beachy99 Posted April 20, 2012 ID:544553 Share Posted April 20, 2012 .DDS (Ver_2011-08-26.01) - NTFSAMD64Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31Run by home at 15:18:38 on 2012-04-20Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3693.991 [GMT -5:00].SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ===============.C:\windows\system32\wininit.exeC:\windows\system32\lsm.exeC:\windows\system32\svchost.exe -k DcomLaunchC:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exeC:\windows\system32\svchost.exe -k RPCSSC:\windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\windows\system32\svchost.exe -k netsvcsC:\windows\system32\svchost.exe -k LocalServiceC:\windows\system32\svchost.exe -k NetworkServiceC:\windows\System32\spoolsv.exeC:\windows\system32\atieclxx.exeC:\windows\system32\svchost.exe -k LocalServiceNoNetworkC:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonationC:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exeC:\windows\system32\svchost.exe -k imgsvcC:\windows\system32\TODDSrv.exeC:\Program Files\Toshiba\Power Saver\TosCoSrv.exeC:\windows\system32\taskhost.exeC:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exeC:\windows\system32\Dwm.exeC:\windows\Explorer.EXEC:\Program Files\Toshiba\FlashCards\TCrdMain.exeC:\Program Files\Realtek\Audio\HDA\RAVCpl64.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exeC:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exeC:\windows\System32\svchost.exe -k LocalServicePeerNetC:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exeC:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exeC:\windows\System32\svchost.exe -k secsvcsC:\windows\explorer.exeC:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXEC:\windows\explorer.exeC:\Program Files (x86)\Mozilla Firefox\firefox.exeC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\windows\system32\notepad.exeC:\windows\system32\taskhost.exeC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\windows\explorer.exeC:\windows\system32\notepad.exeC:\windows\explorer.exeC:\windows\explorer.exeC:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXEC:\windows\splwow64.exeC:\Program Files (x86)\Microsoft Office\Office14\MSPUB.EXEC:\windows\system32\SearchIndexer.exeC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Users\home\Downloads\HijackThis.exeC:\Program Files (x86)\IObit\Advanced SystemCare 5\Promote.exeC:\windows\SysWOW64\NOTEPAD.EXEC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\Program Files (x86)\Internet Explorer\iexplore.exeC:\windows\system32\svchost.exe -k AxInstSVGroupC:\Program Files (x86)\Internet Explorer\IEInstal.exeC:\Users\home\AppData\Local\Temp\HouseCall\housecall.binC:\Users\home\Downloads\RogueKiller.exec:\windows\SysWOW64\notepad.exeC:\windows\system32\SearchProtocolHost.exeC:\windows\system32\SearchFilterHost.exeC:\windows\system32\DllHost.exeC:\windows\system32\DllHost.exeC:\windows\SysWOW64\cmd.exeC:\windows\system32\conhost.exeC:\windows\SysWOW64\cscript.exeC:\windows\system32\wbem\wmiprvse.exe.============== Pseudo HJT Report ===============.uSearch Page = hxxp://www.google.comuStart Page = hxxp://www.google.com/uDefault_Page_URL = hxxp://start.toshiba.com/?cid=C001B2YuSearch Bar = hxxp://www.google.com/ieuDefault_Search_URL = hxxp://www.google.com/ieuInternet Settings,ProxyOverride = <local>uSearchAssistant = hxxp://www.google.com/ieuSearchURL,(Default) = hxxp://www.google.com/search?q=%smWinlogon: Userinit=userinit.exeBHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLLTB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No FileTB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No FileuRun: [Advanced SystemCare 5] "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStartuRunOnce: [FlashPlayerUpdate] C:\windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_228_Plugin.exe -update pluginmRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRunmRun: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDEDmRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbyloginmRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60mPolicies-explorer: NoActiveDesktop = 1 (0x1)mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cabTCP: DhcpNameServer = 192.168.1.1TCP: Interfaces\{F2CBD0D9-C2B8-47E1-A90E-54A123B668A4} : DhcpNameServer = 192.168.1.1TCP: Interfaces\{F2CBD0D9-C2B8-47E1-A90E-54A123B668A4}\C696E6B6379737 : DhcpNameServer = 97.64.209.36 97.64.168.13Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLLBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLLBHO-X64: URLRedirectionBHO - No FileTB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No FileTB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No FilemRun-x64: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRunmRun-x64: [ToshibaAppPlace] "C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe"mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" UNATTENDEDmRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbyloginmRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"mRun-x64: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60.================= FIREFOX ===================.FF - ProfilePath - C:\Users\home\AppData\Roaming\Mozilla\Firefox\Profiles\ytt6pldk.default\FF - prefs.js: browser.search.selectedEngine - YahooFF - prefs.js: browser.startup.homepage - hxxp://google.comFF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=685749&p=FF - prefs.js: network.proxy.type - 0FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLLFF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLLFF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dllFF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dllFF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dllFF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dllFF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dllFF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrlui.dllFF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dllFF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_228.dll.---- FIREFOX POLICIES ----FF - user.js: network.http.max-persistent-connections-per-server - 4.============= SERVICES / DRIVERS ===============.R1 vwififlt;Virtual WiFi Filter Driver;C:\windows\system32\DRIVERS\vwififlt.sys --> C:\windows\system32\DRIVERS\vwififlt.sys [?]R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2012-3-13 913752]R2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\SymcPCCULaunchSvc.exe [2012-2-25 123320]R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2012-2-25 126392]R3 amdkmdag;amdkmdag;C:\windows\system32\DRIVERS\atikmdag.sys --> C:\windows\system32\DRIVERS\atikmdag.sys [?]R3 amdkmdap;amdkmdap;C:\windows\system32\DRIVERS\atikmpag.sys --> C:\windows\system32\DRIVERS\atikmpag.sys [?]R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-10 4925184]R3 PGEffect;Pangu effect driver;C:\windows\system32\DRIVERS\pgeffect.sys --> C:\windows\system32\DRIVERS\pgeffect.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\windows\system32\DRIVERS\Rt64win7.sys --> C:\windows\system32\DRIVERS\Rt64win7.sys [?]R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\system32\DRIVERS\rtl8192Ce.sys --> C:\windows\system32\DRIVERS\rtl8192Ce.sys [?]R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\windows\system32\DRIVERS\vwifimp.sys --> C:\windows\system32\DRIVERS\vwifimp.sys [?]S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]S2 AMD External Events Utility;AMD External Events Utility;C:\windows\system32\atiesrxx.exe --> C:\windows\system32\atiesrxx.exe [?]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S2 GFNEXSrv;GFNEX Service;C:\Windows\System32\GFNEXSrv.exe --> C:\Windows\System32\GFNEXSrv.exe [?]S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-2-25 136176]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-29 253600]S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-2-25 136176]S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\system32\Drivers\RtsUStor.sys --> C:\windows\system32\Drivers\RtsUStor.sys [?]S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]S3 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2012-2-25 57216]S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-6-10 138152]S3 TsUsbFlt;TsUsbFlt;C:\windows\system32\drivers\tsusbflt.sys --> C:\windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\system32\drivers\TsUsbGD.sys --> C:\windows\system32\drivers\TsUsbGD.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\system32\Wat\WatAdminSvc.exe --> C:\windows\system32\Wat\WatAdminSvc.exe [?].=============== Created Last 30 ================.2012-04-20 20:11:59 -------- d--h--w- C:\windows\AxInstSV2012-04-20 19:50:41 8917360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{101FBF07-2AD7-41E1-A36C-2824870319DC}\mpengine.dll2012-04-17 15:46:25 -------- d-----w- C:\Users\home\New folder2012-04-11 18:26:06 -------- d-----w- C:\windows\PCHEALTH2012-04-11 18:22:40 81408 ----a-w- C:\windows\System32\imagehlp.dll2012-04-11 18:22:40 23408 ----a-w- C:\windows\System32\drivers\fs_rec.sys2012-04-11 18:22:40 159232 ----a-w- C:\windows\SysWow64\imagehlp.dll2012-04-11 18:22:39 5120 ----a-w- C:\windows\SysWow64\wmi.dll2012-04-11 18:22:39 5120 ----a-w- C:\windows\System32\wmi.dll2012-04-11 18:22:39 220672 ----a-w- C:\windows\System32\wintrust.dll2012-04-11 18:22:39 172544 ----a-w- C:\windows\SysWow64\wintrust.dll2012-03-30 06:37:13 8669240 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll2012-03-30 02:10:23 418464 ----a-w- C:\windows\SysWow64\FlashPlayerApp.exe2012-03-23 23:04:35 -------- d-----w- C:\Users\home\AppData\Roaming\PeerNetworking2012-03-22 19:12:12 4435968 ----a-w- C:\windows\SysWow64\GPhotos.scr2012-03-22 05:51:23 23896 ----a-w- C:\windows\System32\RegistryDefragBootTime.exe.==================== Find3M ====================.2012-03-30 02:10:23 70304 ----a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-03-27 00:28:52 175736 ----a-w- C:\windows\System32\drivers\SYMEVENT64x86.SYS2012-03-11 14:32:34 472808 ----a-w- C:\windows\SysWow64\deployJava1.dll2012-03-06 06:53:37 5559152 ----a-w- C:\windows\System32\ntoskrnl.exe2012-03-06 05:59:47 3968368 ----a-w- C:\windows\SysWow64\ntkrnlpa.exe2012-03-06 05:59:41 3913072 ----a-w- C:\windows\SysWow64\ntoskrnl.exe2012-02-28 06:56:48 2311168 ----a-w- C:\windows\System32\jscript9.dll2012-02-28 06:49:56 1390080 ----a-w- C:\windows\System32\wininet.dll2012-02-28 06:48:57 1493504 ----a-w- C:\windows\System32\inetcpl.cpl2012-02-28 06:42:55 2382848 ----a-w- C:\windows\System32\mshtml.tlb2012-02-28 01:18:55 1799168 ----a-w- C:\windows\SysWow64\jscript9.dll2012-02-28 01:11:21 1427456 ----a-w- C:\windows\SysWow64\inetcpl.cpl2012-02-28 01:11:07 1127424 ----a-w- C:\windows\SysWow64\wininet.dll2012-02-28 01:03:16 2382848 ----a-w- C:\windows\SysWow64\mshtml.tlb2012-02-26 00:44:48 0 ----a-w- C:\windows\ativpsrm.bin2012-02-23 15:18:36 279656 ------w- C:\windows\System32\MpSigStub.exe2012-02-17 06:38:26 1031680 ----a-w- C:\windows\System32\rdpcore.dll2012-02-17 05:34:22 826880 ----a-w- C:\windows\SysWow64\rdpcore.dll2012-02-17 04:58:24 210944 ----a-w- C:\windows\System32\drivers\rdpwd.sys2012-02-17 04:57:32 23552 ----a-w- C:\windows\System32\drivers\tdtcp.sys2012-02-14 17:09:44 1070352 ----a-w- C:\windows\SysWow64\MSCOMCTL.OCX2012-02-10 06:36:07 1544192 ----a-w- C:\windows\System32\DWrite.dll2012-02-10 05:38:43 1077248 ----a-w- C:\windows\SysWow64\DWrite.dll2012-02-03 04:34:34 3145728 ----a-w- C:\windows\System32\win32k.sys2012-01-25 06:38:39 77312 ----a-w- C:\windows\System32\rdpwsx.dll2012-01-25 06:38:38 149504 ----a-w- C:\windows\System32\rdpcorekmts.dll2012-01-25 06:33:30 9216 ----a-w- C:\windows\System32\rdrmemptylst.exe.============= FINISH: 15:21:00.32 ===============RKreport1.txthijackthis.logDDS.txt Link to post Share on other sites More sharing options...
MrCharlie Posted April 24, 2012 ID:545552 Share Posted April 24, 2012 Welcome to the forum and sorry for the delay.Do you still need help, if so can you tell me your concerns.Thanks....MrC Link to post Share on other sites More sharing options...
Maurice Naggar Posted April 28, 2012 ID:546924 Share Posted April 28, 2012 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts