.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514
Run by user at 21:27:30 on 2011-09-28
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\user\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k SDRSVC
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2012\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2012\klwtbbho.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2012\avp.exe"
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} -
c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} -
c:\program files\kaspersky lab\kaspersky anti-virus 2012\ievkbd.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -
c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} -
c:\program files\kaspersky lab\kaspersky anti-virus 2012\klwtbbho.dll
TCP: DhcpNameServer = 124.106.5.2 124.106.6.2
TCP: Interfaces\{6C1A5379-A85E-48C0-91F9-F0B2765E270D} : DhcpNameServer = 124.106.5.2 124.106.6.2
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: klogon - c:\windows\system32\klogon.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\9mr0548s.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=685749&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
============= SERVICES / DRIVERS ===============
.
R? AVP;Kaspersky Anti-Virus Service
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? MpFilter;Microsoft Malware Protection Driver
R? MpKsl118b3432;MpKsl118b3432
R? MpKsl1436d2b7;MpKsl1436d2b7
R? MpKsl184c2d33;MpKsl184c2d33
R? MpKsl2dfa3d85;MpKsl2dfa3d85
R? MpKsl48fad6da;MpKsl48fad6da
R? MpKsl6382cc9c;MpKsl6382cc9c
R? MpKsl7bd06ada;MpKsl7bd06ada
R? MpKsl9ee766d3;MpKsl9ee766d3
R? MpKslacefb191;MpKslacefb191
R? MpKslb5c39b05;MpKslb5c39b05
R? MpKsldd6c6849;MpKsldd6c6849
R? MpKslf338fa3b;MpKslf338fa3b
R? MpKslf6113022;MpKslf6113022
R? MpKslf6b25d6d;MpKslf6b25d6d
R? MpNWMon;Microsoft Malware Protection Network Driver
R? NisDrv;Microsoft Network Inspection System
R? NisSrv;NisSrv
R? Revoflt;Revoflt
R? SwitchBoard;SwitchBoard
R? TsUsbFlt;TsUsbFlt
S? AntiVirSchedulerService;Avira AntiVir Scheduler
S? AntiVirService;Avira AntiVir Guard
S? avgntflt;avgntflt
S? kl2;kl2
S? KLIM6;Kaspersky Anti-Virus NDIS 6 Filter
S? klmouflt;Kaspersky Lab KLMOUFLT
S? RTL8167;Realtek 8167 NT Driver
.
=============== Created Last 30 ================
.
2011-09-28 12:11:11 12872 ----a-w- c:\windows\system32\bootdelete.exe
2011-09-28 10:24:37 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-09-28 10:24:36 -------- d-----w- c:\program files\Avira
2011-09-26 21:03:25 -------- d-----w- c:\programdata\Kaspersky Lab
2011-09-26 20:27:43 -------- d-----w- c:\programdata\Malwarebytes
2011-09-26 20:27:40 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-26 13:16:35 -------- d-----w- c:\users\user\appdata\local\Apple Computer
2011-09-26 09:21:21 -------- d-----w- c:\users\user\appdata\roaming\Avira
2011-09-26 09:08:33 -------- d-----w- c:\programdata\Avira
2011-09-25 14:57:58 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-09-25 14:57:58 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-09-25 14:57:27 -------- d-----w- c:\programdata\Hitman Pro
2011-09-25 11:27:46 -------- d-----w- c:\users\user\appdata\local\VS Revo Group
2011-09-25 11:27:44 27192 ----a-w- c:\windows\system32\drivers\revoflt.sys
2011-09-24 19:13:36 -------- d-----w- c:\program files\common files\Spigot
2011-09-24 19:06:23 97961 ----a-w- c:\windows\system32\drivers\klick.dat
2011-09-24 19:06:23 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-09-24 18:56:41 -------- d--h--w- C:\kleaner.tmp
