Hello:
I've had a recent problem with Hotmail. Tuesday morning it sent emails to my contact list containing a link. I did not click the link fearing it was more trouble. Microsoft shut down the account. I have reactivated it and changed the pass. The outgoing emails appear in the sent folder. There are several of them to multiple recipients and the link in each email is different. The PC is running fine and I have noticed no problems other than Hotmail.
I followed the instructions and the log files are pasted. The GMER log was blank, so there is nothing to paste.
Thank you for your help with this. It's possible this problem is a hacker from outside, but I would like to be sure I don't have a trojan inside.
++++++++++++++++++++++++++++++++++++++++++++++++++++++
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2011.12.28.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Jay :: NEWOFFICE [administrator]
12/28/2011 12:36:57 PM
mbam-log-2011-12-28 (12-36-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 217020
Time elapsed: 6 minute(s), 39 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by Jay at 13:34:09 on 2011-12-29
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.6135.4485 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe
C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10r_ActiveX.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.weather.com/weather/today/Wilmington+NC+28409
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [MediaFace Integration] C:\Program Files (x86)\Fellowes\MediaFACE 4.2\SetHook.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
mRun: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{98CF92C9-0058-4D3F-8032-032C8A9C6625} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BC6796CD-B8FA-4415-A10E-E3F02069298C} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BC6796CD-B8FA-4415-A10E-E3F02069298C}\C4F6E65635471627E45647 : DhcpNameServer = 209.18.47.61 209.18.47.62
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
mRun-x64: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [MediaFace Integration] C:\Program Files (x86)\Fellowes\MediaFACE 4.2\SetHook.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [(Default)]
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
mRun-x64: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe"
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\quoxygoi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.weather.com/weather/my
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: avast! WebRep: wrc@avast.com - C:\Program Files\Alwil Software\Avast5\WebRep\FF
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 c2scsi64;c2scsi64;C:\Windows\system32\DRIVERS\c2scsi64.sys --> C:\Windows\system32\DRIVERS\c2scsi64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-3-6 42184]
R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2009-6-23 127352]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 scsiscan;SCSI Scanner Driver;C:\Windows\system32\DRIVERS\scsiscan.sys --> C:\Windows\system32\DRIVERS\scsiscan.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 RoxLiveShare10;LiveShare P2P Server 10;"C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" --> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [?]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [2009-7-24 219632]
S2 SessionLauncher;SessionLauncher;C:\Users\Jay\AppData\Local\Temp\DX9\SessionLauncher.exe --> C:\Users\Jay\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 RoxMediaDB12;RoxMediaDB12;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [2009-7-24 1116656]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\RpcAgentSrv.exe [2010-5-21 93336]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vpcuxd;USB Virtualization Stub Service;C:\Windows\system32\drivers\vpcuxd.sys --> C:\Windows\system32\drivers\vpcuxd.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-12-29 15:46:58 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B04B994A-4935-4BF8-92B1-24D4D1F3A88D}\offreg.dll
2011-12-28 17:47:43 388096 ----a-r- C:\Users\Jay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-28 17:47:43 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-12-28 17:35:54 -------- d-----w- C:\Users\Jay\AppData\Roaming\Malwarebytes
2011-12-28 17:35:48 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-28 17:35:47 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-28 17:35:47 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-28 12:19:32 -------- d-----w- C:\Users\Jay\AppData\Local\{5434F421-49DA-4637-83D9-29A5B727B285}
2011-12-28 02:26:25 -------- d-----w- C:\Users\Jay\AppData\Local\{63558786-D34E-46ED-9D7F-9B99C08F8B2A}
2011-12-28 00:00:35 -------- d-----w- C:\Users\Jay\AppData\Local\{F8CB20F0-9D1C-4929-BBA1-F6D1556A7386}
2011-12-28 00:00:23 -------- d-----w- C:\Users\Jay\AppData\Local\{B412AB9F-084D-4FE7-AFC0-6B3B5C7DD5F1}
2011-12-27 17:20:18 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B04B994A-4935-4BF8-92B1-24D4D1F3A88D}\mpengine.dll
2011-12-25 09:37:08 -------- d-----w- C:\Users\Jay\AppData\Local\{E1EBDE92-C8D1-4DEF-9E8A-3492685B4CCB}
2011-12-25 00:04:08 -------- d-----w- C:\Users\Jay\AppData\Local\{4F3A5FCA-37FD-4C2D-97DF-704C20938849}
2011-12-24 17:55:59 -------- d-----w- C:\Users\Jay\AppData\Local\{FA1B0944-DFD2-49DC-96C0-5BBCF8429266}
2011-12-24 17:55:37 -------- d-----w- C:\Users\Jay\AppData\Local\{70387071-E8AC-4FBF-AA82-D59A7059ADEB}
2011-12-24 17:51:23 -------- d-----w- C:\Users\Jay\AppData\Local\{1B8D7723-76D6-4F8D-9CBB-6ED317D34812}
2011-12-24 17:50:59 -------- d-----w- C:\Users\Jay\AppData\Local\{A3F1A3AA-8B75-4F64-ADC0-760A862194FB}
2011-12-24 12:34:00 -------- d-----w- C:\Users\Jay\AppData\Local\{0EAED9FE-F561-45BF-8DC4-A1705EF27CD0}
2011-12-23 18:10:52 -------- d-----w- C:\Users\Jay\AppData\Local\{D8510B3E-5215-441A-88E2-E4EDC9B21237}
2011-12-23 13:50:48 -------- d-----w- C:\Users\Jay\AppData\Local\{5E1D3A7B-8BC7-4065-9660-C11E342410E1}
2011-12-23 13:50:25 -------- d-----w- C:\Users\Jay\AppData\Local\{CD662AF1-BCAB-4832-B77A-31C8C370B3E0}
2011-12-23 13:42:28 -------- d-----w- C:\Users\Jay\AppData\Local\{3F0C231D-444C-46CA-94A8-ED415E95B723}
2011-12-23 13:42:06 -------- d-----w- C:\Users\Jay\AppData\Local\{5234D925-F067-409B-A638-DA334CFC026C}
2011-12-23 13:15:46 -------- d-----w- C:\Users\Jay\AppData\Local\{2484EBF9-E040-4EB6-8F86-94E4CE0528E7}
2011-12-23 13:15:35 -------- d-----w- C:\Users\Jay\AppData\Local\{EE6AD7BE-1D4D-4BC3-9536-B582B1BACBE4}
2011-12-23 12:49:07 -------- d-----w- C:\Users\Jay\AppData\Local\{2329CABF-0A64-47B8-BD36-62A6D475711F}
2011-12-23 12:48:44 -------- d-----w- C:\Users\Jay\AppData\Local\{EF6AC3C6-7263-48FF-AA7F-14BD1D237A68}
2011-12-23 12:38:48 -------- d-----w- C:\Users\Jay\AppData\Local\{D6D0E6F8-0852-419E-AC9E-0628682F27E8}
2011-12-23 12:38:26 -------- d-----w- C:\Users\Jay\AppData\Local\{2934A3F9-653D-4BFE-A010-6BB9D2A4F3B4}
2011-12-23 12:35:09 -------- d-----w- C:\Users\Jay\AppData\Local\{B9833CA9-80E3-406F-A7CA-FE723471DA41}
2011-12-23 12:34:41 -------- d-----w- C:\Users\Jay\AppData\Local\{8BA1586C-7CE3-415C-8597-D0E2E02B28FC}
2011-12-22 20:56:31 -------- d-----w- C:\Users\Jay\AppData\Local\{AFAF1FA1-FE97-4A20-A2B2-547D648918CD}
2011-12-22 20:56:09 -------- d-----w- C:\Users\Jay\AppData\Local\{EA2BE4C5-2519-49E2-B4B0-DB8C4370EFFA}
2011-12-22 17:40:21 -------- d-----w- C:\Users\Jay\AppData\Local\{8231D903-4464-4CC6-8172-D02802C2E127}
2011-12-22 09:34:27 -------- d-----w- C:\Users\Jay\AppData\Local\{F73A9C1D-18F0-4739-8B60-8615B702DC38}
2011-12-22 09:34:04 -------- d-----w- C:\Users\Jay\AppData\Local\{7ECB8096-AC33-4FD9-BEDA-2C1697F3BC25}
2011-12-21 21:56:52 -------- d-----w- C:\Users\Jay\AppData\Local\{F8AF61A0-7A51-41F4-BBD7-483CE475F333}
2011-12-21 21:56:29 -------- d-----w- C:\Users\Jay\AppData\Local\{21820CDF-8E75-4C9A-8AD4-0EA9821A304D}
2011-12-21 14:33:16 -------- d-----w- C:\Users\Jay\AppData\Local\{6D78FFE7-976E-4098-BB80-F38D9D16540F}
2011-12-21 14:32:54 -------- d-----w- C:\Users\Jay\AppData\Local\{E401BC21-D925-4365-8C7F-4044DB7EE367}
2011-12-21 01:55:26 -------- d-----w- C:\Users\Jay\AppData\Local\{A665CB88-9DF3-4696-B9CF-DE63FC3DFB44}
2011-12-21 01:55:04 -------- d-----w- C:\Users\Jay\AppData\Local\{3FBE38F0-E880-4ED9-98B6-F785E5F407D6}
2011-12-21 00:19:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4768D3E5-C6D9-49E6-A512-F22DE3348C67}
2011-12-20 18:24:09 -------- d-----w- C:\ProgramData\Playrix Entertainment
2011-12-20 18:23:05 -------- d-----w- C:\Users\Jay\AppData\Roaming\Oberon Media
2011-12-20 14:24:13 -------- d-----w- C:\Users\Jay\AppData\Local\{718D0C20-50E3-4866-8C25-A35163B106F6}
2011-12-20 14:23:51 -------- d-----w- C:\Users\Jay\AppData\Local\{FCC67391-BA52-494F-A2F1-D79520B6114F}
2011-12-20 12:25:28 -------- d-----w- C:\Users\Jay\AppData\Local\{42D51BD2-7476-4178-BBEF-7800A3C5637A}
2011-12-20 04:58:33 -------- d-----w- C:\Users\Jay\AppData\Local\{912AF255-89E2-4F9C-8945-EEA7F1900B14}
2011-12-20 00:12:20 -------- d-----w- C:\Users\Jay\AppData\Local\{B028EF89-87C1-45EB-B910-B9F2D05064BA}
2011-12-20 00:11:58 -------- d-----w- C:\Users\Jay\AppData\Local\{30078D55-4645-482C-9761-64F3E1E8B485}
2011-12-19 19:12:48 -------- d-----w- C:\Users\Jay\AppData\Local\{E71BD146-A130-4C36-AA48-205522CCC113}
2011-12-19 04:35:57 -------- d-----w- C:\Users\Jay\AppData\Local\{0F2127B7-2662-4F99-8748-EE1CB722FFB7}
2011-12-19 04:35:35 -------- d-----w- C:\Users\Jay\AppData\Local\{B68BEE54-61B1-438B-934B-DFFED73143E5}
2011-12-18 16:06:59 -------- d-----w- C:\Users\Jay\AppData\Local\{67E08AB8-2FEF-4FC3-9AA9-830E2D79337E}
2011-12-18 16:06:37 -------- d-----w- C:\Users\Jay\AppData\Local\{0C755E52-4F61-4D7F-9C71-1C515DC9F8C7}
2011-12-18 14:04:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4D3BBD0D-C7BA-4944-8D42-1A2B84D0B628}
2011-12-18 14:03:43 -------- d-----w- C:\Users\Jay\AppData\Local\{D063175A-4696-49EA-A87B-53B1DB0B6700}
2011-12-18 04:11:56 -------- d-----w- C:\Users\Jay\AppData\Local\{25B4985C-39DB-4ABA-861D-1A5E623CE081}
2011-12-18 04:11:33 -------- d-----w- C:\Users\Jay\AppData\Local\{454DAD95-DB66-4362-976A-E0F1733BADE6}
2011-12-18 00:53:39 -------- d-----w- C:\Users\Jay\AppData\Local\{57B5BE3D-2A57-4FFC-B2E9-1F0683804BA8}
2011-12-15 21:10:12 -------- d-----w- C:\Users\Jay\AppData\Local\{28739CB3-1014-4EC2-92E4-BD435BE4292B}
2011-12-15 12:16:42 -------- d-----w- C:\Users\Jay\AppData\Local\{1CBBBB6C-BC39-4223-BC8F-4F1FECE27A4C}
2011-12-15 11:48:32 -------- d-----w- C:\Users\Jay\AppData\Local\{4DA56215-5E7B-4849-B931-BFB1498814BB}
2011-12-15 11:48:20 -------- d-----w- C:\Users\Jay\AppData\Local\{0A42F385-0460-4A22-A065-1C9053491F69}
2011-12-14 21:54:54 -------- d-----w- C:\Users\Jay\AppData\Local\{0F6871CA-5BD4-410D-9E58-EDA55E348DD6}
2011-12-14 21:54:32 -------- d-----w- C:\Users\Jay\AppData\Local\{E36C5128-8B68-4E4A-8130-2F5D2E4FDFC2}
2011-12-14 20:09:58 -------- d-----w- C:\Users\Jay\AppData\Local\{58BC3F0D-014C-4123-854F-C19A68B1BF0E}
2011-12-14 20:09:36 -------- d-----w- C:\Users\Jay\AppData\Local\{6DC88A0C-8B35-4B30-BAAF-92249DCD021F}
2011-12-14 01:50:43 -------- d-----w- C:\Users\Jay\AppData\Local\{E54DF379-F2E2-47F7-9869-EEE53DD28D6F}
2011-12-13 02:25:27 -------- d-----w- C:\Users\Jay\AppData\Local\{8FFDAF4C-423D-421D-A3EE-93FECBC3319F}
2011-12-12 23:51:47 -------- d-----w- C:\Users\Jay\AppData\Local\{5A977D0A-0E08-4D12-9A6D-C891E66A735F}
2011-12-12 13:14:08 -------- d-----w- C:\Users\Jay\AppData\Local\{402B3E53-D9D6-4464-9B52-BF2E97DFADDB}
2011-12-12 12:19:58 -------- d-----w- C:\Users\Jay\AppData\Local\{21644F67-0F6F-4393-B101-4E2F079ED9AF}
2011-12-11 13:54:01 -------- d-----w- C:\Users\Jay\AppData\Local\{59B02365-124E-45C2-A3B9-38822C894161}
2011-12-10 23:54:59 -------- d-----w- C:\Users\Jay\AppData\Local\{85AFCA50-021F-4729-83CA-38382BA3AF50}
2011-12-10 02:30:26 -------- d-----w- C:\Users\Jay\AppData\Local\{83411C03-9410-43DC-92D4-B35C05E4AA0A}
2011-12-09 12:56:42 -------- d-----w- C:\Users\Jay\AppData\Local\{736E3DFE-1730-49FD-98C0-A47CC611B3C9}
2011-12-09 01:12:26 -------- d-----w- C:\Users\Jay\AppData\Local\{0D25CC6B-075E-491C-A989-1DEA1F0943E1}
2011-12-08 12:34:43 -------- d-----w- C:\Users\Jay\AppData\Local\{442F707D-93CB-4CF1-AB7F-12B359528FF2}
2011-12-08 11:37:50 -------- d-----w- C:\Users\Jay\AppData\Local\{67A7FEAE-0788-44A5-8EA2-E51045D3C261}
2011-12-08 02:50:41 -------- d-----w- C:\Users\Jay\AppData\Local\{EEFD12D0-9108-487C-8EB0-AEAC82A27C82}
2011-12-07 23:32:22 -------- d-----w- C:\Users\Jay\AppData\Local\{7FA55C8F-C410-4AD5-A782-48B6AA66E186}
2011-12-07 23:31:59 -------- d-----w- C:\Users\Jay\AppData\Local\{28070730-AA39-4712-8D54-1020F7161021}
2011-12-07 20:07:39 -------- d-----w- C:\Users\Jay\AppData\Local\{AAAA2D4E-8779-4A51-97DA-73856FB0DA73}
2011-12-07 20:07:17 -------- d-----w- C:\Users\Jay\AppData\Local\{A48FA3BA-A53F-44E7-BDB5-943C81C3625E}
2011-12-07 15:33:14 -------- d-----w- C:\Users\Jay\AppData\Local\{B74F52D1-D019-426B-BE71-FF9130CE9F9D}
2011-12-07 12:35:11 -------- d-----w- C:\Users\Jay\AppData\Local\{75E147AC-5A12-4906-A36F-E15D73C92462}
2011-12-07 12:10:28 -------- d-----w- C:\Users\Jay\AppData\Local\{CA3914C7-DBDF-4F4A-92AE-7497D0DA3FE7}
2011-12-07 12:10:06 -------- d-----w- C:\Users\Jay\AppData\Local\{B3CC81F6-F1F6-4F96-AB4F-1E9288220BB3}
2011-12-06 23:59:06 -------- d-----w- C:\Users\Jay\AppData\Local\{4D853912-5838-4E98-992D-B0099083AECE}
2011-12-06 20:59:03 -------- d-----w- C:\Users\Jay\AppData\Local\{2FE9D022-9D19-4B1E-AACF-0C6C85C39C45}
2011-12-06 17:07:00 -------- d-----w- C:\Users\Jay\AppData\Local\{6F38CD55-9E86-4A8A-957B-769E14173876}
2011-12-06 17:06:38 -------- d-----w- C:\Users\Jay\AppData\Local\{057E2F2E-6EE9-44B6-8284-91D2A120A441}
2011-12-06 14:38:36 -------- d-----w- C:\Users\Jay\AppData\Local\{93301825-1F8F-46FE-97BE-2FB89CCAAD4A}
2011-12-06 12:56:25 -------- d-----w- C:\Users\Jay\AppData\Local\{86952BC1-8C6E-414C-9D78-52C2FF12558A}
2011-12-06 12:56:03 -------- d-----w- C:\Users\Jay\AppData\Local\{B503D05E-56EF-4D7B-8256-79725CEBFFEA}
2011-12-06 12:41:59 -------- d-----w- C:\Users\Jay\AppData\Local\{74B13190-EEFC-4322-9FAC-7B45E4BD7DA0}
2011-12-06 12:41:36 -------- d-----w- C:\Users\Jay\AppData\Local\{8FA5CE15-2E20-4409-8DB4-8EE673EF673C}
2011-12-06 04:04:07 -------- d-----w- C:\Users\Jay\AppData\Local\{B61B1A63-5E41-4003-BC25-B94C3E8A958D}
2011-12-06 03:02:37 -------- d-----w- C:\Users\Jay\AppData\Local\{B577F929-F15A-443C-B2EA-5715E3143505}
2011-12-06 02:26:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4739295B-62B8-42FF-A89B-EAB263150B96}
2011-12-06 02:25:42 -------- d-----w- C:\Users\Jay\AppData\Local\{7244D46E-A1C1-4644-9471-0F9CEB8277EB}
2011-12-06 02:08:26 -------- d-----w- C:\Users\Jay\AppData\Local\{813B39E5-AB8D-42D0-B804-1F7BD77ED6A8}
2011-12-06 02:08:04 -------- d-----w- C:\Users\Jay\AppData\Local\{6DBA3827-700B-4285-A68D-90183CFE1695}
2011-12-06 01:13:59 -------- d-----w- C:\Users\Jay\AppData\Local\{0B8631F1-5129-40F7-A7C9-54624FCF70ED}
2011-12-06 01:13:37 -------- d-----w- C:\Users\Jay\AppData\Local\{F7295420-5851-4500-9C75-1B753ABD798F}
2011-12-05 22:03:06 -------- d-----w- C:\Users\Jay\AppData\Local\{0E6CBBC1-AEA6-4B60-9309-86770CE5275F}
2011-12-05 22:02:43 -------- d-----w- C:\Users\Jay\AppData\Local\{3C25E048-9AEB-4AF7-9265-2410BD360A36}
2011-12-05 19:08:35 -------- d-----w- C:\Users\Jay\AppData\Local\{47EBB7D8-0172-4D3F-9B32-B84C0862C928}
2011-12-05 19:08:13 -------- d-----w- C:\Users\Jay\AppData\Local\{03CC83A0-3F81-478D-B883-246B988C64B3}
2011-12-05 13:16:42 -------- d-----w- C:\Users\Jay\AppData\Local\{71A52DF7-C30D-40D2-BC8B-1BF77C599C7C}
2011-12-05 12:39:16 -------- d-----w- C:\Users\Jay\AppData\Local\{A4F59168-0406-42F6-A9FE-5B6B4ED0FD44}
2011-12-05 00:54:08 -------- d-----w- C:\Users\Jay\AppData\Local\{DEFA752B-9BA5-4840-B187-0FD4A5A0A9AF}
2011-12-05 00:53:45 -------- d-----w- C:\Users\Jay\AppData\Local\{3F20CBE3-DF3B-4F1B-B47F-6CEC6B3FF4E0}
2011-12-04 23:19:33 -------- d-----w- C:\Users\Jay\AppData\Local\{4A781581-3953-46CC-BD3A-B34553E72E43}
2011-12-04 12:54:57 550602 ----a-w- C:\EyeCand3.8bf
2011-12-04 12:54:57 409600 ----a-w- C:\EC3-ENG.8BF
2011-12-04 12:54:57 127184 ----a-w- C:\UNWISE.EXE
2011-12-04 12:54:57 -------- d-----w- C:\Eye Candy 4000
2011-12-03 01:14:24 -------- d-----w- C:\Users\Jay\AppData\Local\{D723E6D9-A93C-418D-8EC4-2DEB29159684}
2011-12-02 22:09:33 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-12-02 22:09:07 -------- d-----w- C:\Windows\SysWow64\xlive
2011-12-02 22:08:52 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-12-02 21:34:30 -------- d-----w- C:\Users\Jay\AppData\Local\{B379370E-E4DD-4FD0-AE41-9B0253D89069}
2011-12-02 13:19:12 -------- d-----w- C:\Users\Jay\AppData\Local\{DBAE392D-399C-4CBD-BABB-C12A40D7A6C3}
2011-12-02 13:18:50 -------- d-----w- C:\Users\Jay\AppData\Local\{43D8271C-EF6A-454D-8A66-B68862793149}
2011-12-02 00:50:27 -------- d-----w- C:\Users\Jay\AppData\Local\{ACE2BB29-4071-4401-BA1C-44CD5F3BEE5F}
2011-12-02 00:50:05 -------- d-----w- C:\Users\Jay\AppData\Local\{977E8DCD-C539-4D38-88C2-BA95CB3AC396}
2011-12-01 13:10:25 -------- d-----w- C:\Users\Jay\AppData\Local\{8827A7B1-8E29-4592-B211-8562141508EF}
2011-12-01 13:10:03 -------- d-----w- C:\Users\Jay\AppData\Local\{02D4E0E6-83F2-4765-8272-F6016183406B}
2011-12-01 12:29:28 -------- d-----w- C:\Users\Jay\AppData\Local\{972958E5-4987-4FDE-A0E5-2E0EEA2F79B7}
2011-12-01 12:29:05 -------- d-----w- C:\Users\Jay\AppData\Local\{191B1C58-E66D-4F04-ADD7-99F75CFBB24B}
2011-12-01 12:09:02 -------- d-----w- C:\Users\Jay\AppData\Local\{9A19B0A0-E7B4-4E0A-9EDD-5DB908CC43F1}
2011-12-01 12:08:40 -------- d-----w- C:\Users\Jay\AppData\Local\{49EA647C-05B1-4944-A0BC-A8BDE876290C}
2011-11-30 22:35:01 -------- d-----w- C:\Users\Jay\AppData\Local\{7F56C190-E864-4C11-AC71-909F3A28E5DC}
2011-11-30 15:47:14 -------- d-----w- C:\Users\Jay\AppData\Local\{A8DCF430-7A6F-449C-8F7F-5151B063791D}
2011-11-30 12:37:41 -------- d-----w- C:\Users\Jay\AppData\Local\{9D038E7F-AADA-4E4D-BF54-3B05E8DF9561}
2011-11-30 12:00:34 -------- d-----w- C:\Users\Jay\AppData\Local\{47BD8344-F8FE-45DA-8CCA-FAE7B92F55E9}
2011-11-30 03:09:06 -------- d-----w- C:\Users\Jay\AppData\Local\{09FA678E-8BE4-40CE-AFBF-00F7936AAF72}
2011-11-30 03:08:43 -------- d-----w- C:\Users\Jay\AppData\Local\{CB236E7C-15CE-4A44-A84F-32D5BBDADA48}
2011-11-30 02:22:06 -------- d-----w- C:\Users\Jay\AppData\Local\{7A9237FF-0144-4F4E-8110-7C99841CA9BC}
2011-11-30 01:18:39 -------- d-----w- C:\Users\Jay\AppData\Local\{4A681FA2-4251-435E-B16A-54135D547524}
2011-11-30 01:18:17 -------- d-----w- C:\Users\Jay\AppData\Local\{AE4BBC7F-D5A3-4C89-8B5C-8BE5381A3573}
2011-11-29 20:47:14 -------- d-----w- C:\Users\Jay\AppData\Local\{C26AB4DE-3725-4C1E-9D21-3A3B15E307AA}
2011-11-29 20:46:52 -------- d-----w- C:\Users\Jay\AppData\Local\{703EEE66-25E8-4470-B2D6-B89207651180}
.
==================== Find3M ====================
.
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 21:28:31 1393736 ----a-w- C:\Users\Jay\gotomypc_626.exe
2011-11-05 05:41:43 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-05 04:35:00 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-11-05 03:32:47 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:48:51 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-10-15 06:31:56 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-10-15 05:38:59 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
.
============= FINISH: 13:34:23.46 ===============
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume3
Install Date: 2/21/2010 1:31:51 PM
System Uptime: 12/29/2011 10:43:36 AM (3 hours ago)
.
Motherboard: Foxconn | | Flaming Blade GTI
Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz | Socket 1366 | 2793/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 596 GiB total, 440.421 GiB free.
D: is FIXED (NTFS) - 298 GiB total, 176.73 GiB free.
E: is FIXED (NTFS) - 298 GiB total, 150.581 GiB free.
F: is FIXED (NTFS) - 931 GiB total, 421.559 GiB free.
G: is CDROM ()
H: is FIXED (NTFS) - 0 GiB total, 0.069 GiB free.
I: is Removable
J: is CDROM ()
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP291: 12/6/2011 2:14:54 AM - Windows Update
RP292: 12/9/2011 8:58:08 AM - Windows Update
RP293: 12/13/2011 10:20:15 AM - Windows Update
RP294: 12/15/2011 3:00:12 AM - Windows Update
RP295: 12/20/2011 6:32:53 AM - Windows Update
RP296: 12/23/2011 9:54:33 AM - Windows Update
RP297: 12/27/2011 12:19:53 PM - Windows Update
RP298: 12/28/2011 12:47:20 PM - Installed HiJackThis
.
==== Installed Programs ======================
.
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 7.0
Adobe Reader 9.4.4
Amazon MP3 Downloader 1.0.12
AMD DnD V1.0.19
AnyDVD
Apple Application Support
Apple Software Update
AQScript_0.7.0.134_installer_0.24
ATI Catalyst Registration
Audacity 1.3.12 (Unicode)
avast! Free Antivirus
Avi to Mpeg 3.2
Avidemux 2.5
AviSynth 2.5
Canon Utilities Easy-PhotoPrint EX
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CinemaNow Media Manager
CloneCD
CloneDVD2
CoffeeCup Flash FireStarter
CoffeeCup Flash Menu Builder
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
D3DX10
DesignPro 5
DirectX 9 Runtime
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EA SPORTS online 2008
Exact Audio Copy 0.95b4
Eye Candy 3
Eye Candy 4000 Demo
FFmpeg for Audacity on Windows
Free RAR Extract Frog
GameSpy Arcade
Halo 2 for Windows Vista
HiJackThis
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
Java Auto Updater
Java(TM) 6 Update 24
Junk Mail filter update
K-Lite Codec Pack 6.4.0 (Full)
KompoZer 0.8b3
LAME v3.98.2 for Audacity
Malwarebytes Anti-Malware version 1.60.0.1800
MediaFACE 4.2
MediaFACE II
Microsoft .NET Framework 1.1
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Halo
Microsoft Office 2000 Disc 2
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox (3.6.25)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Octoshape add-in for Adobe Flash Player
Pepakura Viewer 3
Picasa 3
Plants vs. Zombies
QuickBooks Pro 2008
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Burn Manager
Roxio Burn Manager CDB
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Creator 2010
Roxio Creator 2010 Content
Roxio PhotoShow
Roxio Venue
Roxio Video Capture USB
SmartSound Quicktracks Plugin
SupportSoft Assisted Service
Tiger Woods PGA TOUR 08
Visual Site Designer
Vsk5Online
VueScan
Winamp
Winamp Detector Plug-in
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
12/29/2011 10:44:50 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Roxio Hard Drive Watcher 12 service to connect.
12/29/2011 10:44:50 AM, Error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the file specified.
12/27/2011 6:36:28 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer SKELETOR that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BC6796CD-B8FA-4415-A10E-E3F02069298C}. The master browser is stopping or an election is being forced.
12/24/2011 11:45:57 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user NewOffice\Jay SID (S-1-5-21-1755860278-3572679465-1347495285-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
.
