fjsizemore
New member
My system became infected. I tried several things to remove. I eventually had to run a complete system restore, but it was still infected after restore.
Since the restore, I have downloaded and ran Malwarebytes, superantispyware, spybot search and destroy, and windows malicious file remover, i have also used mcaffee.
the symptoms include redirects using browsers, both internet explorer and firefox.
Also Iexplore starts on its own and then I hear over the speakers various radio stations and ads. Some are local stations I recognize, some are not.
here is the dds log
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by Sizemore at 20:08:27 on 2011-10-20
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3002.1832 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Spybot - Search & Destroy *Enabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wuauclt.exe
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\explorer.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookHelper.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111017014419.dll
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - C:\ProgramData\Partner\Partner.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
TCP: DhcpNameServer = 192.168.254.254
TCP: Interfaces\{71ED1027-C273-4D0D-99C4-D5299971C003} : DhcpNameServer = 192.168.254.254
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Notify: SDWinLogon - SDWinLogon.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111017014419.dll
BHO-X64: scriptproxy - No File
BHO-X64: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
mRun-x64: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
mRun-x64: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun-x64: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Sizemore\AppData\Roaming\Mozilla\Firefox\Profiles\qo4juh29.default\
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [?]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [?]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SDHookDriver;Spybot-S&D 2 Hook Driver;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [2011-10-20 48888]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-4-27 325200]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-10-16 865824]
R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-4-26 13336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McShield;McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2010-4-27 200056]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2010-4-27 245352]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe [2010-4-27 149032]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-3-8 250368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-5 144640]
R2 SDHookService;Spybot S&D 2 Live Protection Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe [2011-10-20 130976]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2011-10-20 892336]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2011-10-20 955816]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2011-10-20 169624]
R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-4-27 243232]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-16 135664]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-16 135664]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-2-1 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-5 50432]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2010-4-27 332272]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-4-26 225280]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
.
=============== Created Last 30 ================
.
2011-10-20 23:34:58 -------- d-----w- C:\ProcAlyzer Dumps
2011-10-20 21:45:36 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-10-20 21:45:26 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2011-10-20 21:45:22 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2011-10-20 01:41:11 99840 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\HPZPPLHN.DLL
2011-10-19 20:43:05 -------- d-----w- C:\Users\Sizemore\AppData\Local\Adobe
2011-10-19 17:04:25 -------- d-----w- C:\Windows\SysWow64\Wat
2011-10-19 17:04:25 -------- d-----w- C:\Windows\System32\Wat
2011-10-18 21:17:14 -------- d-----w- C:\Users\Sizemore\AppData\Local\Microsoft Games
2011-10-18 21:16:07 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\WildTangent
2011-10-18 21:04:23 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\SUPERAntiSpyware.com
2011-10-18 02:25:32 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2011-10-18 02:25:32 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
2011-10-18 02:04:49 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2011-10-18 02:04:49 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2011-10-18 02:04:49 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2011-10-18 02:04:49 444752 ----a-w- C:\Windows\System32\mscoree.dll
2011-10-18 02:04:49 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2011-10-18 02:04:49 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2011-10-18 02:04:49 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2011-10-18 02:04:49 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-10-18 02:04:49 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-10-18 02:04:49 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2011-10-18 01:31:00 -------- d-----w- C:\Users\Sizemore\AppData\Local\ElevatedDiagnostics
2011-10-17 05:36:27 24376 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\Scriptff.dll
2011-10-17 05:22:41 -------- d-----w- C:\Windows\NAPP_Dism_Log
2011-10-17 04:29:20 3 ----a-w- C:\Windows\System32\PLD_Framework.cmd
2011-10-17 04:27:47 -------- d-----w- C:\Windows\SysWow64\x64
2011-10-17 04:27:47 -------- d-----w- C:\Windows\SysWow64\Lang
2011-10-17 04:27:46 1002008 ----a-w- C:\Windows\SysWow64\igxpun.exe
2011-10-17 03:29:15 -------- d-----w- C:\96e3a79989575a52000408d0e44dca
2011-10-17 03:03:11 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2011-10-17 03:03:11 184832 ----a-w- C:\Windows\System32\drivers\usbvideo.sys
2011-10-17 02:36:41 102400 ----a-w- C:\Windows\System32\drivers\dfsc.sys
2011-10-17 02:36:35 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2011-10-17 02:36:35 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2011-10-17 02:36:35 153160 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-10-17 02:36:35 1446912 ----a-w- C:\Windows\System32\lsasrv.dll
2011-10-17 02:36:31 483840 ----a-w- C:\Windows\System32\StructuredQuery.dll
2011-10-17 02:36:31 363520 ----a-w- C:\Windows\SysWow64\StructuredQuery.dll
2011-10-17 02:36:27 1739176 ----a-w- C:\Windows\System32\ntdll.dll
2011-10-17 02:36:26 1293120 ----a-w- C:\Windows\SysWow64\ntdll.dll
2011-10-17 02:34:24 2228224 ----a-w- C:\Windows\System32\mssrch.dll
2011-10-17 02:33:43 1837568 ----a-w- C:\Windows\System32\d3d10warp.dll
2011-10-17 02:32:50 367104 ----a-w- C:\Windows\System32\atmfd.dll
2011-10-17 02:31:48 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-10-17 02:29:58 2870272 ----a-w- C:\Windows\explorer.exe
2011-10-17 02:27:33 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2011-10-17 02:26:54 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-10-17 02:25:57 320512 ----a-w- C:\Windows\System32\d3d10_1core.dll
2011-10-17 02:24:59 52224 ----a-w- C:\Windows\System32\rtutils.dll
2011-10-17 02:24:59 37376 ----a-w- C:\Windows\SysWow64\rtutils.dll
2011-10-17 02:22:22 5507968 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-10-17 02:22:21 3957120 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-10-17 02:22:21 3902336 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-10-17 02:22:15 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2011-10-17 02:22:13 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2011-10-17 02:22:06 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-10-17 02:22:02 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-10-17 02:22:02 740864 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-10-17 02:21:59 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-17 02:21:58 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-17 02:21:58 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-17 02:21:58 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-17 02:21:56 112000 ----a-w- C:\Windows\System32\consent.exe
2011-10-17 02:19:46 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\Malwarebytes
2011-10-17 02:19:35 -------- d-----w- C:\ProgramData\Malwarebytes
2011-10-17 02:19:31 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-10-17 02:18:18 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-10-17 02:12:54 720896 ----a-w- C:\Windows\System32\odbc32.dll
2011-10-17 02:12:54 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
2011-10-17 02:12:54 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-10-17 02:12:52 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-10-17 02:12:52 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-10-17 02:12:52 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-10-17 02:12:51 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-10-17 02:12:50 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-10-17 02:12:50 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-10-17 02:12:50 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-10-17 01:50:00 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-10-17 01:50:00 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-10-17 01:49:42 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-10-17 01:48:59 -------- d-----w- C:\Program Files (x86)\Microsoft
2011-10-17 01:48:32 -------- d-----w- C:\Program Files (x86)\Windows Live SkyDrive
2011-10-17 01:47:55 74520 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca69052d1cc8c6e\DSETUP.dll
2011-10-17 01:47:55 484632 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca69052d1cc8c6e\DXSETUP.exe
2011-10-17 01:47:55 1670936 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca69052d1cc8c6e\dsetup32.dll
2011-10-17 01:47:26 141402440 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlc2656.tmp
2011-10-17 01:47:23 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-10-17 01:46:15 -------- d-----w- C:\Program Files (x86)\Common Files\CyberLink
2011-10-17 01:45:03 505128 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2011-10-17 01:45:03 353576 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2011-10-17 01:45:03 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2011-10-17 01:42:58 -------- d-----w- C:\Program Files\Synaptics
2011-10-17 01:40:57 -------- d-----w- C:\Program Files (x86)\Launch Manager
2011-10-17 01:40:32 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\Intel Corporation
2011-10-17 01:40:12 -------- d---a-w- C:\book
2011-10-17 01:40:11 -------- d-----w- C:\Users\Sizemore\AppData\Local\EgisTec IPS
2011-10-17 01:37:23 220672 ----a-w- C:\Windows\System32\wintrust.dll
2011-10-17 01:37:23 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2011-10-17 01:37:23 139264 ----a-w- C:\Windows\System32\cabview.dll
2011-10-17 01:37:23 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2011-10-17 01:37:23 -------- d-----w- C:\Program Files (x86)\OEM
2011-10-17 01:37:14 -------- d-----w- C:\ProgramData\OEM_E471269A730D
.
==================== Find3M ====================
.
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-09-06 03:07:02 3134976 ----a-w- C:\Windows\System32\win32k.sys
2011-08-20 05:45:20 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-08-20 05:41:16 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-08-20 04:38:10 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-08-20 04:35:20 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-08-20 04:20:23 482816 ----a-w- C:\Windows\System32\html.iec
2011-08-20 03:26:38 386048 ----a-w- C:\Windows\SysWow64\html.iec
2011-08-17 05:32:24 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-08-17 05:27:46 75776 ----a-w- C:\Windows\System32\MSDvbNP.ax
2011-08-17 05:27:46 288256 ----a-w- C:\Windows\System32\MSNP.ax
2011-08-17 05:27:46 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-08-17 05:27:46 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2011-08-17 04:26:02 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-08-17 04:22:23 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-08-17 04:22:23 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-08-17 04:22:23 59904 ----a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-08-17 04:22:23 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
.
============= FINISH: 20:18:10.70 ===============
Since the restore, I have downloaded and ran Malwarebytes, superantispyware, spybot search and destroy, and windows malicious file remover, i have also used mcaffee.
the symptoms include redirects using browsers, both internet explorer and firefox.
Also Iexplore starts on its own and then I hear over the speakers various radio stations and ads. Some are local stations I recognize, some are not.
here is the dds log
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by Sizemore at 20:08:27 on 2011-10-20
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3002.1832 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Spybot - Search & Destroy *Enabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Acer\Acer Updater\UpdaterService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wuauclt.exe
C:\Program Files\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\explorer.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookHelper.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&m=aspire_5734z&r=27361011t225l04f4z1k5t5632o373
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111017014419.dll
BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - C:\ProgramData\Partner\Partner.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
mRun: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
mRun: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
TCP: DhcpNameServer = 192.168.254.254
TCP: Interfaces\{71ED1027-C273-4D0D-99C4-D5299971C003} : DhcpNameServer = 192.168.254.254
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Notify: SDWinLogon - SDWinLogon.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111017014419.dll
BHO-X64: scriptproxy - No File
BHO-X64: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
mRun-x64: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
mRun-x64: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun-x64: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Sizemore\AppData\Roaming\Mozilla\Firefox\Profiles\qo4juh29.default\
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\McAfee\SiteAdvisor\NPMcFFPlg32.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 mwlPSDFilter;mwlPSDFilter;C:\Windows\system32\DRIVERS\mwlPSDFilter.sys --> C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [?]
R1 mwlPSDNServ;mwlPSDNServ;C:\Windows\system32\DRIVERS\mwlPSDNServ.sys --> C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [?]
R1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys --> C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 SDHookDriver;Spybot-S&D 2 Hook Driver;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [2011-10-20 48888]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-11 140672]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-4-27 325200]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2011-10-16 865824]
R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-1-8 23584]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-4-26 13336]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
R2 McShield;McShield;C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe [2010-4-27 200056]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe [2010-4-27 245352]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe [2010-4-27 149032]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-3-8 250368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2009-11-5 144640]
R2 SDHookService;Spybot S&D 2 Live Protection Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe [2011-10-20 130976]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2011-10-20 892336]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2011-10-20 955816]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2011-10-20 169624]
R2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-4-27 243232]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1C62x64.sys --> C:\Windows\system32\DRIVERS\L1C62x64.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-16 135664]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-10-16 135664]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-2-1 305520]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2009-11-5 50432]
S3 Partner Service;Partner Service;C:\ProgramData\Partner\Partner.exe [2010-4-27 332272]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2010-4-26 225280]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 McOobeSv;McAfee OOBE Service;C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe [2011-10-17 355440]
.
=============== Created Last 30 ================
.
2011-10-20 23:34:58 -------- d-----w- C:\ProcAlyzer Dumps
2011-10-20 21:45:36 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-10-20 21:45:26 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2011-10-20 21:45:22 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2011-10-20 01:41:11 99840 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\HPZPPLHN.DLL
2011-10-19 20:43:05 -------- d-----w- C:\Users\Sizemore\AppData\Local\Adobe
2011-10-19 17:04:25 -------- d-----w- C:\Windows\SysWow64\Wat
2011-10-19 17:04:25 -------- d-----w- C:\Windows\System32\Wat
2011-10-18 21:17:14 -------- d-----w- C:\Users\Sizemore\AppData\Local\Microsoft Games
2011-10-18 21:16:07 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\WildTangent
2011-10-18 21:04:23 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\SUPERAntiSpyware.com
2011-10-18 02:25:32 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2011-10-18 02:25:32 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
2011-10-18 02:04:49 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2011-10-18 02:04:49 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2011-10-18 02:04:49 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2011-10-18 02:04:49 444752 ----a-w- C:\Windows\System32\mscoree.dll
2011-10-18 02:04:49 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2011-10-18 02:04:49 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2011-10-18 02:04:49 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2011-10-18 02:04:49 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-10-18 02:04:49 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-10-18 02:04:49 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2011-10-18 01:31:00 -------- d-----w- C:\Users\Sizemore\AppData\Local\ElevatedDiagnostics
2011-10-17 05:36:27 24376 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\Scriptff.dll
2011-10-17 05:22:41 -------- d-----w- C:\Windows\NAPP_Dism_Log
2011-10-17 04:29:20 3 ----a-w- C:\Windows\System32\PLD_Framework.cmd
2011-10-17 04:27:47 -------- d-----w- C:\Windows\SysWow64\x64
2011-10-17 04:27:47 -------- d-----w- C:\Windows\SysWow64\Lang
2011-10-17 04:27:46 1002008 ----a-w- C:\Windows\SysWow64\igxpun.exe
2011-10-17 03:29:15 -------- d-----w- C:\96e3a79989575a52000408d0e44dca
2011-10-17 03:03:11 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2011-10-17 03:03:11 184832 ----a-w- C:\Windows\System32\drivers\usbvideo.sys
2011-10-17 02:36:41 102400 ----a-w- C:\Windows\System32\drivers\dfsc.sys
2011-10-17 02:36:35 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2011-10-17 02:36:35 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2011-10-17 02:36:35 153160 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2011-10-17 02:36:35 1446912 ----a-w- C:\Windows\System32\lsasrv.dll
2011-10-17 02:36:31 483840 ----a-w- C:\Windows\System32\StructuredQuery.dll
2011-10-17 02:36:31 363520 ----a-w- C:\Windows\SysWow64\StructuredQuery.dll
2011-10-17 02:36:27 1739176 ----a-w- C:\Windows\System32\ntdll.dll
2011-10-17 02:36:26 1293120 ----a-w- C:\Windows\SysWow64\ntdll.dll
2011-10-17 02:34:24 2228224 ----a-w- C:\Windows\System32\mssrch.dll
2011-10-17 02:33:43 1837568 ----a-w- C:\Windows\System32\d3d10warp.dll
2011-10-17 02:32:50 367104 ----a-w- C:\Windows\System32\atmfd.dll
2011-10-17 02:31:48 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-10-17 02:29:58 2870272 ----a-w- C:\Windows\explorer.exe
2011-10-17 02:27:33 4582912 ----a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2011-10-17 02:26:54 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-10-17 02:25:57 320512 ----a-w- C:\Windows\System32\d3d10_1core.dll
2011-10-17 02:24:59 52224 ----a-w- C:\Windows\System32\rtutils.dll
2011-10-17 02:24:59 37376 ----a-w- C:\Windows\SysWow64\rtutils.dll
2011-10-17 02:22:22 5507968 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-10-17 02:22:21 3957120 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-10-17 02:22:21 3902336 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-10-17 02:22:15 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2011-10-17 02:22:13 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2011-10-17 02:22:06 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-10-17 02:22:02 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-10-17 02:22:02 740864 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-10-17 02:21:59 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-17 02:21:58 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-17 02:21:58 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-17 02:21:58 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-17 02:21:56 112000 ----a-w- C:\Windows\System32\consent.exe
2011-10-17 02:19:46 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\Malwarebytes
2011-10-17 02:19:35 -------- d-----w- C:\ProgramData\Malwarebytes
2011-10-17 02:19:31 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-10-17 02:18:18 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-10-17 02:12:54 720896 ----a-w- C:\Windows\System32\odbc32.dll
2011-10-17 02:12:54 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
2011-10-17 02:12:54 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2011-10-17 02:12:52 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2011-10-17 02:12:52 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2011-10-17 02:12:52 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2011-10-17 02:12:51 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2011-10-17 02:12:50 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2011-10-17 02:12:50 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2011-10-17 02:12:50 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2011-10-17 01:50:00 4398360 ----a-w- C:\Windows\System32\d3dx9_32.dll
2011-10-17 01:50:00 3426072 ----a-w- C:\Windows\SysWow64\d3dx9_32.dll
2011-10-17 01:49:42 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2011-10-17 01:48:59 -------- d-----w- C:\Program Files (x86)\Microsoft
2011-10-17 01:48:32 -------- d-----w- C:\Program Files (x86)\Windows Live SkyDrive
2011-10-17 01:47:55 74520 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca69052d1cc8c6e\DSETUP.dll
2011-10-17 01:47:55 484632 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca69052d1cc8c6e\DXSETUP.exe
2011-10-17 01:47:55 1670936 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ca69052d1cc8c6e\dsetup32.dll
2011-10-17 01:47:26 141402440 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\wlc2656.tmp
2011-10-17 01:47:23 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2011-10-17 01:46:15 -------- d-----w- C:\Program Files (x86)\Common Files\CyberLink
2011-10-17 01:45:03 505128 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2011-10-17 01:45:03 353576 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2011-10-17 01:45:03 29480 ----a-w- C:\Windows\SysWow64\msxml3a.dll
2011-10-17 01:42:58 -------- d-----w- C:\Program Files\Synaptics
2011-10-17 01:40:57 -------- d-----w- C:\Program Files (x86)\Launch Manager
2011-10-17 01:40:32 -------- d-----w- C:\Users\Sizemore\AppData\Roaming\Intel Corporation
2011-10-17 01:40:12 -------- d---a-w- C:\book
2011-10-17 01:40:11 -------- d-----w- C:\Users\Sizemore\AppData\Local\EgisTec IPS
2011-10-17 01:37:23 220672 ----a-w- C:\Windows\System32\wintrust.dll
2011-10-17 01:37:23 172032 ----a-w- C:\Windows\SysWow64\wintrust.dll
2011-10-17 01:37:23 139264 ----a-w- C:\Windows\System32\cabview.dll
2011-10-17 01:37:23 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2011-10-17 01:37:23 -------- d-----w- C:\Program Files (x86)\OEM
2011-10-17 01:37:14 -------- d-----w- C:\ProgramData\OEM_E471269A730D
.
==================== Find3M ====================
.
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-09-06 03:07:02 3134976 ----a-w- C:\Windows\System32\win32k.sys
2011-08-20 05:45:20 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-08-20 05:41:16 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-08-20 04:38:10 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-08-20 04:35:20 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-08-20 04:20:23 482816 ----a-w- C:\Windows\System32\html.iec
2011-08-20 03:26:38 386048 ----a-w- C:\Windows\SysWow64\html.iec
2011-08-17 05:32:24 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-08-17 05:27:46 75776 ----a-w- C:\Windows\System32\MSDvbNP.ax
2011-08-17 05:27:46 288256 ----a-w- C:\Windows\System32\MSNP.ax
2011-08-17 05:27:46 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-08-17 05:27:46 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2011-08-17 04:26:02 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-08-17 04:22:23 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-08-17 04:22:23 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-08-17 04:22:23 59904 ----a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-08-17 04:22:23 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
.
============= FINISH: 20:18:10.70 ===============