2011-09-24 18:08:28 -------- d-----w- c:\programdata\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-09-24 18:02:19 -------- d-----w- c:\users\user\appdata\local\PackageAware
2011-09-23 11:28:25 -------- d-----w- c:\program files\Adobe Download Assistant
2011-09-23 06:49:53 -------- d-----w- c:\users\user\appdata\local\{A20EDE40-2DFA-42FA-AEF7-CC861189DD92}
2011-09-21 05:43:48 -------- d-----w- c:\program files\VS Revo Group
2011-09-21 05:09:59 -------- d-----w- c:\users\user\appdata\roaming\Malwarebytes
2011-09-21 05:09:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-09-20 10:29:03 -------- d-----w- c:\users\user\appdata\local\{78DB7A7C-4D4F-4CBF-BDA4-19D2583BFC54}
2011-09-20 10:28:48 -------- d-----w- c:\users\user\appdata\local\{602C0DDD-561A-4EE7-9C29-20963DD74023}
2011-09-19 09:54:41 -------- d-----w- c:\users\user\appdata\local\{67E7AA04-FE59-4481-968B-65F1C49161B3}
2011-09-19 09:54:29 -------- d-----w- c:\users\user\appdata\local\{32FC95FF-2D00-44D9-9BDA-E82B4CAEA73C}
2011-09-17 09:13:47 -------- d-----w- c:\users\user\appdata\local\{246B7FEF-69B8-4CD1-9F94-3F1CF0FDD753}
2011-09-17 09:13:36 -------- d-----w- c:\users\user\appdata\local\{EE3D0A9A-40F2-4065-A5D9-A86ACAD1C976}
2011-09-17 09:13:36 -------- d-----w- c:\users\user\appdata\local\{B28450FB-E9C3-4FB3-A8EB-37F07B0FEE6A}
2011-09-15 10:43:58 -------- d-----w- c:\users\user\appdata\local\{B1173AD1-5FEB-4E8E-AC6B-1F9DC0379E21}
2011-09-15 10:43:46 -------- d-----w- c:\users\user\appdata\local\{CE30CC52-10D1-49A8-85C7-30FFF27ABD9A}
2011-09-14 12:49:41 -------- d-----w- c:\users\user\appdata\local\{26DB987C-9DD3-4266-B19E-EBDA0FD39B14}
2011-09-14 12:49:28 -------- d-----w- c:\users\user\appdata\local\{6D46231B-2BC1-43C4-8D91-710AA15DC664}
2011-09-13 14:48:16 -------- d-----w- c:\users\user\appdata\local\{E5A8D38B-8DED-4F78-A09A-11E79B805F60}
2011-09-13 14:48:04 -------- d-----w- c:\users\user\appdata\local\{6E9C5ECC-CBD0-486D-A8C6-5B92D5FFCD20}
2011-09-13 14:47:51 -------- d-----w- c:\users\user\Tracing
2011-09-13 14:40:34 6260088 ----a-w- c:\program files\common files\windows live\.cache\17adc2d61cc722301\Silverlight.4.0.exe
2011-09-13 14:39:28 -------- d-----w- c:\users\user\appdata\local\Windows Live
2011-09-13 14:39:26 -------- d-----w- c:\program files\common files\Windows Live
2011-09-09 12:16:21 -------- d-----w- c:\users\user\appdata\roaming\Boolat
Games
2011-09-04 08:28:38 -------- d-----w- c:\users\user\appdata\roaming\Orneon
.
==================== Find3M ====================
.
2011-09-25 11:38:25 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-01 05:24:02 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-07-22 04:54:18 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-16 04:27:30 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-16 02:17:19 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-12 03:20:54 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 03:20:54 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 03:20:54 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 03:20:54 178536 ----a-w- c:\windows\system32\dnssdX.dll
2011-07-09 04:29:46 2048 ----a-w- c:\windows\system32\tzres.dll
2011-07-09 02:30:00 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-05 10:37:00 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 10:37:00 69632 ----a-w- c:\windows\system32\QuickTime.qts
.
============= FINISH: 21:28:03.97 ===============
Attached File(s)
-
Attach.txt (3.71K)
Number of downloads: 0 -
ark.txt (9.55K)
Number of downloads: 0
This post has been edited by Rowe: 28 September 2011 - 08:51 AM

Help
This topic is locked

Back to top