==== End Of File ===========================
I've had a recent problem with Hotmail. Tuesday morning it sent emails to my contact list containing a link. I did not click the link fearing it was more trouble. Microsoft shut down the account. I have reactivated it and changed the pass. The outgoing emails appear in the sent folder. There are several of them to multiple recipients and the link in each email is different. The PC is running fine and I have noticed no problems other than Hotmail.
I followed the instructions and the log files are pasted. The GMER log was blank, so there is nothing to paste.
Thank you for your help with this. It's possible this problem is a hacker from outside, but I would like to be sure I don't have a trojan inside.
++++++++++++++++++++++++++++++++++++++++++++++++++++++
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org
Database version: v2011.12.28.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Jay :: NEWOFFICE [administrator]
12/28/2011 12:36:57 PM
mbam-log-2011-12-28 (12-36-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 217020
Time elapsed: 6 minute(s), 39 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by Jay at 13:34:09 on 2011-12-29
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.6135.4485 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe
C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10r_ActiveX.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.weather.com/weather/today/Wilmington+NC+28409
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [MediaFace Integration] C:\Program Files (x86)\Fellowes\MediaFACE 4.2\SetHook.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
mRun: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{98CF92C9-0058-4D3F-8032-032C8A9C6625} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BC6796CD-B8FA-4415-A10E-E3F02069298C} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BC6796CD-B8FA-4415-A10E-E3F02069298C}\C4F6E65635471627E45647 : DhcpNameServer = 209.18.47.61 209.18.47.62
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
mRun-x64: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [MediaFace Integration] C:\Program Files (x86)\Fellowes\MediaFACE 4.2\SetHook.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [(Default)]
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
mRun-x64: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe"
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\quoxygoi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.weather.com/weather/my
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: avast! WebRep: wrc@avast.com - C:\Program Files\Alwil Software\Avast5\WebRep\FF
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 c2scsi64;c2scsi64;C:\Windows\system32\DRIVERS\c2scsi64.sys --> C:\Windows\system32\DRIVERS\c2scsi64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-3-6 42184]
R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2009-6-23 127352]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 scsiscan;SCSI Scanner Driver;C:\Windows\system32\DRIVERS\scsiscan.sys --> C:\Windows\system32\DRIVERS\scsiscan.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 RoxLiveShare10;LiveShare P2P Server 10;"C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" --> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [?]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [2009-7-24 219632]
S2 SessionLauncher;SessionLauncher;C:\Users\Jay\AppData\Local\Temp\DX9\SessionLauncher.exe --> C:\Users\Jay\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 RoxMediaDB12;RoxMediaDB12;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [2009-7-24 1116656]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\RpcAgentSrv.exe [2010-5-21 93336]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vpcuxd;USB Virtualization Stub Service;C:\Windows\system32\drivers\vpcuxd.sys --> C:\Windows\system32\drivers\vpcuxd.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-12-29 15:46:58 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B04B994A-4935-4BF8-92B1-24D4D1F3A88D}\offreg.dll
2011-12-28 17:47:43 388096 ----a-r- C:\Users\Jay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-28 17:47:43 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-12-28 17:35:54 -------- d-----w- C:\Users\Jay\AppData\Roaming\Malwarebytes
2011-12-28 17:35:48 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-28 17:35:47 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-28 17:35:47 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-28 12:19:32 -------- d-----w- C:\Users\Jay\AppData\Local\{5434F421-49DA-4637-83D9-29A5B727B285}
2011-12-28 02:26:25 -------- d-----w- C:\Users\Jay\AppData\Local\{63558786-D34E-46ED-9D7F-9B99C08F8B2A}
2011-12-28 00:00:35 -------- d-----w- C:\Users\Jay\AppData\Local\{F8CB20F0-9D1C-4929-BBA1-F6D1556A7386}
2011-12-28 00:00:23 -------- d-----w- C:\Users\Jay\AppData\Local\{B412AB9F-084D-4FE7-AFC0-6B3B5C7DD5F1}
2011-12-27 17:20:18 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B04B994A-4935-4BF8-92B1-24D4D1F3A88D}\mpengine.dll
2011-12-25 09:37:08 -------- d-----w- C:\Users\Jay\AppData\Local\{E1EBDE92-C8D1-4DEF-9E8A-3492685B4CCB}
2011-12-25 00:04:08 -------- d-----w- C:\Users\Jay\AppData\Local\{4F3A5FCA-37FD-4C2D-97DF-704C20938849}
2011-12-24 17:55:59 -------- d-----w- C:\Users\Jay\AppData\Local\{FA1B0944-DFD2-49DC-96C0-5BBCF8429266}
2011-12-24 17:55:37 -------- d-----w- C:\Users\Jay\AppData\Local\{70387071-E8AC-4FBF-AA82-D59A7059ADEB}
2011-12-24 17:51:23 -------- d-----w- C:\Users\Jay\AppData\Local\{1B8D7723-76D6-4F8D-9CBB-6ED317D34812}
2011-12-24 17:50:59 -------- d-----w- C:\Users\Jay\AppData\Local\{A3F1A3AA-8B75-4F64-ADC0-760A862194FB}
2011-12-24 12:34:00 -------- d-----w- C:\Users\Jay\AppData\Local\{0EAED9FE-F561-45BF-8DC4-A1705EF27CD0}
2011-12-23 18:10:52 -------- d-----w- C:\Users\Jay\AppData\Local\{D8510B3E-5215-441A-88E2-E4EDC9B21237}
2011-12-23 13:50:48 -------- d-----w- C:\Users\Jay\AppData\Local\{5E1D3A7B-8BC7-4065-9660-C11E342410E1}
2011-12-23 13:50:25 -------- d-----w- C:\Users\Jay\AppData\Local\{CD662AF1-BCAB-4832-B77A-31C8C370B3E0}
2011-12-23 13:42:28 -------- d-----w- C:\Users\Jay\AppData\Local\{3F0C231D-444C-46CA-94A8-ED415E95B723}
2011-12-23 13:42:06 -------- d-----w- C:\Users\Jay\AppData\Local\{5234D925-F067-409B-A638-DA334CFC026C}
2011-12-23 13:15:46 -------- d-----w- C:\Users\Jay\AppData\Local\{2484EBF9-E040-4EB6-8F86-94E4CE0528E7}
2011-12-23 13:15:35 -------- d-----w- C:\Users\Jay\AppData\Local\{EE6AD7BE-1D4D-4BC3-9536-B582B1BACBE4}
2011-12-23 12:49:07 -------- d-----w- C:\Users\Jay\AppData\Local\{2329CABF-0A64-47B8-BD36-62A6D475711F}
2011-12-23 12:48:44 -------- d-----w- C:\Users\Jay\AppData\Local\{EF6AC3C6-7263-48FF-AA7F-14BD1D237A68}
2011-12-23 12:38:48 -------- d-----w- C:\Users\Jay\AppData\Local\{D6D0E6F8-0852-419E-AC9E-0628682F27E8}
2011-12-23 12:38:26 -------- d-----w- C:\Users\Jay\AppData\Local\{2934A3F9-653D-4BFE-A010-6BB9D2A4F3B4}
2011-12-23 12:35:09 -------- d-----w- C:\Users\Jay\AppData\Local\{B9833CA9-80E3-406F-A7CA-FE723471DA41}
2011-12-23 12:34:41 -------- d-----w- C:\Users\Jay\AppData\Local\{8BA1586C-7CE3-415C-8597-D0E2E02B28FC}
2011-12-22 20:56:31 -------- d-----w- C:\Users\Jay\AppData\Local\{AFAF1FA1-FE97-4A20-A2B2-547D648918CD}
2011-12-22 20:56:09 -------- d-----w- C:\Users\Jay\AppData\Local\{EA2BE4C5-2519-49E2-B4B0-DB8C4370EFFA}
2011-12-22 17:40:21 -------- d-----w- C:\Users\Jay\AppData\Local\{8231D903-4464-4CC6-8172-D02802C2E127}
2011-12-22 09:34:27 -------- d-----w- C:\Users\Jay\AppData\Local\{F73A9C1D-18F0-4739-8B60-8615B702DC38}
2011-12-22 09:34:04 -------- d-----w- C:\Users\Jay\AppData\Local\{7ECB8096-AC33-4FD9-BEDA-2C1697F3BC25}
2011-12-21 21:56:52 -------- d-----w- C:\Users\Jay\AppData\Local\{F8AF61A0-7A51-41F4-BBD7-483CE475F333}
2011-12-21 21:56:29 -------- d-----w- C:\Users\Jay\AppData\Local\{21820CDF-8E75-4C9A-8AD4-0EA9821A304D}
2011-12-21 14:33:16 -------- d-----w- C:\Users\Jay\AppData\Local\{6D78FFE7-976E-4098-BB80-F38D9D16540F}
2011-12-21 14:32:54 -------- d-----w- C:\Users\Jay\AppData\Local\{E401BC21-D925-4365-8C7F-4044DB7EE367}
2011-12-21 01:55:26 -------- d-----w- C:\Users\Jay\AppData\Local\{A665CB88-9DF3-4696-B9CF-DE63FC3DFB44}
2011-12-21 01:55:04 -------- d-----w- C:\Users\Jay\AppData\Local\{3FBE38F0-E880-4ED9-98B6-F785E5F407D6}
2011-12-21 00:19:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4768D3E5-C6D9-49E6-A512-F22DE3348C67}
2011-12-20 18:24:09 -------- d-----w- C:\ProgramData\Playrix Entertainment
2011-12-20 18:23:05 -------- d-----w- C:\Users\Jay\AppData\Roaming\Oberon Media
2011-12-20 14:24:13 -------- d-----w- C:\Users\Jay\AppData\Local\{718D0C20-50E3-4866-8C25-A35163B106F6}
2011-12-20 14:23:51 -------- d-----w- C:\Users\Jay\AppData\Local\{FCC67391-BA52-494F-A2F1-D79520B6114F}
2011-12-20 12:25:28 -------- d-----w- C:\Users\Jay\AppData\Local\{42D51BD2-7476-4178-BBEF-7800A3C5637A}
2011-12-20 04:58:33 -------- d-----w- C:\Users\Jay\AppData\Local\{912AF255-89E2-4F9C-8945-EEA7F1900B14}
2011-12-20 00:12:20 -------- d-----w- C:\Users\Jay\AppData\Local\{B028EF89-87C1-45EB-B910-B9F2D05064BA}
2011-12-20 00:11:58 -------- d-----w- C:\Users\Jay\AppData\Local\{30078D55-4645-482C-9761-64F3E1E8B485}
2011-12-19 19:12:48 -------- d-----w- C:\Users\Jay\AppData\Local\{E71BD146-A130-4C36-AA48-205522CCC113}
2011-12-19 04:35:57 -------- d-----w- C:\Users\Jay\AppData\Local\{0F2127B7-2662-4F99-8748-EE1CB722FFB7}
2011-12-19 04:35:35 -------- d-----w- C:\Users\Jay\AppData\Local\{B68BEE54-61B1-438B-934B-DFFED73143E5}
2011-12-18 16:06:59 -------- d-----w- C:\Users\Jay\AppData\Local\{67E08AB8-2FEF-4FC3-9AA9-830E2D79337E}
2011-12-18 16:06:37 -------- d-----w- C:\Users\Jay\AppData\Local\{0C755E52-4F61-4D7F-9C71-1C515DC9F8C7}
2011-12-18 14:04:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4D3BBD0D-C7BA-4944-8D42-1A2B84D0B628}
2011-12-18 14:03:43 -------- d-----w- C:\Users\Jay\AppData\Local\{D063175A-4696-49EA-A87B-53B1DB0B6700}
2011-12-18 04:11:56 -------- d-----w- C:\Users\Jay\AppData\Local\{25B4985C-39DB-4ABA-861D-1A5E623CE081}
2011-12-18 04:11:33 -------- d-----w- C:\Users\Jay\AppData\Local\{454DAD95-DB66-4362-976A-E0F1733BADE6}
2011-12-18 00:53:39 -------- d-----w- C:\Users\Jay\AppData\Local\{57B5BE3D-2A57-4FFC-B2E9-1F0683804BA8}
2011-12-15 21:10:12 -------- d-----w- C:\Users\Jay\AppData\Local\{28739CB3-1014-4EC2-92E4-BD435BE4292B}
2011-12-15 12:16:42 -------- d-----w- C:\Users\Jay\AppData\Local\{1CBBBB6C-BC39-4223-BC8F-4F1FECE27A4C}
2011-12-15 11:48:32 -------- d-----w- C:\Users\Jay\AppData\Local\{4DA56215-5E7B-4849-B931-BFB1498814BB}
2011-12-15 11:48:20 -------- d-----w- C:\Users\Jay\AppData\Local\{0A42F385-0460-4A22-A065-1C9053491F69}
2011-12-14 21:54:54 -------- d-----w- C:\Users\Jay\AppData\Local\{0F6871CA-5BD4-410D-9E58-EDA55E348DD6}
2011-12-14 21:54:32 -------- d-----w- C:\Users\Jay\AppData\Local\{E36C5128-8B68-4E4A-8130-2F5D2E4FDFC2}
2011-12-14 20:09:58 -------- d-----w- C:\Users\Jay\AppData\Local\{58BC3F0D-014C-4123-854F-C19A68B1BF0E}
2011-12-14 20:09:36 -------- d-----w- C:\Users\Jay\AppData\Local\{6DC88A0C-8B35-4B30-BAAF-92249DCD021F}
2011-12-14 01:50:43 -------- d-----w- C:\Users\Jay\AppData\Local\{E54DF379-F2E2-47F7-9869-EEE53DD28D6F}
2011-12-13 02:25:27 -------- d-----w- C:\Users\Jay\AppData\Local\{8FFDAF4C-423D-421D-A3EE-93FECBC3319F}
2011-12-12 23:51:47 -------- d-----w- C:\Users\Jay\AppData\Local\{5A977D0A-0E08-4D12-9A6D-C891E66A735F}
2011-12-12 13:14:08 -------- d-----w- C:\Users\Jay\AppData\Local\{402B3E53-D9D6-4464-9B52-BF2E97DFADDB}
2011-12-12 12:19:58 -------- d-----w- C:\Users\Jay\AppData\Local\{21644F67-0F6F-4393-B101-4E2F079ED9AF}
2011-12-11 13:54:01 -------- d-----w- C:\Users\Jay\AppData\Local\{59B02365-124E-45C2-A3B9-38822C894161}
2011-12-10 23:54:59 -------- d-----w- C:\Users\Jay\AppData\Local\{85AFCA50-021F-4729-83CA-38382BA3AF50}
2011-12-10 02:30:26 -------- d-----w- C:\Users\Jay\AppData\Local\{83411C03-9410-43DC-92D4-B35C05E4AA0A}
2011-12-09 12:56:42 -------- d-----w- C:\Users\Jay\AppData\Local\{736E3DFE-1730-49FD-98C0-A47CC611B3C9}
2011-12-09 01:12:26 -------- d-----w- C:\Users\Jay\AppData\Local\{0D25CC6B-075E-491C-A989-1DEA1F0943E1}
2011-12-08 12:34:43 -------- d-----w- C:\Users\Jay\AppData\Local\{442F707D-93CB-4CF1-AB7F-12B359528FF2}
2011-12-08 11:37:50 -------- d-----w- C:\Users\Jay\AppData\Local\{67A7FEAE-0788-44A5-8EA2-E51045D3C261}
2011-12-08 02:50:41 -------- d-----w- C:\Users\Jay\AppData\Local\{EEFD12D0-9108-487C-8EB0-AEAC82A27C82}
2011-12-07 23:32:22 -------- d-----w- C:\Users\Jay\AppData\Local\{7FA55C8F-C410-4AD5-A782-48B6AA66E186}
2011-12-07 23:31:59 -------- d-----w- C:\Users\Jay\AppData\Local\{28070730-AA39-4712-8D54-1020F7161021}
2011-12-07 20:07:39 -------- d-----w- C:\Users\Jay\AppData\Local\{AAAA2D4E-8779-4A51-97DA-73856FB0DA73}
2011-12-07 20:07:17 -------- d-----w- C:\Users\Jay\AppData\Local\{A48FA3BA-A53F-44E7-BDB5-943C81C3625E}
2011-12-07 15:33:14 -------- d-----w- C:\Users\Jay\AppData\Local\{B74F52D1-D019-426B-BE71-FF9130CE9F9D}
2011-12-07 12:35:11 -------- d-----w- C:\Users\Jay\AppData\Local\{75E147AC-5A12-4906-A36F-E15D73C92462}
2011-12-07 12:10:28 -------- d-----w- C:\Users\Jay\AppData\Local\{CA3914C7-DBDF-4F4A-92AE-7497D0DA3FE7}
2011-12-07 12:10:06 -------- d-----w- C:\Users\Jay\AppData\Local\{B3CC81F6-F1F6-4F96-AB4F-1E9288220BB3}
2011-12-06 23:59:06 -------- d-----w- C:\Users\Jay\AppData\Local\{4D853912-5838-4E98-992D-B0099083AECE}
2011-12-06 20:59:03 -------- d-----w- C:\Users\Jay\AppData\Local\{2FE9D022-9D19-4B1E-AACF-0C6C85C39C45}
2011-12-06 17:07:00 -------- d-----w- C:\Users\Jay\AppData\Local\{6F38CD55-9E86-4A8A-957B-769E14173876}
2011-12-06 17:06:38 -------- d-----w- C:\Users\Jay\AppData\Local\{057E2F2E-6EE9-44B6-8284-91D2A120A441}
2011-12-06 14:38:36 -------- d-----w- C:\Users\Jay\AppData\Local\{93301825-1F8F-46FE-97BE-2FB89CCAAD4A}
2011-12-06 12:56:25 -------- d-----w- C:\Users\Jay\AppData\Local\{86952BC1-8C6E-414C-9D78-52C2FF12558A}
2011-12-06 12:56:03 -------- d-----w- C:\Users\Jay\AppData\Local\{B503D05E-56EF-4D7B-8256-79725CEBFFEA}
2011-12-06 12:41:59 -------- d-----w- C:\Users\Jay\AppData\Local\{74B13190-EEFC-4322-9FAC-7B45E4BD7DA0}
2011-12-06 12:41:36 -------- d-----w- C:\Users\Jay\AppData\Local\{8FA5CE15-2E20-4409-8DB4-8EE673EF673C}
2011-12-06 04:04:07 -------- d-----w- C:\Users\Jay\AppData\Local\{B61B1A63-5E41-4003-BC25-B94C3E8A958D}
2011-12-06 03:02:37 -------- d-----w- C:\Users\Jay\AppData\Local\{B577F929-F15A-443C-B2EA-5715E3143505}
2011-12-06 02:26:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4739295B-62B8-42FF-A89B-EAB263150B96}
2011-12-06 02:25:42 -------- d-----w- C:\Users\Jay\AppData\Local\{7244D46E-A1C1-4644-9471-0F9CEB8277EB}
2011-12-06 02:08:26 -------- d-----w- C:\Users\Jay\AppData\Local\{813B39E5-AB8D-42D0-B804-1F7BD77ED6A8}
2011-12-06 02:08:04 -------- d-----w- C:\Users\Jay\AppData\Local\{6DBA3827-700B-4285-A68D-90183CFE1695}
2011-12-06 01:13:59 -------- d-----w- C:\Users\Jay\AppData\Local\{0B8631F1-5129-40F7-A7C9-54624FCF70ED}
2011-12-06 01:13:37 -------- d-----w- C:\Users\Jay\AppData\Local\{F7295420-5851-4500-9C75-1B753ABD798F}
2011-12-05 22:03:06 -------- d-----w- C:\Users\Jay\AppData\Local\{0E6CBBC1-AEA6-4B60-9309-86770CE5275F}
2011-12-05 22:02:43 -------- d-----w- C:\Users\Jay\AppData\Local\{3C25E048-9AEB-4AF7-9265-2410BD360A36}
2011-12-05 19:08:35 -------- d-----w- C:\Users\Jay\AppData\Local\{47EBB7D8-0172-4D3F-9B32-B84C0862C928}
2011-12-05 19:08:13 -------- d-----w- C:\Users\Jay\AppData\Local\{03CC83A0-3F81-478D-B883-246B988C64B3}
2011-12-05 13:16:42 -------- d-----w- C:\Users\Jay\AppData\Local\{71A52DF7-C30D-40D2-BC8B-1BF77C599C7C}
2011-12-05 12:39:16 -------- d-----w- C:\Users\Jay\AppData\Local\{A4F59168-0406-42F6-A9FE-5B6B4ED0FD44}
2011-12-05 00:54:08 -------- d-----w- C:\Users\Jay\AppData\Local\{DEFA752B-9BA5-4840-B187-0FD4A5A0A9AF}
2011-12-05 00:53:45 -------- d-----w- C:\Users\Jay\AppData\Local\{3F20CBE3-DF3B-4F1B-B47F-6CEC6B3FF4E0}
2011-12-04 23:19:33 -------- d-----w- C:\Users\Jay\AppData\Local\{4A781581-3953-46CC-BD3A-B34553E72E43}
2011-12-04 12:54:57 550602 ----a-w- C:\EyeCand3.8bf
2011-12-04 12:54:57 409600 ----a-w- C:\EC3-ENG.8BF
2011-12-04 12:54:57 127184 ----a-w- C:\UNWISE.EXE
2011-12-04 12:54:57 -------- d-----w- C:\Eye Candy 4000
2011-12-03 01:14:24 -------- d-----w- C:\Users\Jay\AppData\Local\{D723E6D9-A93C-418D-8EC4-2DEB29159684}
2011-12-02 22:09:33 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-12-02 22:09:07 -------- d-----w- C:\Windows\SysWow64\xlive
2011-12-02 22:08:52 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-12-02 21:34:30 -------- d-----w- C:\Users\Jay\AppData\Local\{B379370E-E4DD-4FD0-AE41-9B0253D89069}
2011-12-02 13:19:12 -------- d-----w- C:\Users\Jay\AppData\Local\{DBAE392D-399C-4CBD-BABB-C12A40D7A6C3}
2011-12-02 13:18:50 -------- d-----w- C:\Users\Jay\AppData\Local\{43D8271C-EF6A-454D-8A66-B68862793149}
2011-12-02 00:50:27 -------- d-----w- C:\Users\Jay\AppData\Local\{ACE2BB29-4071-4401-BA1C-44CD5F3BEE5F}
2011-12-02 00:50:05 -------- d-----w- C:\Users\Jay\AppData\Local\{977E8DCD-C539-4D38-88C2-BA95CB3AC396}
2011-12-01 13:10:25 -------- d-----w- C:\Users\Jay\AppData\Local\{8827A7B1-8E29-4592-B211-8562141508EF}
2011-12-01 13:10:03 -------- d-----w- C:\Users\Jay\AppData\Local\{02D4E0E6-83F2-4765-8272-F6016183406B}
2011-12-01 12:29:28 -------- d-----w- C:\Users\Jay\AppData\Local\{972958E5-4987-4FDE-A0E5-2E0EEA2F79B7}
