BenWoodman
New member
I managed to become infected with what Windows Security Essentials identified as Obfuscator.PS. It removed the infection, but then very shortly after, I started to get hard drive failure messages. Soon after, my wallpaper disappeared, along with my desktop icons, quick launch, everything in the start menu. I rebooted into safe mode, and had difficulty locating any of my files as they were all hidden. I ran a Spybot sweep, and it turned up a few tracking cookies, but the scan only took 4 seconds. Not wanting to do any further damage, I turn to you helpful folk on here. DDS logs follow
.
DDS (Ver_2011-06-03.01) - NTFSAMD64 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Ben at 17:59:09 on 2011-06-09
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.8190.7274 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = <local>;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
uRun: [WindowsLivePhone] "C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe" /AutoRun
uRun: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
uRun: [XYDSfKXFbF] C:\ProgramData\XYDSfKXFbF.exe
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [AsusStartupHelp] "C:\Program Files (x86)\ASUS\AASP\1.00.24\AsRunHelp.exe"
mRun: [NSLauncher] C:\Program Files (x86)\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
mRun: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Mobile Connectivity Suite] "E:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRun: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15030/CTSUEng.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
TCP: Interfaces\{34004F2C-0702-486E-8057-C207DE555446} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{859F9BF7-116B-42B3-AC2A-2903E3A3EFF5} : NameServer = 8.8.4.4
TCP: Interfaces\{B898CFE9-8411-47FD-B663-826D0305C1B6} : DhcpNameServer = 192.168.1.1
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE
mRun-x64: [AsusStartupHelp] "C:\Program Files (x86)\ASUS\AASP\1.00.24\AsRunHelp.exe"
mRun-x64: [NSLauncher] C:\Program Files (x86)\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
mRun-x64: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun-x64: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
mRun-x64: [CTHelper] CTHELPER.EXE
mRun-x64: [CTxfiHlp] CTXFIHLP.EXE
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Mobile Connectivity Suite] "E:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\ao4r6roe.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
.
============= SERVICES / DRIVERS ===============
.
S1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-3-29 21504]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-12 136176]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-6-9 1153368]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdLH6.sys --> C:\Windows\system32\drivers\AtihdLH6.sys [?]
S3 Belkin700F;Belkin Wireless G Desktop Card Service v7;C:\Windows\system32\DRIVERS\BLKWGDx64v7.sys --> C:\Windows\system32\DRIVERS\BLKWGDx64v7.sys [?]
S3 BLKWGDv8x64;Belkin Wireless G Desktop Card Service v8;C:\Windows\system32\DRIVERS\BLKWGDv8x64.sys --> C:\Windows\system32\DRIVERS\BLKWGDv8x64.sys [?]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL1Licensing.exe [2007-9-13 79360]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-12 136176]
S3 HTCAND64;HTC Device Driver;C:\Windows\system32\Drivers\ANDROIDUSB.sys --> C:\Windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 nmwcdcjx64;Nokia USB Port;C:\Windows\system32\drivers\nmwcdcjx64.sys --> C:\Windows\system32\drivers\nmwcdcjx64.sys [?]
S3 nmwcdcmx64;Nokia USB Modem;C:\Windows\system32\drivers\nmwcdcmx64.sys --> C:\Windows\system32\drivers\nmwcdcmx64.sys [?]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\nmwcdcx64.sys --> C:\Windows\system32\drivers\nmwcdcx64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\nmwcdx64.sys --> C:\Windows\system32\drivers\nmwcdx64.sys [?]
S3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50a64.sys --> C:\Windows\system32\Drivers\PCAMp50a64.sys [?]
S3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50a64.sys --> C:\Windows\system32\Drivers\PCASp50a64.sys [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-3-29 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\Windows\system32\DRIVERS\WPN111vx.sys --> C:\Windows\system32\DRIVERS\WPN111vx.sys [?]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-16 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-06-09 16:42:31 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-06-09 16:42:31 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-06-09 16:41:31 -------- d-----w- C:\MSNCleaner
2011-06-08 17:42:17 376832 ----a-w- C:\ProgramData\44097272.exe
2011-06-08 17:35:45 477184 ----a-w- C:\ProgramData\XYDSfKXFbF.exe
2011-06-08 16:35:40 -------- d--h--w- C:\Users\Ben\AppData\Local\{DE8548E5-C987-4D22-BA47-2410A10B61ED}
2011-06-07 17:28:17 -------- d-----w- C:\Program Files\iPod
2011-06-07 17:28:16 -------- d-----w- C:\Program Files\iTunes
2011-06-07 17:15:10 8718160 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DDE3D28C-ADD7-49C7-A583-7B5E1BBE8254}\mpengine.dll
2011-06-07 17:04:24 -------- d--h--w- C:\Users\Ben\AppData\Local\{FF8A0D64-A812-4F8B-9CAD-5C787F451372}
2011-06-05 13:53:55 -------- d--h--w- C:\Users\Ben\AppData\Local\{77207753-38C2-4CB8-A0C8-50568B83F11C}
2011-06-04 18:13:54 -------- d--h--w- C:\Users\Ben\AppData\Local\{11589C69-96F5-469F-B5DF-1D7F48361140}
2011-06-03 21:44:38 -------- d--h--w- C:\Users\Ben\AppData\Local\{1338CB6E-AF0D-4F09-AEED-B0192F91916B}
2011-05-29 14:30:44 -------- d--h--w- C:\Users\Ben\AppData\Local\{C98D0310-9994-4F61-8B27-CE83A5162761}
2011-05-28 14:42:26 -------- d--h--w- C:\Users\Ben\AppData\Local\{4A3CACD9-9AB6-42F8-ACF1-626C629047F3}
2011-05-27 20:18:13 8718160 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-27 20:08:25 -------- d--h--w- C:\Users\Ben\AppData\Local\{6EFA87EB-C9A5-4C1D-B1F3-92AB6406EAF2}
2011-05-22 18:36:44 -------- d-----w- C:\Program Files (x86)\AMD APP
2011-05-22 18:36:32 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2011-05-22 16:05:37 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{69D0A5A0-DB4D-456C-92CA-3E2EEE3CB012}\gapaengine.dll
2011-05-22 15:55:45 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-05-22 15:55:29 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-05-22 15:54:39 345984 ----a-w- C:\Windows\System32\drivers\netio.sys
2011-05-22 14:35:27 -------- d--h--w- C:\Users\Ben\AppData\Local\{5B5407D4-485C-4099-BAC9-2CCC8D1E96D6}
2011-05-21 18:47:27 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-05-21 18:20:54 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9F6A3DF-E51F-4240-9B26-DB81F592CD95}\mpengine.dll
2011-05-21 18:14:08 -------- d--h--w- C:\Users\Ben\AppData\Local\{0EF63A3A-17AC-41A2-8388-3726926835E4}
2011-05-15 13:54:16 -------- d--h--w- C:\Users\Ben\AppData\Local\{18445EE3-68EB-4966-9E0D-78295ECA0D34}
2011-05-14 14:19:51 -------- d--h--w- C:\Users\Ben\AppData\Local\{D06A2C56-0C4A-47DA-AFAD-EBAF3181A9BF}
2011-05-13 14:31:03 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2011-05-13 14:31:03 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2011-05-13 14:28:08 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-05-13 14:28:08 203776 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-05-13 14:28:05 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2011-05-13 14:28:05 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-05-13 14:28:04 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-05-13 14:27:57 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-05-13 14:27:57 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-05-13 14:27:45 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-05-13 14:27:42 6389760 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-05-13 14:27:38 9319936 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-05-13 14:27:09 17693184 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-05-13 14:27:06 1923584 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-05-13 14:27:04 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-05-13 14:27:00 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-05-13 14:27:00 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-05-13 14:26:55 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-05-13 14:26:52 1222656 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-05-13 14:26:44 4286464 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-05-13 14:26:02 22900736 ----a-w- C:\Windows\System32\atio6axx.dll
2011-05-13 14:26:00 4951552 ----a-w- C:\Windows\System32\atidxx64.dll
2011-05-13 14:24:57 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-05-13 14:24:56 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2011-05-13 14:24:51 7768064 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-05-13 14:24:50 262144 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-05-13 14:24:46 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-05-13 14:24:46 4056576 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-05-13 14:24:06 -------- d--h--w- C:\Users\Ben\AppData\Local\{75D8B32C-B2A2-4C6E-BA64-B21DA2C832CC}
.
==================== Find3M ====================
.
2011-05-13 14:27:57 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-05-13 14:26:53 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-05-13 14:26:38 4161536 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-05-13 14:26:18 3868672 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-05-13 14:24:51 676864 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-05-13 14:24:51 45056 ----a-w- C:\Windows\System32\atitmp64.dll
2011-05-04 03:52:22 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-04-19 21:10:34 61952 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-04-19 21:10:32 59904 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-04-19 21:10:22 53760 ----a-w- C:\Windows\System32\OpenCL.dll
2011-04-19 21:10:18 51712 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2011-04-19 21:10:14 16116224 ----a-w- C:\Windows\System32\amdocl64.dll
2011-04-19 21:10:02 12385280 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-04-09 17:55:44 15453336 ----a-w- C:\Windows\SysWow64\xlive.dll
2011-04-09 17:55:42 13642904 ----a-w- C:\Windows\SysWow64\xlivefnt.dll
2011-04-06 15:26:58 96544 ----a-w- C:\Windows\System32\dnssd.dll
2011-04-06 15:26:58 119584 ----a-w- C:\Windows\System32\dns-sd.exe
2011-04-06 15:20:16 91424 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-04-06 15:20:16 107808 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-03-12 22:52:03 1653760 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 21:55:52 876032 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
.
============= FINISH: 17:59:21.12 ===============
Any thanks is very much appreciated.
.
DDS (Ver_2011-06-03.01) - NTFSAMD64 MINIMAL
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by Ben at 17:59:09 on 2011-06-09
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.8190.7274 [GMT 1:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = <local>;*.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
uRun: [WindowsLivePhone] "C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe" /AutoRun
uRun: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
uRun: [XYDSfKXFbF] C:\ProgramData\XYDSfKXFbF.exe
uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
mRun: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [AsusStartupHelp] "C:\Program Files (x86)\ASUS\AASP\1.00.24\AsRunHelp.exe"
mRun: [NSLauncher] C:\Program Files (x86)\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
mRun: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [Mobile Connectivity Suite] "E:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
dRun: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15030/CTSUEng.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
TCP: Interfaces\{34004F2C-0702-486E-8057-C207DE555446} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{859F9BF7-116B-42B3-AC2A-2903E3A3EFF5} : NameServer = 8.8.4.4
TCP: Interfaces\{B898CFE9-8411-47FD-B663-826D0305C1B6} : DhcpNameServer = 192.168.1.1
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "C:\Program Files (x86)\Common Files\LightScribe\LSRunOnce.exe"
BHO-X64: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [VolPanel] "C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE
mRun-x64: [AsusStartupHelp] "C:\Program Files (x86)\ASUS\AASP\1.00.24\AsRunHelp.exe"
mRun-x64: [NSLauncher] C:\Program Files (x86)\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
mRun-x64: [WindowsLivePhone] C:\Program Files (x86)\Windows Live\Device Manager\msgrdvmn.exe /AutoRun
mRun-x64: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
mRun-x64: [CTHelper] CTHELPER.EXE
mRun-x64: [CTxfiHlp] CTXFIHLP.EXE
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [Mobile Connectivity Suite] "E:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\ao4r6roe.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - plugin: E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
.
============= SERVICES / DRIVERS ===============
.
S1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-3-29 21504]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-12 136176]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-6-9 1153368]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdLH6.sys --> C:\Windows\system32\drivers\AtihdLH6.sys [?]
S3 Belkin700F;Belkin Wireless G Desktop Card Service v7;C:\Windows\system32\DRIVERS\BLKWGDx64v7.sys --> C:\Windows\system32\DRIVERS\BLKWGDx64v7.sys [?]
S3 BLKWGDv8x64;Belkin Wireless G Desktop Card Service v8;C:\Windows\system32\DRIVERS\BLKWGDv8x64.sys --> C:\Windows\system32\DRIVERS\BLKWGDv8x64.sys [?]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL1Licensing.exe [2007-9-13 79360]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-5-12 136176]
S3 HTCAND64;HTC Device Driver;C:\Windows\system32\Drivers\ANDROIDUSB.sys --> C:\Windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616]
S3 nmwcdcjx64;Nokia USB Port;C:\Windows\system32\drivers\nmwcdcjx64.sys --> C:\Windows\system32\drivers\nmwcdcjx64.sys [?]
S3 nmwcdcmx64;Nokia USB Modem;C:\Windows\system32\drivers\nmwcdcmx64.sys --> C:\Windows\system32\drivers\nmwcdcmx64.sys [?]
S3 nmwcdcx64;Nokia USB Generic;C:\Windows\system32\drivers\nmwcdcx64.sys --> C:\Windows\system32\drivers\nmwcdcx64.sys [?]
S3 nmwcdx64;Nokia USB Phone Parent;C:\Windows\system32\drivers\nmwcdx64.sys --> C:\Windows\system32\drivers\nmwcdx64.sys [?]
S3 PCAMp50a64;PCAMp50a64 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50a64.sys --> C:\Windows\system32\Drivers\PCAMp50a64.sys [?]
S3 PCASp50a64;PCASp50a64 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50a64.sys --> C:\Windows\system32\Drivers\PCASp50a64.sys [?]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-3-29 19968]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\Windows\system32\DRIVERS\WPN111vx.sys --> C:\Windows\system32\DRIVERS\WPN111vx.sys [?]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-9-16 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-06-09 16:42:31 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-06-09 16:42:31 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy
2011-06-09 16:41:31 -------- d-----w- C:\MSNCleaner
2011-06-08 17:42:17 376832 ----a-w- C:\ProgramData\44097272.exe
2011-06-08 17:35:45 477184 ----a-w- C:\ProgramData\XYDSfKXFbF.exe
2011-06-08 16:35:40 -------- d--h--w- C:\Users\Ben\AppData\Local\{DE8548E5-C987-4D22-BA47-2410A10B61ED}
2011-06-07 17:28:17 -------- d-----w- C:\Program Files\iPod
2011-06-07 17:28:16 -------- d-----w- C:\Program Files\iTunes
2011-06-07 17:15:10 8718160 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{DDE3D28C-ADD7-49C7-A583-7B5E1BBE8254}\mpengine.dll
2011-06-07 17:04:24 -------- d--h--w- C:\Users\Ben\AppData\Local\{FF8A0D64-A812-4F8B-9CAD-5C787F451372}
2011-06-05 13:53:55 -------- d--h--w- C:\Users\Ben\AppData\Local\{77207753-38C2-4CB8-A0C8-50568B83F11C}
2011-06-04 18:13:54 -------- d--h--w- C:\Users\Ben\AppData\Local\{11589C69-96F5-469F-B5DF-1D7F48361140}
2011-06-03 21:44:38 -------- d--h--w- C:\Users\Ben\AppData\Local\{1338CB6E-AF0D-4F09-AEED-B0192F91916B}
2011-05-29 14:30:44 -------- d--h--w- C:\Users\Ben\AppData\Local\{C98D0310-9994-4F61-8B27-CE83A5162761}
2011-05-28 14:42:26 -------- d--h--w- C:\Users\Ben\AppData\Local\{4A3CACD9-9AB6-42F8-ACF1-626C629047F3}
2011-05-27 20:18:13 8718160 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-05-27 20:08:25 -------- d--h--w- C:\Users\Ben\AppData\Local\{6EFA87EB-C9A5-4C1D-B1F3-92AB6406EAF2}
2011-05-22 18:36:44 -------- d-----w- C:\Program Files (x86)\AMD APP
2011-05-22 18:36:32 -------- d-----w- C:\Program Files (x86)\ATI Technologies
2011-05-22 16:05:37 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{69D0A5A0-DB4D-456C-92CA-3E2EEE3CB012}\gapaengine.dll
2011-05-22 15:55:45 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-05-22 15:55:29 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-05-22 15:54:39 345984 ----a-w- C:\Windows\System32\drivers\netio.sys
2011-05-22 14:35:27 -------- d--h--w- C:\Users\Ben\AppData\Local\{5B5407D4-485C-4099-BAC9-2CCC8D1E96D6}
2011-05-21 18:47:27 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-05-21 18:20:54 8718160 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B9F6A3DF-E51F-4240-9B26-DB81F592CD95}\mpengine.dll
2011-05-21 18:14:08 -------- d--h--w- C:\Users\Ben\AppData\Local\{0EF63A3A-17AC-41A2-8388-3726926835E4}
2011-05-15 13:54:16 -------- d--h--w- C:\Users\Ben\AppData\Local\{18445EE3-68EB-4966-9E0D-78295ECA0D34}
2011-05-14 14:19:51 -------- d--h--w- C:\Users\Ben\AppData\Local\{D06A2C56-0C4A-47DA-AFAD-EBAF3181A9BF}
2011-05-13 14:31:03 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2011-05-13 14:31:03 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2011-05-13 14:28:08 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-05-13 14:28:08 203776 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-05-13 14:28:05 53760 ----a-w- C:\Windows\System32\atimpc64.dll
2011-05-13 14:28:05 53760 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-05-13 14:28:04 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-05-13 14:27:57 52736 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-05-13 14:27:57 52736 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-05-13 14:27:45 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-05-13 14:27:42 6389760 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-05-13 14:27:38 9319936 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-05-13 14:27:09 17693184 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-05-13 14:27:06 1923584 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-05-13 14:27:04 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-05-13 14:27:00 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-05-13 14:27:00 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-05-13 14:26:55 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-05-13 14:26:52 1222656 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-05-13 14:26:44 4286464 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-05-13 14:26:02 22900736 ----a-w- C:\Windows\System32\atio6axx.dll
2011-05-13 14:26:00 4951552 ----a-w- C:\Windows\System32\atidxx64.dll
2011-05-13 14:24:57 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-05-13 14:24:56 16384 ----a-w- C:\Windows\System32\atimuixx.dll
2011-05-13 14:24:51 7768064 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-05-13 14:24:50 262144 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-05-13 14:24:46 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-05-13 14:24:46 4056576 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-05-13 14:24:06 -------- d--h--w- C:\Users\Ben\AppData\Local\{75D8B32C-B2A2-4C6E-BA64-B21DA2C832CC}
.
==================== Find3M ====================
.
2011-05-13 14:27:57 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-05-13 14:26:53 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-05-13 14:26:38 4161536 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-05-13 14:26:18 3868672 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-05-13 14:24:51 676864 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-05-13 14:24:51 45056 ----a-w- C:\Windows\System32\atitmp64.dll
2011-05-04 03:52:22 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-04-19 21:10:34 61952 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-04-19 21:10:32 59904 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-04-19 21:10:22 53760 ----a-w- C:\Windows\System32\OpenCL.dll
2011-04-19 21:10:18 51712 ----a-w- C:\Windows\SysWow64\OpenCL.dll
2011-04-19 21:10:14 16116224 ----a-w- C:\Windows\System32\amdocl64.dll
2011-04-19 21:10:02 12385280 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-04-09 17:55:44 15453336 ----a-w- C:\Windows\SysWow64\xlive.dll
2011-04-09 17:55:42 13642904 ----a-w- C:\Windows\SysWow64\xlivefnt.dll
2011-04-06 15:26:58 96544 ----a-w- C:\Windows\System32\dnssd.dll
2011-04-06 15:26:58 119584 ----a-w- C:\Windows\System32\dns-sd.exe
2011-04-06 15:20:16 91424 ----a-w- C:\Windows\SysWow64\dnssd.dll
2011-04-06 15:20:16 107808 ----a-w- C:\Windows\SysWow64\dns-sd.exe
2011-03-12 22:52:03 1653760 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 21:55:52 876032 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
.
============= FINISH: 17:59:21.12 ===============
Any thanks is very much appreciated.