Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: my computer has a nasty virus

  1. #1
    Junior Member
    Join Date
    Aug 2011
    Posts
    24

    Default my computer has a nasty virus

    Hi there,

    My computer is playing sounds randomly without me opening any programs, it is not allowing me to open websites I choose (and instead directing me to advertising websites), and it won't let me open Windows Security Essentials. Here is the DDS log:

    DDS log:

    .
    DDS (Ver_2011-06-23.01) - NTFSAMD64
    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26
    Run by Owner at 22:09:50 on 2011-08-13
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.6143.4430 [GMT 10:00]
    .
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\rundll32.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
    C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: H - No File
    mWinlogon: Userinit=userinit.exe
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    uRun: [DriverFinder] C:\Program Files (x86)\DriverFinder\DriverFinder.exe
    uRun: [googletalk] C:\Users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
    uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
    uRun: [8DDYX0ZBPZ] C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FP10CO~1.LNK - C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    TCP: DhcpNameServer = 211.31.138.11 211.29.132.12
    TCP: Interfaces\{4DC68007-8B57-4F62-8F3B-EB583C05DF61} : DhcpNameServer = 10.1.1.1
    TCP: Interfaces\{F907E1BF-CC5A-43D6-8FCA-32738CB2B923} : DhcpNameServer = 211.31.138.11 211.29.132.12
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    SEH-X64: Eudora's Shell Extension: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Adam Casey\AppData\Roaming\Mozilla\Firefox\Profiles\u88r5vt9.default\
    FF - prefs.js: browser.startup.homepage - www.google.com.au
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-21 1153368]
    R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
    R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
    S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192cu.sys --> C:\Windows\system32\DRIVERS\RTL8192cu.sys [?]
    S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
    S3 SynUSB64;SynUSB64;C:\Windows\system32\DRIVERS\SynUSB64.sys --> C:\Windows\system32\DRIVERS\SynUSB64.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== Created Last 30 ================
    .
    2011-08-12 13:39:48 -------- d-----w- C:\Users\Adam Casey\AppData\Local\eLicenser
    2011-08-12 13:39:27 -------- d-----w- C:\Program Files (x86)\Syncrosoft
    2011-08-12 13:39:26 -------- d-----w- C:\ProgramData\eLicenser
    2011-08-12 13:38:45 -------- d-----w- C:\Program Files (x86)\eLicenser
    2011-08-12 13:35:37 2892 ----a-w- C:\Windows\SysWow64\audcon.sys
    2011-08-12 13:35:37 -------- d-----w- C:\ProgramData\Syncrosoft
    2011-08-12 13:35:35 1695232 ----a-w- C:\Windows\System32\synsoacc.dll
    2011-08-12 13:35:28 29432 ----a-w- C:\Windows\System32\drivers\synUSB64.sys
    2011-08-12 13:35:27 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
    2011-08-12 13:35:22 401462 ----a-w- C:\Windows\SysWow64\temp.002
    2011-08-12 13:35:20 147456 ----a-w- C:\Windows\SysWow64\SynsoLChk.dll
    2011-08-12 13:35:20 1261568 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
    2011-08-12 13:34:55 163840 ----a-w- C:\Windows\SysWow64\ArtFfct.dll
    2011-08-12 13:34:53 -------- d-----w- C:\ProgramData\Arturia
    2011-08-12 13:34:53 -------- d-----w- C:\Program Files (x86)\Arturia
    2011-08-12 13:19:06 186880 ----a-w- C:\Windows\Mcymaa.exe
    2011-08-12 13:19:00 64512 --sha-r- C:\Windows\SysWow64\PSHEDU.dll
    2011-08-12 12:21:22 -------- d-----w- C:\Program Files (x86)\Common Files\Adobe Systems Shared
    2011-08-12 11:15:52 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2011-08-12 11:15:51 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{583709C9-2877-4304-B2A0-E8E456A41DCE}\gapaengine.dll
    2011-08-12 11:15:39 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AB22CCDD-2F44-496A-8F96-5CF3BDB938AE}\mpengine.dll
    2011-08-11 12:05:59 -------- d-sh--w- C:\Windows\System32\%APPDATA%
    2011-08-10 09:52:46 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\dBpoweramp
    2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\VstPlugins
    2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\Common Files\Digidesign
    2011-08-10 01:08:56 -------- d-----w- C:\Program Files (x86)\GForce
    2011-08-04 09:36:47 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\AccurateRip
    2011-08-04 09:36:45 685944 ----a-w- C:\Windows\SysWow64\SpoonUninstall.exe
    2011-08-04 09:36:34 -------- d-----w- C:\Program Files (x86)\Illustrate
    2011-08-04 09:31:51 -------- d-----w- C:\Program Files (x86)\SlySoft
    2011-08-04 09:21:59 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\LEAPS
    2011-08-04 09:20:24 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Pegasys Inc
    2011-08-04 09:18:43 -------- d-----w- C:\Program Files (x86)\Pegasys Inc
    2011-08-04 07:27:41 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Qualcomm
    2011-08-04 07:23:04 317952 ----a-w- C:\Windows\SysWow64\Roboex32.dll
    2011-08-04 07:23:04 1712128 ----a-w- C:\Windows\SysWow64\gdiplus.dll
    2011-08-04 07:23:04 -------- d-----w- C:\Program Files (x86)\Qualcomm
    2011-08-04 07:23:03 48640 ----a-w- C:\Windows\SysWow64\INETWH32.DLL
    2011-08-04 07:22:16 729088 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
    2011-08-04 07:22:16 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
    2011-08-04 07:22:16 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
    2011-08-04 07:22:16 266240 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
    2011-08-04 07:22:16 192512 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
    2011-08-04 07:22:15 311428 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
    2011-08-04 07:22:15 188548 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
    2011-08-02 03:10:07 -------- d-----w- C:\Users\Adam Casey\AppData\Local\etax2011
    2011-08-02 00:45:42 -------- d-----w- C:\Program Files (x86)\Suite Spot Studios
    2011-07-29 01:07:55 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\NeroDCTemplates
    2011-07-28 13:16:36 -------- d-----w- C:\VSTPlugins
    2011-07-28 13:16:35 -------- d-----w- C:\Program Files (x86)\Cakewalk
    2011-07-28 01:57:48 -------- d-----w- C:\Program Files\GForce
    2011-07-27 07:29:00 -------- d-----w- C:\Windows\System32\appmgmt
    2011-07-26 23:29:49 627744 ----a-r- C:\Windows\System32\drivers\rtl8192cu.sys
    2011-07-26 23:29:47 614400 ------r- C:\Windows\System32\Rtlihvs.dll
    2011-07-26 23:29:47 380928 ------r- C:\Windows\System32\RtlUI2.exe
    2011-07-26 23:29:46 188416 ------r- C:\Windows\System32\RTLExtUI.dll
    2011-07-26 23:29:33 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
    2011-07-26 03:57:06 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2011-07-26 03:31:04 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Cakewalk
    2011-07-26 03:26:54 -------- d-----w- C:\Program Files\Cakewalk
    2011-07-26 03:22:46 -------- d-----w- C:\Cakewalk Projects
    2011-07-24 03:44:15 -------- d-----w- C:\Windows\System32\SPReview
    2011-07-24 03:43:23 -------- d-----w- C:\Windows\System32\EventProviders
    2011-07-24 03:30:15 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DSETUP.dll
    2011-07-24 03:30:15 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DXSETUP.exe
    2011-07-24 03:30:15 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\dsetup32.dll
    2011-07-24 03:30:10 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DSETUP.dll
    2011-07-24 03:30:10 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DXSETUP.exe
    2011-07-24 03:30:10 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\dsetup32.dll
    2011-07-24 03:27:51 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\aa1a84891cc49b117\Silverlight.4.0.exe
    2011-07-24 03:25:03 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Windows Live
    2011-07-24 03:25:00 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
    2011-07-24 02:59:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip Courier
    2011-07-24 01:05:09 -------- d-----w- C:\ProgramData\WinZipEC
    2011-07-24 01:05:02 -------- d-----w- C:\Windows\CD95F661A5C411AFB2CCABCD21A325B4.TMP
    2011-07-24 01:03:53 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip
    2011-07-23 17:08:42 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
    2011-07-23 02:56:40 -------- d-----w- C:\ProgramData\KingsIsle Entertainment
    2011-07-23 02:51:35 -------- d-----r- C:\Program Files (x86)\Skype
    2011-07-23 01:53:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Activision
    2011-07-22 17:49:08 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-07-22 11:01:59 605696 ----a-w- C:\Windows\System32\wmpeffects.dll
    2011-07-22 11:00:59 95232 ----a-w- C:\Windows\System32\cca.dll
    2011-07-22 10:59:59 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
    2011-07-22 10:57:13 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
    2011-07-22 07:19:59 163644 ----a-w- C:\Windows\SysWow64\drivers\SECDRV.SYS
    2011-07-22 07:10:51 -------- d-----w- C:\Program Files (x86)\The Creative Assembly
    2011-07-22 07:10:22 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
    2011-07-22 07:10:22 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
    2011-07-22 07:10:22 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
    2011-07-22 07:10:22 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
    2011-07-22 07:10:22 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
    2011-07-22 07:10:22 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
    2011-07-22 07:10:22 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
    2011-07-22 07:10:15 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
    2011-07-22 07:10:14 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
    2011-07-22 04:31:10 -------- d-----w- C:\ProgramData\LightScribe
    2011-07-22 04:25:52 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Ahead
    2011-07-22 04:15:09 -------- d-----w- C:\ProgramData\Nero
    2011-07-22 04:15:09 -------- d-----w- C:\Program Files (x86)\Nero
    2011-07-22 03:16:36 -------- d-----w- C:\Windows\SysWow64\Wat
    2011-07-22 03:16:36 -------- d-----w- C:\Windows\System32\Wat
    2011-07-22 02:36:04 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
    2011-07-22 02:18:03 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2011-07-21 23:32:52 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
    2011-07-21 23:32:47 -------- d-----w- C:\Program Files (x86)\Steam
    2011-07-21 23:30:59 506728 ----a-w- C:\Windows\System32\d3dx10_33.dll
    2011-07-21 21:57:45 -------- d-----w- C:\Windows\Panther
    2011-07-21 21:45:27 -------- d-----w- C:\Windows.old
    2011-07-21 17:56:20 715776 ----a-w- C:\Windows\System32\kerberos.dll
    2011-07-21 17:56:20 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
    2011-07-21 17:55:48 142336 ----a-w- C:\Windows\System32\poqexec.exe
    2011-07-21 17:55:48 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
    2011-07-21 17:55:12 2871808 ----a-w- C:\Windows\explorer.exe
    2011-07-21 17:55:12 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
    2011-07-21 17:55:01 961024 ----a-w- C:\Windows\System32\CPFilters.dll
    2011-07-21 17:55:01 723968 ----a-w- C:\Windows\System32\EncDec.dll
    2011-07-21 17:55:00 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
    2011-07-21 17:55:00 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
    2011-07-21 17:55:00 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
    2011-07-21 17:55:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
    2011-07-21 17:54:59 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
    2011-07-21 17:54:59 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
    2011-07-21 17:52:54 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
    2011-07-21 17:52:53 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
    2011-07-21 17:50:34 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:50:34 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:49:06 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
    2011-07-21 17:49:06 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
    2011-07-21 17:49:00 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
    2011-07-21 17:49:00 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
    2011-07-21 17:47:59 244736 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
    2011-07-21 17:47:52 189952 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
    2011-07-21 17:43:45 613376 ----a-w- C:\Windows\System32\vbscript.dll
    2011-07-21 17:43:44 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2011-07-21 17:42:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
    2011-07-21 17:42:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
    2011-07-21 17:41:55 1395712 ----a-w- C:\Windows\System32\mfc42.dll
    2011-07-21 17:41:55 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
    2011-07-21 17:41:55 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
    2011-07-21 17:41:54 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
    2011-07-21 17:40:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
    2011-07-21 17:40:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
    2011-07-21 17:40:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
    2011-07-21 17:40:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
    2011-07-21 17:40:06 46080 ----a-w- C:\Windows\System32\atmlib.dll
    2011-07-21 17:40:06 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
    2011-07-21 17:37:56 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
    2011-07-21 17:34:04 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
    2011-07-21 17:34:03 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
    2011-07-21 17:34:03 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
    2011-07-21 17:32:43 321024 ----a-w- C:\Windows\System32\d3d10_1core.dll
    2011-07-21 17:32:43 219136 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
    2011-07-21 17:32:42 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
    2011-07-21 17:32:42 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
    2011-07-21 17:32:37 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
    2011-07-21 17:32:37 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
    2011-07-21 17:32:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
    2011-07-21 17:27:55 642944 ----a-w- C:\Windows\System32\winload.efi
    2011-07-21 17:27:55 605552 ----a-w- C:\Windows\System32\winload.exe
    2011-07-21 17:27:54 566208 ----a-w- C:\Windows\System32\winresume.efi
    2011-07-21 17:27:54 518672 ----a-w- C:\Windows\System32\winresume.exe
    2011-07-21 17:27:54 20352 ----a-w- C:\Windows\System32\kdusb.dll
    2011-07-21 17:27:54 19328 ----a-w- C:\Windows\System32\kd1394.dll
    2011-07-21 17:27:54 17792 ----a-w- C:\Windows\System32\kdcom.dll
    2011-07-21 17:27:53 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
    2011-07-21 17:27:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
    2011-07-21 17:27:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
    2011-07-21 17:26:39 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
    2011-07-21 17:26:39 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
    2011-07-21 17:26:39 207872 ----a-w- C:\Windows\System32\cfgmgr32.dll
    2011-07-21 17:26:39 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
    2011-07-21 17:26:38 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
    2011-07-21 17:26:38 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
    2011-07-21 17:26:17 3137536 ----a-w- C:\Windows\System32\win32k.sys
    2011-07-21 17:25:36 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
    2011-07-21 17:25:36 31232 ----a-w- C:\Windows\System32\prevhost.exe
    2011-07-21 17:25:34 974336 ----a-w- C:\Windows\System32\WFS.exe
    2011-07-21 17:25:34 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
    2011-07-21 17:25:33 976896 ----a-w- C:\Windows\System32\inetcomm.dll
    2011-07-21 17:25:33 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
    2011-07-21 17:25:27 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
    2011-07-21 16:21:29 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
    2011-07-21 15:48:54 -------- d-----w- C:\Program Files (x86)\etax2011
    2011-07-21 15:30:25 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
    2011-07-21 15:29:20 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Microsoft Help
    2011-07-21 15:02:15 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
    2011-07-21 15:01:40 -------- d-----w- C:\Program Files\DivX
    2011-07-21 15:01:32 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
    2011-07-21 15:00:42 -------- d-----w- C:\Program Files (x86)\DivX
    2011-07-21 15:00:18 -------- d-----w- C:\ProgramData\DivX
    2011-07-21 14:45:26 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Lexicon PCM Native
    2011-07-21 14:41:36 24576 ----a-w- C:\Windows\SysWow64\Hyperman.dll
    2011-07-21 14:41:35 24576 ----a-w- C:\Windows\SysWow64\Wavlbsys.dll
    2011-07-21 14:41:31 -------- d-----w- C:\Program Files (x86)\Sonic Foundry
    2011-07-21 14:40:19 401462 ----a-w- C:\Windows\SysWow64\temp.001
    2011-07-21 14:40:19 266293 ----a-w- C:\Windows\SysWow64\temp.000
    2011-07-21 14:39:18 -------- d-----w- C:\Program Files (x86)\Steinberg
    2011-07-21 14:39:03 -------- d-----w- C:\Program Files (x86)\Waves
    2011-07-21 13:27:23 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\InfinaDyne
    2011-07-21 13:26:36 -------- d-----w- C:\ProgramData\InfinaDyne
    2011-07-21 13:26:36 -------- d-----w- C:\Program Files (x86)\InfinaDyne
    2011-07-21 12:39:13 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
    2011-07-21 12:39:13 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
    2011-07-21 12:33:02 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
    2011-07-21 12:32:51 -------- d-----w- C:\Program Files\Microsoft Security Client
    2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\PC Unleashed Online
    2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverCure
    2011-07-21 09:06:38 -------- d-----w- C:\ProgramData\PC Unleashed Online
    2011-07-21 09:05:51 -------- d-----w- C:\Users\Adam Casey\AppData\Local\PC_Drivers_Headquarters
    2011-07-21 08:59:33 -------- d-----w- C:\ProgramData\PC Drivers HeadQuarters
    2011-07-21 08:49:49 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverFinder
    2011-07-21 08:24:14 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2011-07-21 08:21:29 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\.minecraft
    2011-07-21 07:40:29 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Google
    2011-07-21 07:39:57 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
    2011-07-21 07:39:56 -------- d-----w- C:\ProgramData\{A97DA822-7B29-4F18-A64A-BF94FFFE77FB}
    2011-07-21 07:36:53 -------- d-----w- C:\Program Files (x86)\Lexicon
    2011-07-21 07:32:42 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Adobe
    2011-07-21 07:30:03 -------- d-----w- C:\Audio
    2011-07-21 07:27:42 -------- d-----w- C:\Windows\Downloaded Installations
    2011-07-21 06:55:36 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
    2011-07-21 06:55:24 -------- d-----w- C:\Windows\PCHEALTH
    2011-07-21 06:47:51 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3283C0BE-461D-4A04-8B8E-74E81274F083}\mpengine.dll
    2011-07-21 06:47:51 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2011-07-21 06:42:38 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Apple
    2011-07-21 06:42:19 -------- d-----w- C:\Program Files\Bonjour
    2011-07-21 06:42:19 -------- d-----w- C:\Program Files (x86)\Bonjour
    2011-07-21 06:41:44 -------- d-sh--w- C:\Windows\Installer
    2011-07-21 06:33:48 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-21 04:39:47 -------- d-----w- C:\Users\Adam Casey\AppData\Local\ElevatedDiagnostics
    2011-07-21 04:04:47 0 ----a-w- C:\Windows\ativpsrm.bin
    .
    ==================== Find3M ====================
    .
    2011-07-24 03:51:31 175616 ----a-w- C:\Windows\System32\msclmd.dll
    2011-07-24 03:51:31 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
    2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
    2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
    2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2011-07-12 01:34:00 96104 ----a-w- C:\Windows\System32\dns-sd.exe
    2011-07-12 01:34:00 85864 ----a-w- C:\Windows\System32\dnssd.dll
    2011-07-12 01:34:00 61288 ----a-w- C:\Windows\System32\jdns_sd.dll
    2011-07-12 01:34:00 212840 ----a-w- C:\Windows\System32\dnssdX.dll
    2011-07-12 01:20:54 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
    2011-07-12 01:20:54 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
    2011-07-12 01:20:54 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
    2011-07-12 01:20:54 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
    2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
    2011-07-05 08:37:00 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
    2011-07-05 08:37:00 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
    2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
    2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
    2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
    2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
    2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
    2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
    2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
    2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
    2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
    2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
    2011-06-02 17:53:02 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
    .
    ============= FINISH: 22:13:19.81 ===============

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hello,

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent
    DC++


    I'd like you to read this thread.

    Please go uninstall the programs listed above (in red).
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Junior Member
    Join Date
    Aug 2011
    Posts
    24

    Default

    Okay: both uninstalled. What's next?

    cheers,

    Adam

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Post fresh dds logs, please.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Junior Member
    Join Date
    Aug 2011
    Posts
    24

    Default

    .
    DDS (Ver_2011-06-23.01) - NTFSAMD64
    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26
    Run by Adam Casey at 15:49:48 on 2011-08-18
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.6143.4149 [GMT 10:00]
    .
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\iTunes\iTunes.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: H - No File
    mWinlogon: Userinit=userinit.exe
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    uRun: [DriverFinder] C:\Program Files (x86)\DriverFinder\DriverFinder.exe
    uRun: [googletalk] C:\Users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
    uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
    uRun: [8DDYX0ZBPZ] C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FP10CO~1.LNK - C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    TCP: DhcpNameServer = 211.31.138.11 211.29.132.12
    TCP: Interfaces\{4DC68007-8B57-4F62-8F3B-EB583C05DF61} : DhcpNameServer = 10.1.1.1
    TCP: Interfaces\{F907E1BF-CC5A-43D6-8FCA-32738CB2B923} : DhcpNameServer = 211.31.138.11 211.29.132.12
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    SEH-X64: Eudora's Shell Extension: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
    Hosts: 127.0.0.1 www.spywareinfo.com
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Adam Casey\AppData\Roaming\Mozilla\Firefox\Profiles\u88r5vt9.default\
    FF - prefs.js: browser.startup.homepage - www.google.com.au
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-21 1153368]
    S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
    S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
    S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192cu.sys --> C:\Windows\system32\DRIVERS\RTL8192cu.sys [?]
    S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
    S3 SynUSB64;SynUSB64;C:\Windows\system32\DRIVERS\SynUSB64.sys --> C:\Windows\system32\DRIVERS\SynUSB64.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== Created Last 30 ================
    .
    2011-08-12 13:39:48 -------- d-----w- C:\Users\Adam Casey\AppData\Local\eLicenser
    2011-08-12 13:39:27 -------- d-----w- C:\Program Files (x86)\Syncrosoft
    2011-08-12 13:39:26 -------- d-----w- C:\ProgramData\eLicenser
    2011-08-12 13:38:45 -------- d-----w- C:\Program Files (x86)\eLicenser
    2011-08-12 13:35:37 2892 ----a-w- C:\Windows\SysWow64\audcon.sys
    2011-08-12 13:35:37 -------- d-----w- C:\ProgramData\Syncrosoft
    2011-08-12 13:35:35 1695232 ----a-w- C:\Windows\System32\synsoacc.dll
    2011-08-12 13:35:28 29432 ----a-w- C:\Windows\System32\drivers\synUSB64.sys
    2011-08-12 13:35:27 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
    2011-08-12 13:35:22 401462 ----a-w- C:\Windows\SysWow64\temp.002
    2011-08-12 13:35:20 147456 ----a-w- C:\Windows\SysWow64\SynsoLChk.dll
    2011-08-12 13:35:20 1261568 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
    2011-08-12 13:34:55 163840 ----a-w- C:\Windows\SysWow64\ArtFfct.dll
    2011-08-12 13:34:53 -------- d-----w- C:\ProgramData\Arturia
    2011-08-12 13:34:53 -------- d-----w- C:\Program Files (x86)\Arturia
    2011-08-12 13:19:06 186880 ----a-w- C:\Windows\Mcymaa.exe
    2011-08-12 13:19:00 64512 --sha-r- C:\Windows\SysWow64\PSHEDU.dll
    2011-08-12 12:21:22 -------- d-----w- C:\Program Files (x86)\Common Files\Adobe Systems Shared
    2011-08-12 11:15:52 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2011-08-12 11:15:51 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{583709C9-2877-4304-B2A0-E8E456A41DCE}\gapaengine.dll
    2011-08-12 11:15:39 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AB22CCDD-2F44-496A-8F96-5CF3BDB938AE}\mpengine.dll
    2011-08-11 12:05:59 -------- d-sh--w- C:\Windows\System32\%APPDATA%
    2011-08-10 09:52:46 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\dBpoweramp
    2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\VstPlugins
    2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\Common Files\Digidesign
    2011-08-10 01:08:56 -------- d-----w- C:\Program Files (x86)\GForce
    2011-08-04 09:36:47 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\AccurateRip
    2011-08-04 09:36:45 685944 ----a-w- C:\Windows\SysWow64\SpoonUninstall.exe
    2011-08-04 09:36:34 -------- d-----w- C:\Program Files (x86)\Illustrate
    2011-08-04 09:31:51 -------- d-----w- C:\Program Files (x86)\SlySoft
    2011-08-04 09:21:59 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\LEAPS
    2011-08-04 09:20:24 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Pegasys Inc
    2011-08-04 09:18:43 -------- d-----w- C:\Program Files (x86)\Pegasys Inc
    2011-08-04 07:27:41 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Qualcomm
    2011-08-04 07:23:04 317952 ----a-w- C:\Windows\SysWow64\Roboex32.dll
    2011-08-04 07:23:04 1712128 ----a-w- C:\Windows\SysWow64\gdiplus.dll
    2011-08-04 07:23:04 -------- d-----w- C:\Program Files (x86)\Qualcomm
    2011-08-04 07:23:03 48640 ----a-w- C:\Windows\SysWow64\INETWH32.DLL
    2011-08-04 07:22:16 729088 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
    2011-08-04 07:22:16 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
    2011-08-04 07:22:16 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
    2011-08-04 07:22:16 266240 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
    2011-08-04 07:22:16 192512 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
    2011-08-04 07:22:15 311428 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
    2011-08-04 07:22:15 188548 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
    2011-08-02 03:10:07 -------- d-----w- C:\Program Files\DC++
    2011-08-02 02:50:55 -------- d-----w- C:\Users\Adam Casey\AppData\Local\etax2011
    2011-08-02 00:45:42 -------- d-----w- C:\Program Files (x86)\Suite Spot Studios
    2011-07-29 01:07:55 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\NeroDCTemplates
    2011-07-28 13:16:36 -------- d-----w- C:\VSTPlugins
    2011-07-28 13:16:35 -------- d-----w- C:\Program Files (x86)\Cakewalk
    2011-07-28 01:57:48 -------- d-----w- C:\Program Files\GForce
    2011-07-27 07:29:00 -------- d-----w- C:\Windows\System32\appmgmt
    2011-07-26 23:29:49 627744 ----a-r- C:\Windows\System32\drivers\rtl8192cu.sys
    2011-07-26 23:29:47 614400 ------r- C:\Windows\System32\Rtlihvs.dll
    2011-07-26 23:29:47 380928 ------r- C:\Windows\System32\RtlUI2.exe
    2011-07-26 23:29:46 188416 ------r- C:\Windows\System32\RTLExtUI.dll
    2011-07-26 23:29:33 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
    2011-07-26 03:57:06 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2011-07-26 03:31:04 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Cakewalk
    2011-07-26 03:26:54 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DC++
    2011-07-26 03:26:54 -------- d-----w- C:\Users\Adam Casey\AppData\Local\DC++
    2011-07-26 03:22:46 -------- d-----w- C:\Program Files\Cakewalk
    2011-07-26 03:22:46 -------- d-----w- C:\Cakewalk Projects
    2011-07-24 03:44:15 -------- d-----w- C:\Windows\System32\SPReview
    2011-07-24 03:43:23 -------- d-----w- C:\Windows\System32\EventProviders
    2011-07-24 03:30:15 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DSETUP.dll
    2011-07-24 03:30:15 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DXSETUP.exe
    2011-07-24 03:30:15 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\dsetup32.dll
    2011-07-24 03:30:10 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DSETUP.dll
    2011-07-24 03:30:10 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DXSETUP.exe
    2011-07-24 03:30:10 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\dsetup32.dll
    2011-07-24 03:27:51 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\aa1a84891cc49b117\Silverlight.4.0.exe
    2011-07-24 03:25:03 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Windows Live
    2011-07-24 03:25:00 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
    2011-07-24 02:59:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip Courier
    2011-07-24 01:05:09 -------- d-----w- C:\ProgramData\WinZipEC
    2011-07-24 01:05:02 -------- d-----w- C:\Windows\CD95F661A5C411AFB2CCABCD21A325B4.TMP
    2011-07-24 01:03:53 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip
    2011-07-23 17:08:42 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
    2011-07-23 02:56:40 -------- d-----w- C:\ProgramData\KingsIsle Entertainment
    2011-07-23 02:51:35 -------- d-----r- C:\Program Files (x86)\Skype
    2011-07-23 01:53:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Activision
    2011-07-22 17:49:08 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-07-22 11:01:59 605696 ----a-w- C:\Windows\System32\wmpeffects.dll
    2011-07-22 11:00:59 95232 ----a-w- C:\Windows\System32\cca.dll
    2011-07-22 10:59:59 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
    2011-07-22 10:57:13 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
    2011-07-22 07:19:59 163644 ----a-w- C:\Windows\SysWow64\drivers\SECDRV.SYS
    2011-07-22 07:10:51 -------- d-----w- C:\Program Files (x86)\The Creative Assembly
    2011-07-22 07:10:22 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
    2011-07-22 07:10:22 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
    2011-07-22 07:10:22 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
    2011-07-22 07:10:22 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
    2011-07-22 07:10:22 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
    2011-07-22 07:10:22 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
    2011-07-22 07:10:22 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
    2011-07-22 07:10:15 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
    2011-07-22 07:10:14 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
    2011-07-22 04:31:10 -------- d-----w- C:\ProgramData\LightScribe
    2011-07-22 04:25:52 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Ahead
    2011-07-22 04:15:09 -------- d-----w- C:\ProgramData\Nero
    2011-07-22 04:15:09 -------- d-----w- C:\Program Files (x86)\Nero
    2011-07-22 03:16:36 -------- d-----w- C:\Windows\SysWow64\Wat
    2011-07-22 03:16:36 -------- d-----w- C:\Windows\System32\Wat
    2011-07-22 02:36:04 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
    2011-07-22 02:18:03 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2011-07-21 23:32:52 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
    2011-07-21 23:32:47 -------- d-----w- C:\Program Files (x86)\Steam
    2011-07-21 23:30:59 506728 ----a-w- C:\Windows\System32\d3dx10_33.dll
    2011-07-21 21:57:45 -------- d-----w- C:\Windows\Panther
    2011-07-21 21:45:27 -------- d-----w- C:\Windows.old
    2011-07-21 17:56:20 715776 ----a-w- C:\Windows\System32\kerberos.dll
    2011-07-21 17:56:20 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
    2011-07-21 17:55:48 142336 ----a-w- C:\Windows\System32\poqexec.exe
    2011-07-21 17:55:48 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
    2011-07-21 17:55:12 2871808 ----a-w- C:\Windows\explorer.exe
    2011-07-21 17:55:12 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
    2011-07-21 17:55:01 961024 ----a-w- C:\Windows\System32\CPFilters.dll
    2011-07-21 17:55:01 723968 ----a-w- C:\Windows\System32\EncDec.dll
    2011-07-21 17:55:00 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
    2011-07-21 17:55:00 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
    2011-07-21 17:55:00 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
    2011-07-21 17:55:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
    2011-07-21 17:54:59 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
    2011-07-21 17:54:59 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
    2011-07-21 17:52:54 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
    2011-07-21 17:52:53 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
    2011-07-21 17:50:34 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:50:34 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:49:06 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
    2011-07-21 17:49:06 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
    2011-07-21 17:49:00 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
    2011-07-21 17:49:00 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
    2011-07-21 17:47:59 244736 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
    2011-07-21 17:47:52 189952 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
    2011-07-21 17:43:45 613376 ----a-w- C:\Windows\System32\vbscript.dll
    2011-07-21 17:43:44 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2011-07-21 17:42:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
    2011-07-21 17:42:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
    2011-07-21 17:41:55 1395712 ----a-w- C:\Windows\System32\mfc42.dll
    2011-07-21 17:41:55 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
    2011-07-21 17:41:55 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
    2011-07-21 17:41:54 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
    2011-07-21 17:40:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
    2011-07-21 17:40:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
    2011-07-21 17:40:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
    2011-07-21 17:40:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
    2011-07-21 17:40:06 46080 ----a-w- C:\Windows\System32\atmlib.dll
    2011-07-21 17:40:06 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
    2011-07-21 17:37:56 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
    2011-07-21 17:34:04 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
    2011-07-21 17:34:03 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
    2011-07-21 17:34:03 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
    2011-07-21 17:32:43 321024 ----a-w- C:\Windows\System32\d3d10_1core.dll
    2011-07-21 17:32:43 219136 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
    2011-07-21 17:32:42 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
    2011-07-21 17:32:42 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
    2011-07-21 17:32:37 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
    2011-07-21 17:32:37 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
    2011-07-21 17:32:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
    2011-07-21 17:27:55 642944 ----a-w- C:\Windows\System32\winload.efi
    2011-07-21 17:27:55 605552 ----a-w- C:\Windows\System32\winload.exe
    2011-07-21 17:27:54 566208 ----a-w- C:\Windows\System32\winresume.efi
    2011-07-21 17:27:54 518672 ----a-w- C:\Windows\System32\winresume.exe
    2011-07-21 17:27:54 20352 ----a-w- C:\Windows\System32\kdusb.dll
    2011-07-21 17:27:54 19328 ----a-w- C:\Windows\System32\kd1394.dll
    2011-07-21 17:27:54 17792 ----a-w- C:\Windows\System32\kdcom.dll
    2011-07-21 17:27:53 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
    2011-07-21 17:27:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
    2011-07-21 17:27:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
    2011-07-21 17:26:39 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
    2011-07-21 17:26:39 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
    2011-07-21 17:26:39 207872 ----a-w- C:\Windows\System32\cfgmgr32.dll
    2011-07-21 17:26:39 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
    2011-07-21 17:26:38 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
    2011-07-21 17:26:38 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
    2011-07-21 17:26:17 3137536 ----a-w- C:\Windows\System32\win32k.sys
    2011-07-21 17:25:36 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
    2011-07-21 17:25:36 31232 ----a-w- C:\Windows\System32\prevhost.exe
    2011-07-21 17:25:34 974336 ----a-w- C:\Windows\System32\WFS.exe
    2011-07-21 17:25:34 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
    2011-07-21 17:25:33 976896 ----a-w- C:\Windows\System32\inetcomm.dll
    2011-07-21 17:25:33 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
    2011-07-21 17:25:27 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
    2011-07-21 16:21:29 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
    2011-07-21 15:48:54 -------- d-----w- C:\Program Files (x86)\etax2011
    2011-07-21 15:30:25 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
    2011-07-21 15:29:20 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Microsoft Help
    2011-07-21 15:02:15 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
    2011-07-21 15:01:40 -------- d-----w- C:\Program Files\DivX
    2011-07-21 15:01:32 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
    2011-07-21 15:00:42 -------- d-----w- C:\Program Files (x86)\DivX
    2011-07-21 15:00:18 -------- d-----w- C:\ProgramData\DivX
    2011-07-21 14:45:26 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Lexicon PCM Native
    2011-07-21 14:41:36 24576 ----a-w- C:\Windows\SysWow64\Hyperman.dll
    2011-07-21 14:41:35 24576 ----a-w- C:\Windows\SysWow64\Wavlbsys.dll
    2011-07-21 14:41:31 -------- d-----w- C:\Program Files (x86)\Sonic Foundry
    2011-07-21 14:40:19 401462 ----a-w- C:\Windows\SysWow64\temp.001
    2011-07-21 14:40:19 266293 ----a-w- C:\Windows\SysWow64\temp.000
    2011-07-21 14:39:18 -------- d-----w- C:\Program Files (x86)\Steinberg
    2011-07-21 14:39:03 -------- d-----w- C:\Program Files (x86)\Waves
    2011-07-21 13:27:23 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\InfinaDyne
    2011-07-21 13:26:36 -------- d-----w- C:\ProgramData\InfinaDyne
    2011-07-21 13:26:36 -------- d-----w- C:\Program Files (x86)\InfinaDyne
    2011-07-21 12:39:13 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
    2011-07-21 12:39:13 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
    2011-07-21 12:33:02 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
    2011-07-21 12:32:51 -------- d-----w- C:\Program Files\Microsoft Security Client
    2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\PC Unleashed Online
    2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverCure
    2011-07-21 09:06:38 -------- d-----w- C:\ProgramData\PC Unleashed Online
    2011-07-21 09:05:51 -------- d-----w- C:\Users\Adam Casey\AppData\Local\PC_Drivers_Headquarters
    2011-07-21 08:59:33 -------- d-----w- C:\ProgramData\PC Drivers HeadQuarters
    2011-07-21 08:49:49 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverFinder
    2011-07-21 08:24:14 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2011-07-21 08:21:29 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\.minecraft
    2011-07-21 07:39:59 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Google
    2011-07-21 07:39:57 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
    2011-07-21 07:39:56 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Conduit
    2011-07-21 07:39:17 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\uTorrent
    2011-07-21 07:36:59 -------- dc-h--w- C:\ProgramData\{A97DA822-7B29-4F18-A64A-BF94FFFE77FB}
    2011-07-21 07:36:53 -------- d-----w- C:\Program Files (x86)\Lexicon
    2011-07-21 07:32:42 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Adobe
    2011-07-21 07:30:03 -------- d-----w- C:\Audio
    2011-07-21 07:27:42 -------- d-----w- C:\Windows\Downloaded Installations
    2011-07-21 06:55:36 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
    2011-07-21 06:55:24 -------- d-----w- C:\Windows\PCHEALTH
    2011-07-21 06:47:51 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3283C0BE-461D-4A04-8B8E-74E81274F083}\mpengine.dll
    2011-07-21 06:47:51 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2011-07-21 06:42:38 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Apple
    2011-07-21 06:42:19 -------- d-----w- C:\Program Files\Bonjour
    2011-07-21 06:42:19 -------- d-----w- C:\Program Files (x86)\Bonjour
    2011-07-21 06:41:44 -------- d-sh--w- C:\Windows\Installer
    2011-07-21 06:33:48 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-21 04:39:47 -------- d-----w- C:\Users\Adam Casey\AppData\Local\ElevatedDiagnostics
    2011-07-21 04:04:47 0 ----a-w- C:\Windows\ativpsrm.bin
    .
    ==================== Find3M ====================
    .
    2011-07-24 03:51:31 175616 ----a-w- C:\Windows\System32\msclmd.dll
    2011-07-24 03:51:31 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
    2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
    2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
    2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2011-07-12 01:34:00 96104 ----a-w- C:\Windows\System32\dns-sd.exe
    2011-07-12 01:34:00 85864 ----a-w- C:\Windows\System32\dnssd.dll
    2011-07-12 01:34:00 61288 ----a-w- C:\Windows\System32\jdns_sd.dll
    2011-07-12 01:34:00 212840 ----a-w- C:\Windows\System32\dnssdX.dll
    2011-07-12 01:20:54 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
    2011-07-12 01:20:54 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
    2011-07-12 01:20:54 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
    2011-07-12 01:20:54 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
    2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
    2011-07-05 08:37:00 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
    2011-07-05 08:37:00 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
    2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
    2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
    2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
    2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
    2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
    2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
    2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
    2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
    2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
    2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
    2011-06-02 17:53:02 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
    .
    ============= FINISH: 15:51:00.44 ===============

  6. #6
    Junior Member
    Join Date
    Aug 2011
    Posts
    24

    Default

    Sorry, forgot to attach the attach.txt log. Here it is...

  7. #7
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully first.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  8. #8
    Junior Member
    Join Date
    Aug 2011
    Posts
    24

    Default combo fix log

    ComboFix 11-08-18.02 - Adam Casey 18/08/2011 23:57:12.1.2 - x64
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.6143.4493 [GMT 10:00]
    Running from: c:\users\Adam Casey\Downloads\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\Mcymaa.exe
    c:\windows\security\Database\tmp.edb
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-07-18 to 2011-08-18 )))))))))))))))))))))))))))))))
    .
    .
    2011-08-18 14:06 . 2011-08-18 14:06 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-08-12 13:39 . 2011-08-12 13:39 -------- d-----w- c:\program files (x86)\Syncrosoft
    2011-08-12 13:39 . 2011-08-12 13:39 -------- d-----w- c:\programdata\eLicenser
    2011-08-12 13:38 . 2011-08-12 13:39 -------- d-----w- c:\program files (x86)\eLicenser
    2011-08-12 13:35 . 2011-08-12 13:35 2892 ----a-w- c:\windows\SysWow64\audcon.sys
    2011-08-12 13:35 . 2011-08-12 13:35 -------- d-----w- c:\programdata\Syncrosoft
    2011-08-12 13:35 . 2009-09-17 07:20 1695232 ----a-w- c:\windows\system32\synsoacc.dll
    2011-08-12 13:35 . 2007-10-24 00:47 29432 ----a-w- c:\windows\system32\drivers\synUSB64.sys
    2011-08-12 13:35 . 2009-05-19 06:21 86016 ----a-w- c:\windows\SysWow64\SYNSOPOS.exe
    2011-08-12 13:35 . 2006-01-29 01:48 401462 ----a-w- c:\windows\SysWow64\temp.002
    2011-08-12 13:35 . 2009-09-17 07:20 1261568 ----a-w- c:\windows\SysWow64\SYNSOACC.dll
    2011-08-12 13:35 . 2006-01-29 01:48 147456 ----a-w- c:\windows\SysWow64\SynsoLChk.dll
    2011-08-12 13:34 . 2006-09-20 05:13 163840 ----a-w- c:\windows\SysWow64\ArtFfct.dll
    2011-08-12 13:34 . 2011-08-12 13:34 -------- d-----w- c:\programdata\Arturia
    2011-08-12 13:34 . 2011-08-12 13:34 -------- d-----w- c:\program files (x86)\Arturia
    2011-08-12 13:21 . 2011-08-12 13:21 -------- d-----w- c:\windows\Sun
    2011-08-12 13:19 . 2011-08-12 13:19 64512 --sha-r- c:\windows\SysWow64\PSHEDU.dll
    2011-08-12 12:21 . 2011-08-12 12:21 -------- d-----w- c:\program files (x86)\Common Files\Adobe Systems Shared
    2011-08-12 11:15 . 2011-07-21 12:36 601424 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2011-08-12 11:15 . 2011-07-21 12:36 601424 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{583709C9-2877-4304-B2A0-E8E456A41DCE}\gapaengine.dll
    2011-08-12 11:15 . 2011-07-12 11:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{AB22CCDD-2F44-496A-8F96-5CF3BDB938AE}\mpengine.dll
    2011-08-11 12:05 . 2011-08-11 12:05 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2011-08-10 01:08 . 2011-08-10 01:08 -------- d-----w- c:\program files (x86)\VstPlugins
    2011-08-10 01:08 . 2011-08-10 01:08 -------- d-----w- c:\program files (x86)\Common Files\Digidesign
    2011-08-10 01:08 . 2011-08-10 01:08 -------- d-----w- c:\program files (x86)\GForce
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
    2011-08-08 07:00 . 2011-08-08 07:00 159744 ----a-w- c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
    2011-08-08 07:00 . 2011-08-08 07:00 -------- d-----w- c:\program files (x86)\QuickTime
    2011-08-04 09:36 . 2009-12-26 23:43 685944 ----a-w- c:\windows\SysWow64\SpoonUninstall.exe
    2011-08-04 09:36 . 2011-08-04 09:36 -------- d-----w- c:\program files (x86)\Illustrate
    2011-08-04 09:33 . 2011-08-04 09:33 -------- d-----w- c:\programdata\SlySoft
    2011-08-04 09:31 . 2011-08-04 22:15 -------- d-----w- c:\program files (x86)\SlySoft
    2011-08-04 09:18 . 2011-08-04 09:18 -------- d-----w- c:\program files (x86)\Pegasys Inc
    2011-08-04 07:23 . 2011-08-04 07:23 -------- d-----w- c:\program files (x86)\Qualcomm
    2011-08-04 07:23 . 2005-11-14 05:17 317952 ----a-w- c:\windows\SysWow64\Roboex32.dll
    2011-08-04 07:23 . 2005-11-14 04:49 1712128 ----a-w- c:\windows\SysWow64\gdiplus.dll
    2011-08-04 07:23 . 2005-11-14 05:17 48640 ----a-w- c:\windows\SysWow64\INETWH32.DLL
    2011-08-02 03:33 . 2011-08-02 03:33 -------- d-----w- c:\program files (x86)\Notepad++
    2011-08-02 03:10 . 2011-08-02 03:10 -------- d-----w- c:\program files\DC++
    2011-08-02 00:45 . 2011-08-02 00:45 -------- d-----w- c:\program files (x86)\Suite Spot Studios
    2011-07-28 13:16 . 2011-08-12 13:35 -------- d-----w- C:\VSTPlugins
    2011-07-28 13:16 . 2011-07-28 13:16 -------- d-----w- c:\program files (x86)\Cakewalk
    2011-07-28 01:57 . 2011-07-28 01:57 -------- d-----w- c:\program files\GForce
    2011-07-27 07:29 . 2011-07-27 07:29 -------- d-----w- c:\windows\system32\appmgmt
    2011-07-26 23:29 . 2010-04-09 08:30 627744 ----a-r- c:\windows\system32\drivers\rtl8192cu.sys
    2011-07-26 23:29 . 2010-04-01 02:37 614400 ------r- c:\windows\system32\Rtlihvs.dll
    2011-07-26 23:29 . 2010-04-01 02:37 380928 ------r- c:\windows\system32\RtlUI2.exe
    2011-07-26 23:29 . 2010-04-01 02:37 188416 ------r- c:\windows\system32\RTLExtUI.dll
    2011-07-26 23:29 . 2009-02-04 16:49 451072 ----a-w- c:\windows\SysWow64\ISSRemoveSP.exe
    2011-07-26 03:22 . 2011-07-28 14:09 -------- d-----w- c:\program files\Cakewalk
    2011-07-26 03:22 . 2011-07-28 14:09 -------- d-----w- C:\Cakewalk Projects
    2011-07-24 03:44 . 2011-07-24 03:44 -------- d-----w- c:\windows\system32\SPReview
    2011-07-24 03:43 . 2011-07-24 03:43 -------- d-----w- c:\windows\system32\EventProviders
    2011-07-24 03:25 . 2011-07-24 03:25 -------- d-----w- c:\program files (x86)\Common Files\Windows Live
    2011-07-24 01:05 . 2011-07-24 01:05 -------- d-----w- c:\windows\CD95F661A5C411AFB2CCABCD21A325B4.TMP
    2011-07-24 01:03 . 2011-07-24 01:14 -------- d-----w- c:\programdata\WinZip
    2011-07-23 17:08 . 2011-07-23 17:08 -------- d-----w- c:\program files (x86)\MSXML 4.0
    2011-07-23 02:56 . 2011-07-23 02:56 -------- d-----w- c:\programdata\KingsIsle Entertainment
    2011-07-23 02:51 . 2011-07-27 07:28 -------- d-----r- c:\program files (x86)\Skype
    2011-07-23 02:51 . 2011-07-23 02:51 -------- d-----w- c:\programdata\Skype
    2011-07-22 17:49 . 2011-07-12 11:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-07-22 11:01 . 2010-11-20 13:27 605696 ----a-w- c:\windows\system32\wmpeffects.dll
    2011-07-22 11:00 . 2010-11-20 13:27 24064 ----a-w- c:\windows\system32\sisbkup.dll
    2011-07-22 10:59 . 2010-11-20 13:27 13824 ----a-w- c:\windows\system32\wshirda.dll
    2011-07-22 10:57 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
    2011-07-22 07:19 . 2011-07-22 07:19 163644 ----a-w- c:\windows\SysWow64\drivers\SECDRV.SYS
    2011-07-22 07:10 . 2011-08-04 07:23 -------- d--h--w- c:\program files (x86)\InstallShield Installation Information
    2011-07-22 07:10 . 2011-07-22 07:10 -------- d-----w- c:\program files (x86)\The Creative Assembly
    2011-07-22 07:10 . 2011-07-22 07:10 -------- d-----w- c:\program files (x86)\Common Files\InstallShield
    2011-07-22 04:31 . 2011-07-22 04:31 -------- d-----w- c:\programdata\LightScribe
    2011-07-22 04:29 . 2011-07-22 04:29 -------- d-----w- c:\program files (x86)\Common Files\LightScribe
    2011-07-22 04:15 . 2011-07-22 04:17 -------- d-----w- c:\program files (x86)\Common Files\Nero
    2011-07-22 04:15 . 2011-07-22 04:15 -------- d-----w- c:\programdata\Nero
    2011-07-22 04:15 . 2011-07-22 04:15 -------- d-----w- c:\program files (x86)\Nero
    2011-07-22 03:16 . 2011-07-22 03:16 -------- d-----w- c:\windows\SysWow64\Wat
    2011-07-22 03:16 . 2011-07-22 03:16 -------- d-----w- c:\windows\system32\Wat
    2011-07-22 02:36 . 2011-07-22 02:36 -------- d-----w- c:\program files (x86)\Microsoft CAPICOM 2.1.0.2
    2011-07-22 02:18 . 2011-07-22 02:18 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
    2011-07-22 02:18 . 2011-07-22 02:18 -------- d-sh--w- c:\windows\SysWow64\%APPDATA%
    2011-07-21 23:32 . 2011-07-28 07:03 -------- d-----w- c:\program files (x86)\Common Files\Steam
    2011-07-21 23:32 . 2011-07-28 07:03 -------- d-----w- c:\program files (x86)\Steam
    2011-07-21 23:30 . 2007-04-04 08:55 403304 ----a-w- c:\windows\system32\xactengine2_7.dll
    2011-07-21 21:57 . 2011-07-21 04:24 -------- d-----w- c:\windows\Panther
    2011-07-21 21:45 . 2011-07-21 21:45 -------- d-----w- C:\Windows.old
    2011-07-21 17:56 . 2010-12-17 11:40 715776 ----a-w- c:\windows\system32\kerberos.dll
    2011-07-21 17:56 . 2010-12-17 07:07 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
    2011-07-21 17:55 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
    2011-07-21 17:55 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
    2011-07-21 17:55 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
    2011-07-21 17:55 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
    2011-07-21 17:55 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
    2011-07-21 17:55 . 2010-12-23 10:42 723968 ----a-w- c:\windows\system32\EncDec.dll
    2011-07-21 17:55 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
    2011-07-21 17:55 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-07-21 17:55 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
    2011-07-21 17:55 . 2010-12-23 05:54 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
    2011-07-21 17:54 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll
    2011-07-21 17:54 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
    2011-07-21 17:52 . 2011-04-25 02:34 499200 ----a-w- c:\windows\system32\drivers\afd.sys
    2011-07-21 17:52 . 2010-11-20 13:33 288640 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
    2011-07-21 17:50 . 2011-04-29 05:55 1110528 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:50 . 2011-04-29 04:57 759296 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:49 . 2011-04-27 02:40 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-07-21 17:49 . 2011-04-27 02:39 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
    2011-07-21 17:49 . 2011-02-24 06:15 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-07-21 17:49 . 2011-02-24 05:38 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
    2011-07-21 17:47 . 2011-04-29 05:55 244736 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
    2011-07-21 17:47 . 2011-04-29 04:57 189952 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
    2011-07-21 17:43 . 2011-02-18 10:56 613376 ----a-w- c:\windows\system32\vbscript.dll
    2011-07-21 17:43 . 2011-02-18 05:43 428032 ----a-w- c:\windows\SysWow64\vbscript.dll
    2011-07-21 17:42 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-07-21 17:42 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
    2011-07-21 17:41 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll
    2011-07-21 17:41 . 2011-03-11 06:34 1395712 ----a-w- c:\windows\system32\mfc42.dll
    2011-07-21 17:41 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
    2011-07-21 17:41 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
    2011-07-21 17:40 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
    2011-07-21 17:40 . 2011-02-19 04:34 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
    2011-07-21 17:40 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
    2011-07-21 17:40 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-07-24 03:51 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
    2011-07-24 03:51 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
    2011-07-16 04:26 . 2011-08-11 03:30 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2011-07-12 01:34 . 2011-07-12 01:34 96104 ----a-w- c:\windows\system32\dns-sd.exe
    2011-07-12 01:34 . 2011-07-12 01:34 85864 ----a-w- c:\windows\system32\dnssd.dll
    2011-07-12 01:34 . 2011-07-12 01:34 61288 ----a-w- c:\windows\system32\jdns_sd.dll
    2011-07-12 01:34 . 2011-07-12 01:34 212840 ----a-w- c:\windows\system32\dnssdX.dll
    2011-07-12 01:20 . 2011-07-12 01:20 83816 ----a-w- c:\windows\SysWow64\dns-sd.exe
    2011-07-12 01:20 . 2011-07-12 01:20 73064 ----a-w- c:\windows\SysWow64\dnssd.dll
    2011-07-12 01:20 . 2011-07-12 01:20 50536 ----a-w- c:\windows\SysWow64\jdns_sd.dll
    2011-07-12 01:20 . 2011-07-12 01:20 178536 ----a-w- c:\windows\SysWow64\dnssdX.dll
    2011-07-05 08:37 . 2011-07-05 08:37 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
    2011-07-05 08:37 . 2011-07-05 08:37 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
    2011-06-19 22:57 . 2011-07-21 06:47 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3283C0BE-461D-4A04-8B8E-74E81274F083}\mpengine.dll
    2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "googletalk"="c:\users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
    "LightScribe Control Panel"="c:\program files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-12-06 2387968]
    "AnyDVD"="c:\program files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-09-20 2177984]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
    "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
    "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
    "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-11 1523360]
    "GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-07-05 421888]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    FP10 Control Panel.lnk - c:\program files\PreSonus\1394AudioDriver_FirePod\FirePod.exe [2011-7-21 1133952]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files (x86)\Qualcomm\Eudora\EuShlExt.dll" [2005-11-14 86016]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [x]
    R3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys [x]
    R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
    R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
    R3 SynUSB64;SynUSB64;c:\windows\system32\DRIVERS\SynUSB64.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
    S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2008-12-06 13:18 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
    "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 211.31.138.11 211.29.132.12
    FF - ProfilePath - c:\users\Adam Casey\AppData\Roaming\Mozilla\Firefox\Profiles\u88r5vt9.default\
    FF - prefs.js: browser.startup.homepage - www.google.com.au
    .
    - - - - ORPHANS REMOVED - - - -
    .
    URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
    Wow6432Node-HKCU-Run-DriverFinder - c:\program files (x86)\DriverFinder\DriverFinder.exe
    AddRemove-dBpoweramp FLAC Codec - c:\windows\system32\SpoonUninstall.exe
    AddRemove-dBpoweramp m4a Codec - c:\windows\system32\SpoonUninstall.exe
    AddRemove-dBpoweramp Music Converter - c:\windows\system32\SpoonUninstall.exe
    AddRemove-dBpoweramp Ogg Vorbis Codec - c:\windows\system32\SpoonUninstall.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\SysWOW64\rundll32.exe
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Bonjour\mDNSResponder.exe
    c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
    c:\program files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
    .
    **************************************************************************
    .
    Completion time: 2011-08-19 00:18:11 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-08-18 14:18
    .
    Pre-Run: 33,914,458,112 bytes free
    Post-Run: 34,441,662,464 bytes free
    .
    - - End Of File - - DFB94F2972605348878289701B1BB3DD

  9. #9
    Junior Member
    Join Date
    Aug 2011
    Posts
    24

    Default DDS logs

    .
    DDS (Ver_2011-06-23.01) - NTFSAMD64
    Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26
    Run by Adam Casey at 0:20:31 on 2011-08-19
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.6143.4717 [GMT 10:00]
    .
    AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\system32\sppsvc.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Windows\system32\notepad.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    uRun: [googletalk] C:\Users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
    uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FP10CO~1.LNK - C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    TCP: DhcpNameServer = 211.31.138.11 211.29.132.12
    TCP: Interfaces\{4DC68007-8B57-4F62-8F3B-EB583C05DF61} : DhcpNameServer = 10.1.1.1
    TCP: Interfaces\{F907E1BF-CC5A-43D6-8FCA-32738CB2B923} : DhcpNameServer = 211.31.138.11 211.29.132.12
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
    BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
    mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
    mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
    mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
    SEH-X64: Eudora's Shell Extension: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Adam Casey\AppData\Roaming\Mozilla\Firefox\Profiles\u88r5vt9.default\
    FF - prefs.js: browser.startup.homepage - www.google.com.au
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-21 1153368]
    R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
    S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
    S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192cu.sys --> C:\Windows\system32\DRIVERS\RTL8192cu.sys [?]
    S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
    S3 SynUSB64;SynUSB64;C:\Windows\system32\DRIVERS\SynUSB64.sys --> C:\Windows\system32\DRIVERS\SynUSB64.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== Created Last 30 ================
    .
    2011-08-18 13:55:35 98816 ----a-w- C:\Windows\sed.exe
    2011-08-18 13:55:35 518144 ----a-w- C:\Windows\SWREG.exe
    2011-08-18 13:55:35 256000 ----a-w- C:\Windows\PEV.exe
    2011-08-18 13:55:35 208896 ----a-w- C:\Windows\MBR.exe
    2011-08-12 13:39:48 -------- d-----w- C:\Users\Adam Casey\AppData\Local\eLicenser
    2011-08-12 13:39:27 -------- d-----w- C:\Program Files (x86)\Syncrosoft
    2011-08-12 13:39:26 -------- d-----w- C:\ProgramData\eLicenser
    2011-08-12 13:38:45 -------- d-----w- C:\Program Files (x86)\eLicenser
    2011-08-12 13:35:37 2892 ----a-w- C:\Windows\SysWow64\audcon.sys
    2011-08-12 13:35:37 -------- d-----w- C:\ProgramData\Syncrosoft
    2011-08-12 13:35:35 1695232 ----a-w- C:\Windows\System32\synsoacc.dll
    2011-08-12 13:35:28 29432 ----a-w- C:\Windows\System32\drivers\synUSB64.sys
    2011-08-12 13:35:27 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
    2011-08-12 13:35:22 401462 ----a-w- C:\Windows\SysWow64\temp.002
    2011-08-12 13:35:20 147456 ----a-w- C:\Windows\SysWow64\SynsoLChk.dll
    2011-08-12 13:35:20 1261568 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
    2011-08-12 13:34:55 163840 ----a-w- C:\Windows\SysWow64\ArtFfct.dll
    2011-08-12 13:34:53 -------- d-----w- C:\ProgramData\Arturia
    2011-08-12 13:34:53 -------- d-----w- C:\Program Files (x86)\Arturia
    2011-08-12 13:19:00 64512 --sha-r- C:\Windows\SysWow64\PSHEDU.dll
    2011-08-12 12:21:22 -------- d-----w- C:\Program Files (x86)\Common Files\Adobe Systems Shared
    2011-08-12 11:15:52 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
    2011-08-12 11:15:51 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{583709C9-2877-4304-B2A0-E8E456A41DCE}\gapaengine.dll
    2011-08-12 11:15:39 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AB22CCDD-2F44-496A-8F96-5CF3BDB938AE}\mpengine.dll
    2011-08-11 12:05:59 -------- d-sh--w- C:\Windows\System32\%APPDATA%
    2011-08-10 09:52:46 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\dBpoweramp
    2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\VstPlugins
    2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\Common Files\Digidesign
    2011-08-10 01:08:56 -------- d-----w- C:\Program Files (x86)\GForce
    2011-08-04 09:36:47 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\AccurateRip
    2011-08-04 09:36:45 685944 ----a-w- C:\Windows\SysWow64\SpoonUninstall.exe
    2011-08-04 09:36:34 -------- d-----w- C:\Program Files (x86)\Illustrate
    2011-08-04 09:31:51 -------- d-----w- C:\Program Files (x86)\SlySoft
    2011-08-04 09:21:59 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\LEAPS
    2011-08-04 09:20:24 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Pegasys Inc
    2011-08-04 09:18:43 -------- d-----w- C:\Program Files (x86)\Pegasys Inc
    2011-08-04 07:27:41 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Qualcomm
    2011-08-04 07:23:04 317952 ----a-w- C:\Windows\SysWow64\Roboex32.dll
    2011-08-04 07:23:04 1712128 ----a-w- C:\Windows\SysWow64\gdiplus.dll
    2011-08-04 07:23:04 -------- d-----w- C:\Program Files (x86)\Qualcomm
    2011-08-04 07:23:03 48640 ----a-w- C:\Windows\SysWow64\INETWH32.DLL
    2011-08-04 07:22:16 729088 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
    2011-08-04 07:22:16 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
    2011-08-04 07:22:16 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
    2011-08-04 07:22:16 266240 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
    2011-08-04 07:22:16 192512 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
    2011-08-04 07:22:15 311428 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
    2011-08-04 07:22:15 188548 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
    2011-08-02 03:10:07 -------- d-----w- C:\Program Files\DC++
    2011-08-02 02:50:55 -------- d-----w- C:\Users\Adam Casey\AppData\Local\etax2011
    2011-08-02 00:45:42 -------- d-----w- C:\Program Files (x86)\Suite Spot Studios
    2011-07-29 01:07:55 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\NeroDCTemplates
    2011-07-28 13:16:36 -------- d-----w- C:\VSTPlugins
    2011-07-28 13:16:35 -------- d-----w- C:\Program Files (x86)\Cakewalk
    2011-07-28 01:57:48 -------- d-----w- C:\Program Files\GForce
    2011-07-27 07:29:00 -------- d-----w- C:\Windows\System32\appmgmt
    2011-07-26 23:29:49 627744 ----a-r- C:\Windows\System32\drivers\rtl8192cu.sys
    2011-07-26 23:29:47 614400 ------r- C:\Windows\System32\Rtlihvs.dll
    2011-07-26 23:29:47 380928 ------r- C:\Windows\System32\RtlUI2.exe
    2011-07-26 23:29:46 188416 ------r- C:\Windows\System32\RTLExtUI.dll
    2011-07-26 23:29:33 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
    2011-07-26 03:57:06 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2011-07-26 03:31:04 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Cakewalk
    2011-07-26 03:26:54 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DC++
    2011-07-26 03:26:54 -------- d-----w- C:\Users\Adam Casey\AppData\Local\DC++
    2011-07-26 03:22:46 -------- d-----w- C:\Program Files\Cakewalk
    2011-07-26 03:22:46 -------- d-----w- C:\Cakewalk Projects
    2011-07-24 03:44:15 -------- d-----w- C:\Windows\System32\SPReview
    2011-07-24 03:43:23 -------- d-----w- C:\Windows\System32\EventProviders
    2011-07-24 03:30:15 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DSETUP.dll
    2011-07-24 03:30:15 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DXSETUP.exe
    2011-07-24 03:30:15 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\dsetup32.dll
    2011-07-24 03:30:10 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DSETUP.dll
    2011-07-24 03:30:10 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DXSETUP.exe
    2011-07-24 03:30:10 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\dsetup32.dll
    2011-07-24 03:27:51 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\aa1a84891cc49b117\Silverlight.4.0.exe
    2011-07-24 03:25:03 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Windows Live
    2011-07-24 03:25:00 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
    2011-07-24 02:59:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip Courier
    2011-07-24 01:05:09 -------- d-----w- C:\ProgramData\WinZipEC
    2011-07-24 01:05:02 -------- d-----w- C:\Windows\CD95F661A5C411AFB2CCABCD21A325B4.TMP
    2011-07-24 01:03:53 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip
    2011-07-23 17:08:42 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
    2011-07-23 02:56:40 -------- d-----w- C:\ProgramData\KingsIsle Entertainment
    2011-07-23 02:51:35 -------- d-----r- C:\Program Files (x86)\Skype
    2011-07-23 01:53:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Activision
    2011-07-22 17:49:08 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2011-07-22 11:01:59 605696 ----a-w- C:\Windows\System32\wmpeffects.dll
    2011-07-22 11:00:59 95232 ----a-w- C:\Windows\System32\cca.dll
    2011-07-22 10:59:59 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
    2011-07-22 10:57:13 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
    2011-07-22 07:19:59 163644 ----a-w- C:\Windows\SysWow64\drivers\SECDRV.SYS
    2011-07-22 07:10:51 -------- d-----w- C:\Program Files (x86)\The Creative Assembly
    2011-07-22 07:10:22 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
    2011-07-22 07:10:22 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
    2011-07-22 07:10:22 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
    2011-07-22 07:10:22 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
    2011-07-22 07:10:22 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
    2011-07-22 07:10:22 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
    2011-07-22 07:10:22 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
    2011-07-22 07:10:15 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
    2011-07-22 07:10:14 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
    2011-07-22 04:31:10 -------- d-----w- C:\ProgramData\LightScribe
    2011-07-22 04:25:52 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Ahead
    2011-07-22 04:15:09 -------- d-----w- C:\ProgramData\Nero
    2011-07-22 04:15:09 -------- d-----w- C:\Program Files (x86)\Nero
    2011-07-22 03:16:36 -------- d-----w- C:\Windows\SysWow64\Wat
    2011-07-22 03:16:36 -------- d-----w- C:\Windows\System32\Wat
    2011-07-22 02:36:04 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
    2011-07-22 02:18:03 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
    2011-07-21 23:32:52 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
    2011-07-21 23:32:47 -------- d-----w- C:\Program Files (x86)\Steam
    2011-07-21 23:30:59 506728 ----a-w- C:\Windows\System32\d3dx10_33.dll
    2011-07-21 21:57:45 -------- d-----w- C:\Windows\Panther
    2011-07-21 21:45:27 -------- d-----w- C:\Windows.old
    2011-07-21 17:56:20 715776 ----a-w- C:\Windows\System32\kerberos.dll
    2011-07-21 17:56:20 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
    2011-07-21 17:55:48 142336 ----a-w- C:\Windows\System32\poqexec.exe
    2011-07-21 17:55:48 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
    2011-07-21 17:55:12 2871808 ----a-w- C:\Windows\explorer.exe
    2011-07-21 17:55:12 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
    2011-07-21 17:55:01 961024 ----a-w- C:\Windows\System32\CPFilters.dll
    2011-07-21 17:55:01 723968 ----a-w- C:\Windows\System32\EncDec.dll
    2011-07-21 17:55:00 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
    2011-07-21 17:55:00 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
    2011-07-21 17:55:00 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
    2011-07-21 17:55:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
    2011-07-21 17:54:59 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
    2011-07-21 17:54:59 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
    2011-07-21 17:52:54 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
    2011-07-21 17:52:53 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
    2011-07-21 17:50:34 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:50:34 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
    2011-07-21 17:49:06 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
    2011-07-21 17:49:06 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
    2011-07-21 17:49:00 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
    2011-07-21 17:49:00 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
    2011-07-21 17:47:59 244736 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
    2011-07-21 17:47:52 189952 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
    2011-07-21 17:43:45 613376 ----a-w- C:\Windows\System32\vbscript.dll
    2011-07-21 17:43:44 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2011-07-21 17:42:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
    2011-07-21 17:42:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
    2011-07-21 17:41:55 1395712 ----a-w- C:\Windows\System32\mfc42.dll
    2011-07-21 17:41:55 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
    2011-07-21 17:41:55 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
    2011-07-21 17:41:54 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
    2011-07-21 17:40:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
    2011-07-21 17:40:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
    2011-07-21 17:40:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
    2011-07-21 17:40:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
    2011-07-21 17:40:06 46080 ----a-w- C:\Windows\System32\atmlib.dll
    2011-07-21 17:40:06 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
    2011-07-21 17:37:56 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
    2011-07-21 17:34:04 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
    2011-07-21 17:34:03 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
    2011-07-21 17:34:03 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
    2011-07-21 17:32:43 321024 ----a-w- C:\Windows\System32\d3d10_1core.dll
    2011-07-21 17:32:43 219136 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
    2011-07-21 17:32:42 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
    2011-07-21 17:32:42 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
    2011-07-21 17:32:37 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
    2011-07-21 17:32:37 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
    2011-07-21 17:32:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
    2011-07-21 17:27:55 642944 ----a-w- C:\Windows\System32\winload.efi
    2011-07-21 17:27:55 605552 ----a-w- C:\Windows\System32\winload.exe
    2011-07-21 17:27:54 566208 ----a-w- C:\Windows\System32\winresume.efi
    2011-07-21 17:27:54 518672 ----a-w- C:\Windows\System32\winresume.exe
    2011-07-21 17:27:54 20352 ----a-w- C:\Windows\System32\kdusb.dll
    2011-07-21 17:27:54 19328 ----a-w- C:\Windows\System32\kd1394.dll
    2011-07-21 17:27:54 17792 ----a-w- C:\Windows\System32\kdcom.dll
    2011-07-21 17:27:53 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
    2011-07-21 17:27:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
    2011-07-21 17:27:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
    2011-07-21 17:26:39 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
    2011-07-21 17:26:39 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
    2011-07-21 17:26:39 207872 ----a-w- C:\Windows\System32\cfgmgr32.dll
    2011-07-21 17:26:39 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
    2011-07-21 17:26:38 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
    2011-07-21 17:26:38 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
    2011-07-21 17:26:17 3137536 ----a-w- C:\Windows\System32\win32k.sys
    2011-07-21 17:25:36 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
    2011-07-21 17:25:36 31232 ----a-w- C:\Windows\System32\prevhost.exe
    2011-07-21 17:25:34 974336 ----a-w- C:\Windows\System32\WFS.exe
    2011-07-21 17:25:34 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
    2011-07-21 17:25:33 976896 ----a-w- C:\Windows\System32\inetcomm.dll
    2011-07-21 17:25:33 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
    2011-07-21 17:25:27 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
    2011-07-21 16:21:29 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
    2011-07-21 15:48:54 -------- d-----w- C:\Program Files (x86)\etax2011
    2011-07-21 15:30:25 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
    2011-07-21 15:29:20 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Microsoft Help
    2011-07-21 15:02:15 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
    2011-07-21 15:01:40 -------- d-----w- C:\Program Files\DivX
    2011-07-21 15:01:32 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
    2011-07-21 15:00:42 -------- d-----w- C:\Program Files (x86)\DivX
    2011-07-21 15:00:18 -------- d-----w- C:\ProgramData\DivX
    2011-07-21 14:45:26 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Lexicon PCM Native
    2011-07-21 14:41:36 24576 ----a-w- C:\Windows\SysWow64\Hyperman.dll
    2011-07-21 14:41:35 24576 ----a-w- C:\Windows\SysWow64\Wavlbsys.dll
    2011-07-21 14:41:31 -------- d-----w- C:\Program Files (x86)\Sonic Foundry
    2011-07-21 14:40:19 401462 ----a-w- C:\Windows\SysWow64\temp.001
    2011-07-21 14:40:19 266293 ----a-w- C:\Windows\SysWow64\temp.000
    2011-07-21 14:39:18 -------- d-----w- C:\Program Files (x86)\Steinberg
    2011-07-21 14:39:03 -------- d-----w- C:\Program Files (x86)\Waves
    2011-07-21 13:27:23 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\InfinaDyne
    2011-07-21 13:26:36 -------- d-----w- C:\ProgramData\InfinaDyne
    2011-07-21 13:26:36 -------- d-----w- C:\Program Files (x86)\InfinaDyne
    2011-07-21 12:39:13 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
    2011-07-21 12:39:13 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
    2011-07-21 12:33:02 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
    2011-07-21 12:32:51 -------- d-----w- C:\Program Files\Microsoft Security Client
    2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\PC Unleashed Online
    2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverCure
    2011-07-21 09:06:38 -------- d-----w- C:\ProgramData\PC Unleashed Online
    2011-07-21 09:05:51 -------- d-----w- C:\Users\Adam Casey\AppData\Local\PC_Drivers_Headquarters
    2011-07-21 08:59:33 -------- d-----w- C:\ProgramData\PC Drivers HeadQuarters
    2011-07-21 08:49:49 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverFinder
    2011-07-21 08:24:14 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2011-07-21 08:21:29 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\.minecraft
    2011-07-21 07:39:59 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Google
    2011-07-21 07:39:57 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
    2011-07-21 07:39:56 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Conduit
    2011-07-21 07:39:17 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\uTorrent
    2011-07-21 07:36:59 -------- dc-h--w- C:\ProgramData\{A97DA822-7B29-4F18-A64A-BF94FFFE77FB}
    2011-07-21 07:36:53 -------- d-----w- C:\Program Files (x86)\Lexicon
    2011-07-21 07:32:42 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Adobe
    2011-07-21 07:30:03 -------- d-----w- C:\Audio
    2011-07-21 07:27:42 -------- d-----w- C:\Windows\Downloaded Installations
    2011-07-21 06:55:36 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
    2011-07-21 06:55:24 -------- d-----w- C:\Windows\PCHEALTH
    2011-07-21 06:47:51 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3283C0BE-461D-4A04-8B8E-74E81274F083}\mpengine.dll
    2011-07-21 06:47:51 270720 ------w- C:\Windows\System32\MpSigStub.exe
    2011-07-21 06:42:38 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Apple
    2011-07-21 06:42:19 -------- d-----w- C:\Program Files\Bonjour
    2011-07-21 06:42:19 -------- d-----w- C:\Program Files (x86)\Bonjour
    2011-07-21 06:41:44 -------- d-sh--w- C:\Windows\Installer
    2011-07-21 06:33:48 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-21 04:39:47 -------- d-----w- C:\Users\Adam Casey\AppData\Local\ElevatedDiagnostics
    2011-07-21 04:04:47 0 ----a-w- C:\Windows\ativpsrm.bin
    .
    ==================== Find3M ====================
    .
    2011-07-24 03:51:31 175616 ----a-w- C:\Windows\System32\msclmd.dll
    2011-07-24 03:51:31 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
    2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
    2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
    2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2011-07-12 01:34:00 96104 ----a-w- C:\Windows\System32\dns-sd.exe
    2011-07-12 01:34:00 85864 ----a-w- C:\Windows\System32\dnssd.dll
    2011-07-12 01:34:00 61288 ----a-w- C:\Windows\System32\jdns_sd.dll
    2011-07-12 01:34:00 212840 ----a-w- C:\Windows\System32\dnssdX.dll
    2011-07-12 01:20:54 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
    2011-07-12 01:20:54 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
    2011-07-12 01:20:54 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
    2011-07-12 01:20:54 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
    2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
    2011-07-05 08:37:00 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
    2011-07-05 08:37:00 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
    2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
    2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
    2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
    2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
    2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
    2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
    2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
    2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
    2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
    2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
    2011-06-02 17:53:02 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
    .
    ============= FINISH: 0:21:08.91 ===============

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi again,


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    http://forums.spybot.info/showthread.php?t=63628
    Collect::
    c:\windows\SysWow64\PSHEDU.dll
    Folder::
    c:\program files\DC++
    C:\Users\Adam Casey\AppData\Roaming\DC++
    C:\Users\Adam Casey\AppData\Local\DC++
    C:\Users\Adam Casey\AppData\Roaming\uTorrent

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
    Then post the resultant log.



    * Go here to run an online scanner from ESET.
    • Note: You will need to use Internet explorer for this scan
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Click Start
    • Make sure that the option Remove found threats is UNchecked and the option Scan unwanted applications is checkmarked.
    • Click Scan
    • Wait for the scan to finish.




    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •