womble
2011-12-13, 01:37
Hi,
Spybot finds but cannot remove Microsoft.Windows.RedirectedHosts and Fraud.Windows.ProtectionSuite
I have run MalwareBytes and it did not find anything.
Cheers
Alex
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_30
Run by Kathie at 18:14:56 on 2011-12-12
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.3999.2407 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\ProgramData\Clickfree\HDDV2USB3\UACProxy.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\ProgramData\Clickfree\HDDV2USB3\reminder\SacReminder.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_CA&c=94&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_CA&c=94&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_CA&c=94&bd=Pavilion&pf=cnnb
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [SacReminderHDDV2] C:\ProgramData\Clickfree\HDDV2USB3\reminder\SacReminder.exe
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Kathie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
uPolicies-explorer: DisallowRun = 1 (0x1)
uPolicies-system: WallpaperStyle = 2
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 207.164.234.193 207.164.234.129
TCP: Interfaces\{C5BC8390-B45F-474A-B33A-5549C62205D4} : DhcpNameServer = 207.164.234.193 207.164.234.129
TCP: Interfaces\{C5BC8390-B45F-474A-B33A-5549C62205D4}\E6F6D6F627567796275637 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{E7EAA283-14ED-403A-BFF6-561E2637DBB4} : DhcpNameServer = 192.168.0.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
IFEO: image file execution options - svchost.exe
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
IFEO-X64: image file execution options - svchost.exe
Hosts: 74.125.45.100 4-open-davinci.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 getantivirusplusnow.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Kathie\AppData\Roaming\Mozilla\Firefox\Profiles\1b950fcb.default\
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-8-18 7390560]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
R2 CFUACProxy_hddv2usb3;CFUACProxy_hddv2usb3;C:\ProgramData\Clickfree\HDDV2USB3\UACProxy.exe [2011-4-14 83792]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-11 1153368]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-8-21 227896]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys --> C:\Windows\system32\drivers\IntcHdmi.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-11-22 517448]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2011-12-12 23:13:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{A75D3F95-6A88-4640-BBD5-5326D0CDDD81}
2011-12-12 23:12:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{89767B68-AD6D-47AA-8C5F-E882FA34E974}
2011-12-12 21:52:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{77CE178B-4B84-4F78-994F-37AB4B909FF7}
2011-12-12 21:52:32 -------- d-----w- C:\Users\Kathie\AppData\Local\{0AAF965D-C8FB-4B80-9123-A6A0B4CDCBDD}
2011-12-10 22:35:14 -------- d-----w- C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
2011-12-10 22:32:51 -------- d-----w- C:\Program Files\CCleaner
2011-12-10 22:18:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{023C6E61-532D-4641-81FC-705C60E91011}
2011-12-09 16:32:56 -------- d-----w- C:\Users\Kathie\AppData\Local\{450F7D98-9159-4C18-BE79-8D804FD85D65}
2011-12-09 16:32:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{22307D9E-F8C2-43A6-9458-EBD9149D5628}
2011-12-09 15:39:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{72E58DF3-6EE2-4050-BA27-091DE906F487}
2011-12-09 15:39:40 -------- d-----w- C:\Users\Kathie\AppData\Local\{A1E0C00D-49CE-4695-8435-3DD460202A50}
2011-12-09 15:36:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{51A50125-7F36-4403-9749-A760DEAD6FD0}
2011-12-09 15:36:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{3D3BABC5-5103-4904-8CEE-DAD27B620A2F}
2011-12-09 14:44:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{CDDB2CA8-8B5F-4A3A-B5BA-0D907E95BC73}
2011-12-09 14:44:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{17601612-36C4-48B7-91A7-28ED90D34C9C}
2011-12-09 14:34:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{5AB40E53-B2E7-48FD-BA58-CEC8961DA6DF}
2011-12-09 14:34:38 -------- d-----w- C:\Users\Kathie\AppData\Local\{2A2A2287-9CB5-4361-B2CB-5B5C5607FAC7}
2011-12-09 14:31:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{7001276F-409C-458F-9854-9C028D57F3E6}
2011-12-09 14:30:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{320312F1-7883-455F-B9B7-73AD279755A3}
2011-12-09 04:51:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{7EE235D6-64A8-4F8A-9B22-B6EA80FD1174}
2011-12-09 04:51:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{84EF98DC-2CAC-44B2-AE9A-02EF3A6ADE53}
2011-12-09 04:36:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{0D755FCC-679B-42E9-8D04-1E0526161F49}
2011-12-09 04:36:33 -------- d-----w- C:\Users\Kathie\AppData\Local\{9F978E04-4418-434A-8E21-6E864AA4533F}
2011-12-09 04:16:29 -------- d-----w- C:\Users\Kathie\AppData\Local\{CF7ABF91-7D26-4673-84D3-7BD29BC3E8C2}
2011-12-09 04:16:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{5CF77BB4-27F8-44CE-9985-37A0580F9210}
2011-12-09 03:07:50 -------- d-----w- C:\Users\Kathie\AppData\Local\{BBFC937A-2E66-44BD-A398-41D65659A367}
2011-12-09 03:07:35 -------- d-----w- C:\Users\Kathie\AppData\Local\{3AE734B8-73B5-4043-9B9F-640D24534684}
2011-12-08 19:22:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{217733F6-9FFB-4565-9ACA-FD25763359BD}
2011-12-08 19:22:39 -------- d-----w- C:\Users\Kathie\AppData\Local\{78128607-A530-480E-AAC8-C6852BB6914F}
2011-12-07 23:08:24 -------- d-----w- C:\Users\Kathie\AppData\Local\{43F6DD77-CCBB-423E-BAA5-FEF55D2252F3}
2011-12-07 23:08:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{632ADA3C-9F9F-419C-B40E-DDFC1C570853}
