PDA

View Full Version : VirusTrigger2.ink w/DDS log



lizrobards1989
2011-09-14, 03:41
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_21
Run by Kitchen at 21:36:26 on 2011-09-13
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.2721 [GMT -4:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe
C:\PROGRA~2\COUPON~2\bar\2.bin\2pbarsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\2pbrmon.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.ipro.net/
uDefault_Search_URL = hxxp://www.ipro.net/search.asp
uStart Page = hxxp://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=CDxdm029YYus&ptb=ABFDCD2F-80D4-4269-A9E2-200549430E04
uURLSearchHooks: N/A: {7b9f8c21-46ec-4c0b-8683-e755ef84577a} - C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\2pSrcAs.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Toolbar BHO: {3a421c8f-e238-4aeb-8874-b8b5f2cc4772} - C:\PROGRA~2\COUPON~2\bar\2.bin\2pbar.dll
BHO: Search Assistant BHO: {60e91567-ef8a-4520-bce2-83aba5256799} - C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\2pSrcAs.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Coupon Alert: {3462c343-be19-4143-af70-cefb56f46fc6} - C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\2pbar.dll
TB: ShopAtHome.com Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Reader Library Launcher] C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
mRun: [CouponAlert_2p Browser Plugin Loader] C:\PROGRA~2\COUPON~2\bar\2.bin\2pbrmon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
StartupFolder: C:\Users\Kitchen\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files (x86)\Dell\DellDock\DellDock.exe
StartupFolder: C:\Users\Kitchen\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Se&nd to OneNote - C:\PROGRA~2\MIF5BA~1\Office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254 192.168.1.254
TCP: Interfaces\{8A320469-3D11-4DA2-9A88-C8AC6EA25638} : DhcpNameServer = 192.168.1.254 192.168.1.254
TCP: Interfaces\{8A320469-3D11-4DA2-9A88-C8AC6EA25638}\3547A4F6375607867457563747 : DhcpNameServer = 192.168.1.1 208.67.222.222 208.67.220.220
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Toolbar BHO: {3a421c8f-e238-4aeb-8874-b8b5f2cc4772} - C:\PROGRA~2\COUPON~2\bar\2.bin\2pbar.dll
BHO-X64: Search Assistant BHO: {60e91567-ef8a-4520-bce2-83aba5256799} - C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\2pSrcAs.dll
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Coupon Alert: {3462c343-be19-4143-af70-cefb56f46fc6} - C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\2pbar.dll
TB-X64: ShopAtHome.com Toolbar: {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files (x86)\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
mRun-x64: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
mRun-x64: [PDVDDXSrv] "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
mRun-x64: [Desktop Disc Tool] "c:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
mRun-x64: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Reader Library Launcher] C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
mRun-x64: [CouponAlert_2p Browser Plugin Loader] C:\PROGRA~2\COUPON~2\bar\2.bin\2pbrmon.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRunOnce-x64: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"
mRunOnce-x64: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Kitchen\AppData\Roaming\Mozilla\Firefox\Profiles\hoom5d2a.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=CDxdm029YYus&ptb=ABFDCD2F-80D4-4269-A9E2-200549430E04&ind=2011012910&ptnrS=CDxdm029YYus&si=17747-direct&n=77dd9f2e&psa=&st=kwd&searchfor=
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\CouponAlert_2p\bar\2.bin\NP2pStub.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol400.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\NPcol500.dll
FF - plugin: C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Kitchen\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2010-2-17 14920]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2010-2-17 12360]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2010-6-29 128752]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AESTFilters;Andrea ST Filters Service;C:\WINDOWS\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe [2010-6-25 89600]
R2 CouponAlert_2pService;Coupon Alert Service;C:\PROGRA~2\COUPON~2\bar\2.bin\2pbarsvc.exe [2011-3-20 36864]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
R2 McciCMService64;McciCMService64;C:\Program Files\Common Files\Motive\McciCMService.exe [2010-7-30 517632]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-7-24 705856]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-23 136176]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-23 136176]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-09-14 01:24:28 -------- d-----w- C:\Users\Kitchen\AppData\Local\{DC50D38B-9FE2-48FD-9B10-6B44A2B8B3E1}
2011-09-14 01:24:17 -------- d-----w- C:\Users\Kitchen\AppData\Local\{1D202041-0859-4915-AD88-9F5F758DF42F}
2011-09-13 22:08:49 -------- d-----w- C:\Users\Kitchen\AppData\Local\{1CE25806-E01A-4065-AC65-5E5384F7662F}
2011-09-13 22:08:39 -------- d-----w- C:\Users\Kitchen\AppData\Local\{BC4CFA84-231E-40BB-B97C-E01ED4A9F53C}
2011-09-13 19:57:48 -------- d-----w- C:\Users\Kitchen\AppData\Local\{D2608428-0F85-4F42-B6C5-7E5EB747B206}
2011-09-13 19:57:37 -------- d-----w- C:\Users\Kitchen\AppData\Local\{4F8672C2-4BD0-4E3B-9D68-15F8B41AF738}
2011-09-13 19:34:41 -------- d-----w- C:\Users\Kitchen\AppData\Local\{D547112A-CED2-4B36-A1FD-3E515DECE3FF}
2011-09-13 19:34:31 -------- d-----w- C:\Users\Kitchen\AppData\Local\{306B9F48-7E8A-4118-872D-6FD5274686EC}
2011-09-13 19:27:34 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{671C4477-240E-472E-AE55-253B38012849}\mpengine.dll
2011-09-13 19:26:20 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C122B945-B8D7-40DB-95FA-6E523C7A6B5E}
2011-09-13 16:26:52 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3DF38222-7BE1-4B87-95AD-2977184C00FE}
2011-09-13 16:26:42 -------- d-----w- C:\Users\Kitchen\AppData\Local\{8F1C436B-9702-47D6-BBAC-1534D1A00CC1}
2011-09-12 22:24:39 -------- d-----w- C:\Users\Kitchen\AppData\Local\{FDC51E4A-E9EA-43D2-95A3-D583C6714973}
2011-09-12 22:24:29 -------- d-----w- C:\Users\Kitchen\AppData\Local\{4A3D535A-9D8C-4E73-8FA5-7C214F83E275}
2011-09-12 21:48:18 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2ED60618-5784-4E43-8A3E-A1BEBE17E3ED}
2011-09-12 21:48:06 -------- d-----w- C:\Users\Kitchen\AppData\Local\{74564240-9D28-45AD-9426-8DB30A2B1469}
