note: i also ran gmer as the preparation guide suggests, but only five of the check boxes worked (services, registry, files, harddrive options, and ads). i proceeded to run the program and generate an ark.log file only to receive a 0kb .log file, as i tried to attach.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64 NETWORK
Internet Explorer: 9.0.8112.16421
Run by Charlie at 6:38:51 on 2011-10-01
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.7197 [GMT -4:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files (x86)\Aurora\firefox.exe
C:\Program Files (x86)\Aurora\plugin-container.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
StartupFolder: C:\Users\Charlie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\POWERS~1.LNK - C:\Program Files (x86)\PowerStrip\PStrip.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: Interfaces\{F3AF9B71-A3CC-4623-B6FB-8FF7485A3C36} : NameServer = 8.8.8.8,8.8.4.4
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~2\Office12\GRA32A~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~2\Office12\GR469A~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\2du9adla.default\
FF - prefs.js: browser.search.selectedEngine - Arccosine
FF - prefs.js: browser.startup.homepage - hxxp://www.reddit.com/
FF - prefs.js: keyword.URL - hxxp://www.arccosine.com/search.php?q=
FF - plugin: C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R3 hidusbf;USB Mouse Rate Adjuster Lower Filter by SweetLow;C:\Windows\system32\DRIVERS\hidusbf.sys --> C:\Windows\system32\DRIVERS\hidusbf.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S1 PStrip64;PStrip64;C:\Windows\system32\drivers\pstrip64.sys --> C:\Windows\system32\drivers\pstrip64.sys [?]
S2 AODService;AODService;C:\Program Files (x86)\AMD\OverDrive\AODAssist.exe [2011-5-25 136616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 lxdd_device;lxdd_device;C:\Windows\system32\lxddcoms.exe -service --> C:\Windows\system32\lxddcoms.exe -service [?]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService;C:\Windows\System32\spool\DRIVERS\x64\3\lxddserv.exe [2007-5-25 34224]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-10-1 366152]
S2 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2011-8-10 227184]
S2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-8-2 2255464]
S3 AODDriver4.01;AODDriver4.01;C:\Program Files (x86)\AMD\OverDrive\amd64\AODDriver2.sys [2011-5-25 55424]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-8-2 79360]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
S3 motandroidusb;Mot ADB Interface Driver;C:\Windows\system32\Drivers\motoandroid.sys --> C:\Windows\system32\Drivers\motoandroid.sys [?]
S3 MotDev;Motorola Inc. USB Device;C:\Windows\system32\DRIVERS\motodrv.sys --> C:\Windows\system32\DRIVERS\motodrv.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 se64a;EnTech softEngine;C:\Windows\System32\drivers\se64a.sys [2007-5-3 14032]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-01 10:34:51 607260 ------r- C:\dds.scr
2011-10-01 08:53:46 -------- d-----w- C:\$RECYCLE.BIN
2011-10-01 08:31:56 98816 ----a-w- C:\Windows\sed.exe
2011-10-01 08:31:56 518144 ----a-w- C:\Windows\SWREG.exe
2011-10-01 08:31:56 256000 ----a-w- C:\Windows\PEV.exe
2011-10-01 08:31:56 208896 ----a-w- C:\Windows\MBR.exe
2011-10-01 08:31:03 4237173 ------r- C:\Combo-Fix.exe
2011-10-01 08:25:36 -------- d-----w- C:\Users\Charlie\AppData\Roaming\Malwarebytes
2011-10-01 08:25:33 -------- d-----w- C:\ProgramData\Malwarebytes
2011-10-01 08:25:30 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-10-01 08:25:30 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-10-01 08:11:13 66896 ----a-w- C:\mbam-clean.exe
2011-10-01 08:06:42 -------- d-----w- C:\Program Files (x86)\ESET
2011-10-01 08:06:28 2322184 ----a-w- C:\esetsmartinstaller_enu.exe
2011-10-01 07:39:38 90 ----a-w- C:\env.bat
2011-10-01 07:37:41 1008092 ----a-w- C:\rkill.scr
2011-09-29 12:37:23 1008092 ----a-w- C:\rkill.exe
2011-09-29 12:33:17 9852544 ----a-w- C:\mbam-setup-1.51.2.1300.exe
2011-09-29 09:21:37 -------- d-----w- C:\logs
2011-09-29 09:05:50 -------- d-----w- C:\Program Files (x86)\Google Books Downloader
2011-09-29 09:05:40 -------- d-----w- C:\Windows\System32\appmgmt
2011-09-29 09:01:42 -------- d-----w- C:\Users\Charlie\AppData\Roaming\adma
2011-09-27 07:07:02 245760 ----a-w- C:\Windows\SysWow64\uxtheme.dll.backup
2011-09-27 07:06:59 2755072 ----a-w- C:\Windows\SysWow64\themeui.dll.backup
2011-09-21 07:31:25 -------- d-----w- C:\Users\Charlie\AppData\Local\Geckofx
2011-09-05 05:14:33 -------- d-----w- C:\Program Files (x86)\EVGA Precision
2011-09-05 05:06:05 -------- d-----w- C:\Program Files (x86)\AMD
2011-09-05 05:05:31 -------- d-----w- C:\Users\Charlie\AppData\Local\Downloaded Installations
2011-09-04 17:37:01 -------- d-----w- C:\ENB
.
==================== Find3M ====================
.
2011-09-27 07:07:27 332288 ----a-w- C:\Windows\System32\uxtheme.dll
2011-09-27 07:07:25 2851840 ----a-w- C:\Windows\System32\themeui.dll
2011-09-27 07:07:22 44544 ----a-w- C:\Windows\System32\themeservice.dll
2011-09-27 07:07:02 245760 ----a-w- C:\Windows\SysWow64\uxtheme.dll
2011-09-27 07:06:59 2755072 ----a-w- C:\Windows\SysWow64\themeui.dll
2011-09-01 09:31:52 868848 ----a-w- C:\Windows\System32\drivers\sptd.sys
2011-08-21 18:56:27 7808 ----a-w- C:\Windows\System32\drivers\hidusbf.sys
2011-08-17 21:06:59 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-12 10:05:48 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-08-02 08:53:49 419840 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-08-02 08:53:49 413696 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-08-02 08:53:49 133632 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-08-02 08:53:49 110592 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-08-01 19:59:06 45416 ----a-w- C:\Windows\System32\drivers\point64.sys
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 05:26:20 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-07-09 04:29:46 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
.
============= FINISH: 6:38:57.58 ===============
Attached File(s)
-
Attach.txt (7.5K)
Number of downloads: 0

Help
This topic is locked

Back to top









