Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- DDS (Ver_10-11-10.01) - NTFSx86
- Run by Uzair at 23:55:23.23 on 15/11/2010
- Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
- Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.2010.825 [GMT 0:00]
- ============== Running Processes ===============
- C:\Windows\system32\wininit.exe
- C:\Windows\system32\lsm.exe
- C:\Windows\system32\svchost.exe -k DcomLaunch
- C:\Windows\system32\svchost.exe -k RPCSS
- C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
- C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
- C:\Windows\system32\svchost.exe -k netsvcs
- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_028821c569ae5894\STacSV.exe
- C:\Windows\system32\svchost.exe -k LocalService
- C:\Windows\system32\svchost.exe -k NetworkService
- C:\Windows\System32\spoolsv.exe
- C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_028821c569ae5894\aestsrv.exe
- C:\Windows\System32\svchost.exe -k Akamai
- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- C:\Program Files\Bonjour\mDNSResponder.exe
- C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
- C:\Program Files\Microsoft LifeCam\MSCamS32.exe
- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
- C:\Windows\system32\svchost.exe -k imgsvc
- C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
- C:\Windows\system32\WUDFHost.exe
- C:\Windows\system32\Dwm.exe
- C:\Windows\system32\taskhost.exe
- C:\Program Files\IDT\WDM\sttray.exe
- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
- C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
- C:\Windows\system32\SearchIndexer.exe
- C:\Program Files\Windows Media Player\wmpnetwk.exe
- C:\Program Files\Common Files\Java\Java Update\jusched.exe
- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
- C:\Program Files\Creative\Creative Live! Cam\Live! Central 2\CTLVCentral2.exe
- C:\Windows\V0640Mon.exe
- C:\Windows\System32\igfxpers.exe
- C:\Program Files\iTunes\iTunesHelper.exe
- C:\Program Files\iPod\bin\iPodService.exe
- C:\Windows\System32\svchost.exe -k LocalServicePeerNet
- C:\Windows\system32\svchost.exe -k SDRSVC
- C:\Windows\system32\wuauclt.exe
- C:\Windows\system32\notepad.exe
- C:\Windows\explorer.exe
- C:\Users\Uzair\AppData\Local\Google\Chrome\Application\chrome.exe
- C:\Users\Uzair\AppData\Local\Google\Chrome\Application\chrome.exe
- C:\Users\Uzair\AppData\Local\Google\Chrome\Application\chrome.exe
- C:\Users\Uzair\AppData\Local\Google\Chrome\Application\chrome.exe
- C:\Users\Uzair\AppData\Local\Google\Chrome\Application\chrome.exe
- C:\Program Files\iTunes\iTunes.exe
- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
- C:\Windows\system32\conhost.exe
- C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
- C:\Windows\system32\conhost.exe
- C:\Users\Uzair\AppData\Local\Google\Chrome\Application\chrome.exe
- C:\Program Files\VideoLAN\VLC\vlc.exe
- C:\Windows\system32\NOTEPAD.EXE
- C:\Users\Uzair\Desktop\dds.scr
- C:\Windows\system32\conhost.exe
- C:\Windows\system32\wbem\wmiprvse.exe
- ============== Pseudo HJT Report ===============
- uInternet Settings,ProxyOverride = *.local
- uURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
- mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
- mURLSearchHooks: H - No File
- mURLSearchHooks: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
- mURLSearchHooks: H - No File
- BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
- BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
- BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
- BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
- BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
- TB: ICQToolBar: {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\program files\icq6toolbar\ICQToolBar.dll
- uRun: [Google Update] "c:\users\uzair\appdata\local\google\update\GoogleUpdate.exe" /c
- uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
- uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
- uRun: [ICQ] "c:\program files\icq7.2\ICQ.exe" silent loginmode=4
- mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
- mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
- mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
- mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
- mRun: [openvpn-gui] c:\program files\ultravpn\bin\openvpn-gui.exe
- mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
- mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
- mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
- mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
- mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
- mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
- mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
- mRun: [Live! Central 2] "c:\program files\creative\creative live! cam\live! central 2\CTLVCentral2.exe" /mode2
- mRun: [V0640Mon.exe] c:\windows\V0640Mon.exe
- mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
- mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
- mRun: [Persistence] c:\windows\system32\igfxpers.exe
- mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
- mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
- mRun: [V0640Pin.dll] RunDLL32.exe V0640Pin.dll,RunDLL32EP 514,/d:2
- mRun: [VX1000] c:\windows\vVX1000.exe
- mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
- mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
- mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
- mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
- IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
- IE: Free YouTube Download - c:\users\uzair\appdata\roaming\dvdvideosoftiehelpers\youtubedownload.htm
- IE: Free YouTube to Mp3 Converter - c:\users\uzair\appdata\roaming\dvdvideosoftiehelpers\youtubetomp3.htm
- IE: {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - c:\program files\icq7.2\ICQ.exe
- IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
- IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
- DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
- DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
- DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
- DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
- DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab
- Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
- Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
- Notify: igfxcui - igfxdev.dll
- AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll
- STS: FencesShlExt Class: {1984dd45-52cf-49cd-ab77-18f378fea264} - c:\program files\stardock\fences\FencesMenu.dll
- ================= FIREFOX ===================
- FF - ProfilePath - c:\users\uzair\appdata\roaming\mozilla\firefox\profiles\vvf95d25.default\
- FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
- FF - component: c:\users\uzair\appdata\roaming\mozilla\firefox\profiles\vvf95d25.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
- FF - component: c:\users\uzair\appdata\roaming\mozilla\firefox\profiles\vvf95d25.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\FFExternalAlert.dll
- FF - component: c:\users\uzair\appdata\roaming\mozilla\firefox\profiles\vvf95d25.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components\RadioWMPCore.dll
- FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
- FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
- FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
- ---- FIREFOX POLICIES ----
- c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
- c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
- ============= SERVICES / DRIVERS ===============
- R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
- R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_028821c569ae5894\AEstSrv.exe [2010-6-27 81920]
- R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
- R2 ICQ Service;ICQ Service;c:\program files\icq6toolbar\ICQ Service.exe [2010-6-27 246520]
- R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [2010-11-10 17984]
- R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
- R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-13 311296]
- S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
- S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-9 136176]
- S2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;c:\program files\autodesk\3ds max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-3-10 86016]
- S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
- S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [2010-10-6 143936]
- S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-6-27 30192]
- S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
- S3 V0640Vid;Creative Live! Cam Socialize (VF0640) Driver;c:\windows\system32\drivers\V0640Vid.sys [2010-10-6 273760]
- S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2009-7-23 47128]
- S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
- S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2009-3-30 366936]
- =============== Created Last 30 ================
- 2010-11-15 15:21:27 -------- d-sh--w- C:\$RECYCLE.BIN
- 2010-11-15 14:39:58 -------- d-----w- c:\windows\system32\appmgmt
- 2010-11-14 11:22:14 98816 ----a-w- c:\windows\sed.exe
- 2010-11-14 11:22:14 89088 ----a-w- c:\windows\MBR.exe
- 2010-11-14 11:22:14 256512 ----a-w- c:\windows\PEV.exe
- 2010-11-14 11:22:14 161792 ----a-w- c:\windows\SWREG.exe
- 2010-11-13 23:34:58 -------- d-----w- c:\program files\Microsoft LifeCam
- 2010-11-13 23:34:49 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
- 2010-11-13 23:34:49 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
- 2010-11-13 22:18:30 -------- d-----w- c:\program files\Veetle
- 2010-11-11 16:17:26 105984 --sha-r- c:\windows\system32\msvbvm60O.dll
- 2010-11-10 15:38:00 180224 ----a-w- c:\windows\system32\WinVd32.sys
- 2010-11-10 15:37:49 7680 ----a-w- c:\windows\system32\WinFLsrv.exe
- 2010-11-10 15:37:42 -------- d-----w- c:\program files\Folder Lock 6
- 2010-11-09 20:54:32 6146896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{1aac5ffb-72a4-40f8-99c5-1551f7210ed5}\mpengine.dll
- 2010-11-08 07:05:46 -------- d-----w- C:\found.001
- 2010-11-06 11:44:49 -------- d-----w- c:\program files\iPod
- 2010-11-06 11:39:58 -------- d-----w- c:\program files\Bonjour
- 2010-11-03 21:53:03 -------- d-----w- c:\users\uzair\Incomplete
- 2010-11-03 21:49:42 -------- d-----w- c:\users\uzair\appdata\roaming\FrostWire
- 2010-11-03 21:47:49 -------- d-----w- c:\program files\FrostWire
- 2010-10-27 09:41:57 641536 ----a-w- c:\windows\system32\CPFilters.dll
- 2010-10-27 09:41:57 417792 ----a-w- c:\windows\system32\msdri.dll
- 2010-10-27 09:41:57 204288 ----a-w- c:\windows\system32\MSNP.ax
- 2010-10-27 09:41:57 199680 ----a-w- c:\windows\system32\mpg2splt.ax
- 2010-10-27 09:41:49 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
- ==================== Find3M ====================
- 2010-10-19 10:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
- 2010-09-15 04:50:37 472808 ----a-w- c:\windows\system32\deployJava1.dll
- 2010-09-08 11:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
- 2010-09-08 11:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
- 2010-09-08 04:30:04 978432 ----a-w- c:\windows\system32\wininet.dll
- 2010-09-08 04:28:15 44544 ----a-w- c:\windows\system32\licmgr10.dll
- 2010-09-08 03:22:31 386048 ----a-w- c:\windows\system32\html.iec
- 2010-09-08 02:48:16 1638912 ----a-w- c:\windows\system32\mshtml.tlb
- 2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
- 2010-09-01 02:34:52 2327552 ----a-w- c:\windows\system32\win32k.sys
- 2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
- 2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll
- 2010-08-27 05:46:48 168448 ----a-w- c:\windows\system32\srvsvc.dll
- 2010-08-26 04:39:58 109056 ----a-w- c:\windows\system32\t2embed.dll
- 2010-08-21 05:36:33 738816 ----a-w- c:\windows\system32\wmpmde.dll
- 2010-08-21 05:36:24 224256 ----a-w- c:\windows\system32\schannel.dll
- 2010-08-21 05:33:24 530432 ----a-w- c:\windows\system32\comctl32.dll
- 2010-08-21 05:32:37 316928 ----a-w- c:\windows\system32\spoolsv.exe
- ============= FINISH: 0:00:10.46 ===============
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement