Hi. Looks like my laptop has also been infected with the google redirect virus/malware.
I've followed steps 1-6. Here are the results.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7795
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
9/25/2011 9:48:53 AM
mbam-log-2011-09-25 (09-48-53).txt
Scan type: Quick scan
Objects scanned: 175823
Time elapsed: 3 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Gmer had nothing at all (blank log)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Kathy at 10:09:06 on 2011-09-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4086.2680 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Encore\Hoyle Card Games 2011\Ereg\encore_reg.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Windows\OEM02Mon.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\splwow64.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Windows Live ID Sign-in Helper: {5e84400c-0b3f-0cbb-4188-3b3a1a8b6d27} - C:\Windows\SysWOW64\WcsPlugInSService.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [20090604] C:\Program Files (x86)\Encore\Hoyle Card Games 2011\Ereg\encore_reg.exe /r "C:\Program Files (x86)\Encore\Hoyle Card Games 2011\Ereg\encore_reg.rpd"
mRun: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Kathy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
StartupFolder: C:\Users\Kathy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\UTORRE~1.LNK - C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{D233F17A-0A12-4A88-A964-E16D74200EBA} : DhcpNameServer = 192.168.1.254
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
BHO-X64: Windows Live ID Sign-in Helper: {5E84400C-0B3F-0CBB-4188-3B3A1A8B6D27} - C:\Windows\SysWOW64\WcsPlugInSService.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
mRun-x64: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-9-22 366152]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-1 136176]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-1 136176]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
.
=============== Created Last 30 ================
.
2011-09-25 14:04:11 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F5A86BB8-508A-4613-80B2-69321B770DB9}\offreg.dll
2011-09-25 14:04:03 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F5A86BB8-508A-4613-80B2-69321B770DB9}\mpengine.dll
2011-09-25 12:24:53 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Bigfish 3 Days Zoo Mystery
2011-09-25 12:23:03 -------- d-----w- C:\Program Files (x86)\Games
2011-09-25 12:20:49 -------- d-----w- C:\Users\Kathy\AppData\Roaming\GameInvest
2011-09-22 11:14:13 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-22 10:35:23 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Malwarebytes
2011-09-22 10:35:11 -------- d-----w- C:\ProgramData\Malwarebytes
2011-09-22 10:35:07 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-09-20 14:57:50 90112 ----a-w- C:\Windows\SysWow64\lfjbg13n.dll
2011-09-20 14:57:50 73728 ----a-w- C:\Windows\SysWow64\lffax13n.dll
2011-09-20 14:57:50 453120 ----a-w- C:\Windows\SysWow64\ltkrn13n.dll
2011-09-20 14:57:50 445440 ----a-w- C:\Windows\SysWow64\ltimg13n.dll
2011-09-20 14:57:50 388608 ----a-w- C:\Windows\SysWow64\lfcmp13n.dll
2011-09-20 14:57:50 265216 ----a-w- C:\Windows\SysWow64\ltdis13n.dll
2011-09-20 14:57:50 246272 ----a-w- C:\Windows\SysWow64\lfj2k13n.dll
2011-09-20 14:57:50 206848 ----a-w- C:\Windows\SysWow64\ltefx13n.dll
2011-09-20 14:57:50 189976 ----a-w- C:\Windows\SysWow64\mfimgvwr.ocx
2011-09-20 14:57:50 1693696 ----a-w- C:\Windows\SysWow64\ltclr13n.dll
2011-09-20 14:57:50 154112 ----a-w- C:\Windows\SysWow64\ltfil13n.dll
2011-09-20 14:57:50 142848 ----a-w- C:\Windows\SysWow64\lftif13n.dll
2011-09-20 14:56:53 -------- d-----w- C:\Program Files (x86)\MFInstall
2011-09-19 11:08:06 -------- d-----w- C:\Windows\SysWow64\2072
2011-09-16 12:22:58 -------- d-----w- C:\ProgramData\AgentSS
2011-09-16 12:22:35 -------- d--h--w- C:\ProgramData\sacache
2011-09-16 12:18:16 90112 ----a-w- C:\Windows\unvise32.exe
2011-09-16 12:18:16 -------- d-----w- C:\Program Files (x86)\WinConfig
2011-09-16 12:18:06 -------- d-----w- C:\Program Files (x86)\Spytech Software
2011-09-15 23:42:29 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-09-15 23:42:28 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A3326CEA-3CDB-4E29-B5FD-42FF992C6784}\gapaengine.dll
2011-09-15 18:39:43 -------- d-----w- C:\Windows\System32\SPReview
2011-09-15 18:39:07 -------- d-----w- C:\Windows\System32\EventProviders
2011-09-15 17:00:22 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Hoyle FaceCreator
2011-09-15 17:00:17 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Hoyle
2011-09-15 16:58:41 3786760 ----a-w- C:\Windows\SysWow64\D3DX9_37.dll
2011-09-15 16:54:12 -------- d-----w- C:\Program Files (x86)\Encore
2011-09-15 10:41:43 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Special K Software
2011-09-12 14:03:56 -------- d-----w- C:\Windows\PCHEALTH
2011-09-12 14:00:07 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-09-12 13:59:17 -------- d-----w- C:\Users\Kathy\AppData\Local\Microsoft Help
2011-09-10 13:23:01 -------- d-----w- C:\Program Files (x86)\MSECache
2011-09-08 10:32:46 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-09-06 10:51:59 -------- d-----w- C:\Users\Kathy\AppData\Local\Nero_AG
2011-09-06 10:51:34 -------- d-----w- C:\Users\Kathy\AppData\Local\Nero
2011-09-06 10:37:44 -------- d-----w- C:\ProgramData\Nero
2011-09-06 10:36:54 -------- d-----w- C:\Program Files (x86)\Nero
2011-09-06 10:33:26 1974616 ----a-w- C:\Windows\SysWow64\D3DCompiler_42.dll
2011-09-06 10:32:09 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2011-09-06 10:30:48 3727720 ----a-w- C:\Windows\SysWow64\d3dx9_35.dll
2011-09-06 09:37:31 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2011-09-06 09:36:11 3497832 ----a-w- C:\Windows\SysWow64\d3dx9_34.dll
2011-09-05 20:11:54 -------- d-----w- C:\Program Files (x86)\Gold Miner Vegas
2011-09-04 19:39:11 -------- d-----w- C:\Program Files (x86)\MagicDisc
2011-09-04 17:08:53 -------- d-----w- C:\Program Files (x86)\Elaborate Bytes
2011-09-04 16:59:49 255552 ----a-w- C:\Windows\SysWow64\drivers\mcdbus.sys
2011-09-04 16:59:49 255552 ----a-w- C:\Windows\System32\drivers\mcdbus.sys
2011-09-04 11:49:28 -------- d-----w- C:\ProgramData\Big Fish Games
2011-09-04 11:49:24 -------- d-----w- C:\Program Files (x86)\bfgclient
2011-09-02 21:06:16 -------- d-----w- C:\Windows\SysWow64\Wat
2011-09-02 21:06:16 -------- d-----w- C:\Windows\System32\Wat
2011-09-02 16:17:27 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-02 13:14:51 -------- d-----w- C:\Program Files (x86)\SilverCreekCommonFiles
2011-09-02 13:14:50 -------- d-----w- C:\Program Files (x86)\Hardwood Euchre
2011-09-02 11:41:06 161736 ----a-w- C:\Program Files (x86)\64res.dll
2011-09-02 11:36:36 -------- d-----w- C:\Program Files (x86)\TelevisionFanaticEI
2011-09-02 11:29:31 -------- d-----w- C:\Users\Kathy\AppData\Local\DDMSettings
2011-09-02 11:28:09 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-09-02 11:27:37 -------- d-----w- C:\Program Files\DivX
2011-09-02 11:27:22 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2011-09-02 11:25:51 -------- d-----w- C:\Program Files (x86)\DivX
2011-09-02 11:25:17 -------- d-----w- C:\ProgramData\DivX
2011-09-02 11:16:39 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-02 11:10:27 -------- d-----w- C:\Program Files (x86)\RealArcade
2011-09-02 11:08:08 -------- d-----w- C:\Program Files\Babylon
2011-09-02 11:07:47 -------- d-----w- C:\Program Files (x86)\uTorrent Turbo Booster
2011-09-02 11:02:46 -------- d-----w- C:\extensions
2011-09-02 11:02:44 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
2011-09-02 11:02:43 -------- d-----w- C:\Users\Kathy\AppData\Local\Conduit
2011-09-02 11:02:34 -------- d-----w- C:\Program Files (x86)\uTorrent
2011-09-02 11:01:52 -------- d-----w- C:\Users\Kathy\AppData\Roaming\uTorrent
2011-09-02 11:01:52 -------- d-----w- C:\Users\Kathy\AppData\Local\uTorrent
2011-09-02 10:48:23 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2011-09-02 10:48:23 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-09-02 10:48:14 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-09-02 10:48:09 59392 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2011-09-02 10:48:09 12288 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2011-09-02 10:48:08 3715584 ----a-w- C:\Windows\System32\mstscax.dll
2011-09-02 10:48:08 1838080 ----a-w- C:\Windows\System32\d3d10warp.dll
2011-09-02 10:48:07 14967808 ----a-w- C:\Program Files\DVD Maker\OmdBase.dll
2011-09-02 10:48:03 3215872 ----a-w- C:\Windows\SysWow64\mstscax.dll
2011-09-02 10:48:00 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2011-09-02 10:48:00 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2011-09-02 10:48:00 1171456 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2011-09-02 10:46:59 933888 ----a-w- C:\Windows\System32\sqlsrv32.dll
2011-09-02 10:45:59 413696 ----a-w- C:\Windows\SysWow64\PhotoScreensaver.scr
2011-09-02 10:44:59 9728 ----a-w- C:\Windows\System32\spwmp.dll
2011-09-02 10:42:24 244736 ----a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2011-09-02 10:42:23 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-09-02 10:42:15 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2011-09-01 22:35:24 -------- d-----w- C:\Users\Kathy\My eBooks
2011-09-01 22:16:57 -------- d-----w- C:\Users\Kathy\AppData\Local\Microsoft Games
2011-09-01 15:57:30 -------- d-----w- C:\Windows\Panther
2011-09-01 15:33:55 780224 ----a-w- C:\ci.dll
2011-09-01 15:02:20 258048 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\hpfppw73.dll
2011-09-01 14:54:17 -------- d-----w- C:\Users\Kathy\AppData\Local\Adobe
2011-09-01 14:53:50 -------- d-----w- C:\Users\Kathy\AppData\Local\Google
2011-09-01 14:29:32 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-09-01 14:29:16 -------- d-sh--w- C:\Windows\Installer
2011-09-01 14:29:15 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-09-01 13:17:52 -------- d-----w- C:\Program Files\Protector Suite
2011-09-01 12:52:37 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-09-01 12:47:36 8862544 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1C608BEE-06BF-467A-9EDB-437EC6262C71}\mpengine.dll
2011-09-01 12:44:18 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-09-01 12:44:18 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-09-01 12:44:11 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-09-01 12:44:11 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-09-01 12:44:00 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-09-01 12:44:00 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-09-01 12:42:48 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-09-01 12:41:19 974336 ----a-w- C:\Windows\System32\WFS.exe
2011-09-01 12:41:19 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-09-01 12:37:09 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-09-01 12:36:57 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-09-01 12:36:55 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-09-01 12:36:55 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-09-01 12:21:58 1002008 ----a-w- C:\Windows\SysWow64\igxpun.exe
2011-09-01 12:21:58 -------- d-----w- C:\Windows\SysWow64\x64
.
==================== Find3M ====================
.
2011-09-15 18:49:56 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-09-15 18:49:55 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-07-22 20:51:50 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 05:26:20 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-07-09 04:29:46 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
.
============= FINISH: 10:09:23.97 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 9/1/2011 8:18:12 AM
System Uptime: 9/25/2011 5:23:44 AM (5 hours ago)
.
Motherboard: Dell Inc. | | 0N6705
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz | Microprocessor | 2000/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 298 GiB total, 222.534 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Base System Device
Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_02091028&REV_12\4&2C68880C&0&0BF0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_02091028&REV_12\4&2C68880C&0&0BF0
Service:
.
==== System Restore Points ===================
.
RP46: 9/15/2011 2:39:34 PM - Windows 7 Service Pack 1
RP47: 9/15/2011 5:51:00 PM - Windows Update
RP48: 9/15/2011 7:41:51 PM - Windows Update
RP49: 9/17/2011 7:32:09 AM - Windows Update
RP50: 9/20/2011 11:51:43 AM - Installed Adobe Acrobat X Pro - English, Français, Deutsch.
RP51: 9/20/2011 3:58:37 PM - Windows Update
RP52: 9/24/2011 9:08:31 AM - Windows Update
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
3 Days - Zoo Mystery 1.00
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader X (10.1.1)
Big Fish Games: Game Manager
Google Toolbar for Internet Explorer
Google Update Helper
Hardwood Euchre
High-Definition Video Playback 10
Hoyle Card Games 2011 (remove only)
MagicDisc 2.7.106
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Excel Viewer
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Primary Interoperability Assemblies 2005
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 10 Menu TemplatePack Basic
Nero 10 Movie ThemePack Basic
Nero BackItUp 10
Nero BackItUp 10 Help (CHM)
Nero Burning ROM 10
Nero BurningROM 10 Help (CHM)
Nero BurnRights 10
Nero BurnRights 10 Help (CHM)
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero CoverDesigner 10
Nero CoverDesigner 10 Help (CHM)
Nero DiscSpeed 10
Nero DiscSpeed 10 Help (CHM)
Nero Dolby Files 10
Nero Express 10
Nero Express 10 Help (CHM)
Nero InfoTool 10
Nero InfoTool 10 Help (CHM)
Nero MediaHub 10
Nero MediaHub 10 Help (CHM)
Nero Multimedia Suite 10
Nero Recode 10
Nero Recode 10 Help (CHM)
Nero RescueAgent 10
Nero RescueAgent 10 Help (CHM)
Nero SoundTrax 10
Nero SoundTrax 10 Help (CHM)
Nero StartSmart 10
Nero StartSmart 10 Help (CHM)
Nero Update
Nero Vision 10
Nero Vision 10 Help (CHM)
Nero WaveEditor 10
Nero WaveEditor 10 Help (CHM)
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Spytech SpyAgent
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2553110)
uTorrent Turbo Booster
VC80CRTRedist - 8.0.50727.6195
.
==== Event Viewer Messages From Past Week ========
.
9/25/2011 5:25:01 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/25/2011 5:24:03 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/24/2011 8:58:26 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/24/2011 1:54:46 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/23/2011 5:18:09 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 7:20:56 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 7:12:30 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:59:48 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:53:04 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:41:47 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:16:42 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 4:35:38 PM, Error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 3 time(s).
9/22/2011 3:54:28 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
9/22/2011 3:12:17 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
9/21/2011 5:45:35 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/21/2011 3:31:04 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 8:16:49 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 3:48:12 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 3:46:39 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 11:47:58 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Kathy-laptop\Kathy SID (S-1-5-21-729279385-1639433662-237037186-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/20/2011 11:47:58 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {B77C4C36-0154-4C52-AB49-FAA03837E47F} and APPID {EA022610-0748-4C24-B229-6C507EBDFDBB} to the user Kathy-laptop\Kathy SID (S-1-5-21-729279385-1639433662-237037186-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/20/2011 11:47:58 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Kathy-laptop\Kathy SID (S-1-5-21-729279385-1639433662-237037186-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/18/2011 8:40:41 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/18/2011 7:24:43 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/18/2011 4:47:42 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
.
==== End Of File ===========================
Please help. Thank you
I've followed steps 1-6. Here are the results.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7795
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
9/25/2011 9:48:53 AM
mbam-log-2011-09-25 (09-48-53).txt
Scan type: Quick scan
Objects scanned: 175823
Time elapsed: 3 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Gmer had nothing at all (blank log)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Kathy at 10:09:06 on 2011-09-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4086.2680 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\taskhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\Explorer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Encore\Hoyle Card Games 2011\Ereg\encore_reg.exe
C:\Program Files (x86)\MagicDisc\MagicDisc.exe
C:\Windows\OEM02Mon.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\splwow64.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Windows Live ID Sign-in Helper: {5e84400c-0b3f-0cbb-4188-3b3a1a8b6d27} - C:\Windows\SysWOW64\WcsPlugInSService.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [20090604] C:\Program Files (x86)\Encore\Hoyle Card Games 2011\Ereg\encore_reg.exe /r "C:\Program Files (x86)\Encore\Hoyle Card Games 2011\Ereg\encore_reg.rpd"
mRun: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Kathy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
StartupFolder: C:\Users\Kathy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\UTORRE~1.LNK - C:\Program Files (x86)\uTorrent Turbo Booster\uTorrent Turbo Booster.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{D233F17A-0A12-4A88-A964-E16D74200EBA} : DhcpNameServer = 192.168.1.254
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
BHO-X64: Windows Live ID Sign-in Helper: {5E84400C-0B3F-0CBB-4188-3B3A1A8B6D27} - C:\Windows\SysWOW64\WcsPlugInSService.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
mRun-x64: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [NBAgent] "C:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-9-22 366152]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-3-25 490280]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-1 136176]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-9-1 136176]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
.
=============== Created Last 30 ================
.
2011-09-25 14:04:11 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F5A86BB8-508A-4613-80B2-69321B770DB9}\offreg.dll
2011-09-25 14:04:03 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F5A86BB8-508A-4613-80B2-69321B770DB9}\mpengine.dll
2011-09-25 12:24:53 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Bigfish 3 Days Zoo Mystery
2011-09-25 12:23:03 -------- d-----w- C:\Program Files (x86)\Games
2011-09-25 12:20:49 -------- d-----w- C:\Users\Kathy\AppData\Roaming\GameInvest
2011-09-22 11:14:13 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-22 10:35:23 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Malwarebytes
2011-09-22 10:35:11 -------- d-----w- C:\ProgramData\Malwarebytes
2011-09-22 10:35:07 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-09-20 14:57:50 90112 ----a-w- C:\Windows\SysWow64\lfjbg13n.dll
2011-09-20 14:57:50 73728 ----a-w- C:\Windows\SysWow64\lffax13n.dll
2011-09-20 14:57:50 453120 ----a-w- C:\Windows\SysWow64\ltkrn13n.dll
2011-09-20 14:57:50 445440 ----a-w- C:\Windows\SysWow64\ltimg13n.dll
2011-09-20 14:57:50 388608 ----a-w- C:\Windows\SysWow64\lfcmp13n.dll
2011-09-20 14:57:50 265216 ----a-w- C:\Windows\SysWow64\ltdis13n.dll
2011-09-20 14:57:50 246272 ----a-w- C:\Windows\SysWow64\lfj2k13n.dll
2011-09-20 14:57:50 206848 ----a-w- C:\Windows\SysWow64\ltefx13n.dll
2011-09-20 14:57:50 189976 ----a-w- C:\Windows\SysWow64\mfimgvwr.ocx
2011-09-20 14:57:50 1693696 ----a-w- C:\Windows\SysWow64\ltclr13n.dll
2011-09-20 14:57:50 154112 ----a-w- C:\Windows\SysWow64\ltfil13n.dll
2011-09-20 14:57:50 142848 ----a-w- C:\Windows\SysWow64\lftif13n.dll
2011-09-20 14:56:53 -------- d-----w- C:\Program Files (x86)\MFInstall
2011-09-19 11:08:06 -------- d-----w- C:\Windows\SysWow64\2072
2011-09-16 12:22:58 -------- d-----w- C:\ProgramData\AgentSS
2011-09-16 12:22:35 -------- d--h--w- C:\ProgramData\sacache
2011-09-16 12:18:16 90112 ----a-w- C:\Windows\unvise32.exe
2011-09-16 12:18:16 -------- d-----w- C:\Program Files (x86)\WinConfig
2011-09-16 12:18:06 -------- d-----w- C:\Program Files (x86)\Spytech Software
2011-09-15 23:42:29 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-09-15 23:42:28 601424 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A3326CEA-3CDB-4E29-B5FD-42FF992C6784}\gapaengine.dll
2011-09-15 18:39:43 -------- d-----w- C:\Windows\System32\SPReview
2011-09-15 18:39:07 -------- d-----w- C:\Windows\System32\EventProviders
2011-09-15 17:00:22 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Hoyle FaceCreator
2011-09-15 17:00:17 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Hoyle
2011-09-15 16:58:41 3786760 ----a-w- C:\Windows\SysWow64\D3DX9_37.dll
2011-09-15 16:54:12 -------- d-----w- C:\Program Files (x86)\Encore
2011-09-15 10:41:43 -------- d-----w- C:\Users\Kathy\AppData\Roaming\Special K Software
2011-09-12 14:03:56 -------- d-----w- C:\Windows\PCHEALTH
2011-09-12 14:00:07 -------- d-----w- C:\Program Files (x86)\Microsoft Visual Studio 8
2011-09-12 13:59:17 -------- d-----w- C:\Users\Kathy\AppData\Local\Microsoft Help
2011-09-10 13:23:01 -------- d-----w- C:\Program Files (x86)\MSECache
2011-09-08 10:32:46 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-09-06 10:51:59 -------- d-----w- C:\Users\Kathy\AppData\Local\Nero_AG
2011-09-06 10:51:34 -------- d-----w- C:\Users\Kathy\AppData\Local\Nero
2011-09-06 10:37:44 -------- d-----w- C:\ProgramData\Nero
2011-09-06 10:36:54 -------- d-----w- C:\Program Files (x86)\Nero
2011-09-06 10:33:26 1974616 ----a-w- C:\Windows\SysWow64\D3DCompiler_42.dll
2011-09-06 10:32:09 1892184 ----a-w- C:\Windows\SysWow64\D3DX9_42.dll
2011-09-06 10:30:48 3727720 ----a-w- C:\Windows\SysWow64\d3dx9_35.dll
2011-09-06 09:37:31 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2011-09-06 09:36:11 3497832 ----a-w- C:\Windows\SysWow64\d3dx9_34.dll
2011-09-05 20:11:54 -------- d-----w- C:\Program Files (x86)\Gold Miner Vegas
2011-09-04 19:39:11 -------- d-----w- C:\Program Files (x86)\MagicDisc
2011-09-04 17:08:53 -------- d-----w- C:\Program Files (x86)\Elaborate Bytes
2011-09-04 16:59:49 255552 ----a-w- C:\Windows\SysWow64\drivers\mcdbus.sys
2011-09-04 16:59:49 255552 ----a-w- C:\Windows\System32\drivers\mcdbus.sys
2011-09-04 11:49:28 -------- d-----w- C:\ProgramData\Big Fish Games
2011-09-04 11:49:24 -------- d-----w- C:\Program Files (x86)\bfgclient
2011-09-02 21:06:16 -------- d-----w- C:\Windows\SysWow64\Wat
2011-09-02 21:06:16 -------- d-----w- C:\Windows\System32\Wat
2011-09-02 16:17:27 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-02 13:14:51 -------- d-----w- C:\Program Files (x86)\SilverCreekCommonFiles
2011-09-02 13:14:50 -------- d-----w- C:\Program Files (x86)\Hardwood Euchre
2011-09-02 11:41:06 161736 ----a-w- C:\Program Files (x86)\64res.dll
2011-09-02 11:36:36 -------- d-----w- C:\Program Files (x86)\TelevisionFanaticEI
2011-09-02 11:29:31 -------- d-----w- C:\Users\Kathy\AppData\Local\DDMSettings
2011-09-02 11:28:09 -------- d-----w- C:\Program Files (x86)\Common Files\PX Storage Engine
2011-09-02 11:27:37 -------- d-----w- C:\Program Files\DivX
2011-09-02 11:27:22 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared
2011-09-02 11:25:51 -------- d-----w- C:\Program Files (x86)\DivX
2011-09-02 11:25:17 -------- d-----w- C:\ProgramData\DivX
2011-09-02 11:16:39 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-02 11:10:27 -------- d-----w- C:\Program Files (x86)\RealArcade
2011-09-02 11:08:08 -------- d-----w- C:\Program Files\Babylon
2011-09-02 11:07:47 -------- d-----w- C:\Program Files (x86)\uTorrent Turbo Booster
2011-09-02 11:02:46 -------- d-----w- C:\extensions
2011-09-02 11:02:44 0 ----a-w- C:\Windows\SysWow64\ConduitEngine.tmp
2011-09-02 11:02:43 -------- d-----w- C:\Users\Kathy\AppData\Local\Conduit
2011-09-02 11:02:34 -------- d-----w- C:\Program Files (x86)\uTorrent
2011-09-02 11:01:52 -------- d-----w- C:\Users\Kathy\AppData\Roaming\uTorrent
2011-09-02 11:01:52 -------- d-----w- C:\Users\Kathy\AppData\Local\uTorrent
2011-09-02 10:48:23 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2011-09-02 10:48:23 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2011-09-02 10:48:14 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2011-09-02 10:48:09 59392 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
2011-09-02 10:48:09 12288 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2011-09-02 10:48:08 3715584 ----a-w- C:\Windows\System32\mstscax.dll
2011-09-02 10:48:08 1838080 ----a-w- C:\Windows\System32\d3d10warp.dll
2011-09-02 10:48:07 14967808 ----a-w- C:\Program Files\DVD Maker\OmdBase.dll
2011-09-02 10:48:03 3215872 ----a-w- C:\Windows\SysWow64\mstscax.dll
2011-09-02 10:48:00 954752 ----a-w- C:\Windows\SysWow64\mfc40.dll
2011-09-02 10:48:00 954288 ----a-w- C:\Windows\SysWow64\mfc40u.dll
2011-09-02 10:48:00 1171456 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2011-09-02 10:46:59 933888 ----a-w- C:\Windows\System32\sqlsrv32.dll
2011-09-02 10:45:59 413696 ----a-w- C:\Windows\SysWow64\PhotoScreensaver.scr
2011-09-02 10:44:59 9728 ----a-w- C:\Windows\System32\spwmp.dll
2011-09-02 10:42:24 244736 ----a-w- C:\Program Files\Windows Portable Devices\sqmapi.dll
2011-09-02 10:42:23 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2011-09-02 10:42:15 244736 ----a-w- C:\Windows\System32\sqmapi.dll
2011-09-01 22:35:24 -------- d-----w- C:\Users\Kathy\My eBooks
2011-09-01 22:16:57 -------- d-----w- C:\Users\Kathy\AppData\Local\Microsoft Games
2011-09-01 15:57:30 -------- d-----w- C:\Windows\Panther
2011-09-01 15:33:55 780224 ----a-w- C:\ci.dll
2011-09-01 15:02:20 258048 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\hpfppw73.dll
2011-09-01 14:54:17 -------- d-----w- C:\Users\Kathy\AppData\Local\Adobe
2011-09-01 14:53:50 -------- d-----w- C:\Users\Kathy\AppData\Local\Google
2011-09-01 14:29:32 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2011-09-01 14:29:16 -------- d-sh--w- C:\Windows\Installer
2011-09-01 14:29:15 -------- d-----w- C:\Program Files\Microsoft Security Client
2011-09-01 13:17:52 -------- d-----w- C:\Program Files\Protector Suite
2011-09-01 12:52:37 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-09-01 12:47:36 8862544 ------w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1C608BEE-06BF-467A-9EDB-437EC6262C71}\mpengine.dll
2011-09-01 12:44:18 31232 ----a-w- C:\Windows\SysWow64\prevhost.exe
2011-09-01 12:44:18 31232 ----a-w- C:\Windows\System32\prevhost.exe
2011-09-01 12:44:11 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-09-01 12:44:11 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-09-01 12:44:00 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-09-01 12:44:00 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-09-01 12:42:48 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-09-01 12:41:19 974336 ----a-w- C:\Windows\System32\WFS.exe
2011-09-01 12:41:19 267776 ----a-w- C:\Windows\System32\FXSCOVER.exe
2011-09-01 12:37:09 90624 ----a-w- C:\Windows\System32\drivers\bowser.sys
2011-09-01 12:36:57 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-09-01 12:36:55 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-09-01 12:36:55 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-09-01 12:21:58 1002008 ----a-w- C:\Windows\SysWow64\igxpun.exe
2011-09-01 12:21:58 -------- d-----w- C:\Windows\SysWow64\x64
.
==================== Find3M ====================
.
2011-09-15 18:49:56 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2011-09-15 18:49:55 175616 ----a-w- C:\Windows\System32\msclmd.dll
2011-07-22 20:51:50 94208 ----a-w- C:\Windows\SysWow64\dpl100.dll
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 05:26:20 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-07-09 04:29:46 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
.
============= FINISH: 10:09:23.97 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 9/1/2011 8:18:12 AM
System Uptime: 9/25/2011 5:23:44 AM (5 hours ago)
.
Motherboard: Dell Inc. | | 0N6705
Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz | Microprocessor | 2000/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 298 GiB total, 222.534 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Base System Device
Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_02091028&REV_12\4&2C68880C&0&0BF0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_02091028&REV_12\4&2C68880C&0&0BF0
Service:
.
==== System Restore Points ===================
.
RP46: 9/15/2011 2:39:34 PM - Windows 7 Service Pack 1
RP47: 9/15/2011 5:51:00 PM - Windows Update
RP48: 9/15/2011 7:41:51 PM - Windows Update
RP49: 9/17/2011 7:32:09 AM - Windows Update
RP50: 9/20/2011 11:51:43 AM - Installed Adobe Acrobat X Pro - English, Français, Deutsch.
RP51: 9/20/2011 3:58:37 PM - Windows Update
RP52: 9/24/2011 9:08:31 AM - Windows Update
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
3 Days - Zoo Mystery 1.00
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader X (10.1.1)
Big Fish Games: Game Manager
Google Toolbar for Internet Explorer
Google Update Helper
Hardwood Euchre
High-Definition Video Playback 10
Hoyle Card Games 2011 (remove only)
MagicDisc 2.7.106
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Excel Viewer
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Primary Interoperability Assemblies 2005
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 10 Menu TemplatePack Basic
Nero 10 Movie ThemePack Basic
Nero BackItUp 10
Nero BackItUp 10 Help (CHM)
Nero Burning ROM 10
Nero BurningROM 10 Help (CHM)
Nero BurnRights 10
Nero BurnRights 10 Help (CHM)
Nero Control Center 10
Nero ControlCenter 10 Help (CHM)
Nero Core Components 10
Nero CoverDesigner 10
Nero CoverDesigner 10 Help (CHM)
Nero DiscSpeed 10
Nero DiscSpeed 10 Help (CHM)
Nero Dolby Files 10
Nero Express 10
Nero Express 10 Help (CHM)
Nero InfoTool 10
Nero InfoTool 10 Help (CHM)
Nero MediaHub 10
Nero MediaHub 10 Help (CHM)
Nero Multimedia Suite 10
Nero Recode 10
Nero Recode 10 Help (CHM)
Nero RescueAgent 10
Nero RescueAgent 10 Help (CHM)
Nero SoundTrax 10
Nero SoundTrax 10 Help (CHM)
Nero StartSmart 10
Nero StartSmart 10 Help (CHM)
Nero Update
Nero Vision 10
Nero Vision 10 Help (CHM)
Nero WaveEditor 10
Nero WaveEditor 10 Help (CHM)
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Spytech SpyAgent
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2553110)
uTorrent Turbo Booster
VC80CRTRedist - 8.0.50727.6195
.
==== Event Viewer Messages From Past Week ========
.
9/25/2011 5:25:01 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/25/2011 5:24:03 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/24/2011 8:58:26 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/24/2011 1:54:46 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/23/2011 5:18:09 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 7:20:56 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 7:12:30 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:59:48 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:53:04 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:41:47 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 6:16:42 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/22/2011 4:35:38 PM, Error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 3 time(s).
9/22/2011 3:54:28 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
9/22/2011 3:12:17 PM, Error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
9/21/2011 5:45:35 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/21/2011 3:31:04 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 8:16:49 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 3:48:12 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 3:46:39 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/20/2011 11:47:58 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Kathy-laptop\Kathy SID (S-1-5-21-729279385-1639433662-237037186-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/20/2011 11:47:58 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {B77C4C36-0154-4C52-AB49-FAA03837E47F} and APPID {EA022610-0748-4C24-B229-6C507EBDFDBB} to the user Kathy-laptop\Kathy SID (S-1-5-21-729279385-1639433662-237037186-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/20/2011 11:47:58 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Kathy-laptop\Kathy SID (S-1-5-21-729279385-1639433662-237037186-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
9/18/2011 8:40:41 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/18/2011 7:24:43 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
9/18/2011 4:47:42 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: Behavior Monitoring Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver requires an up-to-date engine in order to function. You must install the latest definition updates in order to enable real-time protection.
.
==== End Of File ===========================
Please help. Thank you