2011-12-07 21:57:09 -------- d-----w- C:\Users\Kathie\AppData\Local\{9A0F9709-0119-4DA6-97E6-D012BA54AA99}
2011-12-07 21:56:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{AC968916-73D1-49C0-B2C5-C4B1CA37B51B}
2011-12-07 17:08:20 -------- d-----w- C:\Users\Kathie\AppData\Local\{B19E5CF8-DD7D-4AAE-A7A6-C64428688361}
2011-12-07 17:08:05 -------- d-----w- C:\Users\Kathie\AppData\Local\{0AE421BA-C77C-4DC8-9221-CD7CA68A3D04}
2011-12-07 16:54:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{291231F9-6AE9-4C25-BFDE-BC8D2DA5FEAF}
2011-12-07 16:53:57 -------- d-----w- C:\Users\Kathie\AppData\Local\{C0B64FE7-A843-442A-8D6A-B27B651E7584}
2011-12-07 16:09:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{42A94201-467B-4E10-B55A-5137064AA5FF}
2011-12-07 16:09:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{0400C205-475C-4B8F-B826-6BFC32507A99}
2011-12-07 15:51:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{5384E053-C875-406F-B4E2-B50907010A30}
2011-12-07 15:50:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{E7BD2639-EAEF-45D1-B8F0-296DC89092DB}
2011-12-07 03:55:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{A39D7C8B-C80C-475D-8C5F-11C8F9E177A4}
2011-12-07 03:54:56 -------- d-----w- C:\Users\Kathie\AppData\Local\{B1C51B52-8030-4EF4-B574-ACA27BEE5C41}
2011-12-06 15:30:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{9C27A182-3D34-4580-9DE6-69ED4CAC06ED}
2011-12-06 15:30:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{345ED00A-DB19-4C1F-B753-28D06AA1C1DF}
2011-12-06 15:12:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{E373F822-6DD8-4AE6-813F-F2840C52228A}
2011-12-06 15:12:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{11C0DD6B-A173-4334-8A7D-44216DF9F868}
2011-12-06 15:07:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{7A516B4B-A1D1-429E-88CC-CF16603B3D0E}
2011-12-06 15:07:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{1B5AC597-7F04-46E9-B763-6CE9BFF92AAB}
2011-12-06 14:50:29 -------- d-----w- C:\Users\Kathie\AppData\Local\{8013957C-0F89-4CBB-92D9-A922C66A0248}
2011-12-06 14:50:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{2A5AA366-B5E4-4521-8335-1F931D072282}
2011-12-06 14:15:57 -------- d-----w- C:\Users\Kathie\AppData\Local\{17A7AA2C-1B92-4A50-AFD1-1104C6F73392}
2011-12-06 14:15:46 -------- d-----w- C:\Users\Kathie\AppData\Local\{1309A731-5AB4-4162-B5C4-1B16C1315ED5}
2011-12-06 05:07:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{64C61BB0-C0DA-43A1-9B9F-088EF00D9915}
2011-12-06 05:07:06 -------- d-----w- C:\Users\Kathie\AppData\Local\{A79DCD66-CCE7-41C4-8979-EC1922C46B02}
2011-12-06 04:50:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{EEADF6C0-AADA-4CD8-8834-251EF1E680A7}
2011-12-06 04:50:42 -------- d-----w- C:\Users\Kathie\AppData\Local\{D6DDE5E1-11E6-488C-95AE-8FAC64538AC4}
2011-12-05 23:14:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{730DC85F-A1CF-4B03-93F9-D18B8CB9666B}
2011-12-05 23:14:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{1BFB432E-74D2-4D02-9612-50631BB55951}
2011-12-05 22:57:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{34559E18-F04F-4C75-A5AB-5D060A2691BC}
2011-12-05 22:57:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{BFA30C6C-4163-495A-B8FE-F8D0FB9250DC}
2011-12-05 21:54:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{1D67E896-0ED5-4B48-9739-046143DE1992}
2011-12-05 21:53:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{C55AB930-9995-43FE-BA74-114CCF519E81}
2011-12-05 20:47:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{88DD116F-F492-4B1E-8C7C-30CB7538662F}
2011-12-05 20:46:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{05D8BF1B-88BD-4808-B467-9B0C34041A04}
2011-12-05 20:18:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{6029A32B-A1CE-470D-912D-32094859550C}
2011-12-05 20:18:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{BA884EC3-36BF-414D-B46D-E894F12B1194}
2011-12-05 06:26:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{13ECE90F-96F1-4256-BD2B-F20AA6EA2615}
2011-12-05 06:26:32 -------- d-----w- C:\Users\Kathie\AppData\Local\{F632442D-7C2F-45CF-A254-9ABF5C5CF7E5}
2011-12-05 05:19:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{AD5D0785-04C9-422D-8374-2DAD375A1183}
2011-12-05 05:19:38 -------- d-----w- C:\Users\Kathie\AppData\Local\{4FA08D46-112B-4743-A512-56DF30DC5BF8}
2011-12-05 02:15:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{0193DCDC-02AB-4B9F-A877-FC580D26D139}
2011-12-05 02:14:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{87F035E9-9AC2-4FEC-9285-D302E7659BB6}
2011-12-05 00:24:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{CF5EB042-2565-4A89-91ED-A0EB0F6D103C}
2011-12-05 00:23:54 -------- d-----w- C:\Users\Kathie\AppData\Local\{BCD771E6-D579-4CF4-A89D-E466FF73EC78}
2011-12-04 21:52:42 -------- d-----w- C:\Users\Kathie\AppData\Local\{C535D99B-F77A-4586-87D0-57862BF82E51}
2011-12-04 21:52:28 -------- d-----w- C:\Users\Kathie\AppData\Local\{62248A99-E7B6-4F31-A356-B5D5021BAC40}
2011-12-03 02:50:20 -------- d-----w- C:\Users\Kathie\AppData\Local\{91BCB7B8-F1EB-49B4-8489-18B74D61F5CF}
2011-12-03 02:50:09 -------- d-----w- C:\Users\Kathie\AppData\Local\{2FEE6B09-61B6-4BDC-8784-A7C76F9A70C9}
2011-12-02 00:15:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{08D58AF9-42BF-4DAC-871C-128EE97EE5AA}
2011-12-02 00:15:43 -------- d-----w- C:\Users\Kathie\AppData\Local\{F5E23578-CCE6-470A-A189-8320B697B60E}
2011-12-01 18:39:50 -------- d-----w- C:\Users\Kathie\AppData\Local\{5F6F2D66-DB20-4702-8E9D-1D3D0D6C597E}
2011-12-01 18:39:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{1B010E0E-DAA9-4ED0-A564-5E783856A6C5}
2011-12-01 14:24:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{33A941C2-685E-4C0D-9F31-049CEC3EC597}
2011-12-01 14:24:43 -------- d-----w- C:\Users\Kathie\AppData\Local\{26F3E38C-63E0-430E-8B75-5580433C6973}
2011-11-30 18:15:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{F31B93BC-241F-4F75-A1DD-7F98085C9EC7}
2011-11-30 18:15:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{B3ABED28-A90D-43D5-8F46-6A820672553D}
2011-11-30 17:22:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4A12574-6CA7-4D2B-A051-4A1331FE1CEB}
2011-11-30 17:22:04 -------- d-----w- C:\Users\Kathie\AppData\Local\{23FBC25C-E77D-46D2-A74C-42B1D378A490}
2011-11-30 15:18:31 -------- d-----w- C:\Users\Kathie\AppData\Local\{BFBEC189-74F9-44E9-B00E-7DB0AF0256F4}
2011-11-30 15:18:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{C0CBE688-4C18-4E9F-9EC1-051C8C24D0C8}
2011-11-30 01:34:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{884A451F-18A6-453B-BE04-290CB9542511}
2011-11-30 01:34:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{A6C4F515-96D5-4DE7-A3BA-0A763755626F}
2011-11-29 21:31:04 -------- d-----w- C:\Users\Kathie\AppData\Local\{0D493F3A-6005-448A-BE49-EBA99106C5F4}
2011-11-29 21:30:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{97F18D61-C555-470B-AE84-6BB8C398989E}
2011-11-29 21:17:46 -------- d-----w- C:\Users\Kathie\AppData\Local\{29F04B1E-8496-425C-9EBE-8D84E089FAF1}
2011-11-29 21:17:35 -------- d-----w- C:\Users\Kathie\AppData\Local\{2667CEE5-0E80-4CAA-B26F-0169603894B2}
2011-11-29 19:32:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{4D7BC681-70C0-411F-A8B2-EE446A299779}
2011-11-29 19:31:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{83A3583C-E945-4BDD-BF3E-D241F4AB9F46}
2011-11-29 15:23:40 -------- d-----w- C:\Users\Kathie\AppData\Local\{E64DFD34-4E16-443B-8CE3-9AC7CFB4B83C}
2011-11-29 15:23:28 -------- d-----w- C:\Users\Kathie\AppData\Local\{8748B5F1-D5B5-4E6F-98BB-56E2378D705B}
2011-11-29 15:12:23 -------- d-----w- C:\Users\Kathie\AppData\Local\{D4FA95E1-4BF6-44E5-B7D9-7647DDC4C1E1}
2011-11-29 15:12:13 -------- d-----w- C:\Users\Kathie\AppData\Local\{0D82E1D6-87B1-4557-9C2E-05919AED84C7}
2011-11-29 13:49:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4B15C21-93D2-456A-BAEA-B8045F56A71B}
2011-11-29 13:49:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{A59132D4-9150-4304-A957-C38D1B795253}
2011-11-29 05:43:04 -------- d-----w- C:\Users\Kathie\AppData\Local\{CDAA8332-E852-4E80-B79D-4D505C5219C0}
2011-11-29 05:42:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{7C2C1311-E590-443B-AF1A-9D00EB4453E2}
2011-11-28 21:26:31 -------- d-----w- C:\Users\Kathie\AppData\Local\{BB6160D4-FF4C-4915-853C-17E7AE3F6B3A}
2011-11-28 21:26:20 -------- d-----w- C:\Users\Kathie\AppData\Local\{6C30E465-6630-44B4-930F-EA05FB80D420}
2011-11-28 13:46:25 -------- d-----w- C:\Users\Kathie\AppData\Local\{ACE3D8D5-5D47-4152-AECC-052A5AE99C4F}
2011-11-28 13:46:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{7C211AF9-2B5C-451D-A324-1CDD30BE133D}
2011-11-28 01:10:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{D1B425AC-0120-4913-86B3-698A360874F0}
2011-11-28 01:10:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{1586DBE7-FC4F-4FB9-9629-AA24997D4D64}
2011-11-27 05:35:34 -------- d-----w- C:\Users\Kathie\AppData\Local\{AB2D1940-919E-45B1-9B2E-CB8E401270C3}
2011-11-27 05:35:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{32A3B90A-D68A-46DA-BCCB-732D7B6698EA}
2011-11-27 02:00:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{BAC94C35-0EEB-4D53-A26C-9E0539220604}
2011-11-27 02:00:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{F8515D2D-1B04-4A6B-AA18-F004997E0E82}
2011-11-25 13:01:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{6FC6454B-DF86-4855-87DA-0746D498AD97}
2011-11-25 13:00:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{8FA3B695-3E9E-4001-ACE7-88E68BA05E9B}
2011-11-24 16:44:27 -------- d-----w- C:\Users\Kathie\AppData\Local\{A205CCBD-F221-48EA-BBDE-441D5E29769B}
2011-11-24 16:44:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{7E2CF4C6-F4BB-488A-96D1-F463619121DF}
2011-11-24 16:33:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{1680A03A-A475-4961-8E74-B1E363D28C99}
2011-11-24 16:33:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{EBAD4862-9430-40DE-9E66-C91187BDF460}
2011-11-24 03:18:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{E361426D-3954-41DC-B187-56A31611C1D6}
2011-11-24 03:18:47 -------- d-----w- C:\Users\Kathie\AppData\Local\{E36EF0C2-B2D6-474E-BD8D-0A9AC09CC888}
2011-11-24 00:58:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{4E5033B0-D24E-422B-A80B-AC9D66E044E8}
2011-11-24 00:58:31 -------- d-----w- C:\Users\Kathie\AppData\Local\{F0A3A42D-5910-4415-BAD8-C3A5E789B4A2}
2011-11-22 22:11:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{4DE0A5A2-638F-4918-AAA8-BF5293EDE3EE}
2011-11-22 22:11:34 -------- d-----w- C:\Users\Kathie\AppData\Local\{659E6BB9-1988-4EB0-978E-4D704B82DD94}
2011-11-22 15:42:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{C17495F7-EA00-48FA-B6A3-4D3BD014940E}
2011-11-22 15:42:07 -------- d-----w- C:\Users\Kathie\AppData\Local\{8F1664D1-7BF8-4B19-92BD-E810EC8CA16E}
2011-11-22 05:38:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{61F07B05-6C76-4216-8028-4D910C8BB3CF}
2011-11-22 05:38:46 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4F3DBCB-562C-490C-9098-2421B907E566}
2011-11-22 05:17:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{10D43195-D23B-4F8B-84EE-732BFBACE811}
2011-11-22 05:17:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{C703102B-317B-4F2C-AAC7-4E0FF17BD348}
2011-11-22 04:53:23 -------- d-----w- C:\Users\Kathie\AppData\Local\{1BA28B04-A150-41B6-98A7-9E6D2F5AA36D}
2011-11-22 04:53:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{61270267-2512-4AE1-AEB4-E3912A27AF8A}
2011-11-21 23:00:35 -------- d-----w- C:\Users\Kathie\AppData\Local\{A733A1C0-CD46-40BF-8DDA-C2977EF48577}
2011-11-21 23:00:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{34008902-6161-4C78-A3F0-74AB081FC5C6}
2011-11-21 20:05:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{79E80520-AA8E-467C-99A4-9794FE39F557}
2011-11-21 20:04:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{469FE05B-CF71-4DC6-98D2-4256C1AA8DBD}
2011-11-21 03:22:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{D03A5F24-E7E7-41D5-9B58-AAB4F0E64B40}
2011-11-21 03:22:05 -------- d-----w- C:\Users\Kathie\AppData\Local\{2F26DFD1-E836-4128-B4BB-BFFB30053A84}
2011-11-21 02:06:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{D369BFEA-1C49-47FA-BC13-213D2AC06B27}
2011-11-21 02:06:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{031F9EAD-12D5-49F7-96B0-A71A527175A8}
2011-11-20 22:24:24 -------- d-----w- C:\Users\Kathie\AppData\Local\{22CAECAB-10DF-48BD-AEB7-90629E91CD3A}
2011-11-20 22:24:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{0FB5A3D0-C123-4577-94FD-CB17CB4FE47E}
2011-11-19 19:30:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{0B63D4DF-B7B9-4F62-9A3C-59848411DF71}
2011-11-19 19:30:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4C24ECB-8EDE-43BF-9A17-ABB3662FC7E6}
2011-11-19 15:07:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{DAE88209-60F4-4D45-9C68-B4AC6655C7C3}
2011-11-19 15:07:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{33D6A28D-3EB1-4466-82EB-C2DB5A19F15E}
2011-11-19 05:20:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{E1B9FD9F-9DBD-405E-A44F-FA1E8932FD6F}
2011-11-19 05:20:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{3AAE152F-A442-4A0B-BAA4-4B49FD58DA4A}
2011-11-18 21:37:18 -------- d-----w- C:\Users\Kathie\AppData\Local\{8DF097E0-615B-4F74-A999-F072A9CD1ED3}
2011-11-18 21:37:07 -------- d-----w- C:\Users\Kathie\AppData\Local\{8521FCAC-2943-4D9F-B259-1D939CF30A5B}
2011-11-18 18:15:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{DCD77134-DE6A-4F8A-A6EA-DF87E88E46D9}
2011-11-18 18:15:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{0203BE57-D700-408F-8AF1-7D877A49E5CE}
2011-11-18 15:56:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{3D5D86A1-F16E-480E-912D-92378BF2B81A}
2011-11-18 15:56:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{22F7677D-4106-40E7-B1AA-B1FFB5FA7D2B}
2011-11-18 14:13:07 -------- d-----w- C:\Users\Kathie\AppData\Local\{4AE1DF2E-4D95-49C0-BEF8-762179BFD880}
2011-11-18 14:12:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{E5A78A5C-FC4A-4EF9-88B7-FCF8509A3481}
2011-11-18 04:00:39 -------- d-----w- C:\Users\Kathie\AppData\Local\{A7F83F1A-D976-4024-BB73-18F47F42A96C}
2011-11-18 04:00:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{73232BED-B6DD-4CD8-8258-5BACB023C443}
2011-11-18 01:08:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{718E36AA-4FF8-4CC5-8B89-0BA8A452CA34}
2011-11-18 01:08:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{47B063F3-AAF5-4DA2-8404-77C0C7392605}
2011-11-17 20:38:13 -------- d-----w- C:\Users\Kathie\AppData\Local\{84024590-539F-4ABB-92C7-9D42E2AA8B93}
2011-11-17 20:38:00 -------- d-----w- C:\Users\Kathie\AppData\Local\{A2073432-6C08-453D-9C7D-B36F71B1AA3F}
2011-11-16 02:51:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{AE855A96-179C-4E80-A4D7-82B242F00043}
2011-11-16 02:51:18 -------- d-----w- C:\Users\Kathie\AppData\Local\{299A0D50-74EE-4C79-94F7-1A91A6A2D189}
2011-11-16 00:38:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{C9101548-0CB0-48C0-92BF-E0FEECC24527}
2011-11-16 00:38:34 -------- d-----w- C:\Users\Kathie\AppData\Local\{A589F84B-9477-4807-9114-1631F775B268}
2011-11-15 22:14:50 -------- d-----w- C:\Users\Kathie\AppData\Local\{A1E1BFBD-FCCC-404A-8136-10B86C383BAA}
2011-11-15 22:14:38 -------- d-----w- C:\Users\Kathie\AppData\Local\{2DC6EC73-FDF3-4795-AD1D-7A6D2BB1B3C5}
2011-11-15 19:30:49 -------- d-----w- C:\Users\Kathie\AppData\Local\{FB157507-A870-4111-AF3A-E3A82EFBEFFB}
2011-11-15 19:30:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{93D50DBD-A040-42A3-AA6A-96302CBF93C7}
2011-11-15 15:42:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{432457CF-AEB8-4028-B754-579319072469}
2011-11-15 15:42:01 -------- d-----w- C:\Users\Kathie\AppData\Local\{F1F09580-0D9E-4AB8-BBFA-2A3569038A90}
2011-11-15 14:45:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{FF18F52D-4EEC-4887-A2B9-22CFCCDA3B75}
2011-11-15 14:44:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{1BCC0F70-3269-434A-A374-FBA821C6451D}
2011-11-15 04:31:54 -------- d-----w- C:\Users\Kathie\AppData\Local\{7881EC81-2DEC-4B04-ACE6-7C6A2260EC08}
2011-11-15 04:31:40 -------- d-----w- C:\Users\Kathie\AppData\Local\{205EDF1E-01F9-4B84-A845-9BC827940330}
2011-11-15 03:29:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{DA8B7643-7DF0-44D0-B9E5-6BF67AAD4B27}
2011-11-15 03:29:01 -------- d-----w- C:\Users\Kathie\AppData\Local\{D4EA85AA-DADF-4D9F-B9E1-0ECF0C3F18FE}
2011-11-14 20:51:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{CC5591A0-4C6A-455D-93B2-F74923EFCC27}
2011-11-14 20:51:05 -------- d-----w- C:\Users\Kathie\AppData\Local\{65FD3B5A-529F-42F7-B823-D1A3AABB5E89}
2011-11-14 16:40:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{38FA71A5-3AA8-4E9D-8618-381607ABB432}
2011-11-14 16:40:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{4E54712A-9D73-40CE-9976-85EF78B504D1}
2011-11-14 13:01:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{DA72CA6C-8C3E-4B77-9C63-BEBCC11444EB}
2011-11-14 13:01:09 -------- d-----w- C:\Users\Kathie\AppData\Local\{2F0653F7-60E0-45A4-BD63-E7DB8E5BE21A}
.
==================== Find3M ====================
.
2011-11-10 10:54:13 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-09-29 16:24:44 1897328 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-09-29 04:09:30 3141120 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 18:16:45.76 ===============
Spybot finds but cannot remove Microsoft.Windows.RedirectedHosts and Fraud.Windows.ProtectionSuite
I have run MalwareBytes and it did not find anything.
Cheers
Alex
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_30
Run by Kathie at 18:14:56 on 2011-12-12
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.2.1033.18.3999.2407 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG10\avgchsva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
C:\ProgramData\Clickfree\HDDV2USB3\UACProxy.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
C:\Program Files (x86)\AVG\AVG10\avgemca.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\ProgramData\Clickfree\HDDV2USB3\reminder\SacReminder.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\HP\QuickPlay\QPService.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files (x86)\AVG\AVG10\avgtray.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\PROGRA~2\AVG\AVG10\avgrsa.exe
C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_CA&c=94&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_CA&c=94&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_CA&c=94&bd=Pavilion&pf=cnnb
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
uRun: [SacReminderHDDV2] C:\ProgramData\Clickfree\HDDV2USB3\reminder\SacReminder.exe
mRun: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Kathie\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
uPolicies-explorer: DisallowRun = 1 (0x1)
uPolicies-system: WallpaperStyle = 2
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-system: WallpaperStyle = 2
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
TCP: DhcpNameServer = 207.164.234.193 207.164.234.129
TCP: Interfaces\{C5BC8390-B45F-474A-B33A-5549C62205D4} : DhcpNameServer = 207.164.234.193 207.164.234.129
TCP: Interfaces\{C5BC8390-B45F-474A-B33A-5549C62205D4}\E6F6D6F627567796275637 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{E7EAA283-14ED-403A-BFF6-561E2637DBB4} : DhcpNameServer = 192.168.0.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
IFEO: image file execution options - svchost.exe
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: AVG Security Toolbar BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: Microsoft Live Search Toolbar: {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
TB-X64: AVG Security Toolbar: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [QPService] "C:\Program Files (x86)\HP\QuickPlay\QPService.exe"
mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
mRun-x64: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
mRun-x64: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
IFEO-X64: image file execution options - svchost.exe
Hosts: 74.125.45.100 4-open-davinci.com
Hosts: 74.125.45.100 securitysoftwarepayments.com
Hosts: 74.125.45.100 privatesecuredpayments.com
Hosts: 74.125.45.100 secure.privatesecuredpayments.com
Hosts: 74.125.45.100 getantivirusplusnow.com
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Kathie\AppData\Roaming\Mozilla\Firefox\Profiles\1b950fcb.default\
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-8-18 7390560]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
R2 CFUACProxy_hddv2usb3;CFUACProxy_hddv2usb3;C:\ProgramData\Clickfree\HDDV2USB3\UACProxy.exe [2011-4-14 83792]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 20992]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-3-11 1153368]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 Com4QLBEx;Com4QLBEx;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-8-21 227896]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;C:\Windows\system32\drivers\IntcHdmi.sys --> C:\Windows\system32\drivers\IntcHdmi.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-11-22 517448]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
.
=============== Created Last 30 ================
.
2011-12-12 23:13:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{A75D3F95-6A88-4640-BBD5-5326D0CDDD81}
2011-12-12 23:12:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{89767B68-AD6D-47AA-8C5F-E882FA34E974}
2011-12-12 21:52:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{77CE178B-4B84-4F78-994F-37AB4B909FF7}
2011-12-12 21:52:32 -------- d-----w- C:\Users\Kathie\AppData\Local\{0AAF965D-C8FB-4B80-9123-A6A0B4CDCBDD}
2011-12-10 22:35:14 -------- d-----w- C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
2011-12-10 22:32:51 -------- d-----w- C:\Program Files\CCleaner
2011-12-10 22:18:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{023C6E61-532D-4641-81FC-705C60E91011}
2011-12-09 16:32:56 -------- d-----w- C:\Users\Kathie\AppData\Local\{450F7D98-9159-4C18-BE79-8D804FD85D65}
2011-12-09 16:32:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{22307D9E-F8C2-43A6-9458-EBD9149D5628}
2011-12-09 15:39:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{72E58DF3-6EE2-4050-BA27-091DE906F487}
2011-12-09 15:39:40 -------- d-----w- C:\Users\Kathie\AppData\Local\{A1E0C00D-49CE-4695-8435-3DD460202A50}
2011-12-09 15:36:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{51A50125-7F36-4403-9749-A760DEAD6FD0}
2011-12-09 15:36:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{3D3BABC5-5103-4904-8CEE-DAD27B620A2F}
2011-12-09 14:44:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{CDDB2CA8-8B5F-4A3A-B5BA-0D907E95BC73}
2011-12-09 14:44:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{17601612-36C4-48B7-91A7-28ED90D34C9C}
2011-12-09 14:34:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{5AB40E53-B2E7-48FD-BA58-CEC8961DA6DF}
2011-12-09 14:34:38 -------- d-----w- C:\Users\Kathie\AppData\Local\{2A2A2287-9CB5-4361-B2CB-5B5C5607FAC7}
2011-12-09 14:31:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{7001276F-409C-458F-9854-9C028D57F3E6}
2011-12-09 14:30:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{320312F1-7883-455F-B9B7-73AD279755A3}
2011-12-09 04:51:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{7EE235D6-64A8-4F8A-9B22-B6EA80FD1174}
2011-12-09 04:51:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{84EF98DC-2CAC-44B2-AE9A-02EF3A6ADE53}
2011-12-09 04:36:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{0D755FCC-679B-42E9-8D04-1E0526161F49}
2011-12-09 04:36:33 -------- d-----w- C:\Users\Kathie\AppData\Local\{9F978E04-4418-434A-8E21-6E864AA4533F}
2011-12-09 04:16:29 -------- d-----w- C:\Users\Kathie\AppData\Local\{CF7ABF91-7D26-4673-84D3-7BD29BC3E8C2}
2011-12-09 04:16:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{5CF77BB4-27F8-44CE-9985-37A0580F9210}
2011-12-09 03:07:50 -------- d-----w- C:\Users\Kathie\AppData\Local\{BBFC937A-2E66-44BD-A398-41D65659A367}
2011-12-09 03:07:35 -------- d-----w- C:\Users\Kathie\AppData\Local\{3AE734B8-73B5-4043-9B9F-640D24534684}
2011-12-08 19:22:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{217733F6-9FFB-4565-9ACA-FD25763359BD}
2011-12-08 19:22:39 -------- d-----w- C:\Users\Kathie\AppData\Local\{78128607-A530-480E-AAC8-C6852BB6914F}
2011-12-07 23:08:24 -------- d-----w- C:\Users\Kathie\AppData\Local\{43F6DD77-CCBB-423E-BAA5-FEF55D2252F3}
2011-12-07 23:08:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{632ADA3C-9F9F-419C-B40E-DDFC1C570853}
2011-12-07 21:57:09 -------- d-----w- C:\Users\Kathie\AppData\Local\{9A0F9709-0119-4DA6-97E6-D012BA54AA99}
2011-12-07 21:56:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{AC968916-73D1-49C0-B2C5-C4B1CA37B51B}
2011-12-07 17:08:20 -------- d-----w- C:\Users\Kathie\AppData\Local\{B19E5CF8-DD7D-4AAE-A7A6-C64428688361}
2011-12-07 17:08:05 -------- d-----w- C:\Users\Kathie\AppData\Local\{0AE421BA-C77C-4DC8-9221-CD7CA68A3D04}
2011-12-07 16:54:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{291231F9-6AE9-4C25-BFDE-BC8D2DA5FEAF}
2011-12-07 16:53:57 -------- d-----w- C:\Users\Kathie\AppData\Local\{C0B64FE7-A843-442A-8D6A-B27B651E7584}
2011-12-07 16:09:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{42A94201-467B-4E10-B55A-5137064AA5FF}
2011-12-07 16:09:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{0400C205-475C-4B8F-B826-6BFC32507A99}
2011-12-07 15:51:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{5384E053-C875-406F-B4E2-B50907010A30}
2011-12-07 15:50:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{E7BD2639-EAEF-45D1-B8F0-296DC89092DB}
2011-12-07 03:55:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{A39D7C8B-C80C-475D-8C5F-11C8F9E177A4}
2011-12-07 03:54:56 -------- d-----w- C:\Users\Kathie\AppData\Local\{B1C51B52-8030-4EF4-B574-ACA27BEE5C41}
2011-12-06 15:30:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{9C27A182-3D34-4580-9DE6-69ED4CAC06ED}
2011-12-06 15:30:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{345ED00A-DB19-4C1F-B753-28D06AA1C1DF}
2011-12-06 15:12:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{E373F822-6DD8-4AE6-813F-F2840C52228A}
2011-12-06 15:12:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{11C0DD6B-A173-4334-8A7D-44216DF9F868}
2011-12-06 15:07:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{7A516B4B-A1D1-429E-88CC-CF16603B3D0E}
2011-12-06 15:07:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{1B5AC597-7F04-46E9-B763-6CE9BFF92AAB}
2011-12-06 14:50:29 -------- d-----w- C:\Users\Kathie\AppData\Local\{8013957C-0F89-4CBB-92D9-A922C66A0248}
2011-12-06 14:50:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{2A5AA366-B5E4-4521-8335-1F931D072282}
2011-12-06 14:15:57 -------- d-----w- C:\Users\Kathie\AppData\Local\{17A7AA2C-1B92-4A50-AFD1-1104C6F73392}
2011-12-06 14:15:46 -------- d-----w- C:\Users\Kathie\AppData\Local\{1309A731-5AB4-4162-B5C4-1B16C1315ED5}
2011-12-06 05:07:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{64C61BB0-C0DA-43A1-9B9F-088EF00D9915}
2011-12-06 05:07:06 -------- d-----w- C:\Users\Kathie\AppData\Local\{A79DCD66-CCE7-41C4-8979-EC1922C46B02}
2011-12-06 04:50:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{EEADF6C0-AADA-4CD8-8834-251EF1E680A7}
2011-12-06 04:50:42 -------- d-----w- C:\Users\Kathie\AppData\Local\{D6DDE5E1-11E6-488C-95AE-8FAC64538AC4}
2011-12-05 23:14:52 -------- d-----w- C:\Users\Kathie\AppData\Local\{730DC85F-A1CF-4B03-93F9-D18B8CB9666B}
2011-12-05 23:14:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{1BFB432E-74D2-4D02-9612-50631BB55951}
2011-12-05 22:57:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{34559E18-F04F-4C75-A5AB-5D060A2691BC}
2011-12-05 22:57:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{BFA30C6C-4163-495A-B8FE-F8D0FB9250DC}
2011-12-05 21:54:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{1D67E896-0ED5-4B48-9739-046143DE1992}
2011-12-05 21:53:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{C55AB930-9995-43FE-BA74-114CCF519E81}
2011-12-05 20:47:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{88DD116F-F492-4B1E-8C7C-30CB7538662F}
2011-12-05 20:46:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{05D8BF1B-88BD-4808-B467-9B0C34041A04}
2011-12-05 20:18:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{6029A32B-A1CE-470D-912D-32094859550C}
2011-12-05 20:18:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{BA884EC3-36BF-414D-B46D-E894F12B1194}
2011-12-05 06:26:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{13ECE90F-96F1-4256-BD2B-F20AA6EA2615}
2011-12-05 06:26:32 -------- d-----w- C:\Users\Kathie\AppData\Local\{F632442D-7C2F-45CF-A254-9ABF5C5CF7E5}
2011-12-05 05:19:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{AD5D0785-04C9-422D-8374-2DAD375A1183}
2011-12-05 05:19:38 -------- d-----w- C:\Users\Kathie\AppData\Local\{4FA08D46-112B-4743-A512-56DF30DC5BF8}
2011-12-05 02:15:03 -------- d-----w- C:\Users\Kathie\AppData\Local\{0193DCDC-02AB-4B9F-A877-FC580D26D139}
2011-12-05 02:14:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{87F035E9-9AC2-4FEC-9285-D302E7659BB6}
2011-12-05 00:24:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{CF5EB042-2565-4A89-91ED-A0EB0F6D103C}
2011-12-05 00:23:54 -------- d-----w- C:\Users\Kathie\AppData\Local\{BCD771E6-D579-4CF4-A89D-E466FF73EC78}
2011-12-04 21:52:42 -------- d-----w- C:\Users\Kathie\AppData\Local\{C535D99B-F77A-4586-87D0-57862BF82E51}
2011-12-04 21:52:28 -------- d-----w- C:\Users\Kathie\AppData\Local\{62248A99-E7B6-4F31-A356-B5D5021BAC40}
2011-12-03 02:50:20 -------- d-----w- C:\Users\Kathie\AppData\Local\{91BCB7B8-F1EB-49B4-8489-18B74D61F5CF}
2011-12-03 02:50:09 -------- d-----w- C:\Users\Kathie\AppData\Local\{2FEE6B09-61B6-4BDC-8784-A7C76F9A70C9}
2011-12-02 00:15:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{08D58AF9-42BF-4DAC-871C-128EE97EE5AA}
2011-12-02 00:15:43 -------- d-----w- C:\Users\Kathie\AppData\Local\{F5E23578-CCE6-470A-A189-8320B697B60E}
2011-12-01 18:39:50 -------- d-----w- C:\Users\Kathie\AppData\Local\{5F6F2D66-DB20-4702-8E9D-1D3D0D6C597E}
2011-12-01 18:39:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{1B010E0E-DAA9-4ED0-A564-5E783856A6C5}
2011-12-01 14:24:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{33A941C2-685E-4C0D-9F31-049CEC3EC597}
2011-12-01 14:24:43 -------- d-----w- C:\Users\Kathie\AppData\Local\{26F3E38C-63E0-430E-8B75-5580433C6973}
2011-11-30 18:15:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{F31B93BC-241F-4F75-A1DD-7F98085C9EC7}
2011-11-30 18:15:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{B3ABED28-A90D-43D5-8F46-6A820672553D}
2011-11-30 17:22:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4A12574-6CA7-4D2B-A051-4A1331FE1CEB}
2011-11-30 17:22:04 -------- d-----w- C:\Users\Kathie\AppData\Local\{23FBC25C-E77D-46D2-A74C-42B1D378A490}
2011-11-30 15:18:31 -------- d-----w- C:\Users\Kathie\AppData\Local\{BFBEC189-74F9-44E9-B00E-7DB0AF0256F4}
2011-11-30 15:18:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{C0CBE688-4C18-4E9F-9EC1-051C8C24D0C8}
2011-11-30 01:34:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{884A451F-18A6-453B-BE04-290CB9542511}
2011-11-30 01:34:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{A6C4F515-96D5-4DE7-A3BA-0A763755626F}
2011-11-29 21:31:04 -------- d-----w- C:\Users\Kathie\AppData\Local\{0D493F3A-6005-448A-BE49-EBA99106C5F4}
2011-11-29 21:30:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{97F18D61-C555-470B-AE84-6BB8C398989E}
2011-11-29 21:17:46 -------- d-----w- C:\Users\Kathie\AppData\Local\{29F04B1E-8496-425C-9EBE-8D84E089FAF1}
2011-11-29 21:17:35 -------- d-----w- C:\Users\Kathie\AppData\Local\{2667CEE5-0E80-4CAA-B26F-0169603894B2}
2011-11-29 19:32:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{4D7BC681-70C0-411F-A8B2-EE446A299779}
2011-11-29 19:31:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{83A3583C-E945-4BDD-BF3E-D241F4AB9F46}
2011-11-29 15:23:40 -------- d-----w- C:\Users\Kathie\AppData\Local\{E64DFD34-4E16-443B-8CE3-9AC7CFB4B83C}
2011-11-29 15:23:28 -------- d-----w- C:\Users\Kathie\AppData\Local\{8748B5F1-D5B5-4E6F-98BB-56E2378D705B}
2011-11-29 15:12:23 -------- d-----w- C:\Users\Kathie\AppData\Local\{D4FA95E1-4BF6-44E5-B7D9-7647DDC4C1E1}
2011-11-29 15:12:13 -------- d-----w- C:\Users\Kathie\AppData\Local\{0D82E1D6-87B1-4557-9C2E-05919AED84C7}
2011-11-29 13:49:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4B15C21-93D2-456A-BAEA-B8045F56A71B}
2011-11-29 13:49:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{A59132D4-9150-4304-A957-C38D1B795253}
2011-11-29 05:43:04 -------- d-----w- C:\Users\Kathie\AppData\Local\{CDAA8332-E852-4E80-B79D-4D505C5219C0}
2011-11-29 05:42:53 -------- d-----w- C:\Users\Kathie\AppData\Local\{7C2C1311-E590-443B-AF1A-9D00EB4453E2}
2011-11-28 21:26:31 -------- d-----w- C:\Users\Kathie\AppData\Local\{BB6160D4-FF4C-4915-853C-17E7AE3F6B3A}
2011-11-28 21:26:20 -------- d-----w- C:\Users\Kathie\AppData\Local\{6C30E465-6630-44B4-930F-EA05FB80D420}
2011-11-28 13:46:25 -------- d-----w- C:\Users\Kathie\AppData\Local\{ACE3D8D5-5D47-4152-AECC-052A5AE99C4F}
2011-11-28 13:46:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{7C211AF9-2B5C-451D-A324-1CDD30BE133D}
2011-11-28 01:10:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{D1B425AC-0120-4913-86B3-698A360874F0}
2011-11-28 01:10:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{1586DBE7-FC4F-4FB9-9629-AA24997D4D64}
2011-11-27 05:35:34 -------- d-----w- C:\Users\Kathie\AppData\Local\{AB2D1940-919E-45B1-9B2E-CB8E401270C3}
2011-11-27 05:35:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{32A3B90A-D68A-46DA-BCCB-732D7B6698EA}
2011-11-27 02:00:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{BAC94C35-0EEB-4D53-A26C-9E0539220604}
2011-11-27 02:00:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{F8515D2D-1B04-4A6B-AA18-F004997E0E82}
2011-11-25 13:01:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{6FC6454B-DF86-4855-87DA-0746D498AD97}
2011-11-25 13:00:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{8FA3B695-3E9E-4001-ACE7-88E68BA05E9B}
2011-11-24 16:44:27 -------- d-----w- C:\Users\Kathie\AppData\Local\{A205CCBD-F221-48EA-BBDE-441D5E29769B}
2011-11-24 16:44:14 -------- d-----w- C:\Users\Kathie\AppData\Local\{7E2CF4C6-F4BB-488A-96D1-F463619121DF}
2011-11-24 16:33:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{1680A03A-A475-4961-8E74-B1E363D28C99}
2011-11-24 16:33:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{EBAD4862-9430-40DE-9E66-C91187BDF460}
2011-11-24 03:18:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{E361426D-3954-41DC-B187-56A31611C1D6}
2011-11-24 03:18:47 -------- d-----w- C:\Users\Kathie\AppData\Local\{E36EF0C2-B2D6-474E-BD8D-0A9AC09CC888}
2011-11-24 00:58:45 -------- d-----w- C:\Users\Kathie\AppData\Local\{4E5033B0-D24E-422B-A80B-AC9D66E044E8}
2011-11-24 00:58:31 -------- d-----w- C:\Users\Kathie\AppData\Local\{F0A3A42D-5910-4415-BAD8-C3A5E789B4A2}
2011-11-22 22:11:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{4DE0A5A2-638F-4918-AAA8-BF5293EDE3EE}
2011-11-22 22:11:34 -------- d-----w- C:\Users\Kathie\AppData\Local\{659E6BB9-1988-4EB0-978E-4D704B82DD94}
2011-11-22 15:42:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{C17495F7-EA00-48FA-B6A3-4D3BD014940E}
2011-11-22 15:42:07 -------- d-----w- C:\Users\Kathie\AppData\Local\{8F1664D1-7BF8-4B19-92BD-E810EC8CA16E}
2011-11-22 05:38:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{61F07B05-6C76-4216-8028-4D910C8BB3CF}
2011-11-22 05:38:46 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4F3DBCB-562C-490C-9098-2421B907E566}
2011-11-22 05:17:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{10D43195-D23B-4F8B-84EE-732BFBACE811}
2011-11-22 05:17:22 -------- d-----w- C:\Users\Kathie\AppData\Local\{C703102B-317B-4F2C-AAC7-4E0FF17BD348}
2011-11-22 04:53:23 -------- d-----w- C:\Users\Kathie\AppData\Local\{1BA28B04-A150-41B6-98A7-9E6D2F5AA36D}
2011-11-22 04:53:11 -------- d-----w- C:\Users\Kathie\AppData\Local\{61270267-2512-4AE1-AEB4-E3912A27AF8A}
2011-11-21 23:00:35 -------- d-----w- C:\Users\Kathie\AppData\Local\{A733A1C0-CD46-40BF-8DDA-C2977EF48577}
2011-11-21 23:00:17 -------- d-----w- C:\Users\Kathie\AppData\Local\{34008902-6161-4C78-A3F0-74AB081FC5C6}
2011-11-21 20:05:08 -------- d-----w- C:\Users\Kathie\AppData\Local\{79E80520-AA8E-467C-99A4-9794FE39F557}
2011-11-21 20:04:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{469FE05B-CF71-4DC6-98D2-4256C1AA8DBD}
2011-11-21 03:22:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{D03A5F24-E7E7-41D5-9B58-AAB4F0E64B40}
2011-11-21 03:22:05 -------- d-----w- C:\Users\Kathie\AppData\Local\{2F26DFD1-E836-4128-B4BB-BFFB30053A84}
2011-11-21 02:06:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{D369BFEA-1C49-47FA-BC13-213D2AC06B27}
2011-11-21 02:06:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{031F9EAD-12D5-49F7-96B0-A71A527175A8}
2011-11-20 22:24:24 -------- d-----w- C:\Users\Kathie\AppData\Local\{22CAECAB-10DF-48BD-AEB7-90629E91CD3A}
2011-11-20 22:24:12 -------- d-----w- C:\Users\Kathie\AppData\Local\{0FB5A3D0-C123-4577-94FD-CB17CB4FE47E}
2011-11-19 19:30:48 -------- d-----w- C:\Users\Kathie\AppData\Local\{0B63D4DF-B7B9-4F62-9A3C-59848411DF71}
2011-11-19 19:30:36 -------- d-----w- C:\Users\Kathie\AppData\Local\{C4C24ECB-8EDE-43BF-9A17-ABB3662FC7E6}
2011-11-19 15:07:58 -------- d-----w- C:\Users\Kathie\AppData\Local\{DAE88209-60F4-4D45-9C68-B4AC6655C7C3}
2011-11-19 15:07:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{33D6A28D-3EB1-4466-82EB-C2DB5A19F15E}
2011-11-19 05:20:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{E1B9FD9F-9DBD-405E-A44F-FA1E8932FD6F}
2011-11-19 05:20:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{3AAE152F-A442-4A0B-BAA4-4B49FD58DA4A}
2011-11-18 21:37:18 -------- d-----w- C:\Users\Kathie\AppData\Local\{8DF097E0-615B-4F74-A999-F072A9CD1ED3}
2011-11-18 21:37:07 -------- d-----w- C:\Users\Kathie\AppData\Local\{8521FCAC-2943-4D9F-B259-1D939CF30A5B}
2011-11-18 18:15:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{DCD77134-DE6A-4F8A-A6EA-DF87E88E46D9}
2011-11-18 18:15:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{0203BE57-D700-408F-8AF1-7D877A49E5CE}
2011-11-18 15:56:51 -------- d-----w- C:\Users\Kathie\AppData\Local\{3D5D86A1-F16E-480E-912D-92378BF2B81A}
2011-11-18 15:56:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{22F7677D-4106-40E7-B1AA-B1FFB5FA7D2B}
2011-11-18 14:13:07 -------- d-----w- C:\Users\Kathie\AppData\Local\{4AE1DF2E-4D95-49C0-BEF8-762179BFD880}
2011-11-18 14:12:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{E5A78A5C-FC4A-4EF9-88B7-FCF8509A3481}
2011-11-18 04:00:39 -------- d-----w- C:\Users\Kathie\AppData\Local\{A7F83F1A-D976-4024-BB73-18F47F42A96C}
2011-11-18 04:00:26 -------- d-----w- C:\Users\Kathie\AppData\Local\{73232BED-B6DD-4CD8-8258-5BACB023C443}
2011-11-18 01:08:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{718E36AA-4FF8-4CC5-8B89-0BA8A452CA34}
2011-11-18 01:08:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{47B063F3-AAF5-4DA2-8404-77C0C7392605}
2011-11-17 20:38:13 -------- d-----w- C:\Users\Kathie\AppData\Local\{84024590-539F-4ABB-92C7-9D42E2AA8B93}
2011-11-17 20:38:00 -------- d-----w- C:\Users\Kathie\AppData\Local\{A2073432-6C08-453D-9C7D-B36F71B1AA3F}
2011-11-16 02:51:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{AE855A96-179C-4E80-A4D7-82B242F00043}
2011-11-16 02:51:18 -------- d-----w- C:\Users\Kathie\AppData\Local\{299A0D50-74EE-4C79-94F7-1A91A6A2D189}
2011-11-16 00:38:55 -------- d-----w- C:\Users\Kathie\AppData\Local\{C9101548-0CB0-48C0-92BF-E0FEECC24527}
2011-11-16 00:38:34 -------- d-----w- C:\Users\Kathie\AppData\Local\{A589F84B-9477-4807-9114-1631F775B268}
2011-11-15 22:14:50 -------- d-----w- C:\Users\Kathie\AppData\Local\{A1E1BFBD-FCCC-404A-8136-10B86C383BAA}
2011-11-15 22:14:38 -------- d-----w- C:\Users\Kathie\AppData\Local\{2DC6EC73-FDF3-4795-AD1D-7A6D2BB1B3C5}
2011-11-15 19:30:49 -------- d-----w- C:\Users\Kathie\AppData\Local\{FB157507-A870-4111-AF3A-E3A82EFBEFFB}
2011-11-15 19:30:37 -------- d-----w- C:\Users\Kathie\AppData\Local\{93D50DBD-A040-42A3-AA6A-96302CBF93C7}
2011-11-15 15:42:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{432457CF-AEB8-4028-B754-579319072469}
2011-11-15 15:42:01 -------- d-----w- C:\Users\Kathie\AppData\Local\{F1F09580-0D9E-4AB8-BBFA-2A3569038A90}
2011-11-15 14:45:10 -------- d-----w- C:\Users\Kathie\AppData\Local\{FF18F52D-4EEC-4887-A2B9-22CFCCDA3B75}
2011-11-15 14:44:59 -------- d-----w- C:\Users\Kathie\AppData\Local\{1BCC0F70-3269-434A-A374-FBA821C6451D}
2011-11-15 04:31:54 -------- d-----w- C:\Users\Kathie\AppData\Local\{7881EC81-2DEC-4B04-ACE6-7C6A2260EC08}
2011-11-15 04:31:40 -------- d-----w- C:\Users\Kathie\AppData\Local\{205EDF1E-01F9-4B84-A845-9BC827940330}
2011-11-15 03:29:15 -------- d-----w- C:\Users\Kathie\AppData\Local\{DA8B7643-7DF0-44D0-B9E5-6BF67AAD4B27}
2011-11-15 03:29:01 -------- d-----w- C:\Users\Kathie\AppData\Local\{D4EA85AA-DADF-4D9F-B9E1-0ECF0C3F18FE}
2011-11-14 20:51:19 -------- d-----w- C:\Users\Kathie\AppData\Local\{CC5591A0-4C6A-455D-93B2-F74923EFCC27}
2011-11-14 20:51:05 -------- d-----w- C:\Users\Kathie\AppData\Local\{65FD3B5A-529F-42F7-B823-D1A3AABB5E89}
2011-11-14 16:40:41 -------- d-----w- C:\Users\Kathie\AppData\Local\{38FA71A5-3AA8-4E9D-8618-381607ABB432}
2011-11-14 16:40:30 -------- d-----w- C:\Users\Kathie\AppData\Local\{4E54712A-9D73-40CE-9976-85EF78B504D1}
2011-11-14 13:01:21 -------- d-----w- C:\Users\Kathie\AppData\Local\{DA72CA6C-8C3E-4B77-9C63-BEBCC11444EB}
2011-11-14 13:01:09 -------- d-----w- C:\Users\Kathie\AppData\Local\{2F0653F7-60E0-45A4-BD63-E7DB8E5BE21A}
.
==================== Find3M ====================
.
2011-11-10 10:54:13 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-09-29 16:24:44 1897328 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-09-29 04:09:30 3141120 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 18:16:45.76 ===============