Hi, i while back i downloaded (foolishly by accident) ilivid download manager for whatever reason which messed up my firefox, i didn't realise this until much later though.
Searchq was made the homepage, the default search engine in the search bar and in the address bar. I changed these things manually through firefox back to google and removed the toolbar that came with it. Later my search was back to Searchq when you search from the firefox homepage (standard) and through the address bar, the search bar option was added again but was not made the default search engine for that bar.
Last night i started having issues going to some websites, i didn't think much of it, this morning; every time i went to a website it would take a really long time loading and trying to redirect and then it would end up redirecting to random parked domains with ads and nonsense. If the page is refreshed i reach the destination.
I've run Search & Destroy scan and CClean since i started experiencing trouble. That's about it.
Thanks for you help, hopefully we can solve this.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Run by Arnhem at 6:09:03 on 2011-10-14
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.61.1033.18.6139.3485 [GMT 2:00]
.
SP: Spybot - Search & Destroy *Enabled/Outdated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\explorer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe
C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_64server.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\Arnhem\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Net iD\iid.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDRootAlyzer.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com//406
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
uWinlogon: Shell=C:\Users\Arnhem\AppData\Local\c68babac\X
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Web Accessibility Toolbar: {11352a67-0178-46b1-8855-d50b2f81c054} - C:\PROGRA~2\ACCESS~1\ACCESS~1.DLL
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [GameXN (update)] "C:\ProgramData\GameXN\GameXNGO.exe" /u
uRun: [GameXN (news)] "C:\ProgramData\GameXN\GameXNGO.exe" /n
uRun: [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
mRun: [<NO NAME>]
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
StartupFolder: C:\Users\Arnhem\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\Users\Arnhem\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Arnhem\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Arnhem\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 83.255.245.11 193.150.193.150
TCP: Interfaces\{833F4ED1-7FBC-4DF3-8CC7-6AF12719D1DC} : DhcpNameServer = 83.255.245.11 193.150.193.150
TCP: Interfaces\{D100012C-EB29-45AE-A97E-BFE9EA3FFDB6} : DhcpNameServer = 83.255.245.11 193.150.193.150
TCP: Interfaces\{D100012C-EB29-45AE-A97E-BFE9EA3FFDB6}\2556B64757D6E45445 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D100012C-EB29-45AE-A97E-BFE9EA3FFDB6}\35B656A71647368696 : DhcpNameServer = 192.168.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs:
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Web Accessibility Toolbar: {11352A67-0178-46B1-8855-D50B2F81C054} - C:\PROGRA~2\ACCESS~1\ACCESS~1.DLL
mRun-x64: [(Default)]
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe"
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
AppInit_DLLs-X64:
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arnhem\AppData\Roaming\Mozilla\Firefox\Profiles\bqyusmwu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\system32\Wat\npWatWeb.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SDHookDriver;Spybot-S&D 2 Hook Driver;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [2011-10-14 48888]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-3-10 86016]
R2 mi-raysat_3dsmax2011_64;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 64-bit 64-bit;C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_64server.exe [2010-3-10 86016]
R2 SDHookService;Spybot S&D 2 Live Protection Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe [2011-10-14 130976]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2011-10-14 892336]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2011-10-14 955816]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2011-10-14 169624]
R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2010-11-26 5790064]
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2010-11-26 487280]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;C:\Windows\system32\DRIVERS\OA001Ufd.sys --> C:\Windows\system32\DRIVERS\OA001Ufd.sys [?]
R3 OA001Vid;Creative Camera OA001 Function Driver;C:\Windows\system32\DRIVERS\OA001Vid.sys --> C:\Windows\system32\DRIVERS\OA001Vid.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-3-16 1436424]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-14 03:08:50 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-10-14 03:08:38 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2011-10-14 03:08:35 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2011-10-13 20:33:32 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C15863C8-C672-46AD-97F8-D577FF18B40F}
2011-10-13 20:32:58 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E4ABF979-C0E5-4DDB-96C0-7ECB92570008}
2011-10-13 15:34:37 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F7864F62-4331-45FE-982A-B4ABA2FA29F1}\offreg.dll
2011-10-13 03:12:11 -------- d-----we C:\Windows\system64
2011-10-13 03:11:07 -------- d-sh--w- C:\Users\Arnhem\AppData\Local\c68babac
2011-10-13 01:25:47 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F60E279F-41FE-4B1C-9258-70D102459A7C}
2011-10-13 01:25:08 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F1BDDAE4-2C4E-4214-A46E-22DB74F8AC14}
2011-10-12 16:21:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{CEA8F98E-1536-45A8-A87E-151A25DB4B25}
2011-10-12 16:20:50 -------- d-----w- C:\Users\Arnhem\AppData\Local\{70B6F2A3-275B-438A-AAB6-B4BEA9A8B775}
2011-10-12 13:12:45 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-12 13:07:58 9049936 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F7864F62-4331-45FE-982A-B4ABA2FA29F1}\mpengine.dll
2011-10-10 12:16:30 -------- d-----w- C:\Users\Arnhem\AppData\Local\{6A0A16FD-54B1-4E48-911C-81F7281C73BA}
2011-10-10 12:15:54 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E6618734-5CEA-4840-A27E-CB8458DA7479}
2011-10-09 17:10:38 -------- d-----w- C:\Users\Arnhem\AppData\Local\{3F5C3F5B-5E25-4B86-90B4-CA5984C216F1}
2011-10-09 17:10:12 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4119DE13-4778-4A50-A0E8-92FBB4CAA079}
2011-10-08 11:19:10 -------- d-----w- C:\Users\Arnhem\AppData\Local\{141915DC-0EAA-4918-91DD-72026851A830}
2011-10-08 11:18:47 -------- d-----w- C:\Users\Arnhem\AppData\Local\{11A75D34-32D4-47BF-8EF1-65AB72B92430}
2011-10-06 16:32:23 -------- d-----w- C:\Users\Arnhem\AppData\Local\{6B5CDBEF-E60E-40EA-B375-D5C5D5D5C022}
2011-10-06 16:32:00 -------- d-----w- C:\Users\Arnhem\AppData\Local\{D0FA8CC2-F669-4EB6-9D37-84C208DF8DB1}
2011-10-05 15:38:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{BE68F107-987A-41CF-86DE-6C303951F770}
2011-10-05 15:38:04 -------- d-----w- C:\Users\Arnhem\AppData\Local\{1B20D703-E7E5-463E-B8DF-E6E7FDAEBD14}
2011-10-05 01:04:46 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C161C6AA-99FC-417B-B2DA-A73E6BE5C4A0}
2011-10-05 01:04:22 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E77DC846-4CAF-49EF-853C-A42D1EFD734B}
2011-10-03 13:59:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{BEC77D5A-B595-46F7-9396-2E2867FF9B1B}
2011-10-03 13:59:04 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B2F75C00-DBBB-432F-8080-F9612DC2EC59}
2011-10-02 09:53:39 -------- d-----w- C:\Program Files\CCleaner
2011-10-02 09:47:38 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E42AF2C5-25B3-44E6-84C7-1BC5CFFC33CD}
2011-10-02 09:47:11 -------- d-----w- C:\Users\Arnhem\AppData\Local\{FFC03E53-CD63-45C3-A315-71FBF622AEA6}
2011-10-01 12:19:28 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4DDC42B7-F24C-44D0-AF19-B12D1C43C1DC}
2011-10-01 12:18:52 -------- d-----w- C:\Users\Arnhem\AppData\Local\{A84943AB-A09D-433E-BA1F-B0B2064307C0}
2011-10-01 07:31:43 -------- d-----w- C:\Users\Arnhem\AppData\Local\{748085CF-77D2-46CE-B2D9-1AA9C0E45373}
2011-10-01 07:31:17 -------- d-----w- C:\Users\Arnhem\AppData\Local\{FB33D34F-2E42-454D-A997-7D1EA44E3BC6}
2011-09-30 13:43:31 -------- d-----w- C:\Users\Arnhem\AppData\Local\{A3A6DDFD-B5C6-4E66-AA12-8AA8DA41FB56}
2011-09-30 13:42:57 -------- d-----w- C:\Users\Arnhem\AppData\Local\{FDBAEBE9-A92D-4181-B55C-B683F389C364}
2011-09-30 08:09:07 -------- d-----w- C:\Users\Arnhem\AppData\Local\{661A534F-15EB-4168-9C2E-E899D191CFCA}
2011-09-30 08:08:43 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B3AAB1B3-91B2-470C-A311-F7E3C4D85C00}
2011-09-29 19:51:17 -------- d-----w- C:\Program Files (x86)\AMD APP
2011-09-29 19:51:13 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2011-09-29 19:51:13 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2011-09-29 19:42:31 -------- d-----w- C:\Program Files (x86)\Battlelog Web Plugins
2011-09-29 18:31:37 -------- d-----w- C:\ProgramData\EA Core
2011-09-29 18:30:42 -------- d--h--w- C:\Program Files (x86)\Common Files\EAInstaller
2011-09-29 17:22:54 -------- d-----w- C:\Users\Arnhem\AppData\Roaming\Origin
2011-09-29 17:22:51 -------- d-----w- C:\Users\Arnhem\AppData\Local\Origin
2011-09-29 17:22:39 -------- d-----w- C:\ProgramData\Origin
2011-09-29 17:22:39 -------- d-----w- C:\ProgramData\Electronic Arts
2011-09-29 17:22:39 -------- d-----w- C:\Program Files (x86)\Origin Games
2011-09-29 17:22:27 -------- d-----w- C:\Program Files (x86)\Origin
2011-09-29 16:32:08 -------- d-----w- C:\Users\Arnhem\AppData\Local\{BBC5D151-3D43-4546-8FB5-275F1455AAC6}
2011-09-29 16:31:44 -------- d-----w- C:\Users\Arnhem\AppData\Local\{7060EBAB-9C44-4A31-B3CE-CE8C2AF9CC7D}
2011-09-28 08:32:09 -------- d-----w- C:\Users\Arnhem\AppData\Local\{CC97E64C-E406-485D-95CD-66D0DDE55459}
2011-09-28 08:31:36 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B92BFC83-282F-4E0A-89F4-0B77E027AA46}
2011-09-28 05:56:48 -------- d-----w- C:\Users\Arnhem\AppData\Local\{AF92ACC8-6FA3-4EDF-8EF0-066A343928DA}
2011-09-28 05:56:26 -------- d-----w- C:\Users\Arnhem\AppData\Local\{82B6281D-4E0D-49D9-829F-66448031B576}
2011-09-27 20:06:45 -------- d-----w- C:\Program Files (x86)\Thugs at Bay
2011-09-27 19:35:41 -------- d-----w- C:\Fraps
2011-09-27 18:14:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{07ACAD1D-82C0-46C2-B6FE-DA18ED46F979}
2011-09-27 18:13:54 -------- d-----w- C:\Users\Arnhem\AppData\Local\{17434ADB-EF68-427E-B23D-C0D4CFE48D49}
2011-09-27 17:40:46 -------- d-----w- C:\UDK
2011-09-27 13:35:04 -------- d-----w- C:\Users\Arnhem\AppData\Local\{60F10B38-643A-4B27-A2C1-C9A0829EB3D4}
2011-09-27 13:34:39 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E3B824C8-8362-4029-B525-25772C959FDD}
2011-09-26 14:23:10 -------- d-----w- C:\Users\Arnhem\AppData\Local\{9C0D7ED4-33F9-4568-B87D-068B840D0488}
2011-09-26 14:22:46 -------- d-----w- C:\Users\Arnhem\AppData\Local\{D80B1AFD-C29D-4709-9A86-8A7B8D8B4906}
2011-09-25 20:46:49 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2011-09-25 19:50:56 -------- d-----w- C:\Users\Arnhem\AppData\Local\CutePDF Writer
2011-09-25 19:50:23 -------- d-----w- C:\Program Files (x86)\GPLGS
2011-09-25 19:48:42 85504 ----a-w- C:\Windows\System32\cpwmon64.dll
2011-09-25 19:48:42 -------- d-----w- C:\Program Files (x86)\Acro Software
2011-09-25 15:34:15 -------- d-----w- C:\Users\Arnhem\AppData\Local\{7E10DD6E-6A13-43FD-AD8A-C56BB87FCCF8}
2011-09-25 15:33:51 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E05D64BB-4B42-45E9-A106-86DFF63D275D}
2011-09-25 14:09:50 -------- d-----w- C:\Users\Arnhem\AppData\Roaming\UBitMenu
2011-09-25 13:59:28 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-09-25 13:58:44 -------- d-----w- C:\Users\Arnhem\AppData\Local\Microsoft Help
2011-09-25 09:34:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{9FE2D018-2B3D-4568-A1D8-52CAB9288E03}
2011-09-25 09:33:40 -------- d-----w- C:\Users\Arnhem\AppData\Local\{47AF762C-EC7B-4D6C-8E8C-6AA797D4AB89}
2011-09-25 03:47:17 -------- d-----w- C:\Users\Arnhem\AppData\Local\{1DBCA37A-C57B-437A-9094-CF18794EEE1C}
2011-09-25 03:47:02 -------- d-----w- C:\Users\Arnhem\AppData\Local\{072204B6-13F2-47F7-A137-61222C81D13F}
2011-09-23 00:56:40 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E273B139-471D-4C4B-AF49-2FF77B132C5B}
2011-09-23 00:56:17 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C95312FD-8388-4DF1-BA89-396E821DBB62}
2011-09-21 22:19:54 -------- d-----w- C:\Users\Arnhem\AppData\Local\{126677DF-1C24-4093-ADBA-DBF5C000182F}
2011-09-21 22:19:26 -------- d-----w- C:\Users\Arnhem\AppData\Local\{117D4F35-E655-4ACA-8865-168016EA1C8B}
2011-09-21 10:05:49 -------- d-----w- C:\Users\Arnhem\AppData\Local\{097EC7F2-EF06-49AD-B3D1-C0C7DC2CAE76}
2011-09-21 10:05:25 -------- d-----w- C:\Users\Arnhem\AppData\Local\{6B040E85-97AC-4F0E-A3E0-6BF7F7CDFF15}
2011-09-21 02:24:38 -------- d-----w- C:\Users\Arnhem\AppData\Local\{65BAB9A3-5150-4B46-8C77-2A4B26AE412F}
2011-09-21 02:24:03 -------- d-----w- C:\Users\Arnhem\AppData\Local\{539CF775-ACFA-4371-879F-7B6E0A44D83E}
2011-09-20 19:43:03 -------- d-----w- C:\Users\Arnhem\AppData\Local\{9AE85326-FB91-44E9-89A4-C80728857A14}
2011-09-20 19:42:47 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4CF6F820-5953-4299-A930-4F2773899952}
2011-09-20 04:54:48 -------- d-----w- C:\Users\Arnhem\AppData\Local\{D9BAD932-EE65-40E7-BC85-48590B660297}
2011-09-20 04:54:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F188A0D7-6AFB-44E1-9C5F-EF83929F4FC8}
2011-09-20 00:58:07 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B63972DC-231D-4FAF-94B3-051295790ED4}
2011-09-20 00:57:34 -------- d-----w- C:\Users\Arnhem\AppData\Local\{EA80F7F3-3729-4CA7-8C39-1BA5984D218F}
2011-09-19 19:17:24 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C5E95953-BE1A-46C7-BF3B-7D85A24638E7}
2011-09-19 19:16:51 -------- d-----w- C:\Users\Arnhem\AppData\Local\{833F29B3-4A8A-4423-9D5F-60E98A484EE6}
2011-09-19 08:00:26 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E1ADE350-7CDF-4DB0-A037-205A1D147996}
2011-09-19 07:59:58 -------- d-----w- C:\Users\Arnhem\AppData\Local\{A0C16307-4563-42AB-9C77-DCAF1AE5CD3F}
2011-09-19 02:04:23 -------- d-----w- C:\Users\Arnhem\AppData\Local\{10A39B66-E3B6-43F1-807D-C92DB866C1F4}
2011-09-19 02:04:01 -------- d-----w- C:\Users\Arnhem\AppData\Local\{0AA02A5D-4943-4DCC-9430-E18AF8049A07}
2011-09-18 15:39:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C0307087-D258-4851-A4E2-007DCCE35034}
2011-09-18 15:38:49 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F6FD1AFF-F44D-4FBA-B7F8-444116670692}
2011-09-18 04:04:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{3F1B9766-0DE1-495C-9BEA-C2D4A31661F0}
2011-09-18 04:04:05 -------- d-----w- C:\Users\Arnhem\AppData\Local\{354F916B-487C-45DC-902F-5BEBE3B6F357}
2011-09-16 15:31:23 -------- d-----w- C:\Users\Arnhem\School Work
2011-09-16 15:28:25 -------- d-----r- C:\Users\Arnhem\At Your Disposal
2011-09-16 14:05:43 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4E480779-62AC-46E0-A762-15C74E736B1B}
2011-09-16 14:05:18 -------- d-----w- C:\Users\Arnhem\AppData\Local\{62916455-C42B-4549-B196-8692A4256612}
2011-09-15 19:17:20 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F826E5C4-2D65-4A2B-9AF5-E7F305692D76}
2011-09-15 19:16:56 -------- d-----w- C:\Users\Arnhem\AppData\Local\{0CB7E0EC-4A87-4DB9-AAEA-2B50EBC8721C}
2011-09-15 01:41:21 -------- d-----w- C:\ProgramData\boost_interprocess
2011-09-14 23:37:56 36864 ----a-w- C:\Windows\SysWow64\SDDEVMGR.dll
2011-09-14 23:37:51 77824 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2011-09-14 23:37:51 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2011-09-14 23:37:51 225280 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\IScript\IScript.dll
2011-09-14 23:37:51 176128 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2011-09-14 23:37:50 212992 ------w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2011-09-14 23:36:13 -------- d-----w- C:\Users\Arnhem\AppData\Local\Ilivid Player
2011-09-14 23:36:00 -------- d-----w- C:\Program Files (x86)\iLivid
2011-09-14 23:35:24 -------- d-----w- C:\Users\Arnhem\AppData\Local\PackageAware
2011-09-14 14:07:35 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C254F886-116B-4F3D-AF59-AAEFB52F8619}
2011-09-14 14:07:10 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E31C7D90-3AAA-46FC-92A1-4627DCA8D702}
2011-09-14 09:47:42 60416 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-09-14 09:47:40 53760 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-09-14 09:47:10 16652288 ----a-w- C:\Windows\System32\amdocl64.dll
2011-09-14 09:46:58 13625856 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-09-14 09:38:30 44032 ----a-w- C:\Windows\System32\amdoclcl64.dll
2011-09-14 09:38:28 37376 ----a-w- C:\Windows\SysWow64\amdoclcl.dll
.
==================== Find3M ====================
.
2011-10-01 10:58:08 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-10-01 10:58:08 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-10-01 10:50:33 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-09-29 18:30:09 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-09-08 18:27:22 10203648 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-09-08 17:59:44 24229376 ----a-w- C:\Windows\System32\atio6axx.dll
2011-09-08 17:39:44 18534912 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-09-08 17:34:20 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-09-08 17:34:10 732672 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-09-08 17:32:58 862720 ----a-w- C:\Windows\System32\aticfx64.dll
2011-09-08 17:30:38 466944 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-09-08 17:30:26 486912 ----a-w- C:\Windows\System32\atieclxx.exe
2011-09-08 17:29:56 204288 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-09-08 17:28:54 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-09-08 17:28:38 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-09-08 17:28:32 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-09-08 17:28:22 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-09-08 17:28:18 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2011-09-08 17:28:14 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-09-08 17:28:10 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-09-08 17:24:38 4204032 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-09-08 17:18:56 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-09-08 17:18:22 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-09-08 17:18:08 3888640 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-09-08 17:16:00 4944896 ----a-w- C:\Windows\System32\atidxx64.dll
2011-09-08 17:09:42 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-09-08 17:09:40 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-09-08 17:09:30 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-09-08 17:09:28 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-09-08 17:09:18 8723456 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-09-08 17:08:24 4064768 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-09-08 17:05:52 7331840 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-09-08 17:05:44 4289024 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-09-08 17:00:02 5428736 ----a-w- C:\Windows\System32\atiumd64.dll
2011-09-08 16:59:48 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-09-08 16:53:20 381952 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-09-08 16:53:12 270336 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-09-08 16:52:58 15360 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-09-08 16:52:56 13312 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-09-08 16:52:56 13312 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-09-08 16:52:54 39936 ----a-w- C:\Windows\System32\atig6txx.dll
2011-09-08 16:52:46 32768 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-09-08 16:52:40 310784 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-09-08 16:52:00 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-09-08 16:51:54 31744 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-09-08 16:51:50 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-09-08 16:51:44 29184 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-09-08 16:51:12 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-09-08 16:51:02 54784 ----a-w- C:\Windows\System32\atimpc64.dll
2011-09-08 16:51:02 54784 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-09-08 16:50:54 53760 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-09-08 16:50:54 53760 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-09-06 03:07:02 3134976 ----a-w- C:\Windows\System32\win32k.sys
2011-08-27 05:40:28 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:40:28 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:43:07 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:43:06 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-08-20 05:45:20 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-08-20 05:41:16 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-08-20 04:38:10 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-08-20 04:35:20 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-08-20 04:20:23 482816 ----a-w- C:\Windows\System32\html.iec
2011-08-20 03:26:38 386048 ----a-w- C:\Windows\SysWow64\html.iec
2011-08-17 05:32:24 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-08-17 05:27:46 75776 ----a-w- C:\Windows\System32\MSDvbNP.ax
2011-08-17 05:27:46 288256 ----a-w- C:\Windows\System32\MSNP.ax
2011-08-17 05:27:46 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-08-17 05:27:46 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2011-08-17 04:26:02 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-08-17 04:22:23 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-08-17 04:22:23 59904 ----a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-08-17 04:22:23 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2011-07-16 05:26:54 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:26:53 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:26:53 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:26:18 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-07-16 05:24:09 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:21:32 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 05:17:46 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-07-16 04:36:09 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:32:14 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:31:50 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:30:29 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:30:27 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
.
============= FINISH: 6:11:02.52 ===============
I just realised something, it's ONLY when i enter sites through a search engine result that it redirects. It does not redirect if i enter the website into the address bar or if i go through my bookmarks or external links from websites.
I thought that detail might be relevant.
Searchq was made the homepage, the default search engine in the search bar and in the address bar. I changed these things manually through firefox back to google and removed the toolbar that came with it. Later my search was back to Searchq when you search from the firefox homepage (standard) and through the address bar, the search bar option was added again but was not made the default search engine for that bar.
Last night i started having issues going to some websites, i didn't think much of it, this morning; every time i went to a website it would take a really long time loading and trying to redirect and then it would end up redirecting to random parked domains with ads and nonsense. If the page is refreshed i reach the destination.
I've run Search & Destroy scan and CClean since i started experiencing trouble. That's about it.
Thanks for you help, hopefully we can solve this.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Run by Arnhem at 6:09:03 on 2011-10-14
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.61.1033.18.6139.3485 [GMT 2:00]
.
SP: Spybot - Search & Destroy *Enabled/Outdated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\explorer.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe
C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_64server.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Users\Arnhem\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Net iD\iid.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDRootAlyzer.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchqu.com//406
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
uWinlogon: Shell=C:\Users\Arnhem\AppData\Local\c68babac\X
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Web Accessibility Toolbar: {11352a67-0178-46b1-8855-d50b2f81c054} - C:\PROGRA~2\ACCESS~1\ACCESS~1.DLL
uRun: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
uRun: [GameXN (update)] "C:\ProgramData\GameXN\GameXNGO.exe" /u
uRun: [GameXN (news)] "C:\ProgramData\GameXN\GameXNGO.exe" /n
uRun: [ccleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
mRun: [<NO NAME>]
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe"
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
StartupFolder: C:\Users\Arnhem\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\Users\Arnhem\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Arnhem\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\Arnhem\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Program Files (x86)\ERUNT\AUTOBACK.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\WIDCOMM\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 83.255.245.11 193.150.193.150
TCP: Interfaces\{833F4ED1-7FBC-4DF3-8CC7-6AF12719D1DC} : DhcpNameServer = 83.255.245.11 193.150.193.150
TCP: Interfaces\{D100012C-EB29-45AE-A97E-BFE9EA3FFDB6} : DhcpNameServer = 83.255.245.11 193.150.193.150
TCP: Interfaces\{D100012C-EB29-45AE-A97E-BFE9EA3FFDB6}\2556B64757D6E45445 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D100012C-EB29-45AE-A97E-BFE9EA3FFDB6}\35B656A71647368696 : DhcpNameServer = 192.168.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: SDWinLogon - SDWinLogon.dll
AppInit_DLLs:
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Plug-In: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: Web Accessibility Toolbar: {11352A67-0178-46B1-8855-D50B2F81C054} - C:\PROGRA~2\ACCESS~1\ACCESS~1.DLL
mRun-x64: [(Default)]
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Net iD] "C:\Program Files (x86)\Net iD\iid.exe"
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
AppInit_DLLs-X64:
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Arnhem\AppData\Roaming\Mozilla\Firefox\Profiles\bqyusmwu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npiidplg.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\system32\Wat\npWatWeb.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
============= SERVICES / DRIVERS ===============
.
R1 SDHookDriver;Spybot-S&D 2 Hook Driver;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookDrv64.sys [2011-10-14 48888]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 mi-raysat_3dsmax2011_32;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe [2010-3-10 86016]
R2 mi-raysat_3dsmax2011_64;mental ray 3.8 Satellite for Autodesk 3ds Max 2011 64-bit 64-bit;C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_64server.exe [2010-3-10 86016]
R2 SDHookService;Spybot S&D 2 Live Protection Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHookSvc.exe [2011-10-14 130976]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2011-10-14 892336]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2011-10-14 955816]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2011-10-14 169624]
R2 TabletServicePen;TabletServicePen;C:\Program Files\Tablet\Pen\Pen_Tablet.exe [2010-11-26 5790064]
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2010-11-26 487280]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;C:\Windows\system32\DRIVERS\OA001Ufd.sys --> C:\Windows\system32\DRIVERS\OA001Ufd.sys [?]
R3 OA001Vid;Creative Camera OA001 Function Driver;C:\Windows\system32\DRIVERS\OA001Vid.sys --> C:\Windows\system32\DRIVERS\OA001Vid.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-3-16 1436424]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-14 03:08:50 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2011-10-14 03:08:38 17272 ----a-w- C:\Windows\System32\sdnclean64.exe
2011-10-14 03:08:35 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2
2011-10-13 20:33:32 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C15863C8-C672-46AD-97F8-D577FF18B40F}
2011-10-13 20:32:58 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E4ABF979-C0E5-4DDB-96C0-7ECB92570008}
2011-10-13 15:34:37 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F7864F62-4331-45FE-982A-B4ABA2FA29F1}\offreg.dll
2011-10-13 03:12:11 -------- d-----we C:\Windows\system64
2011-10-13 03:11:07 -------- d-sh--w- C:\Users\Arnhem\AppData\Local\c68babac
2011-10-13 01:25:47 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F60E279F-41FE-4B1C-9258-70D102459A7C}
2011-10-13 01:25:08 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F1BDDAE4-2C4E-4214-A46E-22DB74F8AC14}
2011-10-12 16:21:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{CEA8F98E-1536-45A8-A87E-151A25DB4B25}
2011-10-12 16:20:50 -------- d-----w- C:\Users\Arnhem\AppData\Local\{70B6F2A3-275B-438A-AAB6-B4BEA9A8B775}
2011-10-12 13:12:45 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-12 13:07:58 9049936 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F7864F62-4331-45FE-982A-B4ABA2FA29F1}\mpengine.dll
2011-10-10 12:16:30 -------- d-----w- C:\Users\Arnhem\AppData\Local\{6A0A16FD-54B1-4E48-911C-81F7281C73BA}
2011-10-10 12:15:54 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E6618734-5CEA-4840-A27E-CB8458DA7479}
2011-10-09 17:10:38 -------- d-----w- C:\Users\Arnhem\AppData\Local\{3F5C3F5B-5E25-4B86-90B4-CA5984C216F1}
2011-10-09 17:10:12 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4119DE13-4778-4A50-A0E8-92FBB4CAA079}
2011-10-08 11:19:10 -------- d-----w- C:\Users\Arnhem\AppData\Local\{141915DC-0EAA-4918-91DD-72026851A830}
2011-10-08 11:18:47 -------- d-----w- C:\Users\Arnhem\AppData\Local\{11A75D34-32D4-47BF-8EF1-65AB72B92430}
2011-10-06 16:32:23 -------- d-----w- C:\Users\Arnhem\AppData\Local\{6B5CDBEF-E60E-40EA-B375-D5C5D5D5C022}
2011-10-06 16:32:00 -------- d-----w- C:\Users\Arnhem\AppData\Local\{D0FA8CC2-F669-4EB6-9D37-84C208DF8DB1}
2011-10-05 15:38:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{BE68F107-987A-41CF-86DE-6C303951F770}
2011-10-05 15:38:04 -------- d-----w- C:\Users\Arnhem\AppData\Local\{1B20D703-E7E5-463E-B8DF-E6E7FDAEBD14}
2011-10-05 01:04:46 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C161C6AA-99FC-417B-B2DA-A73E6BE5C4A0}
2011-10-05 01:04:22 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E77DC846-4CAF-49EF-853C-A42D1EFD734B}
2011-10-03 13:59:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{BEC77D5A-B595-46F7-9396-2E2867FF9B1B}
2011-10-03 13:59:04 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B2F75C00-DBBB-432F-8080-F9612DC2EC59}
2011-10-02 09:53:39 -------- d-----w- C:\Program Files\CCleaner
2011-10-02 09:47:38 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E42AF2C5-25B3-44E6-84C7-1BC5CFFC33CD}
2011-10-02 09:47:11 -------- d-----w- C:\Users\Arnhem\AppData\Local\{FFC03E53-CD63-45C3-A315-71FBF622AEA6}
2011-10-01 12:19:28 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4DDC42B7-F24C-44D0-AF19-B12D1C43C1DC}
2011-10-01 12:18:52 -------- d-----w- C:\Users\Arnhem\AppData\Local\{A84943AB-A09D-433E-BA1F-B0B2064307C0}
2011-10-01 07:31:43 -------- d-----w- C:\Users\Arnhem\AppData\Local\{748085CF-77D2-46CE-B2D9-1AA9C0E45373}
2011-10-01 07:31:17 -------- d-----w- C:\Users\Arnhem\AppData\Local\{FB33D34F-2E42-454D-A997-7D1EA44E3BC6}
2011-09-30 13:43:31 -------- d-----w- C:\Users\Arnhem\AppData\Local\{A3A6DDFD-B5C6-4E66-AA12-8AA8DA41FB56}
2011-09-30 13:42:57 -------- d-----w- C:\Users\Arnhem\AppData\Local\{FDBAEBE9-A92D-4181-B55C-B683F389C364}
2011-09-30 08:09:07 -------- d-----w- C:\Users\Arnhem\AppData\Local\{661A534F-15EB-4168-9C2E-E899D191CFCA}
2011-09-30 08:08:43 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B3AAB1B3-91B2-470C-A311-F7E3C4D85C00}
2011-09-29 19:51:17 -------- d-----w- C:\Program Files (x86)\AMD APP
2011-09-29 19:51:13 -------- d-----w- C:\Program Files\Common Files\ATI Technologies
2011-09-29 19:51:13 -------- d-----w- C:\Program Files (x86)\Common Files\ATI Technologies
2011-09-29 19:42:31 -------- d-----w- C:\Program Files (x86)\Battlelog Web Plugins
2011-09-29 18:31:37 -------- d-----w- C:\ProgramData\EA Core
2011-09-29 18:30:42 -------- d--h--w- C:\Program Files (x86)\Common Files\EAInstaller
2011-09-29 17:22:54 -------- d-----w- C:\Users\Arnhem\AppData\Roaming\Origin
2011-09-29 17:22:51 -------- d-----w- C:\Users\Arnhem\AppData\Local\Origin
2011-09-29 17:22:39 -------- d-----w- C:\ProgramData\Origin
2011-09-29 17:22:39 -------- d-----w- C:\ProgramData\Electronic Arts
2011-09-29 17:22:39 -------- d-----w- C:\Program Files (x86)\Origin Games
2011-09-29 17:22:27 -------- d-----w- C:\Program Files (x86)\Origin
2011-09-29 16:32:08 -------- d-----w- C:\Users\Arnhem\AppData\Local\{BBC5D151-3D43-4546-8FB5-275F1455AAC6}
2011-09-29 16:31:44 -------- d-----w- C:\Users\Arnhem\AppData\Local\{7060EBAB-9C44-4A31-B3CE-CE8C2AF9CC7D}
2011-09-28 08:32:09 -------- d-----w- C:\Users\Arnhem\AppData\Local\{CC97E64C-E406-485D-95CD-66D0DDE55459}
2011-09-28 08:31:36 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B92BFC83-282F-4E0A-89F4-0B77E027AA46}
2011-09-28 05:56:48 -------- d-----w- C:\Users\Arnhem\AppData\Local\{AF92ACC8-6FA3-4EDF-8EF0-066A343928DA}
2011-09-28 05:56:26 -------- d-----w- C:\Users\Arnhem\AppData\Local\{82B6281D-4E0D-49D9-829F-66448031B576}
2011-09-27 20:06:45 -------- d-----w- C:\Program Files (x86)\Thugs at Bay
2011-09-27 19:35:41 -------- d-----w- C:\Fraps
2011-09-27 18:14:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{07ACAD1D-82C0-46C2-B6FE-DA18ED46F979}
2011-09-27 18:13:54 -------- d-----w- C:\Users\Arnhem\AppData\Local\{17434ADB-EF68-427E-B23D-C0D4CFE48D49}
2011-09-27 17:40:46 -------- d-----w- C:\UDK
2011-09-27 13:35:04 -------- d-----w- C:\Users\Arnhem\AppData\Local\{60F10B38-643A-4B27-A2C1-C9A0829EB3D4}
2011-09-27 13:34:39 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E3B824C8-8362-4029-B525-25772C959FDD}
2011-09-26 14:23:10 -------- d-----w- C:\Users\Arnhem\AppData\Local\{9C0D7ED4-33F9-4568-B87D-068B840D0488}
2011-09-26 14:22:46 -------- d-----w- C:\Users\Arnhem\AppData\Local\{D80B1AFD-C29D-4709-9A86-8A7B8D8B4906}
2011-09-25 20:46:49 -------- d-----w- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
2011-09-25 19:50:56 -------- d-----w- C:\Users\Arnhem\AppData\Local\CutePDF Writer
2011-09-25 19:50:23 -------- d-----w- C:\Program Files (x86)\GPLGS
2011-09-25 19:48:42 85504 ----a-w- C:\Windows\System32\cpwmon64.dll
2011-09-25 19:48:42 -------- d-----w- C:\Program Files (x86)\Acro Software
2011-09-25 15:34:15 -------- d-----w- C:\Users\Arnhem\AppData\Local\{7E10DD6E-6A13-43FD-AD8A-C56BB87FCCF8}
2011-09-25 15:33:51 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E05D64BB-4B42-45E9-A106-86DFF63D275D}
2011-09-25 14:09:50 -------- d-----w- C:\Users\Arnhem\AppData\Roaming\UBitMenu
2011-09-25 13:59:28 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-09-25 13:58:44 -------- d-----w- C:\Users\Arnhem\AppData\Local\Microsoft Help
2011-09-25 09:34:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{9FE2D018-2B3D-4568-A1D8-52CAB9288E03}
2011-09-25 09:33:40 -------- d-----w- C:\Users\Arnhem\AppData\Local\{47AF762C-EC7B-4D6C-8E8C-6AA797D4AB89}
2011-09-25 03:47:17 -------- d-----w- C:\Users\Arnhem\AppData\Local\{1DBCA37A-C57B-437A-9094-CF18794EEE1C}
2011-09-25 03:47:02 -------- d-----w- C:\Users\Arnhem\AppData\Local\{072204B6-13F2-47F7-A137-61222C81D13F}
2011-09-23 00:56:40 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E273B139-471D-4C4B-AF49-2FF77B132C5B}
2011-09-23 00:56:17 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C95312FD-8388-4DF1-BA89-396E821DBB62}
2011-09-21 22:19:54 -------- d-----w- C:\Users\Arnhem\AppData\Local\{126677DF-1C24-4093-ADBA-DBF5C000182F}
2011-09-21 22:19:26 -------- d-----w- C:\Users\Arnhem\AppData\Local\{117D4F35-E655-4ACA-8865-168016EA1C8B}
2011-09-21 10:05:49 -------- d-----w- C:\Users\Arnhem\AppData\Local\{097EC7F2-EF06-49AD-B3D1-C0C7DC2CAE76}
2011-09-21 10:05:25 -------- d-----w- C:\Users\Arnhem\AppData\Local\{6B040E85-97AC-4F0E-A3E0-6BF7F7CDFF15}
2011-09-21 02:24:38 -------- d-----w- C:\Users\Arnhem\AppData\Local\{65BAB9A3-5150-4B46-8C77-2A4B26AE412F}
2011-09-21 02:24:03 -------- d-----w- C:\Users\Arnhem\AppData\Local\{539CF775-ACFA-4371-879F-7B6E0A44D83E}
2011-09-20 19:43:03 -------- d-----w- C:\Users\Arnhem\AppData\Local\{9AE85326-FB91-44E9-89A4-C80728857A14}
2011-09-20 19:42:47 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4CF6F820-5953-4299-A930-4F2773899952}
2011-09-20 04:54:48 -------- d-----w- C:\Users\Arnhem\AppData\Local\{D9BAD932-EE65-40E7-BC85-48590B660297}
2011-09-20 04:54:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F188A0D7-6AFB-44E1-9C5F-EF83929F4FC8}
2011-09-20 00:58:07 -------- d-----w- C:\Users\Arnhem\AppData\Local\{B63972DC-231D-4FAF-94B3-051295790ED4}
2011-09-20 00:57:34 -------- d-----w- C:\Users\Arnhem\AppData\Local\{EA80F7F3-3729-4CA7-8C39-1BA5984D218F}
2011-09-19 19:17:24 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C5E95953-BE1A-46C7-BF3B-7D85A24638E7}
2011-09-19 19:16:51 -------- d-----w- C:\Users\Arnhem\AppData\Local\{833F29B3-4A8A-4423-9D5F-60E98A484EE6}
2011-09-19 08:00:26 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E1ADE350-7CDF-4DB0-A037-205A1D147996}
2011-09-19 07:59:58 -------- d-----w- C:\Users\Arnhem\AppData\Local\{A0C16307-4563-42AB-9C77-DCAF1AE5CD3F}
2011-09-19 02:04:23 -------- d-----w- C:\Users\Arnhem\AppData\Local\{10A39B66-E3B6-43F1-807D-C92DB866C1F4}
2011-09-19 02:04:01 -------- d-----w- C:\Users\Arnhem\AppData\Local\{0AA02A5D-4943-4DCC-9430-E18AF8049A07}
2011-09-18 15:39:14 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C0307087-D258-4851-A4E2-007DCCE35034}
2011-09-18 15:38:49 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F6FD1AFF-F44D-4FBA-B7F8-444116670692}
2011-09-18 04:04:29 -------- d-----w- C:\Users\Arnhem\AppData\Local\{3F1B9766-0DE1-495C-9BEA-C2D4A31661F0}
2011-09-18 04:04:05 -------- d-----w- C:\Users\Arnhem\AppData\Local\{354F916B-487C-45DC-902F-5BEBE3B6F357}
2011-09-16 15:31:23 -------- d-----w- C:\Users\Arnhem\School Work
2011-09-16 15:28:25 -------- d-----r- C:\Users\Arnhem\At Your Disposal
2011-09-16 14:05:43 -------- d-----w- C:\Users\Arnhem\AppData\Local\{4E480779-62AC-46E0-A762-15C74E736B1B}
2011-09-16 14:05:18 -------- d-----w- C:\Users\Arnhem\AppData\Local\{62916455-C42B-4549-B196-8692A4256612}
2011-09-15 19:17:20 -------- d-----w- C:\Users\Arnhem\AppData\Local\{F826E5C4-2D65-4A2B-9AF5-E7F305692D76}
2011-09-15 19:16:56 -------- d-----w- C:\Users\Arnhem\AppData\Local\{0CB7E0EC-4A87-4DB9-AAEA-2B50EBC8721C}
2011-09-15 01:41:21 -------- d-----w- C:\ProgramData\boost_interprocess
2011-09-14 23:37:56 36864 ----a-w- C:\Windows\SysWow64\SDDEVMGR.dll
2011-09-14 23:37:51 77824 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2011-09-14 23:37:51 32768 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2011-09-14 23:37:51 225280 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\IScript\IScript.dll
2011-09-14 23:37:51 176128 ----a-w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2011-09-14 23:37:50 212992 ------w- C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2011-09-14 23:36:13 -------- d-----w- C:\Users\Arnhem\AppData\Local\Ilivid Player
2011-09-14 23:36:00 -------- d-----w- C:\Program Files (x86)\iLivid
2011-09-14 23:35:24 -------- d-----w- C:\Users\Arnhem\AppData\Local\PackageAware
2011-09-14 14:07:35 -------- d-----w- C:\Users\Arnhem\AppData\Local\{C254F886-116B-4F3D-AF59-AAEFB52F8619}
2011-09-14 14:07:10 -------- d-----w- C:\Users\Arnhem\AppData\Local\{E31C7D90-3AAA-46FC-92A1-4627DCA8D702}
2011-09-14 09:47:42 60416 ----a-w- C:\Windows\System32\OVDecode64.dll
2011-09-14 09:47:40 53760 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2011-09-14 09:47:10 16652288 ----a-w- C:\Windows\System32\amdocl64.dll
2011-09-14 09:46:58 13625856 ----a-w- C:\Windows\SysWow64\amdocl.dll
2011-09-14 09:38:30 44032 ----a-w- C:\Windows\System32\amdoclcl64.dll
2011-09-14 09:38:28 37376 ----a-w- C:\Windows\SysWow64\amdoclcl.dll
.
==================== Find3M ====================
.
2011-10-01 10:58:08 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-10-01 10:58:08 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-10-01 10:50:33 280904 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-10-01 03:21:20 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-10-01 02:59:14 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-09-29 18:30:09 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-09-08 18:27:22 10203648 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2011-09-08 17:59:44 24229376 ----a-w- C:\Windows\System32\atio6axx.dll
2011-09-08 17:39:44 18534912 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2011-09-08 17:34:20 151552 ----a-w- C:\Windows\System32\atiapfxx.exe
2011-09-08 17:34:10 732672 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2011-09-08 17:32:58 862720 ----a-w- C:\Windows\System32\aticfx64.dll
2011-09-08 17:30:38 466944 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2011-09-08 17:30:26 486912 ----a-w- C:\Windows\System32\atieclxx.exe
2011-09-08 17:29:56 204288 ----a-w- C:\Windows\System32\atiesrxx.exe
2011-09-08 17:28:54 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2011-09-08 17:28:38 423424 ----a-w- C:\Windows\System32\atipdl64.dll
2011-09-08 17:28:32 356352 ----a-w- C:\Windows\SysWow64\atipdlxx.dll
2011-09-08 17:28:22 278528 ----a-w- C:\Windows\SysWow64\Oemdspif.dll
2011-09-08 17:28:18 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2011-09-08 17:28:14 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2011-09-08 17:28:10 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2011-09-08 17:24:38 4204032 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2011-09-08 17:18:56 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll
2011-09-08 17:18:22 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2011-09-08 17:18:08 3888640 ----a-w- C:\Windows\System32\atiumd6a.dll
2011-09-08 17:16:00 4944896 ----a-w- C:\Windows\System32\atidxx64.dll
2011-09-08 17:09:42 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2011-09-08 17:09:40 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2011-09-08 17:09:30 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2011-09-08 17:09:28 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2011-09-08 17:09:18 8723456 ----a-w- C:\Windows\System32\aticaldd64.dll
2011-09-08 17:08:24 4064768 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2011-09-08 17:05:52 7331840 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2011-09-08 17:05:44 4289024 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2011-09-08 17:00:02 5428736 ----a-w- C:\Windows\System32\atiumd64.dll
2011-09-08 16:59:48 58880 ----a-w- C:\Windows\System32\coinst.dll
2011-09-08 16:53:20 381952 ----a-w- C:\Windows\System32\atiadlxx.dll
2011-09-08 16:53:12 270336 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2011-09-08 16:52:58 15360 ----a-w- C:\Windows\System32\atig6pxx.dll
2011-09-08 16:52:56 13312 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2011-09-08 16:52:56 13312 ----a-w- C:\Windows\System32\atiglpxx.dll
2011-09-08 16:52:54 39936 ----a-w- C:\Windows\System32\atig6txx.dll
2011-09-08 16:52:46 32768 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2011-09-08 16:52:40 310784 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2011-09-08 16:52:00 40960 ----a-w- C:\Windows\System32\atiuxp64.dll
2011-09-08 16:51:54 31744 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2011-09-08 16:51:50 38912 ----a-w- C:\Windows\System32\atiu9p64.dll
2011-09-08 16:51:44 29184 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2011-09-08 16:51:12 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2011-09-08 16:51:02 54784 ----a-w- C:\Windows\System32\atimpc64.dll
2011-09-08 16:51:02 54784 ----a-w- C:\Windows\System32\amdpcom64.dll
2011-09-08 16:50:54 53760 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2011-09-08 16:50:54 53760 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2011-09-06 03:07:02 3134976 ----a-w- C:\Windows\System32\win32k.sys
2011-08-27 05:40:28 861184 ----a-w- C:\Windows\System32\oleaut32.dll
2011-08-27 05:40:28 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-08-27 04:43:07 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-08-27 04:43:06 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-08-20 05:45:20 1197568 ----a-w- C:\Windows\System32\wininet.dll
2011-08-20 05:41:16 57856 ----a-w- C:\Windows\System32\licmgr10.dll
2011-08-20 04:38:10 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-08-20 04:35:20 44544 ----a-w- C:\Windows\SysWow64\licmgr10.dll
2011-08-20 04:20:23 482816 ----a-w- C:\Windows\System32\html.iec
2011-08-20 03:26:38 386048 ----a-w- C:\Windows\SysWow64\html.iec
2011-08-17 05:32:24 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-08-17 05:27:46 75776 ----a-w- C:\Windows\System32\MSDvbNP.ax
2011-08-17 05:27:46 288256 ----a-w- C:\Windows\System32\MSNP.ax
2011-08-17 05:27:46 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-08-17 05:27:46 104960 ----a-w- C:\Windows\System32\Mpeg2Data.ax
2011-08-17 04:26:02 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-08-17 04:22:23 72704 ----a-w- C:\Windows\SysWow64\Mpeg2Data.ax
2011-08-17 04:22:23 59904 ----a-w- C:\Windows\SysWow64\MSDvbNP.ax
2011-08-17 04:22:23 204288 ----a-w- C:\Windows\SysWow64\MSNP.ax
2011-07-16 05:26:54 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:26:53 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:26:53 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:26:18 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-07-16 05:24:09 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:21:32 422400 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 05:17:46 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-07-16 04:36:09 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:32:14 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:31:50 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:30:29 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:30:27 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
.
============= FINISH: 6:11:02.52 ===============
I just realised something, it's ONLY when i enter sites through a search engine result that it redirects. It does not redirect if i enter the website into the address bar or if i go through my bookmarks or external links from websites.
I thought that detail might be relevant.
Last edited by a moderator: