Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- DDS (Ver_2012-11-20.01) - NTFS_x86
- Internet Explorer: 6.0.2900.2180
- Run by Pedja at 21:04:59 on 2013-07-13
- Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1321 [GMT 2:00]
- .
- AV: AVG AntiVirus Free Edition 2013 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
- .
- ============== Running Processes ================
- .
- C:\WINDOWS\system32\nvsvc32.exe
- C:\WINDOWS\system32\spoolsv.exe
- C:\WINDOWS\Explorer.EXE
- C:\WINDOWS\system32\RUNDLL32.EXE
- C:\WINDOWS\RTHDCPL.EXE
- C:\WINDOWS\system32\ctfmon.exe
- C:\Documents and Settings\Pedja\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
- C:\Program Files\Skype\Phone\Skype.exe
- C:\Program Files\MCShield\MCShieldRTM.exe
- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
- C:\WINDOWS\System32\alg.exe
- C:\Program Files\Mozilla Firefox\firefox.exe
- C:\Program Files\Mozilla Firefox\plugin-container.exe
- C:\WINDOWS\system32\wbem\wmiprvse.exe
- C:\WINDOWS\System32\svchost.exe -k netsvcs
- C:\WINDOWS\system32\svchost.exe -k NetworkService
- C:\WINDOWS\system32\svchost.exe -k LocalService
- C:\WINDOWS\system32\svchost.exe -k imgsvc
- .
- ============== Pseudo HJT Report ===============
- .
- uStart Page = hxxp://www.google.com
- BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
- uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
- uRun: [Google Update] "c:\documents and settings\pedja\local settings\application data\google\update\GoogleUpdate.exe" /c
- uRun: [Facebook Update] "c:\documents and settings\pedja\local settings\application data\facebook\update\FacebookUpdate.exe" /c /nocrashserver
- uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
- uRun: [MCShield Monitor] c:\program files\mcshield\MCShieldRTM.exe
- mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install
- mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
- mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
- mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
- mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
- mRun: [RTHDCPL] RTHDCPL.EXE
- mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
- uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
- mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
- IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
- IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
- IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
- DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1367525119187
- TCP: NameServer = 79.143.160.20 79.143.168.8
- TCP: Interfaces\{6E250B0A-5289-4F49-A575-F8EDE5AC939F} : DHCPNameServer = 79.143.160.20 79.143.168.8
- Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
- AppInit_DLLs= c:\docume~1\alluse~1\applic~1\browse~1\261249~1.132\{c16c1~1\browse~1.dll
- .
- ================= FIREFOX ===================
- .
- FF - ProfilePath - c:\documents and settings\pedja\application data\mozilla\firefox\profiles\spy0hywg.default\
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.ba/
- FF - plugin: c:\documents and settings\pedja\local settings\application data\facebook\video\skype\npFacebookVideoCalling.dll
- FF - plugin: c:\documents and settings\pedja\local settings\application data\google\update\1.3.21.153\npGoogleUpdate3.dll
- FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
- FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_224.dll
- FF - ExtSQL: 2013-07-08 11:00; jid1-tdms4EWes6XF5w@jetpack; c:\documents and settings\pedja\application data\mozilla\firefox\profiles\spy0hywg.default\extensions\[email protected]
- .
- ============= SERVICES / DRIVERS ===============
- .
- R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2013-2-8 60216]
- R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2013-2-8 245048]
- R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2013-2-8 96568]
- R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2013-2-8 39224]
- R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2013-2-26 208184]
- R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2013-3-1 22328]
- R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2013-2-8 170808]
- R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2013-2-14 182072]
- R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-5-2 37664]
- R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2013-5-14 4937264]
- R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2013-4-18 283136]
- S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-4-19 161384]
- S2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\15.2.0\toolbarupdater.exe --> c:\program files\common files\avg secure search\vtoolbarupdater\15.2.0\ToolbarUpdater.exe [?]
- S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2013-5-3 1684736]
- .
- =============== Created Last 30 ================
- .
- 2013-07-13 16:11:06 24064 ----a-w- c:\windows\zoek-delete.exe
- 2013-07-11 08:57:32 -------- d-----w- c:\documents and settings\all users\application data\MCShield
- 2013-07-11 08:57:31 -------- d-----w- c:\program files\MCShield
- 2013-07-08 09:08:28 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2013-07-08 08:33:57 -------- d-----w- c:\windows\system32\wbem\repository\FS
- 2013-07-08 08:33:57 -------- d-----w- c:\windows\system32\wbem\Repository
- 2013-07-08 08:28:17 -------- d-----w- c:\program files\OpenAL
- 2013-07-07 12:37:00 -------- d-----w- c:\documents and settings\pedja\application data\avidemux
- 2013-07-07 09:25:35 -------- d-----w- c:\documents and settings\pedja\application data\NCH Software
- 2013-07-07 09:25:24 -------- d-----w- c:\program files\NCH Software
- 2013-07-07 08:37:25 -------- d-----w- c:\documents and settings\pedja\application data\Malwarebytes
- 2013-07-07 08:35:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
- 2013-07-07 08:35:18 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
- 2013-07-07 08:34:44 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
- 2013-06-30 13:58:44 -------- d-----w- c:\documents and settings\all users\GlarySoft
- 2013-06-30 13:32:59 -------- d-----w- c:\program files\Glary Utilities 3
- .
- ==================== Find3M ====================
- .
- 2013-06-18 16:52:44 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
- 2013-06-18 16:52:44 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
- 2013-06-01 16:07:35 444952 ----a-w- c:\windows\system32\wrap_oal.dll
- 2013-06-01 16:07:35 109080 ----a-w- c:\windows\system32\OpenAL32.dll
- 2013-05-23 09:34:14 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
- .
- ============= FINISH: 21:10:12.25 ===============
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement