture service;c:\windows\system32\drivers\NxpCap.sys [2008-9-25 1332576]
S3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2009-12-2 16472]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-2 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-9 1343400]
.
=============== Created Last 30 ================
.
2011-07-07 16:36:19 28752 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35895193-04ca-46a6-aa98-2c753ef0bed2}\MpKsl80ec1be2.sys
2011-07-06 22:08:17 -------- d-----w- c:\users\andy\appdata\roaming\Malwarebytes
2011-07-06 22:08:08 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 22:08:06 -------- d-----w- c:\programdata\Malwarebytes
2011-07-06 22:08:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-06 20:56:40 7074640 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{35895193-04ca-46a6-aa98-2c753ef0bed2}\mpengine.dll
2011-06-28 21:18:36 427520 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-06-28 21:18:36 337408 ----a-w- c:\windows\system32\mssph.dll
2011-06-28 21:18:36 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-28 21:18:36 1549312 ----a-w- c:\windows\system32\tquery.dll
2011-06-28 21:18:36 1401344 ----a-w- c:\windows\system32\mssrch.dll
2011-06-28 21:18:35 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-28 21:18:35 666624 ----a-w- c:\windows\system32\mssvp.dll
2011-06-28 21:18:35 59392 ----a-w- c:\windows\system32\msscntrs.dll
2011-06-28 21:18:35 197120 ----a-w- c:\windows\system32\mssphtb.dll
2011-06-28 21:17:48 293376 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-28 21:17:48 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-06-20 17:49:55 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-20 17:49:54 141104 ----a-w- c:\program files\internet explorer\sqmapi.dll
2011-06-20 17:49:53 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-19 16:34:23 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-19 16:34:23 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-19 16:34:23 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-19 16:34:22 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-19 16:34:22 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-19 16:34:21 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-19 16:34:20 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-19 16:34:19 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-19 16:34:19 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-19 16:34:18 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
==================== Find3M ====================
.
2011-05-04 03:52:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-02 12:38:26 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-04-09 06:02:25 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02:25 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56:38 123904 ----a-w- c:\windows\system32\poqexec.exe
.
============= FINISH: 18:08:53.95 ===============
Attached File(s)
-
DDS.txt (15.34K)
Number of downloads: 0
This post has been edited by Fullsusser: 09 July 2011 - 02:24 PM