Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- .
- DDS (Ver_2011-08-26.01) - NTFSx86
- Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
- Run by radnik at 0:08:59 on 2012-02-01
- Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1791.1029 [GMT 1:00]
- .
- AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
- .
- ============== Running Processes ===============
- .
- C:\windows\system32\Ati2evxx.exe
- C:\windows\system32\svchost -k DcomLaunch
- svchost.exe
- C:\windows\System32\svchost.exe -k netsvcs
- svchost.exe
- svchost.exe
- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- C:\windows\system32\Ati2evxx.exe
- C:\windows\Explorer.EXE
- C:\Program Files\Java\jre6\bin\jqs.exe
- C:\windows\RTHDCPL.EXE
- C:\windows\system32\PnkBstrA.exe
- C:\Program Files\AVAST Software\Avast\avastUI.exe
- C:\windows\system32\ctfmon.exe
- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
- C:\Program Files\Macro Express3\MacExp.exe
- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
- C:\windows\System32\TUProgSt.exe
- C:\Program Files\TightVNC\tvnserver.exe
- C:\Program Files\TeamViewer\Version7\TeamViewer.exe
- C:\Program Files\UltraVNC\WinVNC.exe
- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
- C:\Program Files\UltraVNC\WinVNC.exe
- C:\Program Files\TeamViewer\Version7\tv_w32.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- c:\program files\teamviewer\version7\TeamViewer_Desktop.exe
- C:\Documents and Settings\radnik\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
- C:\Program Files\totalcmd\TOTALCMD.EXE
- .
- ============== Pseudo HJT Report ===============
- .
- BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
- BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
- BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
- BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
- BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
- BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
- BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
- TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
- uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 52\AxAutoMntSrv.exe" -automount
- uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
- uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
- mRun: [RTHDCPL] RTHDCPL.EXE
- mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
- mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
- mExplorerRun: [HpqpPhUnl] c:\windows\system32\HpqpPhUnl.exe
- StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\macroe~1.lnk - c:\program files\macro express3\MacExp.exe
- uPolicies-explorer: NoActiveDesktop = 1 (0x1)
- uPolicies-explorer: NoFileUrl = 0 (0x0)
- mPolicies-explorer: NoActiveDesktop = 1 (0x1)
- mPolicies-explorer: NoFileUrl = 0 (0x0)
- dPolicies-explorer: NoActiveDesktop = 1 (0x1)
- dPolicies-explorer: NoFileUrl = 0 (0x0)
- IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
- DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
- DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
- DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
- DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
- TCP: DhcpNameServer = 192.168.1.1
- TCP: Interfaces\{BA2944C4-15E3-4A73-90CF-BE93939BC053} : DhcpNameServer = 192.168.1.1
- Notify: AtiExtEvent - Ati2evxx.dll
- Hosts: 66.220.158.18 www.facebook.com
- .
- ================= FIREFOX ===================
- .
- FF - ProfilePath - c:\documents and settings\radnik\application data\mozilla\firefox\profiles\clq2mpim.default\
- FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
- FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
- FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
- FF - plugin: c:\documents and settings\radnik\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
- FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
- FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
- FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
- FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
- FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
- FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
- .
- ---- FIREFOX POLICIES ----
- FF - user.js: network.http.max-persistent-connections-per-server - 4
- FF - user.js: nglayout.initialpaint.delay - 600
- FF - user.js: content.notify.interval - 600000
- FF - user.js: content.max.tokenizing.time - 1800000
- FF - user.js: content.switch.threshold - 600000
- .
- ============= SERVICES / DRIVERS ===============
- .
- R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-30 435032]
- R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-30 314456]
- R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-30 20568]
- R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-1-30 44768]
- R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 52\starwind\StarWindServiceAE.exe [2009-12-23 370688]
- R2 TeamViewer6;TeamViewer 6;c:\program files\teamviewer\version6\TeamViewer_Service.exe [2011-11-3 2358656]
- R2 TeamViewer7;TeamViewer 7;c:\program files\teamviewer\version7\TeamViewer_Service.exe [2011-11-29 2916736]
- R2 tvnserver;TightVNC Server;c:\program files\tightvnc\tvnserver.exe [2011-8-3 828944]
- R2 uvnc_service;uvnc_service;c:\program files\ultravnc\winvnc.exe [2011-12-6 2016504]
- R3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [2011-10-22 11496]
- S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
- S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-2-3 1684736]
- S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\garena\safedrv.sys --> c:\program files\garena\safedrv.sys [?]
- S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2011-2-5 24576]
- S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
- .
- =============== Created Last 30 ================
- .
- 2012-01-31 12:43:08 -------- d-----w- C:\Riot Games
- 2012-01-31 11:36:02 -------- d-----w- C:\lol
- 2012-01-31 11:35:09 -------- d-----w- c:\documents and settings\radnik\local settings\application data\PMB Files
- 2012-01-31 11:35:03 -------- d-----w- c:\documents and settings\all users\application data\PMB Files
- 2012-01-31 00:24:45 -------- d-sh--w- c:\documents and settings\radnik\IECompatCache
- 2012-01-30 23:36:51 -------- d-----w- c:\windows\pss
- 2012-01-30 21:15:50 -------- d-----w- c:\documents and settings\radnik\application data\Malwarebytes
- 2012-01-30 21:15:01 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
- 2012-01-30 21:15:00 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
- 2012-01-30 21:15:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
- 2012-01-30 19:40:12 -------- d-----w- c:\program files\Unlocker
- 2012-01-30 15:03:14 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
- 2012-01-30 15:02:55 41184 ----a-w- c:\windows\avastSS.scr
- 2012-01-30 15:02:45 -------- d-----w- c:\program files\AVAST Software
- 2012-01-30 15:02:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
- 2012-01-24 21:04:35 -------- d-----w- c:\program files\SpeedFan
- 2012-01-22 22:00:22 -------- d-----w- c:\program files\AMD APP
- 2012-01-15 16:31:21 -------- d-----w- c:\program files\GRETECH
- 2012-01-15 16:27:27 536064 ----a-w- c:\windows\system32\RegShellSM.exe
- .
- ==================== Find3M ====================
- .
- 2011-12-31 12:05:54 352256 ----a-w- c:\windows\eSellerateEngine.dll
- 2011-12-06 10:13:38 11496 ----a-w- c:\windows\system32\drivers\mv2.sys
- 2011-12-06 10:13:37 21480 ----a-w- c:\windows\system32\mv2.dll
- 2011-12-06 09:59:49 499712 ----a-w- c:\windows\system32\msvcp71.dll
- 2011-12-06 09:59:49 348160 ----a-w- c:\windows\system32\msvcr71.dll
- 2011-11-27 22:06:56 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
- 2011-11-19 11:29:45 138264 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
- 2011-11-19 11:29:37 234768 ----a-w- c:\windows\system32\PnkBstrB.xtr
- 2011-11-19 11:29:37 234768 ----a-w- c:\windows\system32\PnkBstrB.exe
- 2011-11-10 03:42:12 7493120 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
- 2011-11-10 03:34:58 311296 ----a-w- c:\windows\system32\atiiiexx.dll
- 2011-11-10 03:26:40 57344 ----a-w- c:\windows\system32\aticalrt.dll
- 2011-11-10 03:26:32 53248 ----a-w- c:\windows\system32\aticalcl.dll
- 2011-11-10 03:20:22 7196672 ----a-w- c:\windows\system32\aticaldd.dll
- 2011-11-10 03:06:36 19210240 ----a-w- c:\windows\system32\atioglxx.dll
- 2011-11-10 02:54:28 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
- 2011-11-10 02:53:20 304640 ----a-w- c:\windows\system32\ati2dvag.dll
- 2011-11-10 02:50:00 5266624 ----a-w- c:\windows\system32\ati3duag.dll
- 2011-11-10 02:41:00 956160 ----a-w- c:\windows\system32\ativvamv.dll
- 2011-11-10 02:32:38 212992 ----a-w- c:\windows\system32\atipdlxx.dll
- 2011-11-10 02:32:24 155648 ----a-w- c:\windows\system32\Oemdspif.dll
- 2011-11-10 02:32:16 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
- 2011-11-10 02:32:08 43520 ----a-w- c:\windows\system32\ati2edxx.dll
- 2011-11-10 02:31:56 192512 ----a-w- c:\windows\system32\ati2evxx.dll
- 2011-11-10 02:30:42 643072 ----a-w- c:\windows\system32\ati2evxx.exe
- 2011-11-10 02:30:14 3303040 ----a-w- c:\windows\system32\ativvaxx.dll
- 2011-11-10 02:29:24 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
- 2011-11-10 02:27:54 159744 ----a-w- c:\windows\system32\atiapfxx.exe
- 2011-11-10 02:23:30 806912 ----a-w- c:\windows\system32\atikvmag.dll
- 2011-11-10 02:20:58 602112 ----a-w- c:\windows\system32\atiok3x2.dll
- 2011-11-10 02:18:32 233472 ----a-w- c:\windows\system32\atiadlxx.dll
- 2011-11-10 02:18:08 17408 ----a-w- c:\windows\system32\atitvo32.dll
- 2011-11-10 02:12:22 884736 ----a-w- c:\windows\system32\ati2cqag.dll
- 2011-11-10 02:12:02 65024 ----a-w- c:\windows\system32\atimpc32.dll
- 2011-11-10 02:12:02 65024 ----a-w- c:\windows\system32\amdpcom32.dll
- 2011-11-10 02:12:00 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
- 2011-11-09 21:39:44 59904 ----a-w- c:\windows\system32\OpenVideo.dll
- 2011-11-09 21:39:32 54784 ----a-w- c:\windows\system32\OVDecode.dll
- 2011-11-09 21:38:40 14375936 ----a-w- c:\windows\system32\amdocl.dll
- 2011-11-09 21:37:46 44032 ----a-w- c:\windows\system32\OpenCL.dll
- .
- ============= FINISH: 0:11:07.57 ===============
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement