theboywhospokeclouds
New member
Hi there,
My computer is playing sounds randomly without me opening any programs, it is not allowing me to open websites I choose (and instead directing me to advertising websites), and it won't let me open Windows Security Essentials. Here is the DDS log:
DDS log:
.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26
Run by Owner at 22:09:50 on 2011-08-13
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.6143.4430 [GMT 10:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [DriverFinder] C:\Program Files (x86)\DriverFinder\DriverFinder.exe
uRun: [googletalk] C:\Users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
uRun: [8DDYX0ZBPZ] C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FP10CO~1.LNK - C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 211.31.138.11 211.29.132.12
TCP: Interfaces\{4DC68007-8B57-4F62-8F3B-EB583C05DF61} : DhcpNameServer = 10.1.1.1
TCP: Interfaces\{F907E1BF-CC5A-43D6-8FCA-32738CB2B923} : DhcpNameServer = 211.31.138.11 211.29.132.12
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SEH-X64: Eudora's Shell Extension: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Adam Casey\AppData\Roaming\Mozilla\Firefox\Profiles\u88r5vt9.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-21 1153368]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192cu.sys --> C:\Windows\system32\DRIVERS\RTL8192cu.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 SynUSB64;SynUSB64;C:\Windows\system32\DRIVERS\SynUSB64.sys --> C:\Windows\system32\DRIVERS\SynUSB64.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-08-12 13:39:48 -------- d-----w- C:\Users\Adam Casey\AppData\Local\eLicenser
2011-08-12 13:39:27 -------- d-----w- C:\Program Files (x86)\Syncrosoft
2011-08-12 13:39:26 -------- d-----w- C:\ProgramData\eLicenser
2011-08-12 13:38:45 -------- d-----w- C:\Program Files (x86)\eLicenser
2011-08-12 13:35:37 2892 ----a-w- C:\Windows\SysWow64\audcon.sys
2011-08-12 13:35:37 -------- d-----w- C:\ProgramData\Syncrosoft
2011-08-12 13:35:35 1695232 ----a-w- C:\Windows\System32\synsoacc.dll
2011-08-12 13:35:28 29432 ----a-w- C:\Windows\System32\drivers\synUSB64.sys
2011-08-12 13:35:27 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
2011-08-12 13:35:22 401462 ----a-w- C:\Windows\SysWow64\temp.002
2011-08-12 13:35:20 147456 ----a-w- C:\Windows\SysWow64\SynsoLChk.dll
2011-08-12 13:35:20 1261568 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
2011-08-12 13:34:55 163840 ----a-w- C:\Windows\SysWow64\ArtFfct.dll
2011-08-12 13:34:53 -------- d-----w- C:\ProgramData\Arturia
2011-08-12 13:34:53 -------- d-----w- C:\Program Files (x86)\Arturia
2011-08-12 13:19:06 186880 ----a-w- C:\Windows\Mcymaa.exe
2011-08-12 13:19:00 64512 --sha-r- C:\Windows\SysWow64\PSHEDU.dll
2011-08-12 12:21:22 -------- d-----w- C:\Program Files (x86)\Common Files\Adobe Systems Shared
2011-08-12 11:15:52 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-08-12 11:15:51 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{583709C9-2877-4304-B2A0-E8E456A41DCE}\gapaengine.dll
2011-08-12 11:15:39 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AB22CCDD-2F44-496A-8F96-5CF3BDB938AE}\mpengine.dll
2011-08-11 12:05:59 -------- d-sh--w- C:\Windows\System32\%APPDATA%
2011-08-10 09:52:46 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\dBpoweramp
2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\VstPlugins
2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\Common Files\Digidesign
2011-08-10 01:08:56 -------- d-----w- C:\Program Files (x86)\GForce
2011-08-04 09:36:47 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\AccurateRip
2011-08-04 09:36:45 685944 ----a-w- C:\Windows\SysWow64\SpoonUninstall.exe
2011-08-04 09:36:34 -------- d-----w- C:\Program Files (x86)\Illustrate
2011-08-04 09:31:51 -------- d-----w- C:\Program Files (x86)\SlySoft
2011-08-04 09:21:59 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\LEAPS
2011-08-04 09:20:24 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Pegasys Inc
2011-08-04 09:18:43 -------- d-----w- C:\Program Files (x86)\Pegasys Inc
2011-08-04 07:27:41 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Qualcomm
2011-08-04 07:23:04 317952 ----a-w- C:\Windows\SysWow64\Roboex32.dll
2011-08-04 07:23:04 1712128 ----a-w- C:\Windows\SysWow64\gdiplus.dll
2011-08-04 07:23:04 -------- d-----w- C:\Program Files (x86)\Qualcomm
2011-08-04 07:23:03 48640 ----a-w- C:\Windows\SysWow64\INETWH32.DLL
2011-08-04 07:22:16 729088 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-08-04 07:22:16 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-08-04 07:22:16 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-08-04 07:22:16 266240 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-08-04 07:22:16 192512 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-08-04 07:22:15 311428 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-08-04 07:22:15 188548 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-08-02 03:10:07 -------- d-----w- C:\Users\Adam Casey\AppData\Local\etax2011
2011-08-02 00:45:42 -------- d-----w- C:\Program Files (x86)\Suite Spot Studios
2011-07-29 01:07:55 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\NeroDCTemplates
2011-07-28 13:16:36 -------- d-----w- C:\VSTPlugins
2011-07-28 13:16:35 -------- d-----w- C:\Program Files (x86)\Cakewalk
2011-07-28 01:57:48 -------- d-----w- C:\Program Files\GForce
2011-07-27 07:29:00 -------- d-----w- C:\Windows\System32\appmgmt
2011-07-26 23:29:49 627744 ----a-r- C:\Windows\System32\drivers\rtl8192cu.sys
2011-07-26 23:29:47 614400 ------r- C:\Windows\System32\Rtlihvs.dll
2011-07-26 23:29:47 380928 ------r- C:\Windows\System32\RtlUI2.exe
2011-07-26 23:29:46 188416 ------r- C:\Windows\System32\RTLExtUI.dll
2011-07-26 23:29:33 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
2011-07-26 03:57:06 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-07-26 03:31:04 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Cakewalk
2011-07-26 03:26:54 -------- d-----w- C:\Program Files\Cakewalk
2011-07-26 03:22:46 -------- d-----w- C:\Cakewalk Projects
2011-07-24 03:44:15 -------- d-----w- C:\Windows\System32\SPReview
2011-07-24 03:43:23 -------- d-----w- C:\Windows\System32\EventProviders
2011-07-24 03:30:15 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DSETUP.dll
2011-07-24 03:30:15 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DXSETUP.exe
2011-07-24 03:30:15 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\dsetup32.dll
2011-07-24 03:30:10 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DSETUP.dll
2011-07-24 03:30:10 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DXSETUP.exe
2011-07-24 03:30:10 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\dsetup32.dll
2011-07-24 03:27:51 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\aa1a84891cc49b117\Silverlight.4.0.exe
2011-07-24 03:25:03 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Windows Live
2011-07-24 03:25:00 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-07-24 02:59:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip Courier
2011-07-24 01:05:09 -------- d-----w- C:\ProgramData\WinZipEC
2011-07-24 01:05:02 -------- d-----w- C:\Windows\CD95F661A5C411AFB2CCABCD21A325B4.TMP
2011-07-24 01:03:53 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip
2011-07-23 17:08:42 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-07-23 02:56:40 -------- d-----w- C:\ProgramData\KingsIsle Entertainment
2011-07-23 02:51:35 -------- d-----r- C:\Program Files (x86)\Skype
2011-07-23 01:53:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Activision
2011-07-22 17:49:08 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-22 11:01:59 605696 ----a-w- C:\Windows\System32\wmpeffects.dll
2011-07-22 11:00:59 95232 ----a-w- C:\Windows\System32\cca.dll
2011-07-22 10:59:59 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2011-07-22 10:57:13 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-07-22 07:19:59 163644 ----a-w- C:\Windows\SysWow64\drivers\SECDRV.SYS
2011-07-22 07:10:51 -------- d-----w- C:\Program Files (x86)\The Creative Assembly
2011-07-22 07:10:22 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-07-22 07:10:22 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-07-22 07:10:22 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-07-22 07:10:22 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2011-07-22 07:10:22 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-07-22 07:10:22 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-07-22 07:10:22 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-07-22 07:10:15 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-07-22 07:10:14 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2011-07-22 04:31:10 -------- d-----w- C:\ProgramData\LightScribe
2011-07-22 04:25:52 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Ahead
2011-07-22 04:15:09 -------- d-----w- C:\ProgramData\Nero
2011-07-22 04:15:09 -------- d-----w- C:\Program Files (x86)\Nero
2011-07-22 03:16:36 -------- d-----w- C:\Windows\SysWow64\Wat
2011-07-22 03:16:36 -------- d-----w- C:\Windows\System32\Wat
2011-07-22 02:36:04 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2011-07-22 02:18:03 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2011-07-21 23:32:52 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2011-07-21 23:32:47 -------- d-----w- C:\Program Files (x86)\Steam
2011-07-21 23:30:59 506728 ----a-w- C:\Windows\System32\d3dx10_33.dll
2011-07-21 21:57:45 -------- d-----w- C:\Windows\Panther
2011-07-21 21:45:27 -------- d-----w- C:\Windows.old
2011-07-21 17:56:20 715776 ----a-w- C:\Windows\System32\kerberos.dll
2011-07-21 17:56:20 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
2011-07-21 17:55:48 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-07-21 17:55:48 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-07-21 17:55:12 2871808 ----a-w- C:\Windows\explorer.exe
2011-07-21 17:55:12 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2011-07-21 17:55:01 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2011-07-21 17:55:01 723968 ----a-w- C:\Windows\System32\EncDec.dll
2011-07-21 17:55:00 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-07-21 17:55:00 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-07-21 17:55:00 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2011-07-21 17:55:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
2011-07-21 17:54:59 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-07-21 17:54:59 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-07-21 17:52:54 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
2011-07-21 17:52:53 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2011-07-21 17:50:34 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-21 17:50:34 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-21 17:49:06 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-07-21 17:49:06 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-07-21 17:49:00 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-07-21 17:49:00 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-07-21 17:47:59 244736 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2011-07-21 17:47:52 189952 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2011-07-21 17:43:45 613376 ----a-w- C:\Windows\System32\vbscript.dll
2011-07-21 17:43:44 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-07-21 17:42:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-07-21 17:42:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-07-21 17:41:55 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-07-21 17:41:55 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-07-21 17:41:55 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-07-21 17:41:54 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-07-21 17:40:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2011-07-21 17:40:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-07-21 17:40:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-07-21 17:40:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
2011-07-21 17:40:06 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-07-21 17:40:06 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-07-21 17:37:56 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-07-21 17:34:04 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-07-21 17:34:03 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-07-21 17:34:03 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-07-21 17:32:43 321024 ----a-w- C:\Windows\System32\d3d10_1core.dll
2011-07-21 17:32:43 219136 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
2011-07-21 17:32:42 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
2011-07-21 17:32:42 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2011-07-21 17:32:37 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-07-21 17:32:37 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-07-21 17:32:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-07-21 17:27:55 642944 ----a-w- C:\Windows\System32\winload.efi
2011-07-21 17:27:55 605552 ----a-w- C:\Windows\System32\winload.exe
2011-07-21 17:27:54 566208 ----a-w- C:\Windows\System32\winresume.efi
2011-07-21 17:27:54 518672 ----a-w- C:\Windows\System32\winresume.exe
2011-07-21 17:27:54 20352 ----a-w- C:\Windows\System32\kdusb.dll
2011-07-21 17:27:54 19328 ----a-w- C:\Windows\System32\kd1394.dll
2011-07-21 17:27:54 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-07-21 17:27:53 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2011-07-21 17:27:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-07-21 17:27:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-07-21 17:26:39 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-07-21 17:26:39 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-07-21 17:26:39 207872 ----a-w- C:\Windows\System32\cfgmgr32.dll
2011-07-21 17:26:39 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-07-21 17:26:38 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-07-21 17:26:38 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-07-21 17:26:17 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-07-21 17:25:36 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-07-21 17:25:36 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-07-21 17:25:34 974336 ----a-w- C:\Windows\System32\WFS.exe
2011-07-21 17:25:34 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-07-21 17:25:33 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-07-21 17:25:33 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-07-21 17:25:27 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-07-21 16:21:29 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2011-07-21 15:48:54 -------- d-----w- C:\Program Files (x86)\etax2011
2011-07-21 15:30:25 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-07-21 15:29:20 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Microsoft Help
2011-07-21 15:02:15 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-07-21 15:01:40 -------- d-----w- C:\Program Files\DivX
2011-07-21 15:01:32 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2011-07-21 15:00:42 -------- d-----w- C:\Program Files (x86)\DivX
2011-07-21 15:00:18 -------- d-----w- C:\ProgramData\DivX
2011-07-21 14:45:26 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Lexicon PCM Native
2011-07-21 14:41:36 24576 ----a-w- C:\Windows\SysWow64\Hyperman.dll
2011-07-21 14:41:35 24576 ----a-w- C:\Windows\SysWow64\Wavlbsys.dll
2011-07-21 14:41:31 -------- d-----w- C:\Program Files (x86)\Sonic Foundry
2011-07-21 14:40:19 401462 ----a-w- C:\Windows\SysWow64\temp.001
2011-07-21 14:40:19 266293 ----a-w- C:\Windows\SysWow64\temp.000
2011-07-21 14:39:18 -------- d-----w- C:\Program Files (x86)\Steinberg
2011-07-21 14:39:03 -------- d-----w- C:\Program Files (x86)\Waves
2011-07-21 13:27:23 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\InfinaDyne
2011-07-21 13:26:36 -------- d-----w- C:\ProgramData\InfinaDyne
2011-07-21 13:26:36 -------- d-----w- C:\Program Files (x86)\InfinaDyne
2011-07-21 12:39:13 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-07-21 12:39:13 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-07-21 12:33:02 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-07-21 12:32:51 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\PC Unleashed Online
2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverCure
2011-07-21 09:06:38 -------- d-----w- C:\ProgramData\PC Unleashed Online
2011-07-21 09:05:51 -------- d-----w- C:\Users\Adam Casey\AppData\Local\PC_Drivers_Headquarters
2011-07-21 08:59:33 -------- d-----w- C:\ProgramData\PC Drivers HeadQuarters
2011-07-21 08:49:49 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverFinder
2011-07-21 08:24:14 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-07-21 08:21:29 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\.minecraft
2011-07-21 07:40:29 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Google
2011-07-21 07:39:57 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
2011-07-21 07:39:56 -------- d-----w- C:\ProgramData\{A97DA822-7B29-4F18-A64A-BF94FFFE77FB}
2011-07-21 07:36:53 -------- d-----w- C:\Program Files (x86)\Lexicon
2011-07-21 07:32:42 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Adobe
2011-07-21 07:30:03 -------- d-----w- C:\Audio
2011-07-21 07:27:42 -------- d-----w- C:\Windows\Downloaded Installations
2011-07-21 06:55:36 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
2011-07-21 06:55:24 -------- d-----w- C:\Windows\PCHEALTH
2011-07-21 06:47:51 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3283C0BE-461D-4A04-8B8E-74E81274F083}\mpengine.dll
2011-07-21 06:47:51 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-07-21 06:42:38 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Apple
2011-07-21 06:42:19 -------- d-----w- C:\Program Files\Bonjour
2011-07-21 06:42:19 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-07-21 06:41:44 -------- d-sh--w- C:\Windows\Installer
2011-07-21 06:33:48 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-21 04:39:47 -------- d-----w- C:\Users\Adam Casey\AppData\Local\ElevatedDiagnostics
2011-07-21 04:04:47 0 ----a-w- C:\Windows\ativpsrm.bin
.
==================== Find3M ====================
.
2011-07-24 03:51:31 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-07-24 03:51:31 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-12 01:34:00 96104 ----a-w- C:\Windows\System32\dns-sd.exe
2011-07-12 01:34:00 85864 ----a-w- C:\Windows\System32\dnssd.dll
2011-07-12 01:34:00 61288 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-07-12 01:34:00 212840 ----a-w- C:\Windows\System32\dnssdX.dll
2011-07-12 01:20:54 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-07-12 01:20:54 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-07-12 01:20:54 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-07-12 01:20:54 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-07-05 08:37:00 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-07-05 08:37:00 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-06-02 17:53:02 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
.
============= FINISH: 22:13:19.81 ===============
My computer is playing sounds randomly without me opening any programs, it is not allowing me to open websites I choose (and instead directing me to advertising websites), and it won't let me open Windows Security Essentials. Here is the DDS log:
DDS log:
.
DDS (Ver_2011-06-23.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26
Run by Owner at 22:09:50 on 2011-08-13
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.61.1033.18.6143.4430 [GMT 10:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [DriverFinder] C:\Program Files (x86)\DriverFinder\DriverFinder.exe
uRun: [googletalk] C:\Users\Adam Casey\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
uRun: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
uRun: [8DDYX0ZBPZ] C:\Users\Adam Casey\AppData\Local\Temp\Mzx.exe
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FP10CO~1.LNK - C:\Program Files\PreSonus\1394AudioDriver_FirePod\FirePod.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 211.31.138.11 211.29.132.12
TCP: Interfaces\{4DC68007-8B57-4F62-8F3B-EB583C05DF61} : DhcpNameServer = 10.1.1.1
TCP: Interfaces\{F907E1BF-CC5A-43D6-8FCA-32738CB2B923} : DhcpNameServer = 211.31.138.11 211.29.132.12
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun-x64: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SEH-X64: Eudora's Shell Extension: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files (x86)\Qualcomm\Eudora\EuShlExt.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Adam Casey\AppData\Roaming\Mozilla\Firefox\Profiles\u88r5vt9.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-7-21 1153368]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk62x64.sys --> C:\Windows\system32\DRIVERS\yk62x64.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8192cu.sys --> C:\Windows\system32\DRIVERS\RTL8192cu.sys [?]
S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 SynUSB64;SynUSB64;C:\Windows\system32\DRIVERS\SynUSB64.sys --> C:\Windows\system32\DRIVERS\SynUSB64.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-08-12 13:39:48 -------- d-----w- C:\Users\Adam Casey\AppData\Local\eLicenser
2011-08-12 13:39:27 -------- d-----w- C:\Program Files (x86)\Syncrosoft
2011-08-12 13:39:26 -------- d-----w- C:\ProgramData\eLicenser
2011-08-12 13:38:45 -------- d-----w- C:\Program Files (x86)\eLicenser
2011-08-12 13:35:37 2892 ----a-w- C:\Windows\SysWow64\audcon.sys
2011-08-12 13:35:37 -------- d-----w- C:\ProgramData\Syncrosoft
2011-08-12 13:35:35 1695232 ----a-w- C:\Windows\System32\synsoacc.dll
2011-08-12 13:35:28 29432 ----a-w- C:\Windows\System32\drivers\synUSB64.sys
2011-08-12 13:35:27 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
2011-08-12 13:35:22 401462 ----a-w- C:\Windows\SysWow64\temp.002
2011-08-12 13:35:20 147456 ----a-w- C:\Windows\SysWow64\SynsoLChk.dll
2011-08-12 13:35:20 1261568 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
2011-08-12 13:34:55 163840 ----a-w- C:\Windows\SysWow64\ArtFfct.dll
2011-08-12 13:34:53 -------- d-----w- C:\ProgramData\Arturia
2011-08-12 13:34:53 -------- d-----w- C:\Program Files (x86)\Arturia
2011-08-12 13:19:06 186880 ----a-w- C:\Windows\Mcymaa.exe
2011-08-12 13:19:00 64512 --sha-r- C:\Windows\SysWow64\PSHEDU.dll
2011-08-12 12:21:22 -------- d-----w- C:\Program Files (x86)\Common Files\Adobe Systems Shared
2011-08-12 11:15:52 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-08-12 11:15:51 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{583709C9-2877-4304-B2A0-E8E456A41DCE}\gapaengine.dll
2011-08-12 11:15:39 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{AB22CCDD-2F44-496A-8F96-5CF3BDB938AE}\mpengine.dll
2011-08-11 12:05:59 -------- d-sh--w- C:\Windows\System32\%APPDATA%
2011-08-10 09:52:46 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\dBpoweramp
2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\VstPlugins
2011-08-10 01:08:57 -------- d-----w- C:\Program Files (x86)\Common Files\Digidesign
2011-08-10 01:08:56 -------- d-----w- C:\Program Files (x86)\GForce
2011-08-04 09:36:47 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\AccurateRip
2011-08-04 09:36:45 685944 ----a-w- C:\Windows\SysWow64\SpoonUninstall.exe
2011-08-04 09:36:34 -------- d-----w- C:\Program Files (x86)\Illustrate
2011-08-04 09:31:51 -------- d-----w- C:\Program Files (x86)\SlySoft
2011-08-04 09:21:59 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\LEAPS
2011-08-04 09:20:24 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Pegasys Inc
2011-08-04 09:18:43 -------- d-----w- C:\Program Files (x86)\Pegasys Inc
2011-08-04 07:27:41 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Qualcomm
2011-08-04 07:23:04 317952 ----a-w- C:\Windows\SysWow64\Roboex32.dll
2011-08-04 07:23:04 1712128 ----a-w- C:\Windows\SysWow64\gdiplus.dll
2011-08-04 07:23:04 -------- d-----w- C:\Program Files (x86)\Qualcomm
2011-08-04 07:23:03 48640 ----a-w- C:\Windows\SysWow64\INETWH32.DLL
2011-08-04 07:22:16 729088 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-08-04 07:22:16 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-08-04 07:22:16 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-08-04 07:22:16 266240 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-08-04 07:22:16 192512 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-08-04 07:22:15 311428 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-08-04 07:22:15 188548 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-08-02 03:10:07 -------- d-----w- C:\Users\Adam Casey\AppData\Local\etax2011
2011-08-02 00:45:42 -------- d-----w- C:\Program Files (x86)\Suite Spot Studios
2011-07-29 01:07:55 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\NeroDCTemplates
2011-07-28 13:16:36 -------- d-----w- C:\VSTPlugins
2011-07-28 13:16:35 -------- d-----w- C:\Program Files (x86)\Cakewalk
2011-07-28 01:57:48 -------- d-----w- C:\Program Files\GForce
2011-07-27 07:29:00 -------- d-----w- C:\Windows\System32\appmgmt
2011-07-26 23:29:49 627744 ----a-r- C:\Windows\System32\drivers\rtl8192cu.sys
2011-07-26 23:29:47 614400 ------r- C:\Windows\System32\Rtlihvs.dll
2011-07-26 23:29:47 380928 ------r- C:\Windows\System32\RtlUI2.exe
2011-07-26 23:29:46 188416 ------r- C:\Windows\System32\RTLExtUI.dll
2011-07-26 23:29:33 451072 ----a-w- C:\Windows\SysWow64\ISSRemoveSP.exe
2011-07-26 03:57:06 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-07-26 03:31:04 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Cakewalk
2011-07-26 03:26:54 -------- d-----w- C:\Program Files\Cakewalk
2011-07-26 03:22:46 -------- d-----w- C:\Cakewalk Projects
2011-07-24 03:44:15 -------- d-----w- C:\Windows\System32\SPReview
2011-07-24 03:43:23 -------- d-----w- C:\Windows\System32\EventProviders
2011-07-24 03:30:15 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DSETUP.dll
2011-07-24 03:30:15 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\DXSETUP.exe
2011-07-24 03:30:15 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\576efc1cc49b22a\dsetup32.dll
2011-07-24 03:30:10 94040 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DSETUP.dll
2011-07-24 03:30:10 525656 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\DXSETUP.exe
2011-07-24 03:30:10 1691480 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\fd03a3a31cc49b129\dsetup32.dll
2011-07-24 03:27:51 6260088 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\aa1a84891cc49b117\Silverlight.4.0.exe
2011-07-24 03:25:03 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Windows Live
2011-07-24 03:25:00 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-07-24 02:59:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip Courier
2011-07-24 01:05:09 -------- d-----w- C:\ProgramData\WinZipEC
2011-07-24 01:05:02 -------- d-----w- C:\Windows\CD95F661A5C411AFB2CCABCD21A325B4.TMP
2011-07-24 01:03:53 -------- d-----w- C:\Users\Adam Casey\AppData\Local\WinZip
2011-07-23 17:08:42 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-07-23 02:56:40 -------- d-----w- C:\ProgramData\KingsIsle Entertainment
2011-07-23 02:51:35 -------- d-----r- C:\Program Files (x86)\Skype
2011-07-23 01:53:36 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Activision
2011-07-22 17:49:08 8578896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-22 11:01:59 605696 ----a-w- C:\Windows\System32\wmpeffects.dll
2011-07-22 11:00:59 95232 ----a-w- C:\Windows\System32\cca.dll
2011-07-22 10:59:59 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2011-07-22 10:57:13 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-07-22 07:19:59 163644 ----a-w- C:\Windows\SysWow64\drivers\SECDRV.SYS
2011-07-22 07:10:51 -------- d-----w- C:\Program Files (x86)\The Creative Assembly
2011-07-22 07:10:22 757760 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-07-22 07:10:22 69715 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-07-22 07:10:22 65024 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-07-22 07:10:22 5632 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2011-07-22 07:10:22 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2011-07-22 07:10:22 274432 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-07-22 07:10:22 204800 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-07-22 07:10:15 200836 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-07-22 07:10:14 331908 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2011-07-22 04:31:10 -------- d-----w- C:\ProgramData\LightScribe
2011-07-22 04:25:52 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Ahead
2011-07-22 04:15:09 -------- d-----w- C:\ProgramData\Nero
2011-07-22 04:15:09 -------- d-----w- C:\Program Files (x86)\Nero
2011-07-22 03:16:36 -------- d-----w- C:\Windows\SysWow64\Wat
2011-07-22 03:16:36 -------- d-----w- C:\Windows\System32\Wat
2011-07-22 02:36:04 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2011-07-22 02:18:03 -------- d-sh--w- C:\Windows\SysWow64\%APPDATA%
2011-07-21 23:32:52 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2011-07-21 23:32:47 -------- d-----w- C:\Program Files (x86)\Steam
2011-07-21 23:30:59 506728 ----a-w- C:\Windows\System32\d3dx10_33.dll
2011-07-21 21:57:45 -------- d-----w- C:\Windows\Panther
2011-07-21 21:45:27 -------- d-----w- C:\Windows.old
2011-07-21 17:56:20 715776 ----a-w- C:\Windows\System32\kerberos.dll
2011-07-21 17:56:20 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
2011-07-21 17:55:48 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-07-21 17:55:48 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-07-21 17:55:12 2871808 ----a-w- C:\Windows\explorer.exe
2011-07-21 17:55:12 2616320 ----a-w- C:\Windows\SysWow64\explorer.exe
2011-07-21 17:55:01 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2011-07-21 17:55:01 723968 ----a-w- C:\Windows\System32\EncDec.dll
2011-07-21 17:55:00 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-07-21 17:55:00 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-07-21 17:55:00 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2011-07-21 17:55:00 1118720 ----a-w- C:\Windows\System32\sbe.dll
2011-07-21 17:54:59 850944 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-07-21 17:54:59 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-07-21 17:52:54 499200 ----a-w- C:\Windows\System32\drivers\afd.sys
2011-07-21 17:52:53 288640 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2011-07-21 17:50:34 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-21 17:50:34 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2011-07-21 17:49:06 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-07-21 17:49:06 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-07-21 17:49:00 476160 ----a-w- C:\Windows\System32\XpsGdiConverter.dll
2011-07-21 17:49:00 288256 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2011-07-21 17:47:59 244736 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
2011-07-21 17:47:52 189952 ----a-w- C:\Program Files (x86)\Internet Explorer\sqmapi.dll
2011-07-21 17:43:45 613376 ----a-w- C:\Windows\System32\vbscript.dll
2011-07-21 17:43:44 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-07-21 17:42:42 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-07-21 17:42:41 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-07-21 17:41:55 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-07-21 17:41:55 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-07-21 17:41:55 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-07-21 17:41:54 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-07-21 17:40:07 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2011-07-21 17:40:07 367616 ----a-w- C:\Windows\System32\atmfd.dll
2011-07-21 17:40:07 294912 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-07-21 17:40:07 100864 ----a-w- C:\Windows\System32\fontsub.dll
2011-07-21 17:40:06 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-07-21 17:40:06 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-07-21 17:37:56 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-07-21 17:34:04 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-07-21 17:34:03 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-07-21 17:34:03 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
2011-07-21 17:32:43 321024 ----a-w- C:\Windows\System32\d3d10_1core.dll
2011-07-21 17:32:43 219136 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll
2011-07-21 17:32:42 197120 ----a-w- C:\Windows\System32\d3d10_1.dll
2011-07-21 17:32:42 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll
2011-07-21 17:32:37 467456 ----a-w- C:\Windows\System32\drivers\srv.sys
2011-07-21 17:32:37 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys
2011-07-21 17:32:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys
2011-07-21 17:27:55 642944 ----a-w- C:\Windows\System32\winload.efi
2011-07-21 17:27:55 605552 ----a-w- C:\Windows\System32\winload.exe
2011-07-21 17:27:54 566208 ----a-w- C:\Windows\System32\winresume.efi
2011-07-21 17:27:54 518672 ----a-w- C:\Windows\System32\winresume.exe
2011-07-21 17:27:54 20352 ----a-w- C:\Windows\System32\kdusb.dll
2011-07-21 17:27:54 19328 ----a-w- C:\Windows\System32\kd1394.dll
2011-07-21 17:27:54 17792 ----a-w- C:\Windows\System32\kdcom.dll
2011-07-21 17:27:53 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2011-07-21 17:27:44 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-07-21 17:27:44 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-07-21 17:26:39 404480 ----a-w- C:\Windows\System32\umpnpmgr.dll
2011-07-21 17:26:39 252928 ----a-w- C:\Windows\SysWow64\drvinst.exe
2011-07-21 17:26:39 207872 ----a-w- C:\Windows\System32\cfgmgr32.dll
2011-07-21 17:26:39 145920 ----a-w- C:\Windows\SysWow64\cfgmgr32.dll
2011-07-21 17:26:38 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2011-07-21 17:26:38 44544 ----a-w- C:\Windows\SysWow64\devrtl.dll
2011-07-21 17:26:17 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-07-21 17:25:36 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-07-21 17:25:36 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-07-21 17:25:34 974336 ----a-w- C:\Windows\System32\WFS.exe
2011-07-21 17:25:34 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-07-21 17:25:33 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-07-21 17:25:33 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-07-21 17:25:27 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-07-21 16:21:29 -------- d-----w- C:\ProgramData\regid.1986-12.com.adobe
2011-07-21 15:48:54 -------- d-----w- C:\Program Files (x86)\etax2011
2011-07-21 15:30:25 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-07-21 15:29:20 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Microsoft Help
2011-07-21 15:02:15 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-07-21 15:01:40 -------- d-----w- C:\Program Files\DivX
2011-07-21 15:01:32 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2011-07-21 15:00:42 -------- d-----w- C:\Program Files (x86)\DivX
2011-07-21 15:00:18 -------- d-----w- C:\ProgramData\DivX
2011-07-21 14:45:26 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\Lexicon PCM Native
2011-07-21 14:41:36 24576 ----a-w- C:\Windows\SysWow64\Hyperman.dll
2011-07-21 14:41:35 24576 ----a-w- C:\Windows\SysWow64\Wavlbsys.dll
2011-07-21 14:41:31 -------- d-----w- C:\Program Files (x86)\Sonic Foundry
2011-07-21 14:40:19 401462 ----a-w- C:\Windows\SysWow64\temp.001
2011-07-21 14:40:19 266293 ----a-w- C:\Windows\SysWow64\temp.000
2011-07-21 14:39:18 -------- d-----w- C:\Program Files (x86)\Steinberg
2011-07-21 14:39:03 -------- d-----w- C:\Program Files (x86)\Waves
2011-07-21 13:27:23 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\InfinaDyne
2011-07-21 13:26:36 -------- d-----w- C:\ProgramData\InfinaDyne
2011-07-21 13:26:36 -------- d-----w- C:\Program Files (x86)\InfinaDyne
2011-07-21 12:39:13 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-07-21 12:39:13 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-07-21 12:33:02 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-07-21 12:32:51 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\PC Unleashed Online
2011-07-21 09:06:51 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverCure
2011-07-21 09:06:38 -------- d-----w- C:\ProgramData\PC Unleashed Online
2011-07-21 09:05:51 -------- d-----w- C:\Users\Adam Casey\AppData\Local\PC_Drivers_Headquarters
2011-07-21 08:59:33 -------- d-----w- C:\ProgramData\PC Drivers HeadQuarters
2011-07-21 08:49:49 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\DriverFinder
2011-07-21 08:24:14 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-07-21 08:21:29 -------- d-----w- C:\Users\Adam Casey\AppData\Roaming\.minecraft
2011-07-21 07:40:29 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Google
2011-07-21 07:39:57 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
2011-07-21 07:39:56 -------- d-----w- C:\ProgramData\{A97DA822-7B29-4F18-A64A-BF94FFFE77FB}
2011-07-21 07:36:53 -------- d-----w- C:\Program Files (x86)\Lexicon
2011-07-21 07:32:42 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Adobe
2011-07-21 07:30:03 -------- d-----w- C:\Audio
2011-07-21 07:27:42 -------- d-----w- C:\Windows\Downloaded Installations
2011-07-21 06:55:36 -------- d-----w- C:\Program Files\Microsoft IntelliPoint
2011-07-21 06:55:24 -------- d-----w- C:\Windows\PCHEALTH
2011-07-21 06:47:51 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3283C0BE-461D-4A04-8B8E-74E81274F083}\mpengine.dll
2011-07-21 06:47:51 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-07-21 06:42:38 -------- d-----w- C:\Users\Adam Casey\AppData\Local\Apple
2011-07-21 06:42:19 -------- d-----w- C:\Program Files\Bonjour
2011-07-21 06:42:19 -------- d-----w- C:\Program Files (x86)\Bonjour
2011-07-21 06:41:44 -------- d-sh--w- C:\Windows\Installer
2011-07-21 06:33:48 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-21 04:39:47 -------- d-----w- C:\Users\Adam Casey\AppData\Local\ElevatedDiagnostics
2011-07-21 04:04:47 0 ----a-w- C:\Windows\ativpsrm.bin
.
==================== Find3M ====================
.
2011-07-24 03:51:31 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-07-24 03:51:31 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-12 01:34:00 96104 ----a-w- C:\Windows\System32\dns-sd.exe
2011-07-12 01:34:00 85864 ----a-w- C:\Windows\System32\dnssd.dll
2011-07-12 01:34:00 61288 ----a-w- C:\Windows\System32\jdns_sd.dll
2011-07-12 01:34:00 212840 ----a-w- C:\Windows\System32\dnssdX.dll
2011-07-12 01:20:54 83816 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-07-12 01:20:54 73064 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-07-12 01:20:54 50536 ----a-w- C:\Windows\SysWow64\jdns_sd.dll
2011-07-12 01:20:54 178536 ----a-w- C:\Windows\SysWow64\dnssdX.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-07-05 08:37:00 94208 ----a-w- C:\Windows\SysWow64\QuickTimeVR.qtx
2011-07-05 08:37:00 69632 ----a-w- C:\Windows\SysWow64\QuickTime.qts
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-06-02 17:53:02 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
.
============= FINISH: 22:13:19.81 ===============