Inactive [A] Hotmail virus?

Status
Not open for further replies.
Hello:

I've had a recent problem with Hotmail. Tuesday morning it sent emails to my contact list containing a link. I did not click the link fearing it was more trouble. Microsoft shut down the account. I have reactivated it and changed the pass. The outgoing emails appear in the sent folder. There are several of them to multiple recipients and the link in each email is different. The PC is running fine and I have noticed no problems other than Hotmail.

I followed the instructions and the log files are pasted. The GMER log was blank, so there is nothing to paste.

Thank you for your help with this. It's possible this problem is a hacker from outside, but I would like to be sure I don't have a trojan inside.


++++++++++++++++++++++++++++++++++++++++++++++++++++++
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2011.12.28.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Jay :: NEWOFFICE [administrator]

12/28/2011 12:36:57 PM
mbam-log-2011-12-28 (12-36-57).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 217020
Time elapsed: 6 minute(s), 39 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by Jay at 13:34:09 on 2011-12-29
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.6135.4485 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe
C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10r_ActiveX.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.weather.com/weather/today/Wilmington+NC+28409
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
uRun: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
mRun: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [MediaFace Integration] C:\Program Files (x86)\Fellowes\MediaFACE 4.2\SetHook.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
mRun: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\QUICKB~1.LNK - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\OFFICE11\REFIEBAR.DLL
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{98CF92C9-0058-4D3F-8032-032C8A9C6625} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BC6796CD-B8FA-4415-A10E-E3F02069298C} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{BC6796CD-B8FA-4415-A10E-E3F02069298C}\C4F6E65635471627E45647 : DhcpNameServer = 209.18.47.61 209.18.47.62
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\System32\mscoree.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
mRun-x64: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
mRun-x64: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
mRun-x64: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [MediaFace Integration] C:\Program Files (x86)\Fellowes\MediaFACE 4.2\SetHook.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [CloneCDTray] "C:\Program Files (x86)\SlySoft\CloneCD\CloneCDTray.exe" /s
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [(Default)]
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
mRun-x64: [CPMonitor] "C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe"
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jay\AppData\Roaming\Mozilla\Firefox\Profiles\quoxygoi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.weather.com/weather/my
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: avast! WebRep: wrc@avast.com - C:\Program Files\Alwil Software\Avast5\WebRep\FF
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 c2scsi64;c2scsi64;C:\Windows\system32\DRIVERS\c2scsi64.sys --> C:\Windows\system32\DRIVERS\c2scsi64.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-3-6 42184]
R2 CinemaNow Service;CinemaNow Service;C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [2009-6-23 127352]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 scsiscan;SCSI Scanner Driver;C:\Windows\system32\DRIVERS\scsiscan.sys --> C:\Windows\system32\DRIVERS\scsiscan.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 RoxLiveShare10;LiveShare P2P Server 10;"C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" --> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [?]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [2009-7-24 219632]
S2 SessionLauncher;SessionLauncher;C:\Users\Jay\AppData\Local\Temp\DX9\SessionLauncher.exe --> C:\Users\Jay\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 RoxMediaDB12;RoxMediaDB12;C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [2009-7-24 1116656]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010.SP1d\RpcAgentSrv.exe [2010-5-21 93336]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vpcuxd;USB Virtualization Stub Service;C:\Windows\system32\drivers\vpcuxd.sys --> C:\Windows\system32\drivers\vpcuxd.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-12-29 15:46:58 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B04B994A-4935-4BF8-92B1-24D4D1F3A88D}\offreg.dll
2011-12-28 17:47:43 388096 ----a-r- C:\Users\Jay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-28 17:47:43 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-12-28 17:35:54 -------- d-----w- C:\Users\Jay\AppData\Roaming\Malwarebytes
2011-12-28 17:35:48 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-28 17:35:47 23152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-28 17:35:47 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-12-28 12:19:32 -------- d-----w- C:\Users\Jay\AppData\Local\{5434F421-49DA-4637-83D9-29A5B727B285}
2011-12-28 02:26:25 -------- d-----w- C:\Users\Jay\AppData\Local\{63558786-D34E-46ED-9D7F-9B99C08F8B2A}
2011-12-28 00:00:35 -------- d-----w- C:\Users\Jay\AppData\Local\{F8CB20F0-9D1C-4929-BBA1-F6D1556A7386}
2011-12-28 00:00:23 -------- d-----w- C:\Users\Jay\AppData\Local\{B412AB9F-084D-4FE7-AFC0-6B3B5C7DD5F1}
2011-12-27 17:20:18 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B04B994A-4935-4BF8-92B1-24D4D1F3A88D}\mpengine.dll
2011-12-25 09:37:08 -------- d-----w- C:\Users\Jay\AppData\Local\{E1EBDE92-C8D1-4DEF-9E8A-3492685B4CCB}
2011-12-25 00:04:08 -------- d-----w- C:\Users\Jay\AppData\Local\{4F3A5FCA-37FD-4C2D-97DF-704C20938849}
2011-12-24 17:55:59 -------- d-----w- C:\Users\Jay\AppData\Local\{FA1B0944-DFD2-49DC-96C0-5BBCF8429266}
2011-12-24 17:55:37 -------- d-----w- C:\Users\Jay\AppData\Local\{70387071-E8AC-4FBF-AA82-D59A7059ADEB}
2011-12-24 17:51:23 -------- d-----w- C:\Users\Jay\AppData\Local\{1B8D7723-76D6-4F8D-9CBB-6ED317D34812}
2011-12-24 17:50:59 -------- d-----w- C:\Users\Jay\AppData\Local\{A3F1A3AA-8B75-4F64-ADC0-760A862194FB}
2011-12-24 12:34:00 -------- d-----w- C:\Users\Jay\AppData\Local\{0EAED9FE-F561-45BF-8DC4-A1705EF27CD0}
2011-12-23 18:10:52 -------- d-----w- C:\Users\Jay\AppData\Local\{D8510B3E-5215-441A-88E2-E4EDC9B21237}
2011-12-23 13:50:48 -------- d-----w- C:\Users\Jay\AppData\Local\{5E1D3A7B-8BC7-4065-9660-C11E342410E1}
2011-12-23 13:50:25 -------- d-----w- C:\Users\Jay\AppData\Local\{CD662AF1-BCAB-4832-B77A-31C8C370B3E0}
2011-12-23 13:42:28 -------- d-----w- C:\Users\Jay\AppData\Local\{3F0C231D-444C-46CA-94A8-ED415E95B723}
2011-12-23 13:42:06 -------- d-----w- C:\Users\Jay\AppData\Local\{5234D925-F067-409B-A638-DA334CFC026C}
2011-12-23 13:15:46 -------- d-----w- C:\Users\Jay\AppData\Local\{2484EBF9-E040-4EB6-8F86-94E4CE0528E7}
2011-12-23 13:15:35 -------- d-----w- C:\Users\Jay\AppData\Local\{EE6AD7BE-1D4D-4BC3-9536-B582B1BACBE4}
2011-12-23 12:49:07 -------- d-----w- C:\Users\Jay\AppData\Local\{2329CABF-0A64-47B8-BD36-62A6D475711F}
2011-12-23 12:48:44 -------- d-----w- C:\Users\Jay\AppData\Local\{EF6AC3C6-7263-48FF-AA7F-14BD1D237A68}
2011-12-23 12:38:48 -------- d-----w- C:\Users\Jay\AppData\Local\{D6D0E6F8-0852-419E-AC9E-0628682F27E8}
2011-12-23 12:38:26 -------- d-----w- C:\Users\Jay\AppData\Local\{2934A3F9-653D-4BFE-A010-6BB9D2A4F3B4}
2011-12-23 12:35:09 -------- d-----w- C:\Users\Jay\AppData\Local\{B9833CA9-80E3-406F-A7CA-FE723471DA41}
2011-12-23 12:34:41 -------- d-----w- C:\Users\Jay\AppData\Local\{8BA1586C-7CE3-415C-8597-D0E2E02B28FC}
2011-12-22 20:56:31 -------- d-----w- C:\Users\Jay\AppData\Local\{AFAF1FA1-FE97-4A20-A2B2-547D648918CD}
2011-12-22 20:56:09 -------- d-----w- C:\Users\Jay\AppData\Local\{EA2BE4C5-2519-49E2-B4B0-DB8C4370EFFA}
2011-12-22 17:40:21 -------- d-----w- C:\Users\Jay\AppData\Local\{8231D903-4464-4CC6-8172-D02802C2E127}
2011-12-22 09:34:27 -------- d-----w- C:\Users\Jay\AppData\Local\{F73A9C1D-18F0-4739-8B60-8615B702DC38}
2011-12-22 09:34:04 -------- d-----w- C:\Users\Jay\AppData\Local\{7ECB8096-AC33-4FD9-BEDA-2C1697F3BC25}
2011-12-21 21:56:52 -------- d-----w- C:\Users\Jay\AppData\Local\{F8AF61A0-7A51-41F4-BBD7-483CE475F333}
2011-12-21 21:56:29 -------- d-----w- C:\Users\Jay\AppData\Local\{21820CDF-8E75-4C9A-8AD4-0EA9821A304D}
2011-12-21 14:33:16 -------- d-----w- C:\Users\Jay\AppData\Local\{6D78FFE7-976E-4098-BB80-F38D9D16540F}
2011-12-21 14:32:54 -------- d-----w- C:\Users\Jay\AppData\Local\{E401BC21-D925-4365-8C7F-4044DB7EE367}
2011-12-21 01:55:26 -------- d-----w- C:\Users\Jay\AppData\Local\{A665CB88-9DF3-4696-B9CF-DE63FC3DFB44}
2011-12-21 01:55:04 -------- d-----w- C:\Users\Jay\AppData\Local\{3FBE38F0-E880-4ED9-98B6-F785E5F407D6}
2011-12-21 00:19:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4768D3E5-C6D9-49E6-A512-F22DE3348C67}
2011-12-20 18:24:09 -------- d-----w- C:\ProgramData\Playrix Entertainment
2011-12-20 18:23:05 -------- d-----w- C:\Users\Jay\AppData\Roaming\Oberon Media
2011-12-20 14:24:13 -------- d-----w- C:\Users\Jay\AppData\Local\{718D0C20-50E3-4866-8C25-A35163B106F6}
2011-12-20 14:23:51 -------- d-----w- C:\Users\Jay\AppData\Local\{FCC67391-BA52-494F-A2F1-D79520B6114F}
2011-12-20 12:25:28 -------- d-----w- C:\Users\Jay\AppData\Local\{42D51BD2-7476-4178-BBEF-7800A3C5637A}
2011-12-20 04:58:33 -------- d-----w- C:\Users\Jay\AppData\Local\{912AF255-89E2-4F9C-8945-EEA7F1900B14}
2011-12-20 00:12:20 -------- d-----w- C:\Users\Jay\AppData\Local\{B028EF89-87C1-45EB-B910-B9F2D05064BA}
2011-12-20 00:11:58 -------- d-----w- C:\Users\Jay\AppData\Local\{30078D55-4645-482C-9761-64F3E1E8B485}
2011-12-19 19:12:48 -------- d-----w- C:\Users\Jay\AppData\Local\{E71BD146-A130-4C36-AA48-205522CCC113}
2011-12-19 04:35:57 -------- d-----w- C:\Users\Jay\AppData\Local\{0F2127B7-2662-4F99-8748-EE1CB722FFB7}
2011-12-19 04:35:35 -------- d-----w- C:\Users\Jay\AppData\Local\{B68BEE54-61B1-438B-934B-DFFED73143E5}
2011-12-18 16:06:59 -------- d-----w- C:\Users\Jay\AppData\Local\{67E08AB8-2FEF-4FC3-9AA9-830E2D79337E}
2011-12-18 16:06:37 -------- d-----w- C:\Users\Jay\AppData\Local\{0C755E52-4F61-4D7F-9C71-1C515DC9F8C7}
2011-12-18 14:04:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4D3BBD0D-C7BA-4944-8D42-1A2B84D0B628}
2011-12-18 14:03:43 -------- d-----w- C:\Users\Jay\AppData\Local\{D063175A-4696-49EA-A87B-53B1DB0B6700}
2011-12-18 04:11:56 -------- d-----w- C:\Users\Jay\AppData\Local\{25B4985C-39DB-4ABA-861D-1A5E623CE081}
2011-12-18 04:11:33 -------- d-----w- C:\Users\Jay\AppData\Local\{454DAD95-DB66-4362-976A-E0F1733BADE6}
2011-12-18 00:53:39 -------- d-----w- C:\Users\Jay\AppData\Local\{57B5BE3D-2A57-4FFC-B2E9-1F0683804BA8}
2011-12-15 21:10:12 -------- d-----w- C:\Users\Jay\AppData\Local\{28739CB3-1014-4EC2-92E4-BD435BE4292B}
2011-12-15 12:16:42 -------- d-----w- C:\Users\Jay\AppData\Local\{1CBBBB6C-BC39-4223-BC8F-4F1FECE27A4C}
2011-12-15 11:48:32 -------- d-----w- C:\Users\Jay\AppData\Local\{4DA56215-5E7B-4849-B931-BFB1498814BB}
2011-12-15 11:48:20 -------- d-----w- C:\Users\Jay\AppData\Local\{0A42F385-0460-4A22-A065-1C9053491F69}
2011-12-14 21:54:54 -------- d-----w- C:\Users\Jay\AppData\Local\{0F6871CA-5BD4-410D-9E58-EDA55E348DD6}
2011-12-14 21:54:32 -------- d-----w- C:\Users\Jay\AppData\Local\{E36C5128-8B68-4E4A-8130-2F5D2E4FDFC2}
2011-12-14 20:09:58 -------- d-----w- C:\Users\Jay\AppData\Local\{58BC3F0D-014C-4123-854F-C19A68B1BF0E}
2011-12-14 20:09:36 -------- d-----w- C:\Users\Jay\AppData\Local\{6DC88A0C-8B35-4B30-BAAF-92249DCD021F}
2011-12-14 01:50:43 -------- d-----w- C:\Users\Jay\AppData\Local\{E54DF379-F2E2-47F7-9869-EEE53DD28D6F}
2011-12-13 02:25:27 -------- d-----w- C:\Users\Jay\AppData\Local\{8FFDAF4C-423D-421D-A3EE-93FECBC3319F}
2011-12-12 23:51:47 -------- d-----w- C:\Users\Jay\AppData\Local\{5A977D0A-0E08-4D12-9A6D-C891E66A735F}
2011-12-12 13:14:08 -------- d-----w- C:\Users\Jay\AppData\Local\{402B3E53-D9D6-4464-9B52-BF2E97DFADDB}
2011-12-12 12:19:58 -------- d-----w- C:\Users\Jay\AppData\Local\{21644F67-0F6F-4393-B101-4E2F079ED9AF}
2011-12-11 13:54:01 -------- d-----w- C:\Users\Jay\AppData\Local\{59B02365-124E-45C2-A3B9-38822C894161}
2011-12-10 23:54:59 -------- d-----w- C:\Users\Jay\AppData\Local\{85AFCA50-021F-4729-83CA-38382BA3AF50}
2011-12-10 02:30:26 -------- d-----w- C:\Users\Jay\AppData\Local\{83411C03-9410-43DC-92D4-B35C05E4AA0A}
2011-12-09 12:56:42 -------- d-----w- C:\Users\Jay\AppData\Local\{736E3DFE-1730-49FD-98C0-A47CC611B3C9}
2011-12-09 01:12:26 -------- d-----w- C:\Users\Jay\AppData\Local\{0D25CC6B-075E-491C-A989-1DEA1F0943E1}
2011-12-08 12:34:43 -------- d-----w- C:\Users\Jay\AppData\Local\{442F707D-93CB-4CF1-AB7F-12B359528FF2}
2011-12-08 11:37:50 -------- d-----w- C:\Users\Jay\AppData\Local\{67A7FEAE-0788-44A5-8EA2-E51045D3C261}
2011-12-08 02:50:41 -------- d-----w- C:\Users\Jay\AppData\Local\{EEFD12D0-9108-487C-8EB0-AEAC82A27C82}
2011-12-07 23:32:22 -------- d-----w- C:\Users\Jay\AppData\Local\{7FA55C8F-C410-4AD5-A782-48B6AA66E186}
2011-12-07 23:31:59 -------- d-----w- C:\Users\Jay\AppData\Local\{28070730-AA39-4712-8D54-1020F7161021}
2011-12-07 20:07:39 -------- d-----w- C:\Users\Jay\AppData\Local\{AAAA2D4E-8779-4A51-97DA-73856FB0DA73}
2011-12-07 20:07:17 -------- d-----w- C:\Users\Jay\AppData\Local\{A48FA3BA-A53F-44E7-BDB5-943C81C3625E}
2011-12-07 15:33:14 -------- d-----w- C:\Users\Jay\AppData\Local\{B74F52D1-D019-426B-BE71-FF9130CE9F9D}
2011-12-07 12:35:11 -------- d-----w- C:\Users\Jay\AppData\Local\{75E147AC-5A12-4906-A36F-E15D73C92462}
2011-12-07 12:10:28 -------- d-----w- C:\Users\Jay\AppData\Local\{CA3914C7-DBDF-4F4A-92AE-7497D0DA3FE7}
2011-12-07 12:10:06 -------- d-----w- C:\Users\Jay\AppData\Local\{B3CC81F6-F1F6-4F96-AB4F-1E9288220BB3}
2011-12-06 23:59:06 -------- d-----w- C:\Users\Jay\AppData\Local\{4D853912-5838-4E98-992D-B0099083AECE}
2011-12-06 20:59:03 -------- d-----w- C:\Users\Jay\AppData\Local\{2FE9D022-9D19-4B1E-AACF-0C6C85C39C45}
2011-12-06 17:07:00 -------- d-----w- C:\Users\Jay\AppData\Local\{6F38CD55-9E86-4A8A-957B-769E14173876}
2011-12-06 17:06:38 -------- d-----w- C:\Users\Jay\AppData\Local\{057E2F2E-6EE9-44B6-8284-91D2A120A441}
2011-12-06 14:38:36 -------- d-----w- C:\Users\Jay\AppData\Local\{93301825-1F8F-46FE-97BE-2FB89CCAAD4A}
2011-12-06 12:56:25 -------- d-----w- C:\Users\Jay\AppData\Local\{86952BC1-8C6E-414C-9D78-52C2FF12558A}
2011-12-06 12:56:03 -------- d-----w- C:\Users\Jay\AppData\Local\{B503D05E-56EF-4D7B-8256-79725CEBFFEA}
2011-12-06 12:41:59 -------- d-----w- C:\Users\Jay\AppData\Local\{74B13190-EEFC-4322-9FAC-7B45E4BD7DA0}
2011-12-06 12:41:36 -------- d-----w- C:\Users\Jay\AppData\Local\{8FA5CE15-2E20-4409-8DB4-8EE673EF673C}
2011-12-06 04:04:07 -------- d-----w- C:\Users\Jay\AppData\Local\{B61B1A63-5E41-4003-BC25-B94C3E8A958D}
2011-12-06 03:02:37 -------- d-----w- C:\Users\Jay\AppData\Local\{B577F929-F15A-443C-B2EA-5715E3143505}
2011-12-06 02:26:05 -------- d-----w- C:\Users\Jay\AppData\Local\{4739295B-62B8-42FF-A89B-EAB263150B96}
2011-12-06 02:25:42 -------- d-----w- C:\Users\Jay\AppData\Local\{7244D46E-A1C1-4644-9471-0F9CEB8277EB}
2011-12-06 02:08:26 -------- d-----w- C:\Users\Jay\AppData\Local\{813B39E5-AB8D-42D0-B804-1F7BD77ED6A8}
2011-12-06 02:08:04 -------- d-----w- C:\Users\Jay\AppData\Local\{6DBA3827-700B-4285-A68D-90183CFE1695}
2011-12-06 01:13:59 -------- d-----w- C:\Users\Jay\AppData\Local\{0B8631F1-5129-40F7-A7C9-54624FCF70ED}
2011-12-06 01:13:37 -------- d-----w- C:\Users\Jay\AppData\Local\{F7295420-5851-4500-9C75-1B753ABD798F}
2011-12-05 22:03:06 -------- d-----w- C:\Users\Jay\AppData\Local\{0E6CBBC1-AEA6-4B60-9309-86770CE5275F}
2011-12-05 22:02:43 -------- d-----w- C:\Users\Jay\AppData\Local\{3C25E048-9AEB-4AF7-9265-2410BD360A36}
2011-12-05 19:08:35 -------- d-----w- C:\Users\Jay\AppData\Local\{47EBB7D8-0172-4D3F-9B32-B84C0862C928}
2011-12-05 19:08:13 -------- d-----w- C:\Users\Jay\AppData\Local\{03CC83A0-3F81-478D-B883-246B988C64B3}
2011-12-05 13:16:42 -------- d-----w- C:\Users\Jay\AppData\Local\{71A52DF7-C30D-40D2-BC8B-1BF77C599C7C}
2011-12-05 12:39:16 -------- d-----w- C:\Users\Jay\AppData\Local\{A4F59168-0406-42F6-A9FE-5B6B4ED0FD44}
2011-12-05 00:54:08 -------- d-----w- C:\Users\Jay\AppData\Local\{DEFA752B-9BA5-4840-B187-0FD4A5A0A9AF}
2011-12-05 00:53:45 -------- d-----w- C:\Users\Jay\AppData\Local\{3F20CBE3-DF3B-4F1B-B47F-6CEC6B3FF4E0}
2011-12-04 23:19:33 -------- d-----w- C:\Users\Jay\AppData\Local\{4A781581-3953-46CC-BD3A-B34553E72E43}
2011-12-04 12:54:57 550602 ----a-w- C:\EyeCand3.8bf
2011-12-04 12:54:57 409600 ----a-w- C:\EC3-ENG.8BF
2011-12-04 12:54:57 127184 ----a-w- C:\UNWISE.EXE
2011-12-04 12:54:57 -------- d-----w- C:\Eye Candy 4000
2011-12-03 01:14:24 -------- d-----w- C:\Users\Jay\AppData\Local\{D723E6D9-A93C-418D-8EC4-2DEB29159684}
2011-12-02 22:09:33 453456 ----a-w- C:\Windows\SysWow64\d3dx10_42.dll
2011-12-02 22:09:07 -------- d-----w- C:\Windows\SysWow64\xlive
2011-12-02 22:08:52 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-12-02 21:34:30 -------- d-----w- C:\Users\Jay\AppData\Local\{B379370E-E4DD-4FD0-AE41-9B0253D89069}
2011-12-02 13:19:12 -------- d-----w- C:\Users\Jay\AppData\Local\{DBAE392D-399C-4CBD-BABB-C12A40D7A6C3}
2011-12-02 13:18:50 -------- d-----w- C:\Users\Jay\AppData\Local\{43D8271C-EF6A-454D-8A66-B68862793149}
2011-12-02 00:50:27 -------- d-----w- C:\Users\Jay\AppData\Local\{ACE2BB29-4071-4401-BA1C-44CD5F3BEE5F}
2011-12-02 00:50:05 -------- d-----w- C:\Users\Jay\AppData\Local\{977E8DCD-C539-4D38-88C2-BA95CB3AC396}
2011-12-01 13:10:25 -------- d-----w- C:\Users\Jay\AppData\Local\{8827A7B1-8E29-4592-B211-8562141508EF}
2011-12-01 13:10:03 -------- d-----w- C:\Users\Jay\AppData\Local\{02D4E0E6-83F2-4765-8272-F6016183406B}
2011-12-01 12:29:28 -------- d-----w- C:\Users\Jay\AppData\Local\{972958E5-4987-4FDE-A0E5-2E0EEA2F79B7}
2011-12-01 12:29:05 -------- d-----w- C:\Users\Jay\AppData\Local\{191B1C58-E66D-4F04-ADD7-99F75CFBB24B}
2011-12-01 12:09:02 -------- d-----w- C:\Users\Jay\AppData\Local\{9A19B0A0-E7B4-4E0A-9EDD-5DB908CC43F1}
2011-12-01 12:08:40 -------- d-----w- C:\Users\Jay\AppData\Local\{49EA647C-05B1-4944-A0BC-A8BDE876290C}
2011-11-30 22:35:01 -------- d-----w- C:\Users\Jay\AppData\Local\{7F56C190-E864-4C11-AC71-909F3A28E5DC}
2011-11-30 15:47:14 -------- d-----w- C:\Users\Jay\AppData\Local\{A8DCF430-7A6F-449C-8F7F-5151B063791D}
2011-11-30 12:37:41 -------- d-----w- C:\Users\Jay\AppData\Local\{9D038E7F-AADA-4E4D-BF54-3B05E8DF9561}
2011-11-30 12:00:34 -------- d-----w- C:\Users\Jay\AppData\Local\{47BD8344-F8FE-45DA-8CCA-FAE7B92F55E9}
2011-11-30 03:09:06 -------- d-----w- C:\Users\Jay\AppData\Local\{09FA678E-8BE4-40CE-AFBF-00F7936AAF72}
2011-11-30 03:08:43 -------- d-----w- C:\Users\Jay\AppData\Local\{CB236E7C-15CE-4A44-A84F-32D5BBDADA48}
2011-11-30 02:22:06 -------- d-----w- C:\Users\Jay\AppData\Local\{7A9237FF-0144-4F4E-8110-7C99841CA9BC}
2011-11-30 01:18:39 -------- d-----w- C:\Users\Jay\AppData\Local\{4A681FA2-4251-435E-B16A-54135D547524}
2011-11-30 01:18:17 -------- d-----w- C:\Users\Jay\AppData\Local\{AE4BBC7F-D5A3-4C89-8B5C-8BE5381A3573}
2011-11-29 20:47:14 -------- d-----w- C:\Users\Jay\AppData\Local\{C26AB4DE-3725-4C1E-9D21-3A3B15E307AA}
2011-11-29 20:46:52 -------- d-----w- C:\Users\Jay\AppData\Local\{703EEE66-25E8-4470-B2D6-B89207651180}
.
==================== Find3M ====================
.
2011-11-24 04:52:09 3145216 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 21:28:31 1393736 ----a-w- C:\Users\Jay\gotomypc_626.exe
2011-11-05 05:41:43 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-11-05 05:32:50 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-05 04:35:00 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-11-05 04:26:03 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-11-05 03:32:47 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-11-05 02:48:51 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-10-26 05:21:20 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2011-10-15 06:31:56 723456 ----a-w- C:\Windows\System32\EncDec.dll
2011-10-15 05:38:59 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
.
============= FINISH: 13:34:23.46 ===============

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume3
Install Date: 2/21/2010 1:31:51 PM
System Uptime: 12/29/2011 10:43:36 AM (3 hours ago)
.
Motherboard: Foxconn | | Flaming Blade GTI
Processor: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz | Socket 1366 | 2793/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 596 GiB total, 440.421 GiB free.
D: is FIXED (NTFS) - 298 GiB total, 176.73 GiB free.
E: is FIXED (NTFS) - 298 GiB total, 150.581 GiB free.
F: is FIXED (NTFS) - 931 GiB total, 421.559 GiB free.
G: is CDROM ()
H: is FIXED (NTFS) - 0 GiB total, 0.069 GiB free.
I: is Removable
J: is CDROM ()
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP291: 12/6/2011 2:14:54 AM - Windows Update
RP292: 12/9/2011 8:58:08 AM - Windows Update
RP293: 12/13/2011 10:20:15 AM - Windows Update
RP294: 12/15/2011 3:00:12 AM - Windows Update
RP295: 12/20/2011 6:32:53 AM - Windows Update
RP296: 12/23/2011 9:54:33 AM - Windows Update
RP297: 12/27/2011 12:19:53 PM - Windows Update
RP298: 12/28/2011 12:47:20 PM - Installed HiJackThis
.
==== Installed Programs ======================
.
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 7.0
Adobe Reader 9.4.4
Amazon MP3 Downloader 1.0.12
AMD DnD V1.0.19
AnyDVD
Apple Application Support
Apple Software Update
AQScript_0.7.0.134_installer_0.24
ATI Catalyst Registration
Audacity 1.3.12 (Unicode)
avast! Free Antivirus
Avi to Mpeg 3.2
Avidemux 2.5
AviSynth 2.5
Canon Utilities Easy-PhotoPrint EX
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CinemaNow Media Manager
CloneCD
CloneDVD2
CoffeeCup Flash FireStarter
CoffeeCup Flash Menu Builder
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
D3DX10
DesignPro 5
DirectX 9 Runtime
DVD Decrypter (Remove Only)
DVD Shrink 3.2
EA SPORTS online 2008
Exact Audio Copy 0.95b4
Eye Candy 3
Eye Candy 4000 Demo
FFmpeg for Audacity on Windows
Free RAR Extract Frog
GameSpy Arcade
Halo 2 for Windows Vista
HiJackThis
HPPhotoSmartDiscLabelContent1
HPPhotosmartEssential
Java Auto Updater
Java(TM) 6 Update 24
Junk Mail filter update
K-Lite Codec Pack 6.4.0 (Full)
KompoZer 0.8b3
LAME v3.98.2 for Audacity
Malwarebytes Anti-Malware version 1.60.0.1800
MediaFACE 4.2
MediaFACE II
Microsoft .NET Framework 1.1
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Halo
Microsoft Office 2000 Disc 2
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox (3.6.25)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Octoshape add-in for Adobe Flash Player
Pepakura Viewer 3
Picasa 3
Plants vs. Zombies
QuickBooks Pro 2008
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Burn Manager
Roxio Burn Manager CDB
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Creator 2010
Roxio Creator 2010 Content
Roxio PhotoShow
Roxio Venue
Roxio Video Capture USB
SmartSound Quicktracks Plugin
SupportSoft Assisted Service
Tiger Woods PGA TOUR 08
Visual Site Designer
Vsk5Online
VueScan
Winamp
Winamp Detector Plug-in
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
.
==== Event Viewer Messages From Past Week ========
.
12/29/2011 10:44:50 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Roxio Hard Drive Watcher 12 service to connect.
12/29/2011 10:44:50 AM, Error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the file specified.
12/27/2011 6:36:28 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer SKELETOR that believes that it is the master browser for the domain on transport NetBT_Tcpip_{BC6796CD-B8FA-4415-A10E-E3F02069298C}. The master browser is stopping or an election is being forced.
12/24/2011 11:45:57 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user NewOffice\Jay SID (S-1-5-21-1755860278-3572679465-1347495285-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
.
==== End Of File ===========================
 
Welcome aboard
yahooo.gif


Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running tools or applying updates other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

==============================================================

Did the issue stop after you change the password?

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

===============================================================

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  4. Double click on combofix.exe & follow the prompts.
  5. When finished, it will produce a report for you.
  6. Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.

**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try one of the following:

1. Run Combofix from Safe Mode (How to...)

2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
Do NOT run it yet.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.com
Rkill.scr
Rkill.exe

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
 
Status
Not open for further replies.
Back