2011-09-12 19:43:54 -------- d-----w- C:\Users\Kitchen\AppData\Local\{39B1F007-3181-42E0-A4C9-DA5FE5BBDDB0}
2011-09-12 19:43:44 -------- d-----w- C:\Users\Kitchen\AppData\Local\{B444F104-7B78-49D0-83E4-7635D130DE31}
2011-09-11 17:09:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{069981DA-C7F7-44B3-B7B8-828AAF21911E}
2011-09-11 17:09:10 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6564CC6F-C818-4043-BD17-214DBE58E551}
2011-09-11 14:54:35 -------- d-----w- C:\Users\Kitchen\AppData\Local\{D18399A6-F062-46DD-BBF1-FBBD5F1C4D10}
2011-09-11 14:54:24 -------- d-----w- C:\Users\Kitchen\AppData\Local\{1CE4BC05-0B16-428D-BDD7-A7D3D214F359}
2011-09-11 10:42:20 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7F3A82EB-3A5E-4EDA-9F02-AA4191682152}
2011-09-11 10:42:07 -------- d-----w- C:\Users\Kitchen\AppData\Local\{0FE91EAE-01EE-4ACD-8DAA-5121B1D1E5BD}
2011-09-11 01:10:34 -------- d-----w- C:\Users\Kitchen\AppData\Local\{0742394F-5BB8-4AC4-818F-81E1FA29CDB2}
2011-09-11 01:10:22 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6842EEBF-E478-4BB6-8EBD-3144F3DF0E4A}
2011-09-10 21:36:40 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2B70A34E-70E2-475D-96E1-C7E0FBA0069D}
2011-09-10 21:36:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{482A2231-FF0E-4185-9513-28D367FE3BE2}
2011-09-10 18:06:57 -------- d-----w- C:\Users\Kitchen\AppData\Local\{B3A8EA7D-EDBC-47B5-8501-8E42F32DCAE0}
2011-09-10 18:06:46 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C8037FC4-CDAF-4138-A792-8559E8CF1ABA}
2011-09-10 16:54:20 -------- d-----w- C:\Users\Kitchen\AppData\Local\{BF10FCC9-DDE2-4C06-8D68-E1C6056A285A}
2011-09-10 16:54:09 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3A4D6B33-F382-471F-8272-DCB7BEA4D885}
2011-09-10 12:43:26 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7BFA372B-D528-42F0-B498-3B5C676579C7}
2011-09-10 12:43:15 -------- d-----w- C:\Users\Kitchen\AppData\Local\{249F685D-3FD5-4366-B7EF-CE8D9776B074}
2011-09-09 20:43:09 -------- d-----w- C:\Users\Kitchen\AppData\Local\{D06A11A5-03D4-4E5B-9509-2CAC39C8AD9F}
2011-09-09 20:42:56 -------- d-----w- C:\Users\Kitchen\AppData\Local\{AC30FE29-4677-48F9-8C73-ECAA421DEF3D}
2011-09-09 09:40:49 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F91EBA82-6778-454B-982D-D55766EC3DC0}
2011-09-09 09:40:38 -------- d-----w- C:\Users\Kitchen\AppData\Local\{43FBA57A-9EF1-475C-A0E4-D9FD2C72CE4A}
2011-09-08 22:23:29 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7C9D4AC5-EC60-4038-93E0-71AB2D566F61}
2011-09-08 22:23:18 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F8CB2548-298C-42D7-8400-74722E38D429}
2011-09-08 10:23:09 -------- d-----w- C:\Users\Kitchen\AppData\Local\{BB1D6A8D-5C2A-432A-B45A-5D67C4C775C5}
2011-09-08 10:22:59 -------- d-----w- C:\Users\Kitchen\AppData\Local\{4BEF6CFA-D0A5-4118-8BED-10DAEBC0EECC}
2011-09-07 19:59:48 -------- d-----w- C:\Users\Kitchen\AppData\Local\{0624153A-3848-4E7F-A7A3-3D7A17FD0EA6}
2011-09-07 19:59:37 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6EF46A9E-20DE-49B2-9302-DC04D89F66D7}
2011-09-07 16:05:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{448251DF-6B5E-49FE-911D-FDAD2AA21BF2}
2011-09-07 16:05:20 -------- d-----w- C:\Users\Kitchen\AppData\Local\{B31B6E63-6C65-4CE3-8BA1-3F6995D4D5E0}
2011-09-06 09:26:01 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7BEA8A67-AE0F-4A67-BBE8-33FB6A30F2E4}
2011-09-06 09:25:50 -------- d-----w- C:\Users\Kitchen\AppData\Local\{FE7ED099-68E9-40A7-928D-41F09B2C3619}
2011-09-05 16:12:13 -------- d-----w- C:\Users\Kitchen\AppData\Local\{4B02609B-4051-4AFF-9478-461958026C10}
2011-09-05 16:12:01 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F80BD4E3-44E4-4B3E-BD48-87CE8687FB7C}
2011-09-05 15:02:02 -------- d-----w- C:\Users\Kitchen\AppData\Local\{D4FE376C-0FFA-4FA3-AC0B-CEFAA13AA52C}
2011-09-05 15:01:52 -------- d-----w- C:\Users\Kitchen\AppData\Local\{DACF166C-B6A4-4155-81D7-25B12BC9A8A4}
2011-09-05 13:59:45 -------- d-----w- C:\Users\Kitchen\AppData\Local\{23EBB755-D7F9-4426-993B-29AE58434AD0}
2011-09-05 13:59:32 -------- d-----w- C:\Users\Kitchen\AppData\Local\{410150CC-C8BE-44FD-B9DF-C0E34754F733}
2011-09-04 22:16:32 -------- d-----w- C:\Users\Kitchen\AppData\Local\{B949C1C4-8748-4251-9528-DD30B2FE5CB8}
2011-09-04 22:16:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{90D4706C-7C71-4A21-B7CD-53F94015BFFB}
2011-09-04 13:29:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2BEAE345-0EC4-4E75-B980-043969AE7E96}
2011-09-04 13:29:09 -------- d-----w- C:\Users\Kitchen\AppData\Local\{FEAC0EDE-6F5F-4AD6-B86F-8B95C1546C83}
2011-09-04 04:38:00 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C447A8AF-C3E9-4027-98C2-FE8C7A1369C4}
2011-09-04 04:37:50 -------- d-----w- C:\Users\Kitchen\AppData\Local\{12F5C610-E7EB-4534-B118-79F1D1C9E666}
2011-09-03 18:25:53 -------- d-----w- C:\Users\Kitchen\AppData\Local\{E0BAD6A7-33EF-4C39-8B8B-83F0BEBDE543}
2011-09-03 18:25:42 -------- d-----w- C:\Users\Kitchen\AppData\Local\{87EF6092-BE9B-4B68-BECB-7AE94542F4CB}
2011-09-03 11:36:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{A5430811-C38B-4FA3-A6EF-121BDB48B98A}
2011-09-03 11:36:20 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6BB98251-A265-4CA5-BF4F-53E6BA905E58}
2011-09-03 00:00:33 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F5A34CEE-23B4-41FB-963D-607245BDC6D5}
2011-09-03 00:00:23 -------- d-----w- C:\Users\Kitchen\AppData\Local\{A0B9364F-5660-4C61-95AC-9B4AF15C7B2A}
2011-09-02 11:02:28 -------- d-----w- C:\Users\Kitchen\AppData\Local\{85EDA399-CBAC-48CA-90C5-7CF6C6A6ECBD}
2011-09-02 11:02:18 -------- d-----w- C:\Users\Kitchen\AppData\Local\{11089A2D-4420-4EBC-B6EB-84439CC77A27}
2011-09-02 01:29:17 -------- d-----w- C:\Users\Kitchen\AppData\Local\{385001FB-1148-4809-B53F-525F204D77AD}
2011-09-02 01:29:03 -------- d-----w- C:\Users\Kitchen\AppData\Local\{73C57E32-7101-4201-A8F6-BED0EDAFA62D}
2011-09-01 16:25:23 -------- d-----w- C:\Users\Kitchen\AppData\Local\{511F00FB-501F-4E85-8987-CA1AA3173842}
2011-09-01 16:25:12 -------- d-----w- C:\Users\Kitchen\AppData\Local\{A6401372-D4B3-48DF-8674-B46F736C0AA1}
2011-09-01 13:41:55 -------- d-----w- C:\Users\Kitchen\AppData\Local\{43F83C69-2325-4C0B-8AA0-EE203E6C36A6}
2011-09-01 13:41:44 -------- d-----w- C:\Users\Kitchen\AppData\Local\{592CD5AA-6946-4343-8590-6F692570C50B}
2011-09-01 09:27:29 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6238456E-2F4A-495F-8A4F-83D00C3D5402}
2011-09-01 09:27:18 -------- d-----w- C:\Users\Kitchen\AppData\Local\{1BBF4A5E-30FB-4FBC-88ED-58A7543A84C2}
2011-09-01 00:34:04 -------- d-----w- C:\Users\Kitchen\AppData\Local\{90DAC52C-08E3-44A9-8C1D-066D05DFD4AE}
2011-09-01 00:33:51 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C7AEB78C-A565-4EA9-A70A-353545E1B2FC}
2011-09-01 00:12:12 -------- d-----w- C:\Users\Kitchen\AppData\Local\{36ADAB35-CBC0-473B-ABAF-C126A2AD7298}
2011-09-01 00:11:56 -------- d-----w- C:\Users\Kitchen\AppData\Local\{06BCB312-AD42-44AD-A3A3-9C9660BA9618}
2011-08-31 23:58:19 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7134F83A-5D06-4C3F-8F2B-84750064E96C}
2011-08-31 23:58:04 -------- d-----w- C:\Users\Kitchen\AppData\Local\{74178574-39AF-44B1-AF5D-86A7A97A0748}
2011-08-31 22:57:26 -------- d-----w- C:\Users\Kitchen\AppData\Roaming\SUPERAntiSpyware.com
2011-08-31 22:57:26 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-08-31 22:57:24 -------- d-----w- C:\ProgramData\!SASCORE
2011-08-31 22:57:22 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-08-31 20:25:01 -------- d-----w- C:\Users\Kitchen\AppData\Local\{698CFC06-F8D9-4E3F-9C3F-A0FE2FA0D912}
2011-08-31 20:24:46 -------- d-----w- C:\Users\Kitchen\AppData\Local\{CD44A24D-D1BC-4592-A9DC-A320878591BB}
2011-08-31 14:42:52 -------- d-----w- C:\Users\Kitchen\AppData\Local\{04944734-C0F6-4BC1-AFC7-14519C847578}
2011-08-31 14:42:41 -------- d-----w- C:\Users\Kitchen\AppData\Local\{B33B22B4-691F-4D78-A5BD-172B179D4809}
2011-08-31 11:35:54 -------- d-----w- C:\Users\Kitchen\AppData\Roaming\Malwarebytes
2011-08-31 11:35:46 -------- d-----w- C:\ProgramData\Malwarebytes
2011-08-31 11:35:43 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-08-31 09:22:46 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7C03CAC9-F983-43E8-B76D-D4E002894CAB}
2011-08-31 09:22:33 -------- d-----w- C:\Users\Kitchen\AppData\Local\{E3E8F59A-5088-483C-B429-788BB32443FA}
2011-08-30 21:54:59 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F82A3CF9-C438-41F0-A031-383683E3DAD6}
2011-08-30 21:54:47 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2C763526-EAAF-4AE7-9DC6-C02938EE5007}
2011-08-30 17:49:24 -------- d-----w- C:\Users\Kitchen\AppData\Local\{8F5AD934-0E4A-4C71-BED6-4524C1F4E758}
2011-08-30 17:49:11 -------- d-----w- C:\Users\Kitchen\AppData\Local\{29BA4767-03F4-4F51-AA9C-02318EB31957}
2011-08-30 10:15:07 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F6536AC9-2540-49A1-8409-6C7C346F610A}
2011-08-30 10:14:57 -------- d-----w- C:\Users\Kitchen\AppData\Local\{E5DFA2DB-2674-43C0-8B59-5E1353C11D32}
2011-08-29 20:23:08 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7020C51C-F1E5-4E48-8BFE-1651354C859A}
2011-08-29 20:22:52 -------- d-----w- C:\Users\Kitchen\AppData\Local\{61A4FAF2-410B-4843-8338-454D07ACB627}
2011-08-29 10:51:32 -------- d-----w- C:\Users\Kitchen\AppData\Local\{4423B51E-57E1-42C7-8284-04CC8B98CFF7}
2011-08-29 10:51:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{66C69D22-C812-4888-8ECE-DB27A04D73CD}
2011-08-29 09:25:43 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7A13CAC0-D8AC-42FE-AB3F-999317E89F93}
2011-08-29 09:25:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6D595B89-F0EC-4FF7-9F07-0F0DC1FDEA76}
2011-08-28 13:46:21 737072 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-08-28 13:46:05 4283672 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-08-28 13:45:35 42776 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-08-28 13:45:31 539968 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-08-28 12:58:10 -------- d-----w- C:\Users\Kitchen\AppData\Local\{9CF7D71C-A91A-4BD3-B1CD-3AC02E6913CD}
2011-08-28 12:58:00 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C62F3F0E-E8C6-41E6-B2AA-B5FC93646FF0}
2011-08-28 11:50:02 -------- d-----w- C:\Users\Kitchen\AppData\Local\{74A7C79B-EE88-4D3F-902C-742442288D71}
2011-08-28 11:49:47 -------- d-----w- C:\Users\Kitchen\AppData\Local\{BD436F84-CF79-46DE-A47F-396B7C712C27}
2011-08-27 19:41:24 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7AABE8E8-9B5E-4515-BEA1-C29EED65F74E}
2011-08-27 19:41:14 -------- d-----w- C:\Users\Kitchen\AppData\Local\{626C069B-83D9-40CE-BF68-2F85A5B64077}
2011-08-27 17:09:07 -------- d-----w- C:\Users\Kitchen\AppData\Local\{CC7797BD-B58B-4E94-B538-92986A1F7218}
2011-08-27 17:08:56 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F1949BAB-157E-4BD4-B3B7-CCD687417124}
2011-08-27 13:10:32 -------- d-----w- C:\Users\Kitchen\AppData\Local\{AA9CD27D-C312-4857-8935-051E4D9FCE6C}
2011-08-27 13:10:19 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F5912BCD-BD21-4DB2-9BB9-1C33FEC7B086}
2011-08-26 23:57:15 -------- d-----w- C:\Users\Kitchen\AppData\Local\{4EBD37E7-C484-4746-A15A-81F89653618C}
2011-08-26 23:57:04 -------- d-----w- C:\Users\Kitchen\AppData\Local\{440FD8AE-BCA3-492B-B328-DC1435E6FEAB}
2011-08-26 11:51:25 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C01F4563-D2A8-49B8-AA2B-8FFE1C531B96}
2011-08-26 11:51:15 -------- d-----w- C:\Users\Kitchen\AppData\Local\{53754CA0-4F5A-4825-9006-7BC1A3B3261F}
2011-08-26 09:53:06 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C8EBDF02-6CD7-4E8D-A2A5-9EB51D82D089}
2011-08-26 09:52:54 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2B566AF0-DF17-4C1C-A9D9-F2D21FFA6749}
2011-08-25 19:43:24 -------- d-----w- C:\Users\Kitchen\AppData\Local\{ABECF4DC-FD6D-47D6-A74C-40CB604B7402}
2011-08-25 19:43:13 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F6ED4119-1890-4B23-8BA7-F0E59CDA71F4}
2011-08-25 17:24:02 -------- d-----w- C:\Users\Kitchen\AppData\Local\{22479C81-65FB-404F-9B8A-33140044026B}
2011-08-25 17:23:51 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C63B4838-9FBD-4F98-B80C-5424C060F2F4}
2011-08-25 15:19:34 -------- d-----w- C:\Users\Kitchen\AppData\Local\{815E7B54-EB90-4913-A744-C77B5E9D1983}
2011-08-25 15:19:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3690BF37-D843-4C79-BCA3-9090998A5476}
2011-08-25 10:26:57 -------- d-----w- C:\Users\Kitchen\AppData\Local\{73E02199-DE07-4789-9D2B-1C35546AA846}
2011-08-25 10:26:45 -------- d-----w- C:\Users\Kitchen\AppData\Local\{8E13D40A-AC29-49DE-89BA-509D99BC2CDA}
2011-08-24 20:01:35 -------- d-----w- C:\Users\Kitchen\AppData\Local\{773B646E-9BB2-4263-B45B-030A65F50E63}
2011-08-24 20:01:25 -------- d-----w- C:\Users\Kitchen\AppData\Local\{297A2959-FC5C-42C5-BEBC-250D0624FE64}
2011-08-24 14:43:42 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2235DC5F-0915-4785-8B8E-49ED0F04C26F}
2011-08-24 14:43:28 -------- d-----w- C:\Users\Kitchen\AppData\Local\{F61A181F-4E4B-41D8-A647-2FFC81CC0E8D}
2011-08-24 09:33:31 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C6E3EACF-039B-4018-A0C1-7776AD032C66}
2011-08-24 09:33:18 -------- d-----w- C:\Users\Kitchen\AppData\Local\{09906FF8-A5F3-4BF4-92EA-FC2A9E82DCDB}
2011-08-23 21:51:56 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-23 21:51:56 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-23 16:03:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7F524CA8-A3CD-4972-8AB8-D91C40366392}
2011-08-23 16:03:13 -------- d-----w- C:\Users\Kitchen\AppData\Local\{EC2E658D-67C9-41A0-A1BF-2DA357D4A047}
2011-08-22 21:11:33 -------- d-----w- C:\Users\Kitchen\AppData\Local\{0C1E29C3-38D3-4DD8-8DE0-502F8D574E6A}
2011-08-22 21:11:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{BEDE1111-5D8E-4B4D-9FEA-89FB88FE287B}
2011-08-21 18:45:35 -------- d-----w- C:\Users\Kitchen\AppData\Local\{D4CB3BBB-8D21-40DB-848C-5DBBA675218E}
2011-08-21 18:45:21 -------- d-----w- C:\Users\Kitchen\AppData\Local\{65CAC135-5FAA-4E5D-8A77-BD0EDACEE868}
2011-08-21 12:02:12 -------- d-----w- C:\Users\Kitchen\AppData\Local\{AB26F099-FEF7-4D49-A324-9C7DC062D0F7}
2011-08-21 12:02:02 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7DE7733E-A422-4B05-BCEE-AB8DC01D1E3D}
2011-08-20 18:06:19 -------- d-----w- C:\Users\Kitchen\AppData\Local\{7A5E5945-F7D6-4C1E-A54B-A5171C2A4EC3}
2011-08-20 18:06:05 -------- d-----w- C:\Users\Kitchen\AppData\Local\{441885E1-1F88-43EE-A5E9-CDB822353C4B}
2011-08-20 12:53:55 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3F3D5560-87DF-4273-B349-F3F4BC577C4E}
2011-08-20 12:53:38 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3D9199FD-781F-4E18-A0CB-F09D1E821E33}
2011-08-19 20:24:46 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2990F9B2-5EE9-4D88-9E48-E3B8696E26C5}
2011-08-19 20:24:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{1C0019A3-5AF4-41D4-AAD2-B729AA368948}
2011-08-18 20:25:54 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C0BACF14-E9CE-4036-9F35-6A0665C2F9E7}
2011-08-18 20:25:42 -------- d-----w- C:\Users\Kitchen\AppData\Local\{6DAE6AE4-80D9-414B-8B0D-D09C973B35F4}
2011-08-18 16:25:59 -------- d-----w- C:\Users\Kitchen\AppData\Local\{89C9CA89-7497-49D4-87F7-7350B1469285}
2011-08-18 16:25:48 -------- d-----w- C:\Users\Kitchen\AppData\Local\{FD396A28-3C02-4FAF-BE25-04EA40D80B73}
2011-08-18 09:29:41 -------- d-----w- C:\Users\Kitchen\AppData\Local\{CC3595AC-CCB2-4C3F-BFDA-6A35CDF2D2DF}
2011-08-18 09:29:28 -------- d-----w- C:\Users\Kitchen\AppData\Local\{58FA8601-BA55-4E58-9C02-43E52E9CCEDE}
2011-08-17 20:12:05 -------- d-----w- C:\Users\Kitchen\AppData\Local\{710BE211-19CF-44C2-8F5B-6F0D7B5EF74A}
2011-08-17 20:11:52 -------- d-----w- C:\Users\Kitchen\AppData\Local\{63DF8877-4198-4FCE-B3CA-D6249D535334}
2011-08-17 11:44:44 -------- d-----w- C:\Users\Kitchen\AppData\Local\{97EED021-7E85-4154-82AD-8680BB0D428E}
2011-08-17 11:44:30 -------- d-----w- C:\Users\Kitchen\AppData\Local\{234DAC90-FA05-4341-837D-D09486F4A154}
2011-08-17 09:21:58 -------- d-----w- C:\Users\Kitchen\AppData\Local\{C1C19DD9-ABE9-44CA-AE60-44FFAFC37D0D}
2011-08-17 09:21:48 -------- d-----w- C:\Users\Kitchen\AppData\Local\{DE070627-5F58-455F-A559-5BC174DA21CC}
2011-08-16 17:29:59 -------- d-----w- C:\Users\Kitchen\AppData\Local\{292DA24A-323A-4F6E-AABD-95141B666A6A}
2011-08-16 17:29:49 -------- d-----w- C:\Users\Kitchen\AppData\Local\{39DFB76B-2028-4231-ADA2-C66E13DE5807}
2011-08-16 13:31:40 -------- d-----w- C:\Users\Kitchen\AppData\Local\{5EC60153-007F-4C1F-926B-766F651FD667}
2011-08-16 13:31:25 -------- d-----w- C:\Users\Kitchen\AppData\Local\{ED20AE7A-2752-4536-BA3B-2A4A0A4D65D4}
2011-08-16 09:54:51 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-08-16 09:52:23 -------- d-----w- C:\Users\Kitchen\AppData\Local\{51D3F87D-52C1-4563-9F81-433ED025C386}
2011-08-16 09:52:12 -------- d-----w- C:\Users\Kitchen\AppData\Local\{A2B643E2-513A-423A-926D-BABBA4ACFB27}
2011-08-15 23:30:59 -------- d-----w- C:\Users\Kitchen\AppData\Local\{ED56AC6D-A0F9-4B3D-B854-F1D1F7291ABB}
2011-08-15 23:30:49 -------- d-----w- C:\Users\Kitchen\AppData\Local\{98EA5A13-CB28-44C4-A5BE-BDF072A0EB2A}
2011-08-15 23:30:06 -------- d-----w- C:\Users\Kitchen\AppData\Local\{A236DE3D-EBC2-430C-A077-CAE7D4C106D5}
2011-08-15 23:29:56 -------- d-----w- C:\Users\Kitchen\AppData\Local\{64167995-1EA8-4D7F-87BE-CC1B3DE51B6F}
2011-08-15 20:40:16 -------- d-----w- C:\Users\Kitchen\AppData\Local\{116F6D23-AA13-4E40-BE7C-EAECFDC7CCFA}
2011-08-15 20:40:03 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3CD40A6A-A2D3-4D2A-A8BE-7E8F71B23E89}
2011-08-15 11:41:27 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3E25CF5B-EB8F-4F07-B357-DD79BE481337}
2011-08-15 11:41:15 -------- d-----w- C:\Users\Kitchen\AppData\Local\{2C6D2561-A417-4678-88DB-C25C1B516064}
2011-08-15 09:41:57 -------- d-----w- C:\Users\Kitchen\AppData\Local\{3586BCF7-E408-4A19-B8C7-F295056F6258}
2011-08-15 09:41:46 -------- d-----w- C:\Users\Kitchen\AppData\Local\{ACBE5571-B7B0-428A-B83E-AF355DDEE110}
.
==================== Find3M ====================
.
2011-08-17 09:22:06 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 16:33:38 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-07-16 16:33:37 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
============= FINISH: 21:37:36.25 ===============

HAHA! I managed to stop my antispyware on the file name.

C:\Users\Kitchen\App Data\Roaming\Microsoft\Internet Explorer\Quick Launch\VirusTrigger2.1.lnk

Also, it keeps trying to change IE's homepage whenever the computer boots up. I've got it set to notify me if anything attempts to change the homepage but one of the humans, and I've blocked it everytime. Other than that though, it hasn't done anything.

I can still search for ways to remove this thing, and so far, nothing weird has happened.

Also, when I first realized something was up, I immediately shut the computer down. When I booted it back up, the computer notified me something went wrong and I tried to do system repair/ system restore. That didn't seem to do anything, but when I rebooted everything back up, nothing seemed to be wrong. I than ran antispyware software (I thought I had gotten hacked) which is where I spotted the virus trigger 2.1 file.

Blade81
2011-09-23, 10:36
Hi,

If help still needed post fresh dds logs, please.

Blade81
2011-09-28, 06:52
Due to inactivity, this thread will now be closed.

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.