2011-12-01 12:29:05 -------- d-----w- C:\Users\Jay\AppData\Local\{191B1C58-E66D-4F04-ADD7-99F75CFBB24B}
2011-12-01 12:09:02 -------- d-----w- C:\Users\Jay\AppData\Local\{9A19B0A0-E7B4-4E0A-9EDD-5DB908CC43F1}
2011-12-01 12:08:40 -------- d-----w- C:\Users\Jay\AppData\Local\{49EA647C-05B1-4944-A0BC-A8BDE876290C}
2011-11-30 22:35:01 -------- d-----w- C:\Users\Jay\AppData\Local\{7F56C190-E864-4C11-AC71-909F3A28E5DC}
2011-11-30 15:47:14 -------- d-----w- C:\Users\Jay\AppData\Local\{A8DCF430-7A6F-449C-8F7F-5151B063791D}
2011-11-30 12:37:41 -------- d-----w- C:\Users\Jay\AppData\Local\{9D038E7F-AADA-4E4D-BF54-3B05E8DF9561}
2011-11-30 12:00:34 -------- d-----w- C:\Users\Jay\AppData\Local\{47BD8344-F8FE-45DA-8CCA-FAE7B92F55E9}
2011-11-30 03:09:06 -------- d-----w- C:\Users\Jay\AppData\Local\{09FA678E-8BE4-40CE-AFBF-00F7936AAF72}
2011-11-30 03:08:43 -------- d-----w- C:\Users\Jay\AppData\Local\{CB236E7C-15CE-4A44-A84F-32D5BBDADA48}
2011-11-30 02:22:06 -------- d-----w- C:\Users\Jay\AppData\Local\{7A9237FF-0144-4F4E-8110-7C99841CA9BC}
2011-11-30 01:18:39 -------- d-----w- C:\Users\Jay\AppData\Local\{4A681FA2-4251-435E-B16A-54135D547524}
2011-11-30 01:18:17 -------- d-----w- C:\Users\Jay\AppData\Local\{AE4BBC7F-D5A3-4C89-8B5C-8BE5381A3573}
2011-11-29 20:47:14 -------- d-----w- C:\Users\Jay\AppData\Local\{C26AB4DE-3725-4C1E-9D21-3A3B15E307AA}
2011-11-29 20:46:52 -------- d-----w- C:\Users\Jay\AppData\Local\{703EEE66-25E8-4470-B2D6-B89207651180}
.
==================== Find3M ====================
.
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 21:28:31 1393736 ----a-w- C:\Users\Jay\gotomypc_626.exe
2011-11-05 05:41:43 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-05 04:35:00 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-11-05 03:32:47 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:48:51 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-10-15 06:31:56 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-10-15 05:38:59 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
.
============= FINISH: 13:34:23.46 ===============
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume3
Install Date: 2/21/2010 1:31:51 PM
System Uptime: 12/29/2011 10:43:36 AM (3 hours ago)
.
Motherboard: Foxconn | | Flaming Blade GTI
Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz | Socket 1366 | 2793/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 596 GiB total, 440.421 GiB free.
D: is FIXED (NTFS) - 298 GiB total, 176.73 GiB free.
E: is FIXED (NTFS) - 298 GiB total, 150.581 GiB free.
F: is FIXED (NTFS) - 931 GiB total, 421.559 GiB free.
G: is CDROM ()
H: is FIXED (NTFS) - 0 GiB total, 0.069 GiB free.
I: is Removable
J: is CDROM ()
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP291: 12/6/2011 2:14:54 AM - Windows Update
RP292: 12/9/2011 8:58:08 AM - Windows Update
RP293: 12/13/2011 10:20:15 AM - Windows Update
RP294: 12/15/2011 3:00:12 AM - Windows Update
RP295: 12/20/2011 6:32:53 AM - Windows Update
RP296: 12/23/2011 9:54:33 AM - Windows Update
RP297: 12/27/2011 12:19:53 PM - Windows Update
RP298: 12/28/2011 12:47:20 PM - Installed HiJackThis
.
==== Installed Programs ======================
.
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 7.0
Adobe Reader 9.4.4
Amazon MP3 Downloader 1.0.12
AMD DnD V1.0.19
AnyDVD
Apple Application Support
Apple Software Update
AQScript_0.7.0.134_installer_0.24
ATI Catalyst Registration
Audacity 1.3.12 (Unicode)
avast! Free Antivirus
Avi to Mpeg 3.2
Avidemux 2.5
AviSynth 2.5
Canon Utilities Easy-PhotoPrint EX
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CinemaNow Media Manager
CloneCD
CloneDVD2
CoffeeCup Flash FireStarter
CoffeeCup Flash Menu Builder
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
D3DX10
DesignPro 5
DirectX 9 Runtime
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EA SPORTS online 2008
Exact Audio Copy 0.95b4
Eye Candy 3
Eye Candy 4000 Demo
FFmpeg for Audacity on Windows
Free RAR Extract Frog
GameSpy Arcade
Halo 2 for Windows Vista
HiJackThis
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
Java Auto Updater
Java(TM) 6 Update 24
Junk Mail filter update
K-Lite Codec Pack 6.4.0 (Full)
KompoZer 0.8b3
LAME v3.98.2 for Audacity
Malwarebytes Anti-Malware version 1.60.0.1800
MediaFACE 4.2
MediaFACE II
Microsoft .NET Framework 1.1
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Halo
Microsoft Office 2000 Disc 2
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox (3.6.25)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Octoshape add-in for Adobe Flash Player
Pepakura Viewer 3
Picasa 3
Plants vs. Zombies
QuickBooks Pro 2008
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Burn Manager
Roxio Burn Manager CDB
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Creator 2010
Roxio Creator 2010 Content
Roxio PhotoShow
Roxio Venue
Roxio Video Capture USB
SmartSound Quicktracks Plugin
SupportSoft Assisted Service
Tiger Woods PGA TOUR 08
Visual Site Designer
Vsk5Online
VueScan
Winamp
Winamp Detector Plug-in
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
12/29/2011 10:44:50 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Roxio Hard Drive Watcher 12 service to connect.
12/29/2011 10:44:50 AM, Error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the file specified.
12/27/2011 6:36:28 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer SKELETOR that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BC6796CD-B8FA-4415-A10E-E3F02069298C}. The master browser is stopping or an election is being forced.
12/24/2011 11:45:57 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user NewOffice\Jay SID (S-1-5-21-1755860278-3572679465-1347495285-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
.
==== End Of File ===========================