DDS (Ver_09-12-01.01) - NTFSx86 Run by Fredrik at 16:16:47,37 on 29.01.2010 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.47.1033.18.3326.2150 [GMT 1:00] ============== Running Processes =============== D:\Windows\system32\wininit.exe D:\Windows\system32\lsm.exe D:\Windows\system32\svchost.exe -k DcomLaunch D:\Windows\system32\svchost.exe -k RPCSS d:\Program Files\Microsoft Security Essentials\MsMpEng.exe D:\Windows\system32\atiesrxx.exe D:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted D:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted D:\Windows\system32\svchost.exe -k netsvcs D:\Windows\system32\svchost.exe -k LocalService D:\Windows\system32\svchost.exe -k NetworkService D:\Windows\system32\atieclxx.exe D:\Windows\System32\spoolsv.exe D:\Windows\system32\svchost.exe -k LocalServiceNoNetwork D:\Program Files\LogMeIn Hamachi\hamachi-2.exe D:\Windows\system32\OSPPSVC.EXE D:\Program Files\Raxco\PerfectDisk10\PDAgent.exe D:\Windows\system32\taskhost.exe D:\Windows\system32\Dwm.exe D:\Windows\Explorer.EXE D:\Windows\system32\PnkBstrA.exe D:\Windows\system32\svchost.exe -k imgsvc D:\Program Files\Voddler\service\voddler.exe D:\Program Files\Raxco\PerfectDisk10\PDEngine.exe D:\Windows\system32\WUDFHost.exe D:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe D:\Program Files\Microsoft Security Essentials\msseces.exe D:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe D:\Program Files\Common Files\Java\Java Update\jusched.exe D:\Program Files\Voddler\service\VNetManager.exe D:\Program Files\DAEMON Tools Lite\DTLite.exe D:\Program Files\Windows Live\Messenger\msnmsgr.exe D:\Program Files\Windows Live\Contacts\wlcomm.exe D:\Windows\system32\SearchIndexer.exe D:\Program Files\Windows Media Player\wmpnetwk.exe D:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation D:\Windows\system32\SearchProtocolHost.exe D:\Windows\system32\taskeng.exe D:\Users\Fredrik\AppData\Local\Google\Chrome\Application\chrome.exe D:\Windows\system32\sppsvc.exe D:\Windows\system32\wbem\wmiprvse.exe D:\Users\Fredrik\AppData\Local\Google\Chrome\Application\chrome.exe D:\Users\Fredrik\AppData\Local\Google\Chrome\Application\chrome.exe D:\Windows\system32\msiexec.exe D:\Windows\System32\svchost.exe -k WerSvcGroup D:\Windows\system32\svchost.exe -k SDRSVC D:\Program Files\hjt\TrendMicro\HiJackThis\HiJackThis.exe D:\Users\Fredrik\AppData\Local\Google\Chrome\Application\chrome.exe D:\Windows\system32\wbem\wmiprvse.exe D:\Windows\system32\SearchFilterHost.exe D:\Windows\system32\NOTEPAD.EXE D:\Windows\system32\DllHost.exe D:\Windows\system32\DllHost.exe D:\Users\Fredrik\Documents\Downloads\Chrome\dds.scr D:\Windows\system32\conhost.exe ============== Pseudo HJT Report =============== BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~4\office14\GROOVEEX.DLL BHO: Påloggingshjelp for Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - d:\progra~1\micros~4\office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll uRun: [DAEMON Tools Lite] "d:\program files\daemon tools lite\DTLite.exe" -autorun uRun: [msnmsgr] "d:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [MSSE] "d:\program files\microsoft security essentials\msseces.exe" -hide mRun: [RtHDVCpl] d:\program files\realtek\audio\hda\RtHDVCpl.exe -s mRun: [ATICustomerCare] "d:\program files\ati\aticustomercare\ATICustomerCare.exe" mRun: [EasyTuneVI] d:\program files\gigabyte\et6\ETcall.exe mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "d:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [VoddlerNet Manager] d:\program files\voddler\service\VNetManager.exe mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - d:\progra~1\micros~4\office14\EXCEL.EXE/3000 IE: S&end to OneNote - d:\progra~1\micros~4\office14\ONBttnIE.dll/105 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - d:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - d:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~4\office14\GROOVEEX.DLL ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;d:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832] R1 vwififlt;Virtual WiFi Filter Driver;d:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 AMD External Events Utility;AMD External Events Utility;d:\windows\system32\atiesrxx.exe [2009-11-25 172032] R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\logmein hamachi\hamachi-2.exe [2009-10-29 1074568] R2 osppsvc;Office Software Protection Platform;d:\windows\system32\OSPPSVC.EXE [2009-4-8 4319136] R2 VoddlerNet;VoddlerNet;d:\program files\voddler\service\voddler.exe [2010-1-26 1235664] R3 MpNWMon;Microsoft Malware Protection Network Driver;d:\windows\system32\drivers\MpNWMon.sys [2009-6-18 42480] R3 RTL8167;Realtek 8167 NT Driver;d:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;d:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336] S3 AODDriver;AODDriver;d:\program files\gigabyte\et6\i386\AODDriver.sys [2009-2-23 7168] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;d:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-31 25832] S3 etdrv;etdrv;d:\windows\etdrv.sys [2010-1-16 17488] S3 EverestDriver;Lavalys EVEREST Kernel Driver;d:\windows.old\program files\lavalys\everest ultimate edition\kerneld.wnt [2009-11-27 27248] S3 GVTDrv;GVTDrv;d:\windows\system32\drivers\GVTDrv.sys [2010-1-16 24944] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;d:\program files\microsoft office\office14\GROOVE.EXE [2009-4-25 33480048] S3 WinRing0_1_2_0;WinRing0_1_2_0;d:\program files\realtemp\WinRing0.sys [2008-7-26 14416] =============== Created Last 30 ================ 2010-01-28 20:24:42 65110 ----a-w- d:\users\fredrik\animals_216_12.jpg 2010-01-28 19:47:08 1181334 ----atw- d:\users\fredrik\Shoe on the head.bmp 2010-01-28 17:50:51 0 d-----w- d:\program files\Reality Pump 2010-01-27 20:18:51 241558 ----a-w- d:\users\fredrik\Untitled.png 2010-01-27 12:40:30 2614272 ----a-w- d:\windows\explorer.exe 2010-01-27 12:40:29 285696 ----a-w- d:\windows\system32\winlogon.exe 2010-01-27 12:35:46 0 d-----w- d:\programdata\Voddler 2010-01-27 12:35:22 0 d-----w- d:\program files\Voddler 2010-01-26 21:29:35 139152 ----a-w- d:\users\fredrik\appdata\roaming\PnkBstrK.sys 2010-01-26 21:29:04 794408 ----a-w- d:\windows\system32\pbsvc.exe 2010-01-26 16:43:58 0 d-----w- d:\programdata\Raxco 2010-01-26 16:43:16 0 d-----w- d:\program files\Raxco 2010-01-26 16:19:57 0 d-----w- d:\users\fredrik\appdata\roaming\Malwarebytes 2010-01-26 16:19:54 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys 2010-01-26 16:19:53 19160 ----a-w- d:\windows\system32\drivers\mbam.sys 2010-01-26 16:19:53 0 d-----w- d:\programdata\Malwarebytes 2010-01-26 16:19:53 0 d-----w- d:\program files\Malwarebytes' Anti-Malware 2010-01-26 16:08:43 0 d-----w- d:\program files\hjt 2010-01-25 19:55:32 0 d-----w- d:\users\fredrik\appdata\roaming\ManyCam 2010-01-24 22:04:16 51248 ----a-w- d:\windows\system32\vmnetbridge.dll 2010-01-24 22:03:44 0 d-----w- d:\programdata\VMware 2010-01-24 19:55:26 225280 ----a-w- d:\windows\system32\rewire.dll 2010-01-24 19:55:17 1554944 ----a-w- d:\windows\system32\vorbis.acm 2010-01-24 19:54:44 0 d-----w- d:\program files\VstPlugins 2010-01-24 19:54:36 0 d-----w- d:\program files\Outsim 2010-01-24 19:53:23 0 d-----w- d:\program files\Image-Line 2010-01-23 18:02:45 4573 ----a-w- d:\users\fredrik\bug.png 2010-01-23 14:47:53 0 d-----w- d:\users\fredrik\Program Files 2010-01-22 19:55:25 1069508 ----a-w- d:\users\fredrik\Idle.wmv 2010-01-22 18:43:42 17764 ----a-w- d:\users\fredrik\Banner.jpg 2010-01-22 18:43:33 21779 ----a-w- d:\users\fredrik\Banner.pdn 2010-01-22 18:38:09 19951 ----a-w- d:\users\fredrik\Logo.jpg 2010-01-22 17:53:07 34125 ----a-w- d:\users\fredrik\Promo.jpg 2010-01-22 17:52:45 68599 ----a-w- d:\users\fredrik\Promo.pdn 2010-01-22 17:34:11 0 d-----w- d:\program files\Paint.NET 2010-01-22 15:41:58 23 ----a-w- d:\windows\BlendSettings.ini 2010-01-21 23:22:11 0 d-----w- d:\programdata\Sun 2010-01-21 23:22:00 411368 ----a-w- d:\windows\system32\deploytk.dll 2010-01-21 21:46:26 1307 ----a-w- d:\users\fredrik\logo.png 2010-01-21 20:10:48 17821 ----a-w- d:\users\fredrik\ProComputing.png 2010-01-21 19:56:12 0 d-----w- d:\program files\Livestream Procaster 2010-01-21 19:22:55 977920 ----a-w- d:\windows\system32\wininet.dll 2010-01-17 15:43:02 0 d-----w- d:\users\fredrik\Unigine Heaven 2010-01-16 21:08:12 0 d-----w- D:\ATI 2010-01-16 21:02:18 0 d-----w- d:\program files\Phyxion.net 2010-01-16 12:01:00 0 d-----w- d:\users\fredrik\appdata\roaming\Turbine 2010-01-16 11:55:33 0 d-----w- d:\windows\system32\URTTEMP 2010-01-16 11:35:04 0 d-----w- d:\program files\Turbine 2010-01-16 01:09:52 17488 ----a-w- d:\windows\etdrv.sys 2010-01-16 01:09:20 4 ----a-w- d:\windows\system32\GVTunner.ref 2010-01-16 01:09:20 24944 ----a-w- d:\windows\system32\drivers\GVTDrv.sys 2010-01-16 01:09:03 0 d-----w- d:\program files\GIGABYTE 2010-01-16 01:09:03 0 d-----w- d:\program files\AMD 2010-01-16 01:08:53 17488 ----a-w- d:\windows\gdrv.sys 2010-01-16 00:03:30 0 d-----w- d:\program files\Pando Networks 2010-01-14 23:32:08 4096 ----a-w- d:\windows\d3dx.dat 2010-01-14 23:25:53 327168 ----a-w- d:\windows\system32\cutil32.dll 2010-01-14 23:25:53 285696 ----a-w- d:\windows\system32\cudart.dll 2010-01-14 15:48:48 2513 ----a-w- d:\windows\CDPlayer.ini 2010-01-14 15:07:46 0 ---ha-w- d:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-01-14 14:57:14 0 d-----w- d:\program files\MediaMonkey 2010-01-13 22:35:15 0 d-----w- d:\users\fredrik\appdata\roaming\Ubisoft 2010-01-13 22:32:09 281760 ----a-w- d:\windows\system32\drivers\atksgt.sys 2010-01-13 22:32:08 25888 ----a-w- d:\windows\system32\drivers\lirsgt.sys 2010-01-13 21:53:31 70656 ----a-w- d:\windows\system32\fontsub.dll 2010-01-13 21:53:31 108544 ----a-w- d:\windows\system32\t2embed.dll 2010-01-13 20:06:44 0 d-----w- d:\program files\LogMeIn Hamachi 2010-01-13 19:39:40 90304138 ----a-w- d:\users\fredrik\collagepng.png 2010-01-13 19:13:50 5021426 ----a-w- d:\users\fredrik\collagehalvertjpg.jpg 2010-01-13 17:21:02 0 d-----w- d:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition 2010-01-10 20:48:15 0 d-----w- d:\users\fredrik\appdata\roaming\Folding@home-gpu 2010-01-10 20:48:15 0 d-----w- d:\program files\Folding@home 2010-01-10 20:25:10 0 d--h--w- d:\windows\msdownld.tmp 2010-01-10 20:25:07 0 d-----w- d:\windows\system32\directx 2010-01-10 20:13:55 0 d-----w- d:\programdata\ATI 2010-01-10 20:12:07 0 d-----w- d:\program files\common files\ATI Technologies 2010-01-10 20:10:56 0 d-----w- d:\program files\ATI Technologies 2010-01-10 20:10:55 0 d-----w- d:\program files\ATI 2010-01-10 19:39:44 0 d-----w- d:\program files\Realtemp 2009-12-31 16:52:42 0 d-----w- d:\programdata\BioWare 2009-12-31 16:48:04 0 d-----w- d:\windows\1C4551A64743409391E41477CD655043.TMP 2009-12-31 16:47:58 0 d-----w- d:\program files\common files\Wise Installation Wizard 2009-12-31 16:47:56 0 d-----w- d:\programdata\Media Center Programs 2009-12-31 16:32:01 0 d-----w- d:\program files\Dragon Age 2009-12-31 16:32:01 0 d-----w- d:\program files\common files\BioWare ==================== Find3M ==================== 2010-01-29 15:16:15 79094 ----a-w- d:\windows\system32\perfc014.dat 2010-01-29 15:16:15 459180 ----a-w- d:\windows\system32\perfh014.dat 2010-01-28 20:06:22 137544 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys 2010-01-28 20:06:08 189480 ----a-w- d:\windows\system32\PnkBstrB.exe 2010-01-26 21:29:06 75064 ----a-w- d:\windows\system32\PnkBstrA.exe 2010-01-14 10:12:06 181120 ------w- d:\windows\system32\MpSigStub.exe 2009-12-15 20:53:40 39554 ----a-w- d:\windows\fonts\EUDC.EUF 2009-12-15 20:53:40 112072 ----a-w- d:\windows\fonts\EUDC.TTE 2009-12-12 22:44:43 107888 ----a-w- d:\windows\system32\CmdLineExt.dll 2009-12-11 22:39:45 691696 ----a-w- d:\windows\system32\drivers\sptd.sys 2009-12-11 21:39:32 0 ---ha-w- d:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf 2009-12-08 09:54:03 413696 ----a-w- d:\windows\system32\wrap_oal.dll 2009-12-08 09:54:03 110592 ----a-w- d:\windows\system32\OpenAL32.dll 2009-12-03 02:12:06 36156 ----a-w- d:\windows\system32\perfd014.dat 2009-12-03 02:12:06 36156 ----a-w- d:\windows\inf\perflib\0414\perfd.dat 2009-12-03 02:12:06 36156 ----a-w- d:\windows\inf\perflib\0414\perfc.dat 2009-12-03 02:12:06 298300 ----a-w- d:\windows\system32\perfi014.dat 2009-12-03 02:12:06 298300 ----a-w- d:\windows\inf\perflib\0414\perfi.dat 2009-12-03 02:12:06 298300 ----a-w- d:\windows\inf\perflib\0414\perfh.dat 2009-11-25 03:18:02 446464 ----a-w- d:\windows\system32\ATIDEMGX.dll 2009-11-25 03:17:34 368640 ----a-w- d:\windows\system32\atieclxx.exe 2009-11-25 03:17:04 172032 ----a-w- d:\windows\system32\atiesrxx.exe 2009-11-25 03:15:46 159744 ----a-w- d:\windows\system32\atitmmxx.dll 2009-11-25 03:15:28 356352 ----a-w- d:\windows\system32\atipdlxx.dll 2009-11-25 03:15:14 274432 ----a-w- d:\windows\system32\Oemdspif.dll 2009-11-25 03:15:04 11776 ----a-w- d:\windows\system32\atimuixx.dll 2009-11-25 03:14:58 43520 ----a-w- d:\windows\system32\ati2edxx.dll 2009-11-25 03:12:12 3055616 ----a-w- d:\windows\system32\atidxx32.dll 2009-11-25 02:55:58 3617792 ----a-w- d:\windows\system32\atiumdag.dll 2009-11-25 02:44:56 13487616 ----a-w- d:\windows\system32\atioglxx.dll 2009-11-25 02:37:58 2899968 ----a-w- d:\windows\system32\atiumdva.dll 2009-11-25 02:25:38 52224 ----a-w- d:\windows\system32\atimpc32.dll 2009-11-25 02:25:38 52224 ----a-w- d:\windows\system32\amdpcom32.dll 2009-11-25 02:25:06 225280 ----a-w- d:\windows\system32\atiadlxx.dll 2009-11-25 02:21:52 53248 ----a-w- d:\windows\system32\aticalrt.dll 2009-11-25 02:21:36 53248 ----a-w- d:\windows\system32\aticalcl.dll 2009-11-25 02:20:26 3629056 ----a-w- d:\windows\system32\aticaldd.dll 2009-07-14 04:56:42 31548 ----a-w- d:\windows\inf\perflib\0409\perfd.dat 2009-07-14 04:56:42 31548 ----a-w- d:\windows\inf\perflib\0409\perfc.dat 2009-07-14 04:56:42 291294 ----a-w- d:\windows\inf\perflib\0409\perfi.dat 2009-07-14 04:56:42 291294 ----a-w- d:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:41:57 174 --sha-w- d:\program files\desktop.ini 2009-07-14 00:34:40 291294 ----a-w- d:\windows\inf\perflib\0000\perfi.dat 2009-07-14 00:34:40 291294 ----a-w- d:\windows\inf\perflib\0000\perfh.dat 2009-07-14 00:34:38 31548 ----a-w- d:\windows\inf\perflib\0000\perfd.dat 2009-07-14 00:34:38 31548 ----a-w- d:\windows\inf\perflib\0000\perfc.dat 2009-06-10 21:26:35 9633792 --sha-r- d:\windows\fonts\StaticCache.dat 2009-07-14 01:14:45 396800 --sha-w- d:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 16:17:07,75 ===============