mjd59
2012-12-07, 23:00
i am coming across greyboxs not letting me update security or vist certain web pages . think redirect browser an maybe running older version , possable malware ??? help .
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.16982
Run by fido at 7:27:18 on 2012-12-08
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1033.18.3316.1946 [GMT -8:00]
.
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\AMT\atchk.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_5_502_110_ActiveX.exe
C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\System32\svchost.exe -k wdisvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\fido\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{47B72BCD-B410-4D07-8519-46E98618273F} : DHCPNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-12-8 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-12-8 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-12-8 168384]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2012-12-7 2521880]
.
=============== Created Last 30 ================
.
2012-12-08 13:48:19 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-12-08 13:48:11 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-12-08 13:48:04 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-12-08 11:03:57 268800 ----a-w- c:\windows\system32\es.dll
2012-12-08 10:27:31 229888 ----a-w- c:\windows\system32\msshsq.dll
2012-12-08 10:17:52 -------- d-----w- c:\users\fido\appdata\local\Deployment
2012-12-08 10:17:52 -------- d-----w- c:\users\fido\appdata\local\Apps
2012-12-08 10:01:18 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{bb5b9871-8949-47fa-9e4a-941a7d8098d2}\mpengine.dll
2012-12-08 08:47:41 -------- d-----w- c:\users\fido\New Folder
2012-12-08 08:27:34 -------- d-----w- c:\windows\pss
2012-12-08 08:10:02 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-12-08 08:02:19 -------- d-----w- c:\program files\Microsoft Security Client
2012-12-08 07:47:47 96760 ----a-w- c:\windows\system32\dfshim.dll
2012-12-08 07:47:43 41984 ----a-w- c:\windows\system32\netfxperf.dll
2012-12-08 07:47:41 83968 ----a-w- c:\windows\system32\mscories.dll
2012-12-08 07:47:41 282112 ----a-w- c:\windows\system32\mscoree.dll
2012-12-08 07:47:41 158720 ----a-w- c:\windows\system32\mscorier.dll
2012-12-08 07:30:50 -------- d-----w- c:\program files\SystemRequirementsLab
2012-12-08 07:26:11 -------- d-----w- c:\program files\GUMDA57.tmp
2012-12-08 07:25:05 -------- d-----w- c:\users\fido\appdata\local\Google
2012-12-08 07:24:45 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-08 07:24:45 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-07 16:10:53 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-12-07 16:10:53 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-07 16:10:53 289792 ----a-w- c:\windows\system32\atmfd.dll
2012-12-07 16:10:53 24064 ----a-w- c:\windows\system32\lpk.dll
2012-12-07 16:10:53 156672 ----a-w- c:\windows\system32\t2embed.dll
2012-12-07 16:10:53 10240 ----a-w- c:\windows\system32\dciman32.dll
2012-12-07 16:08:13 61440 ----a-w- c:\windows\system32\winipsec.dll
2012-12-07 16:08:13 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2012-12-07 16:08:13 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2012-12-07 16:08:13 272896 ----a-w- c:\windows\system32\polstore.dll
2012-12-07 16:06:57 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-12-07 16:06:56 306688 ----a-w- c:\windows\system32\drivers\srv.sys
2012-12-07 16:06:20 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2012-12-07 16:06:20 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2012-12-07 16:06:20 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2012-12-07 16:05:45 87040 ----a-w- c:\windows\system32\msoert2.dll
2012-12-07 16:05:45 707072 ----a-w- c:\program files\common files\system\wab32.dll
2012-12-07 16:05:45 41984 ----a-w- c:\program files\windows mail\wabimp.dll
2012-12-07 16:05:45 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2012-12-07 16:05:45 205824 ----a-w- c:\windows\system32\msoeacct.dll
2012-12-07 16:05:45 1098752 ----a-w- c:\program files\common files\system\wab32res.dll
2012-12-07 16:05:44 2836992 ----a-w- c:\program files\windows mail\MSOERES.dll
2012-12-07 16:05:44 1614848 ----a-w- c:\program files\windows mail\msoe.dll
2012-12-07 16:05:42 397312 ----a-w- c:\program files\windows mail\WinMail.exe
2012-12-07 16:05:41 81408 ----a-w- c:\program files\windows mail\oeimport.dll
2012-12-07 16:05:41 24064 ----a-w- c:\program files\common files\system\DirectDB.dll
2012-12-07 16:04:50 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2012-12-07 16:04:50 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2012-12-07 16:04:50 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2012-12-07 16:04:50 19968 ----a-w- c:\windows\system32\ARP.EXE
2012-12-07 16:04:50 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2012-12-07 16:04:50 15360 ----a-w- c:\windows\system32\netevent.dll
2012-12-07 16:04:50 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2012-12-07 16:04:50 103936 ----a-w- c:\windows\system32\netiohlp.dll
2012-12-07 16:04:50 10240 ----a-w- c:\windows\system32\finger.exe
2012-12-07 16:03:55 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2012-12-07 16:03:55 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2012-12-07 16:03:54 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2012-12-07 16:03:54 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2012-12-07 16:03:52 542720 ----a-w- c:\windows\system32\sysmain.dll
2012-12-07 16:03:20 194560 ----a-w- c:\windows\system32\WebClnt.dll
2012-12-07 16:03:20 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2012-12-07 16:02:47 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2012-12-07 16:02:46 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2012-12-07 16:02:46 502272 ----a-w- c:\windows\system32\wlansvc.dll
2012-12-07 16:02:46 47104 ----a-w- c:\windows\system32\wlanapi.dll
2012-12-07 16:02:46 297984 ----a-w- c:\windows\system32\wlansec.dll
2012-12-07 16:02:46 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2012-12-07 16:02:04 2048 ----a-w- c:\windows\system32\msxml6r.dll
2012-12-07 16:02:04 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-12-07 16:02:04 1406464 ----a-w- c:\windows\system32\msxml6.dll
2012-12-07 16:02:04 1260032 ----a-w- c:\windows\system32\msxml3.dll
2012-12-07 16:01:21 997912 ----a-w- c:\windows\system32\igxpun.exe
2012-12-07 16:01:21 -------- d-----w- c:\windows\system32\x64
2012-12-07 16:00:39 216576 ----a-w- c:\windows\system32\msv1_0.dll
2012-12-07 16:00:02 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-12-07 16:00:02 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-12-07 16:00:02 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-12-07 15:59:32 49664 ----a-w- c:\windows\system32\csrsrv.dll
2012-12-07 15:59:31 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-12-07 15:58:59 98816 ----a-w- c:\windows\system32\mfps.dll
2012-12-07 15:58:59 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2012-12-07 15:58:59 2855424 ----a-w- c:\windows\system32\mf.dll
2012-12-07 15:58:59 24576 ----a-w- c:\windows\system32\mfpmp.exe
2012-12-07 15:58:59 2048 ----a-w- c:\windows\system32\mferror.dll
2012-12-07 15:58:18 3502480 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-12-07 15:58:18 3468168 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-12-07 15:56:45 376832 ----a-w- c:\windows\system32\winhttp.dll
2012-12-07 15:56:11 434176 ----a-w- c:\windows\system32\vbscript.dll
2012-12-07 15:55:36 71680 ----a-w- c:\windows\system32\atl.dll
2012-12-07 15:54:34 297472 ----a-w- c:\windows\system32\gdi32.dll
2012-12-07 15:54:04 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2012-12-07 15:54:04 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-12-07 15:52:05 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2012-12-07 15:51:38 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2012-12-07 15:51:38 30208 ----a-w- c:\windows\system32\xolehlp.dll
2012-12-07 15:51:06 156160 ----a-w- c:\windows\system32\wkssvc.dll
2012-12-07 15:50:31 116736 ----a-w- c:\windows\system32\aaclient.dll
2012-12-07 15:50:30 36352 ----a-w- c:\windows\system32\tsgqec.dll
2012-12-07 15:50:30 1871872 ----a-w- c:\windows\system32\mstscax.dll
2012-12-07 15:49:55 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2012-12-07 15:48:54 414208 ----a-w- c:\windows\system32\msscp.dll
2012-12-07 15:47:43 713728 ----a-w- c:\windows\system32\timedate.cpl
2012-12-07 15:47:10 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2012-12-07 15:46:41 86016 ----a-w- c:\windows\system32\icfupgd.dll
2012-12-07 15:46:41 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2012-12-07 15:46:41 61952 ----a-w- c:\windows\system32\cmifw.dll
2012-12-07 15:46:41 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2012-12-07 15:46:41 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2012-12-07 15:46:41 16896 ----a-w- c:\windows\system32\wfapigp.dll
2012-12-07 15:45:41 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2012-12-07 15:45:41 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2012-12-07 15:45:41 10922496 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2012-12-07 15:45:40 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2012-12-07 15:43:14 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-07 15:42:34 696832 ----a-w- c:\windows\system32\localspl.dll
2012-12-07 15:42:06 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
2012-12-07 15:42:05 45112 ----a-w- c:\windows\system32\drivers\pciidex.sys
2012-12-07 15:42:05 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
2012-12-07 15:42:05 15928 ----a-w- c:\windows\system32\drivers\pciide.sys
2012-12-07 15:42:05 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
2012-12-07 15:42:05 109624 ----a-w- c:\windows\system32\drivers\ataport.sys
2012-12-07 15:41:43 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2012-12-07 15:41:19 2923520 ----a-w- c:\windows\explorer.exe
2012-12-07 15:40:24 171520 ----a-w- c:\windows\system32\wintrust.dll
2012-12-07 15:39:51 7680 ----a-w- c:\windows\system32\lsass.exe
2012-12-07 15:39:51 72704 ----a-w- c:\windows\system32\secur32.dll
2012-12-07 15:39:51 494592 ----a-w- c:\windows\system32\kerberos.dll
2012-12-07 15:39:51 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-12-07 15:39:51 175104 ----a-w- c:\windows\system32\wdigest.dll
2012-12-07 15:39:51 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2012-12-07 15:39:50 272384 ----a-w- c:\windows\system32\schannel.dll
2012-12-07 15:39:22 24064 ----a-w- c:\windows\system32\netcfg.exe
2012-12-07 15:35:40 1585664 ----a-w- c:\windows\system32\setupapi.dll
2012-12-07 15:34:18 549888 ----a-w- c:\windows\system32\rpcss.dll
2012-12-07 15:34:17 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2012-12-07 15:34:17 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2012-12-07 15:34:17 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2012-12-07 15:34:17 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2012-12-07 15:34:17 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2012-12-07 15:34:17 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2012-12-07 15:34:16 97280 ----a-w- c:\windows\system32\iasrecst.dll
2012-12-07 15:34:16 53248 ----a-w- c:\windows\system32\iasads.dll
2012-12-07 15:34:16 37888 ----a-w- c:\windows\system32\iasdatastore.dll
2012-12-07 15:34:16 158720 ----a-w- c:\windows\system32\sdohlp.dll
2012-12-07 15:33:46 62464 ----a-w- c:\windows\system32\l3codeca.acm
2012-12-07 15:33:46 220672 ----a-w- c:\windows\system32\l3codecp.acm
2012-12-07 15:32:51 815104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-12-07 15:32:51 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2012-12-07 15:32:51 22016 ----a-w- c:\windows\system32\netiougc.exe
2012-12-07 15:32:51 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2012-12-07 15:32:51 179712 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-12-07 15:32:51 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2012-12-07 15:32:51 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2012-12-07 15:32:08 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2012-12-07 15:31:46 9728 ----a-w- c:\windows\system32\LAPRXY.DLL
2012-12-07 15:31:46 223232 ----a-w- c:\windows\system32\WMASF.DLL
2012-12-07 15:31:46 2048 ----a-w- c:\windows\system32\asferror.dll
2012-12-07 15:31:25 25600 ----a-w- c:\windows\system32\amxread.dll
2012-12-07 15:31:24 14848 ----a-w- c:\windows\system32\apilogen.dll
2012-12-07 15:30:56 33280 ----a-w- c:\windows\system32\slwmi.dll
2012-12-07 15:30:56 268288 ----a-w- c:\windows\system32\mcbuilder.exe
2012-12-07 15:30:56 223232 ----a-w- c:\windows\system32\SLC.dll
2012-12-07 15:30:55 57856 ----a-w- c:\windows\system32\SLUINotify.dll
2012-12-07 15:30:55 566784 ----a-w- c:\windows\system32\SLCommDlg.dll
2012-12-07 15:30:55 39936 ----a-w- c:\windows\system32\slcinst.dll
2012-12-07 15:30:55 351232 ----a-w- c:\windows\system32\SLUI.exe
2012-12-07 15:30:55 2605568 ----a-w- c:\windows\system32\SLsvc.exe
2012-12-07 15:30:55 186368 ----a-w- c:\windows\system32\SLLUA.exe
2012-12-07 15:30:27 712192 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-12-07 15:30:27 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-12-07 15:30:26 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-12-07 15:29:56 97792 ----a-w- c:\windows\system32\cabview.dll
2012-12-07 15:29:06 320000 ----a-w- c:\windows\system32\drivers\csc.sys
2012-12-07 15:29:06 105984 ----a-w- c:\windows\system32\CscMig.dll
2012-12-07 15:29:03 61440 ----a-w- c:\windows\system32\ntprint.exe
2012-12-07 15:29:03 220160 ----a-w- c:\windows\system32\ntprint.dll
2012-12-07 15:29:02 1984512 ----a-w- c:\windows\system32\authui.dll
2012-12-07 15:29:02 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-12-07 15:29:02 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
2012-12-07 15:29:01 8138240 ----a-w- c:\windows\system32\ssBranded.scr
2012-12-07 15:29:01 69632 ----a-w- c:\windows\system32\sendmail.dll
2012-12-07 15:28:16 441856 ----a-w- c:\windows\system32\win32spl.dll
2012-12-07 15:28:16 37376 ----a-w- c:\windows\system32\printcom.dll
2012-12-07 15:27:54 2031104 ----a-w- c:\windows\system32\win32k.sys
2012-12-07 15:27:33 14848 ----a-w- c:\windows\system32\wshrm.dll
2012-12-07 15:27:33 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2012-12-07 15:27:22 2565432 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2012-12-07 15:27:16 6812136 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\{d6b8f43e-ebcc-4c70-854f-aaa24a31a9f8}\mpengine.dll
2012-12-07 15:27:15 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-07 15:26:50 43520 ----a-w- c:\windows\system32\msdxm.tlb
2012-12-07 15:26:50 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2012-12-07 15:26:50 18432 ----a-w- c:\windows\system32\amcompat.tlb
2012-12-07 15:26:14 435712 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2012-12-07 15:26:14 431104 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2012-12-07 15:26:14 312320 ----a-w- c:\windows\system32\msdrm.dll
2012-12-07 15:26:14 154624 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2012-12-07 15:26:14 154112 ----a-w- c:\windows\system32\secproc_ssp.dll
2012-12-07 15:26:13 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2012-12-07 15:26:13 515584 ----a-w- c:\windows\system32\RMActivate.exe
2012-12-07 15:26:13 473088 ----a-w- c:\windows\system32\secproc_isv.dll
2012-12-07 15:26:13 472576 ----a-w- c:\windows\system32\secproc.dll
2012-12-07 15:25:51 66048 ----a-w- c:\program files\windows sidebar\sbdrop.dll
2012-12-07 15:25:51 1232896 ----a-w- c:\program files\windows sidebar\sidebar.exe
2012-12-07 15:25:51 11776 ----a-w- c:\windows\system32\sbunattend.exe
2012-12-07 15:25:27 83968 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-12-07 15:25:27 24576 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-12-07 15:25:19 53760 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2012-12-07 15:24:37 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-12-07 15:24:36 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-12-07 15:24:35 1686528 ----a-w- c:\windows\system32\gameux.dll
2012-12-07 15:23:58 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2012-12-07 15:23:58 94720 ----a-w- c:\windows\system32\logagent.exe
2012-12-07 15:23:25 765952 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2012-12-07 15:23:12 84480 ----a-w- c:\windows\system32\INETRES.dll
2012-12-07 15:23:12 737792 ----a-w- c:\windows\system32\inetcomm.dll
2012-12-07 15:22:49 60928 ----a-w- c:\windows\system32\msasn1.dll
2012-12-07 15:22:29 1645568 ----a-w- c:\windows\system32\connect.dll
2012-12-07 15:22:13 5120 ----a-w- c:\windows\system32\wmi.dll
2012-12-07 15:22:13 152576 ----a-w- c:\windows\system32\imagehlp.dll
2012-12-07 15:22:13 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-12-07 15:21:56 788992 ----a-w- c:\windows\system32\rpcrt4.dll
2012-12-07 15:21:17 396800 ----a-w- c:\windows\system32\drivers\http.sys
2012-12-07 15:21:17 31232 ----a-w- c:\windows\system32\httpapi.dll
2012-12-07 15:21:17 24064 ----a-w- c:\windows\system32\nshhttp.dll
2012-12-07 15:19:51 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-12-07 15:19:39 974336 ----a-w- c:\windows\system32\crypt32.dll
2012-12-07 15:19:28 274432 ----a-w- c:\windows\system32\raschap.dll
2012-12-07 15:19:28 232960 ----a-w- c:\windows\system32\rastls.dll
2012-12-07 15:19:10 321536 ----a-w- c:\windows\system32\WSDApi.dll
2012-12-07 15:17:48 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2012-12-07 15:17:24 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2012-12-07 15:17:24 7680 ----a-w- c:\windows\system32\spwmp.dll
2012-12-07 15:17:23 4096 ----a-w- c:\windows\system32\msdxm.ocx
2012-12-07 15:17:23 4096 ----a-w- c:\windows\system32\dxmasf.dll
2012-12-07 15:17:23 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2012-12-07 15:17:23 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2012-12-07 15:17:23 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2012-12-07 15:17:21 311296 ----a-w- c:\windows\system32\unregmp2.exe
2012-12-07 15:17:21 1418240 ----a-w- c:\program files\windows media player\setup_wm.exe
2012-12-07 14:07:22 920344 ----a-w- c:\windows\system32\mesoludlg.exe
2012-12-07 14:07:22 319456 ----a-w- c:\windows\system32\difxapi.dll
2012-12-07 14:07:22 -------- d-----w- c:\windows\system32\Lang
2012-12-07 14:07:22 -------- d-----w- c:\program files\common files\postureAgent
2012-12-07 14:05:43 39288 ----a-w- c:\windows\system32\NicInE6.dll
2012-12-07 14:05:42 28536 ----a-w- c:\windows\system32\NicCo6.dll
2012-12-07 14:05:42 228224 ----a-w- c:\windows\system32\drivers\e1e6032.sys
2012-12-07 14:05:40 179048 ----a-w- c:\windows\system32\e1000msg.dll
2012-12-07 14:05:40 154496 ----a-w- c:\windows\system32\Prounstl.exe
2012-12-07 14:03:08 -------- d-----w- c:\windows\system32\vmm32
2012-12-07 14:03:08 -------- d-----w- c:\program files\Dell
2012-12-07 14:00:58 -------- d-sh--w- c:\windows\Installer
2012-12-07 13:58:01 -------- d-----w- c:\users\fido\appdata\local\VirtualStore
2012-12-07 13:43:45 -------- d-----w- c:\windows\Panther
2012-12-07 13:43:09 -------- d-----w- c:\windows\system32\OEM
2012-12-07 13:30:22 -------- d-----w- C:\Windows.old
2012-12-07 03:55:40 -------- d-----w- C:\DellMPv3.1.1
2012-12-07 02:42:34 -------- d-----w- C:\temp
2012-12-07 01:06:19 -------- d-----w- C:\PerfLogs
2012-12-06 13:34:19 -------- d-----w- C:\inetpub
2012-12-06 01:15:11 -------- d-----w- C:\Intel
2012-12-06 01:12:09 -------- d-----w- C:\dell
2012-12-06 00:14:07 -------- d-sh--w- C:\Boot
.
==================== Find3M ====================
.
2012-12-07 16:09:46 72704 ----a-w- c:\windows\system32\admparse.dll
2012-12-07 16:09:45 832512 ----a-w- c:\windows\system32\wininet.dll
2012-12-07 16:09:45 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2012-12-07 16:09:42 389120 ----a-w- c:\windows\system32\html.iec
2012-12-07 16:09:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-12-07 16:09:41 48128 ----a-w- c:\windows\system32\mshtmler.dll
2012-12-07 16:09:40 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-07 16:09:38 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-07 16:09:37 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2012-12-07 16:09:35 56320 ----a-w- c:\windows\system32\iesetup.dll
2012-12-07 15:38:53 1808896 ----a-w- c:\windows\system32\NlsLexicons0046.dll
2012-12-07 15:35:25 5632 ----a-w- c:\windows\system32\drivers\en-us\sermouse.sys.mui
2012-12-07 15:31:25 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2012-12-07 15:24:37 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2012-12-07 15:24:37 2143744 ----a-w- c:\windows\apppatch\AcGenral.dll
2012-12-07 15:24:36 537600 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-12-07 15:24:36 449024 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2012-12-07 15:24:36 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
.
============= FINISH: 7:27:32.13 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-08 07:30:11
-----------------------------
07:30:11.003 OS Version: Windows 6.0.6000
07:30:11.003 Number of processors: 2 586 0xF0B
07:30:11.003 ComputerName: FIDO-PC UserName: fido
07:30:11.877 Initialize success
07:33:47.516 AVAST engine defs: 12120700
07:43:00.645 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
07:43:00.660 Disk 0 Vendor: ST380815AS 4.ADA Size: 76293MB BusType: 3
07:43:00.676 Disk 0 MBR read successfully
07:43:00.676 Disk 0 MBR scan
07:43:00.676 Disk 0 Windows VISTA default MBR code
07:43:00.692 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76291 MB offset 2048
07:43:00.707 Disk 0 scanning sectors +156246016
07:43:00.785 Disk 0 scanning C:\Windows\system32\drivers
07:43:11.846 Service scanning
07:43:21.798 Service MpKsl6041ee77 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BB5B9871-8949-47FA-9E4A-941A7D8098D2}\MpKsl6041ee77.sys **LOCKED** 32
07:43:37.554 Modules scanning
07:43:44.138 Disk 0 trace - called modules:
07:43:44.169 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll pciide.sys PCIIDEX.SYS atapi.sys
07:43:44.184 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84df1ad8]
07:43:44.184 3 ntkrnlpa.exe[818b07e2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x848a48b8]
07:43:44.684 AVAST engine scan C:\Windows
07:43:46.478 AVAST engine scan C:\Windows\system32
07:46:18.968 AVAST engine scan C:\Windows\system32\drivers
07:46:33.600 AVAST engine scan C:\Users\fido
07:47:03.406 AVAST engine scan C:\ProgramData
07:47:14.794 Scan finished successfully
07:47:15.200 Disk 0 MBR has been saved successfully to "C:\Users\fido\Documents\dds\MBR.dat"
07:47:15.216 The log file has been saved successfully to "C:\Users\fido\Documents\dds\aswMBR.txt"
07:47:27.134 Disk 0 MBR has been saved successfully to "C:\Users\fido\Desktop\MBR.dat"
07:47:27.134 The log file has been saved successfully to "C:\Users\fido\Desktop\aswMBR.txt"
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.16982
Run by fido at 7:27:18 on 2012-12-08
Microsoft® Windows Vista™ Business 6.0.6000.0.1252.1.1033.18.3316.1946 [GMT -8:00]
.
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\AMT\atchk.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_5_502_110_ActiveX.exe
C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\System32\svchost.exe -k wdisvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Spybot-S&D Cleaning] "c:\program files\spybot - search & destroy 2\SDCleaner.exe" /autoclean
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
StartupFolder: c:\users\fido\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.11.0.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{47B72BCD-B410-4D07-8519-46E98618273F} : DHCPNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-12-8 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-12-8 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2012-12-8 168384]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2012-12-7 2521880]
.
=============== Created Last 30 ================
.
2012-12-08 13:48:19 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-12-08 13:48:11 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-12-08 13:48:04 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-12-08 11:03:57 268800 ----a-w- c:\windows\system32\es.dll
2012-12-08 10:27:31 229888 ----a-w- c:\windows\system32\msshsq.dll
2012-12-08 10:17:52 -------- d-----w- c:\users\fido\appdata\local\Deployment
2012-12-08 10:17:52 -------- d-----w- c:\users\fido\appdata\local\Apps
2012-12-08 10:01:18 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{bb5b9871-8949-47fa-9e4a-941a7d8098d2}\mpengine.dll
2012-12-08 08:47:41 -------- d-----w- c:\users\fido\New Folder
2012-12-08 08:27:34 -------- d-----w- c:\windows\pss
2012-12-08 08:10:02 6812136 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-12-08 08:02:19 -------- d-----w- c:\program files\Microsoft Security Client
2012-12-08 07:47:47 96760 ----a-w- c:\windows\system32\dfshim.dll
2012-12-08 07:47:43 41984 ----a-w- c:\windows\system32\netfxperf.dll
2012-12-08 07:47:41 83968 ----a-w- c:\windows\system32\mscories.dll
2012-12-08 07:47:41 282112 ----a-w- c:\windows\system32\mscoree.dll
2012-12-08 07:47:41 158720 ----a-w- c:\windows\system32\mscorier.dll
2012-12-08 07:30:50 -------- d-----w- c:\program files\SystemRequirementsLab
2012-12-08 07:26:11 -------- d-----w- c:\program files\GUMDA57.tmp
2012-12-08 07:25:05 -------- d-----w- c:\users\fido\appdata\local\Google
2012-12-08 07:24:45 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-08 07:24:45 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-07 16:10:53 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-12-07 16:10:53 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-07 16:10:53 289792 ----a-w- c:\windows\system32\atmfd.dll
2012-12-07 16:10:53 24064 ----a-w- c:\windows\system32\lpk.dll
2012-12-07 16:10:53 156672 ----a-w- c:\windows\system32\t2embed.dll
2012-12-07 16:10:53 10240 ----a-w- c:\windows\system32\dciman32.dll
2012-12-07 16:08:13 61440 ----a-w- c:\windows\system32\winipsec.dll
2012-12-07 16:08:13 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2012-12-07 16:08:13 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2012-12-07 16:08:13 272896 ----a-w- c:\windows\system32\polstore.dll
2012-12-07 16:06:57 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-12-07 16:06:56 306688 ----a-w- c:\windows\system32\drivers\srv.sys
2012-12-07 16:06:20 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2012-12-07 16:06:20 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2012-12-07 16:06:20 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2012-12-07 16:05:45 87040 ----a-w- c:\windows\system32\msoert2.dll
2012-12-07 16:05:45 707072 ----a-w- c:\program files\common files\system\wab32.dll
2012-12-07 16:05:45 41984 ----a-w- c:\program files\windows mail\wabimp.dll
2012-12-07 16:05:45 39424 ----a-w- c:\windows\system32\ACCTRES.dll
2012-12-07 16:05:45 205824 ----a-w- c:\windows\system32\msoeacct.dll
2012-12-07 16:05:45 1098752 ----a-w- c:\program files\common files\system\wab32res.dll
2012-12-07 16:05:44 2836992 ----a-w- c:\program files\windows mail\MSOERES.dll
2012-12-07 16:05:44 1614848 ----a-w- c:\program files\windows mail\msoe.dll
2012-12-07 16:05:42 397312 ----a-w- c:\program files\windows mail\WinMail.exe
2012-12-07 16:05:41 81408 ----a-w- c:\program files\windows mail\oeimport.dll
2012-12-07 16:05:41 24064 ----a-w- c:\program files\common files\system\DirectDB.dll
2012-12-07 16:04:50 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2012-12-07 16:04:50 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2012-12-07 16:04:50 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2012-12-07 16:04:50 19968 ----a-w- c:\windows\system32\ARP.EXE
2012-12-07 16:04:50 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2012-12-07 16:04:50 15360 ----a-w- c:\windows\system32\netevent.dll
2012-12-07 16:04:50 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2012-12-07 16:04:50 103936 ----a-w- c:\windows\system32\netiohlp.dll
2012-12-07 16:04:50 10240 ----a-w- c:\windows\system32\finger.exe
2012-12-07 16:03:55 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2012-12-07 16:03:55 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2012-12-07 16:03:54 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2012-12-07 16:03:54 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2012-12-07 16:03:52 542720 ----a-w- c:\windows\system32\sysmain.dll
2012-12-07 16:03:20 194560 ----a-w- c:\windows\system32\WebClnt.dll
2012-12-07 16:03:20 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2012-12-07 16:02:47 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2012-12-07 16:02:46 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2012-12-07 16:02:46 502272 ----a-w- c:\windows\system32\wlansvc.dll
2012-12-07 16:02:46 47104 ----a-w- c:\windows\system32\wlanapi.dll
2012-12-07 16:02:46 297984 ----a-w- c:\windows\system32\wlansec.dll
2012-12-07 16:02:46 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2012-12-07 16:02:04 2048 ----a-w- c:\windows\system32\msxml6r.dll
2012-12-07 16:02:04 2048 ----a-w- c:\windows\system32\msxml3r.dll
2012-12-07 16:02:04 1406464 ----a-w- c:\windows\system32\msxml6.dll
2012-12-07 16:02:04 1260032 ----a-w- c:\windows\system32\msxml3.dll
2012-12-07 16:01:21 997912 ----a-w- c:\windows\system32\igxpun.exe
2012-12-07 16:01:21 -------- d-----w- c:\windows\system32\x64
2012-12-07 16:00:39 216576 ----a-w- c:\windows\system32\msv1_0.dll
2012-12-07 16:00:02 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-12-07 16:00:02 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-12-07 16:00:02 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-12-07 15:59:32 49664 ----a-w- c:\windows\system32\csrsrv.dll
2012-12-07 15:59:31 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-12-07 15:58:59 98816 ----a-w- c:\windows\system32\mfps.dll
2012-12-07 15:58:59 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2012-12-07 15:58:59 2855424 ----a-w- c:\windows\system32\mf.dll
2012-12-07 15:58:59 24576 ----a-w- c:\windows\system32\mfpmp.exe
2012-12-07 15:58:59 2048 ----a-w- c:\windows\system32\mferror.dll
2012-12-07 15:58:18 3502480 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-12-07 15:58:18 3468168 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-12-07 15:56:45 376832 ----a-w- c:\windows\system32\winhttp.dll
2012-12-07 15:56:11 434176 ----a-w- c:\windows\system32\vbscript.dll
2012-12-07 15:55:36 71680 ----a-w- c:\windows\system32\atl.dll
2012-12-07 15:54:34 297472 ----a-w- c:\windows\system32\gdi32.dll
2012-12-07 15:54:04 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2012-12-07 15:54:04 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-12-07 15:52:05 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2012-12-07 15:51:38 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2012-12-07 15:51:38 30208 ----a-w- c:\windows\system32\xolehlp.dll
2012-12-07 15:51:06 156160 ----a-w- c:\windows\system32\wkssvc.dll
2012-12-07 15:50:31 116736 ----a-w- c:\windows\system32\aaclient.dll
2012-12-07 15:50:30 36352 ----a-w- c:\windows\system32\tsgqec.dll
2012-12-07 15:50:30 1871872 ----a-w- c:\windows\system32\mstscax.dll
2012-12-07 15:49:55 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2012-12-07 15:48:54 414208 ----a-w- c:\windows\system32\msscp.dll
2012-12-07 15:47:43 713728 ----a-w- c:\windows\system32\timedate.cpl
2012-12-07 15:47:10 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2012-12-07 15:46:41 86016 ----a-w- c:\windows\system32\icfupgd.dll
2012-12-07 15:46:41 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2012-12-07 15:46:41 61952 ----a-w- c:\windows\system32\cmifw.dll
2012-12-07 15:46:41 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2012-12-07 15:46:41 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2012-12-07 15:46:41 16896 ----a-w- c:\windows\system32\wfapigp.dll
2012-12-07 15:45:41 23040 ----a-w- c:\program files\movie maker\WMM2EXT.dll
2012-12-07 15:45:41 150016 ----a-w- c:\program files\movie maker\MOVIEMK.exe
2012-12-07 15:45:41 10922496 ----a-w- c:\program files\movie maker\MOVIEMK.dll
2012-12-07 15:45:40 195072 ----a-w- c:\program files\movie maker\WMM2AE.dll
2012-12-07 15:43:14 2048 ----a-w- c:\windows\system32\tzres.dll
2012-12-07 15:42:34 696832 ----a-w- c:\windows\system32\localspl.dll
2012-12-07 15:42:06 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
2012-12-07 15:42:05 45112 ----a-w- c:\windows\system32\drivers\pciidex.sys
2012-12-07 15:42:05 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
2012-12-07 15:42:05 15928 ----a-w- c:\windows\system32\drivers\pciide.sys
2012-12-07 15:42:05 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
2012-12-07 15:42:05 109624 ----a-w- c:\windows\system32\drivers\ataport.sys
2012-12-07 15:41:43 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2012-12-07 15:41:19 2923520 ----a-w- c:\windows\explorer.exe
2012-12-07 15:40:24 171520 ----a-w- c:\windows\system32\wintrust.dll
2012-12-07 15:39:51 7680 ----a-w- c:\windows\system32\lsass.exe
2012-12-07 15:39:51 72704 ----a-w- c:\windows\system32\secur32.dll
2012-12-07 15:39:51 494592 ----a-w- c:\windows\system32\kerberos.dll
2012-12-07 15:39:51 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-12-07 15:39:51 175104 ----a-w- c:\windows\system32\wdigest.dll
2012-12-07 15:39:51 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2012-12-07 15:39:50 272384 ----a-w- c:\windows\system32\schannel.dll
2012-12-07 15:39:22 24064 ----a-w- c:\windows\system32\netcfg.exe
2012-12-07 15:35:40 1585664 ----a-w- c:\windows\system32\setupapi.dll
2012-12-07 15:34:18 549888 ----a-w- c:\windows\system32\rpcss.dll
2012-12-07 15:34:17 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2012-12-07 15:34:17 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2012-12-07 15:34:17 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2012-12-07 15:34:17 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2012-12-07 15:34:17 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2012-12-07 15:34:17 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2012-12-07 15:34:16 97280 ----a-w- c:\windows\system32\iasrecst.dll
2012-12-07 15:34:16 53248 ----a-w- c:\windows\system32\iasads.dll
2012-12-07 15:34:16 37888 ----a-w- c:\windows\system32\iasdatastore.dll
2012-12-07 15:34:16 158720 ----a-w- c:\windows\system32\sdohlp.dll
2012-12-07 15:33:46 62464 ----a-w- c:\windows\system32\l3codeca.acm
2012-12-07 15:33:46 220672 ----a-w- c:\windows\system32\l3codecp.acm
2012-12-07 15:32:51 815104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-12-07 15:32:51 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2012-12-07 15:32:51 22016 ----a-w- c:\windows\system32\netiougc.exe
2012-12-07 15:32:51 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2012-12-07 15:32:51 179712 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-12-07 15:32:51 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2012-12-07 15:32:51 15360 ----a-w- c:\windows\system32\drivers\TUNMP.SYS
2012-12-07 15:32:08 454656 ----a-w- c:\program files\common files\system\msadc\msadce.dll
2012-12-07 15:31:46 9728 ----a-w- c:\windows\system32\LAPRXY.DLL
2012-12-07 15:31:46 223232 ----a-w- c:\windows\system32\WMASF.DLL
2012-12-07 15:31:46 2048 ----a-w- c:\windows\system32\asferror.dll
2012-12-07 15:31:25 25600 ----a-w- c:\windows\system32\amxread.dll
2012-12-07 15:31:24 14848 ----a-w- c:\windows\system32\apilogen.dll
2012-12-07 15:30:56 33280 ----a-w- c:\windows\system32\slwmi.dll
2012-12-07 15:30:56 268288 ----a-w- c:\windows\system32\mcbuilder.exe
2012-12-07 15:30:56 223232 ----a-w- c:\windows\system32\SLC.dll
2012-12-07 15:30:55 57856 ----a-w- c:\windows\system32\SLUINotify.dll
2012-12-07 15:30:55 566784 ----a-w- c:\windows\system32\SLCommDlg.dll
2012-12-07 15:30:55 39936 ----a-w- c:\windows\system32\slcinst.dll
2012-12-07 15:30:55 351232 ----a-w- c:\windows\system32\SLUI.exe
2012-12-07 15:30:55 2605568 ----a-w- c:\windows\system32\SLsvc.exe
2012-12-07 15:30:55 186368 ----a-w- c:\windows\system32\SLLUA.exe
2012-12-07 15:30:27 712192 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-12-07 15:30:27 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-12-07 15:30:26 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-12-07 15:29:56 97792 ----a-w- c:\windows\system32\cabview.dll
2012-12-07 15:29:06 320000 ----a-w- c:\windows\system32\drivers\csc.sys
2012-12-07 15:29:06 105984 ----a-w- c:\windows\system32\CscMig.dll
2012-12-07 15:29:03 61440 ----a-w- c:\windows\system32\ntprint.exe
2012-12-07 15:29:03 220160 ----a-w- c:\windows\system32\ntprint.dll
2012-12-07 15:29:02 1984512 ----a-w- c:\windows\system32\authui.dll
2012-12-07 15:29:02 120320 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-12-07 15:29:02 10240 ----a-w- c:\windows\system32\dhcpcmonitor.dll
2012-12-07 15:29:01 8138240 ----a-w- c:\windows\system32\ssBranded.scr
2012-12-07 15:29:01 69632 ----a-w- c:\windows\system32\sendmail.dll
2012-12-07 15:28:16 441856 ----a-w- c:\windows\system32\win32spl.dll
2012-12-07 15:28:16 37376 ----a-w- c:\windows\system32\printcom.dll
2012-12-07 15:27:54 2031104 ----a-w- c:\windows\system32\win32k.sys
2012-12-07 15:27:33 14848 ----a-w- c:\windows\system32\wshrm.dll
2012-12-07 15:27:33 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2012-12-07 15:27:22 2565432 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2012-12-07 15:27:16 6812136 ---ha-w- c:\programdata\microsoft\windows defender\definition updates\{d6b8f43e-ebcc-4c70-854f-aaa24a31a9f8}\mpengine.dll
2012-12-07 15:27:15 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-12-07 15:26:50 43520 ----a-w- c:\windows\system32\msdxm.tlb
2012-12-07 15:26:50 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2012-12-07 15:26:50 18432 ----a-w- c:\windows\system32\amcompat.tlb
2012-12-07 15:26:14 435712 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2012-12-07 15:26:14 431104 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2012-12-07 15:26:14 312320 ----a-w- c:\windows\system32\msdrm.dll
2012-12-07 15:26:14 154624 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2012-12-07 15:26:14 154112 ----a-w- c:\windows\system32\secproc_ssp.dll
2012-12-07 15:26:13 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2012-12-07 15:26:13 515584 ----a-w- c:\windows\system32\RMActivate.exe
2012-12-07 15:26:13 473088 ----a-w- c:\windows\system32\secproc_isv.dll
2012-12-07 15:26:13 472576 ----a-w- c:\windows\system32\secproc.dll
2012-12-07 15:25:51 66048 ----a-w- c:\program files\windows sidebar\sbdrop.dll
2012-12-07 15:25:51 1232896 ----a-w- c:\program files\windows sidebar\sidebar.exe
2012-12-07 15:25:51 11776 ----a-w- c:\windows\system32\sbunattend.exe
2012-12-07 15:25:27 83968 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-12-07 15:25:27 24576 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-12-07 15:25:19 53760 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2012-12-07 15:24:37 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2012-12-07 15:24:36 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2012-12-07 15:24:35 1686528 ----a-w- c:\windows\system32\gameux.dll
2012-12-07 15:23:58 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2012-12-07 15:23:58 94720 ----a-w- c:\windows\system32\logagent.exe
2012-12-07 15:23:25 765952 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2012-12-07 15:23:12 84480 ----a-w- c:\windows\system32\INETRES.dll
2012-12-07 15:23:12 737792 ----a-w- c:\windows\system32\inetcomm.dll
2012-12-07 15:22:49 60928 ----a-w- c:\windows\system32\msasn1.dll
2012-12-07 15:22:29 1645568 ----a-w- c:\windows\system32\connect.dll
2012-12-07 15:22:13 5120 ----a-w- c:\windows\system32\wmi.dll
2012-12-07 15:22:13 152576 ----a-w- c:\windows\system32\imagehlp.dll
2012-12-07 15:22:13 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-12-07 15:21:56 788992 ----a-w- c:\windows\system32\rpcrt4.dll
2012-12-07 15:21:17 396800 ----a-w- c:\windows\system32\drivers\http.sys
2012-12-07 15:21:17 31232 ----a-w- c:\windows\system32\httpapi.dll
2012-12-07 15:21:17 24064 ----a-w- c:\windows\system32\nshhttp.dll
2012-12-07 15:19:51 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-12-07 15:19:39 974336 ----a-w- c:\windows\system32\crypt32.dll
2012-12-07 15:19:28 274432 ----a-w- c:\windows\system32\raschap.dll
2012-12-07 15:19:28 232960 ----a-w- c:\windows\system32\rastls.dll
2012-12-07 15:19:10 321536 ----a-w- c:\windows\system32\WSDApi.dll
2012-12-07 15:17:48 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2012-12-07 15:17:24 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2012-12-07 15:17:24 7680 ----a-w- c:\windows\system32\spwmp.dll
2012-12-07 15:17:23 4096 ----a-w- c:\windows\system32\msdxm.ocx
2012-12-07 15:17:23 4096 ----a-w- c:\windows\system32\dxmasf.dll
2012-12-07 15:17:23 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2012-12-07 15:17:23 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
2012-12-07 15:17:23 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
2012-12-07 15:17:21 311296 ----a-w- c:\windows\system32\unregmp2.exe
2012-12-07 15:17:21 1418240 ----a-w- c:\program files\windows media player\setup_wm.exe
2012-12-07 14:07:22 920344 ----a-w- c:\windows\system32\mesoludlg.exe
2012-12-07 14:07:22 319456 ----a-w- c:\windows\system32\difxapi.dll
2012-12-07 14:07:22 -------- d-----w- c:\windows\system32\Lang
2012-12-07 14:07:22 -------- d-----w- c:\program files\common files\postureAgent
2012-12-07 14:05:43 39288 ----a-w- c:\windows\system32\NicInE6.dll
2012-12-07 14:05:42 28536 ----a-w- c:\windows\system32\NicCo6.dll
2012-12-07 14:05:42 228224 ----a-w- c:\windows\system32\drivers\e1e6032.sys
2012-12-07 14:05:40 179048 ----a-w- c:\windows\system32\e1000msg.dll
2012-12-07 14:05:40 154496 ----a-w- c:\windows\system32\Prounstl.exe
2012-12-07 14:03:08 -------- d-----w- c:\windows\system32\vmm32
2012-12-07 14:03:08 -------- d-----w- c:\program files\Dell
2012-12-07 14:00:58 -------- d-sh--w- c:\windows\Installer
2012-12-07 13:58:01 -------- d-----w- c:\users\fido\appdata\local\VirtualStore
2012-12-07 13:43:45 -------- d-----w- c:\windows\Panther
2012-12-07 13:43:09 -------- d-----w- c:\windows\system32\OEM
2012-12-07 13:30:22 -------- d-----w- C:\Windows.old
2012-12-07 03:55:40 -------- d-----w- C:\DellMPv3.1.1
2012-12-07 02:42:34 -------- d-----w- C:\temp
2012-12-07 01:06:19 -------- d-----w- C:\PerfLogs
2012-12-06 13:34:19 -------- d-----w- C:\inetpub
2012-12-06 01:15:11 -------- d-----w- C:\Intel
2012-12-06 01:12:09 -------- d-----w- C:\dell
2012-12-06 00:14:07 -------- d-sh--w- C:\Boot
.
==================== Find3M ====================
.
2012-12-07 16:09:46 72704 ----a-w- c:\windows\system32\admparse.dll
2012-12-07 16:09:45 832512 ----a-w- c:\windows\system32\wininet.dll
2012-12-07 16:09:45 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2012-12-07 16:09:42 389120 ----a-w- c:\windows\system32\html.iec
2012-12-07 16:09:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2012-12-07 16:09:41 48128 ----a-w- c:\windows\system32\mshtmler.dll
2012-12-07 16:09:40 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2012-12-07 16:09:38 1830912 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-07 16:09:37 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2012-12-07 16:09:35 56320 ----a-w- c:\windows\system32\iesetup.dll
2012-12-07 15:38:53 1808896 ----a-w- c:\windows\system32\NlsLexicons0046.dll
2012-12-07 15:35:25 5632 ----a-w- c:\windows\system32\drivers\en-us\sermouse.sys.mui
2012-12-07 15:31:25 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2012-12-07 15:24:37 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2012-12-07 15:24:37 2143744 ----a-w- c:\windows\apppatch\AcGenral.dll
2012-12-07 15:24:36 537600 ----a-w- c:\windows\apppatch\AcLayers.dll
2012-12-07 15:24:36 449024 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2012-12-07 15:24:36 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
.
============= FINISH: 7:27:32.13 ===============
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-12-08 07:30:11
-----------------------------
07:30:11.003 OS Version: Windows 6.0.6000
07:30:11.003 Number of processors: 2 586 0xF0B
07:30:11.003 ComputerName: FIDO-PC UserName: fido
07:30:11.877 Initialize success
07:33:47.516 AVAST engine defs: 12120700
07:43:00.645 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
07:43:00.660 Disk 0 Vendor: ST380815AS 4.ADA Size: 76293MB BusType: 3
07:43:00.676 Disk 0 MBR read successfully
07:43:00.676 Disk 0 MBR scan
07:43:00.676 Disk 0 Windows VISTA default MBR code
07:43:00.692 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76291 MB offset 2048
07:43:00.707 Disk 0 scanning sectors +156246016
07:43:00.785 Disk 0 scanning C:\Windows\system32\drivers
07:43:11.846 Service scanning
07:43:21.798 Service MpKsl6041ee77 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{BB5B9871-8949-47FA-9E4A-941A7D8098D2}\MpKsl6041ee77.sys **LOCKED** 32
07:43:37.554 Modules scanning
07:43:44.138 Disk 0 trace - called modules:
07:43:44.169 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll pciide.sys PCIIDEX.SYS atapi.sys
07:43:44.184 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84df1ad8]
07:43:44.184 3 ntkrnlpa.exe[818b07e2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x848a48b8]
07:43:44.684 AVAST engine scan C:\Windows
07:43:46.478 AVAST engine scan C:\Windows\system32
07:46:18.968 AVAST engine scan C:\Windows\system32\drivers
07:46:33.600 AVAST engine scan C:\Users\fido
07:47:03.406 AVAST engine scan C:\ProgramData
07:47:14.794 Scan finished successfully
07:47:15.200 Disk 0 MBR has been saved successfully to "C:\Users\fido\Documents\dds\MBR.dat"
07:47:15.216 The log file has been saved successfully to "C:\Users\fido\Documents\dds\aswMBR.txt"
07:47:27.134 Disk 0 MBR has been saved successfully to "C:\Users\fido\Desktop\MBR.dat"
07:47:27.134 The log file has been saved successfully to "C:\Users\fido\Desktop\aswMBR.txt"