I am running windows 7 x64. I foolishly downloaded a codec pack that was infected and now Im paying the price. Im getting redirects in firefox when I visit websites. I followed all the instructions and my logs are as follows.
Malwarebytes Anti-Malware (Trial) 1.65.0.1400
www.malwarebytes.org
Database version: v2012.10.14.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Babydoll :: BABYDOLL-PC [administrator]
Protection: Enabled
10/14/2012 1:05:57 PM
mbam-log-2012-10-14 (13-05-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206756
Time elapsed: 6 minute(s), 22 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 4
C:\Users\Babydoll\Downloads\coretemp_1236.exe (PUP.BundleOffers.IIQ) -> No action taken.
C:\Windows\Installer\{04cfe51a-6306-2045-1172-609246c62773}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{04cfe51a-6306-2045-1172-609246c62773}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{04cfe51a-6306-2045-1172-609246c62773}\U\80000000.@ (Rootkit.0Access.64) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-10-14 14:16:42
Windows 6.1.7601 Service Pack 1
Running: tdod0y70.exe
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Babydoll\AppData\Local\Logitech\xae Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe 1
---- EOF - GMER 1.0.15 ----
DDS (Ver_2012-10-14.05) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by Babydoll at 14:18:45 on 2012-10-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.5717 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Babydoll\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\ASUS\AI Suite\QFan4\FanHelp.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\Babydoll\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Users\Babydoll\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\AVG\AVG2012\avgcfgex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/?l=dis&o=APN10635&gct=hp
mWinlogon: Userinit = userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
uRun: [Google Update] "C:\Users\Babydoll\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
uRun: [Spotify Web Helper] "C:\Users\Babydoll\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [QFan Help] "C:\Program Files (x86)\ASUS\AI Suite\QFan4\FanHelp.exe"
mRun: [Cpu Level Up help] "C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction
mRun: [ContentTransferWMDetector.exe] C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ROC_ROC_JULY_P1] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Babydoll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: mswsock.dll
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{46D2BCDE-7C84-4F6F-9848-39AF9E896812} : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp
x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Babydoll\AppData\Roaming\Mozilla\Firefox\Profiles\6qdbqp86.default\
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7Bfeec4952-16d5-4827-9c1f-f9b426e47249%7D&mid=e4232c8089aa47d087916de78371ad09-b787440fbb17ee6c270c9e1b2f7e6e39c4a510ec&ds=AVG&v=12.2.5.32&lang=en&pr=fr&d=2012-05-06%2012%3A23%3A23&sap=ku&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Babydoll\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-08-30 14:29; avg@toolbar; C:\ProgramData\AVG Secure Search\12.2.5.32
FF - ExtSQL: 2012-09-11 08:45; {1E73965B-8B48-48be-9C8D-68B920ABC1C4}; C:\Program Files (x86)\AVG\AVG2012\Firefox4
FF - ExtSQL: 2012-10-03 09:41; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Babydoll\AppData\Roaming\Mozilla\Firefox\Profiles\6qdbqp86.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-7-26 291680]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-8-24 384352]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-8-30 31080]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-7-27 239616]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2012-5-8 96896]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-8-13 5167736]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-14 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-14 676936]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\System32\ViakaraokeSrv.exe [2011-3-29 27760]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-8-30 722528]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2012-5-6 46136]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2012-7-28 10278912]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2012-7-27 368640]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-5-14 96896]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2011-12-23 124496]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2011-9-2 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2011-9-2 15128]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-14 25928]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2011-3-29 2157680]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-7 250808]
S3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-5-6 245760]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-1-18 351136]
S3 LVUVC64;Logitech HD Webcam C270(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-18 4865568]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-9-29 114144]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-5-5 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-5-7 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-5-6 1255736]
.
=============== Created Last 30 ================
.
2012-10-14 17:18:0469000----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9624E30A-CAD6-495B-B230-65FA31120BD7}\offreg.dll
2012-10-14 17:01:56--------d-----w-C:\Users\Babydoll\AppData\Roaming\Malwarebytes
2012-10-14 17:01:4725928----a-w-C:\Windows\System32\drivers\mbam.sys
2012-10-14 17:01:47--------d-----w-C:\ProgramData\Malwarebytes
2012-10-14 17:01:47--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-10-14 16:43:308917360----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-10-14 16:43:279308616----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9624E30A-CAD6-495B-B230-65FA31120BD7}\mpengine.dll
2012-10-14 16:26:58--------d-----w-C:\TDSSKiller_Quarantine
2012-10-14 14:10:27--------d-----w-C:\Windows\SysWow64\QuickTime
2012-10-14 14:03:49--------d-sh--w-C:\Windows\SysWow64\%APPDATA%
2012-10-14 13:55:33--------d-----w-C:\Program Files (x86)\Mega Codec Pack
2012-10-10 17:42:14424448------w-C:\Windows\System32\KernelBase.dll
2012-10-10 17:42:13215040------w-C:\Windows\System32\winsrv.dll
2012-10-10 17:42:12274944------w-C:\Windows\SysWow64\KernelBase.dll
2012-10-10 17:42:11243200------w-C:\Windows\System32\wow64.dll
2012-10-10 17:42:10362496------w-C:\Windows\System32\wow64win.dll
2012-10-10 17:42:1013312------w-C:\Windows\System32\wow64cpu.dll
2012-10-10 17:41:56220160------w-C:\Windows\System32\wintrust.dll
2012-10-10 17:41:56172544------w-C:\Windows\SysWow64\wintrust.dll
2012-10-10 17:41:46715776------w-C:\Windows\System32\kerberos.dll
2012-10-10 17:41:431464320------w-C:\Windows\System32\crypt32.dll
2012-10-10 17:41:42140288------w-C:\Windows\System32\cryptnet.dll
2012-10-10 17:41:421159680------w-C:\Windows\SysWow64\crypt32.dll
2012-10-08 16:04:26--------d-----w-C:\Program Files (x86)\Coupons
2012-10-03 15:21:16359424----a-w-C:\Windows\System32\CmiInstallResAll64.dll
2012-10-03 15:21:151310720----a-w-C:\Windows\System32\drivers\CM10864.sys
2012-10-02 15:42:45--------d-----w-C:\Users\Babydoll\AppData\Local\MFAData
2012-10-02 15:42:45--------d-----w-C:\Users\Babydoll\AppData\Local\Avg2013
2012-10-01 16:30:18--------d-----w-C:\Users\Babydoll\AppData\Local\Macromedia
2012-09-30 16:04:12--------d-----r-C:\Users\Babydoll\AppData\Roaming\Brother
2012-09-30 02:22:34--------d-----w-C:\Users\Babydoll\AppData\Local\Mozilla
2012-09-30 02:22:29--------d-----w-C:\Program Files (x86)\Mozilla Maintenance Service
2012-09-27 13:47:01245760----a-w-C:\Windows\System32\OxpsConverter.exe
2012-09-21 17:51:37--------d-----w-C:\ProgramData\NVIDIA Corporation
2012-09-21 17:51:34--------d-----w-C:\Program Files\NVIDIA Corporation
2012-09-19 19:57:2733240----a-w-C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-09-19 19:56:02--------d-----w-C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-09-19 19:56:02--------d-----w-C:\Program Files\iTunes
2012-09-19 19:56:02--------d-----w-C:\Program Files\iPod
2012-09-19 19:56:02--------d-----w-C:\Program Files (x86)\iTunes
2012-09-19 17:55:51--------d-----w-C:\Program Files (x86)\Seagate
2012-09-19 17:35:07--------d-----w-C:\ProgramData\Hi-Rez Studios
2012-09-19 17:35:02--------d-----w-C:\Program Files (x86)\Hi-Rez Studios
2012-09-17 14:13:26--------d--h--r-C:\AHCache
.
==================== Find3M ====================
.
2012-10-14 17:07:1373656----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-14 17:07:13696760----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2012-09-22 17:48:1018960----a-w-C:\Windows\System32\drivers\LNonPnP.sys
2012-09-09 16:27:21255352----a-w-C:\Windows\SysWow64\awrdscdc.ax
2012-09-02 19:43:5595208----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-02 19:43:54821736----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2012-09-02 19:43:54746984----a-w-C:\Windows\SysWow64\deployJava1.dll
2012-08-30 18:29:1731080----a-w-C:\Windows\System32\drivers\avgtpx64.sys
2012-08-24 19:43:16384352----a-w-C:\Windows\System32\drivers\avgtdia.sys
2012-08-24 10:31:322312704----a-w-C:\Windows\System32\jscript9.dll
2012-08-24 10:21:181392128----a-w-C:\Windows\System32\wininet.dll
2012-08-24 10:20:111494528----a-w-C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45173056----a-w-C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29599040----a-w-C:\Windows\System32\vbscript.dll
2012-08-24 10:09:422382848----a-w-C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:171800704----a-w-C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:271129472----a-w-C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:021427968----a-w-C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26142848----a-w-C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12420864----a-w-C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:582382848----a-w-C:\Windows\SysWow64\mshtml.tlb
2012-08-22 18:12:501913200----a-w-C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40950128----a-w-C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40376688----a-w-C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33288624----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 17:01:20125872----a-w-C:\Windows\System32\GEARAspi64.dll
2012-08-21 17:01:20106928----a-w-C:\Windows\SysWow64\GEARAspi.dll
2012-08-10 15:23:11152576----a-w-C:\Windows\SysWow64\msclmd.dll
2012-08-10 15:23:10175616----a-w-C:\Windows\System32\msclmd.dll
2012-08-02 17:58:52574464----a-w-C:\Windows\System32\d3d10level9.dll
2012-08-02 16:57:20490496----a-w-C:\Windows\SysWow64\d3d10level9.dll
2012-07-28 04:09:205538984----a-w-C:\Windows\SysWow64\atiumdag.dll
2012-07-28 04:07:4410278912----a-w-C:\Windows\System32\drivers\atikmdag.sys
2012-07-28 03:43:1270144----a-w-C:\Windows\System32\coinst_8.982.dll
2012-07-28 03:19:3424935424----a-w-C:\Windows\System32\atio6axx.dll
2012-07-28 02:50:1020546560----a-w-C:\Windows\SysWow64\atioglxx.dll
2012-07-28 02:47:40187392----a-w-C:\Windows\System32\clinfo.exe
2012-07-28 02:47:2475776----a-w-C:\Windows\System32\OpenVideo64.dll
2012-07-28 02:47:1665024----a-w-C:\Windows\SysWow64\OpenVideo.dll
2012-07-28 02:47:1063488----a-w-C:\Windows\System32\OVDecode64.dll
2012-07-28 02:47:0656320----a-w-C:\Windows\SysWow64\OVDecode.dll
2012-07-28 02:46:5616464896----a-w-C:\Windows\System32\amdocl64.dll
2012-07-28 02:46:0613013504----a-w-C:\Windows\SysWow64\amdocl.dll
2012-07-28 02:15:50163840----a-w-C:\Windows\System32\atiapfxx.exe
2012-07-28 02:15:42931328----a-w-C:\Windows\SysWow64\aticfx32.dll
2012-07-28 02:13:561100288----a-w-C:\Windows\System32\aticfx64.dll
2012-07-28 02:10:40442368----a-w-C:\Windows\System32\ATIDEMGX.dll
2012-07-28 02:10:34534528----a-w-C:\Windows\System32\atieclxx.exe
2012-07-28 02:09:44239616----a-w-C:\Windows\System32\atiesrxx.exe
2012-07-28 02:08:20120320----a-w-C:\Windows\System32\atitmm64.dll
2012-07-28 02:08:0421504----a-w-C:\Windows\System32\atimuixx.dll
2012-07-28 02:07:5859392----a-w-C:\Windows\System32\atiedu64.dll
2012-07-28 02:07:5243520----a-w-C:\Windows\SysWow64\ati2edxx.dll
2012-07-28 02:07:106430208----a-w-C:\Windows\SysWow64\atidxx32.dll
2012-07-28 01:51:127052288----a-w-C:\Windows\System32\atidxx64.dll
2012-07-28 01:41:324266496----a-w-C:\Windows\System32\atiumd6a.dll
2012-07-28 01:35:1051200----a-w-C:\Windows\System32\aticalrt64.dll
2012-07-28 01:35:0846080----a-w-C:\Windows\SysWow64\aticalrt.dll
2012-07-28 01:35:0244544----a-w-C:\Windows\System32\aticalcl64.dll
2012-07-28 01:35:0044032----a-w-C:\Windows\SysWow64\aticalcl.dll
2012-07-28 01:34:4816034304----a-w-C:\Windows\System32\aticaldd64.dll
2012-07-28 01:32:324751872----a-w-C:\Windows\SysWow64\atiumdva.dll
2012-07-28 01:30:1013605888----a-w-C:\Windows\SysWow64\aticaldd.dll
2012-07-28 01:25:526676480----a-w-C:\Windows\System32\atiumd64.dll
2012-07-28 01:15:32540160----a-w-C:\Windows\System32\atiadlxx.dll
2012-07-28 01:15:22368640----a-w-C:\Windows\SysWow64\atiadlxy.dll
2012-07-28 01:15:1217920----a-w-C:\Windows\System32\atig6pxx.dll
2012-07-28 01:15:0814848----a-w-C:\Windows\SysWow64\atiglpxx.dll
2012-07-28 01:15:0814848----a-w-C:\Windows\System32\atiglpxx.dll
2012-07-28 01:15:0441984----a-w-C:\Windows\System32\atig6txx.dll
2012-07-28 01:14:5633280----a-w-C:\Windows\SysWow64\atigktxx.dll
2012-07-28 01:14:46368640----a-w-C:\Windows\System32\drivers\atikmpag.sys
2012-07-28 01:13:54129536----a-w-C:\Windows\System32\atiuxp64.dll
2012-07-28 01:13:48109568----a-w-C:\Windows\SysWow64\atiuxpag.dll
2012-07-28 01:13:40103936----a-w-C:\Windows\System32\atiu9p64.dll
2012-07-28 01:13:3283456----a-w-C:\Windows\SysWow64\atiu9pag.dll
2012-07-28 01:12:5453248----a-w-C:\Windows\System32\drivers\ati2erec.dll
2012-07-28 01:08:4256320----a-w-C:\Windows\System32\atimpc64.dll
2012-07-28 01:08:4256320----a-w-C:\Windows\System32\amdpcom64.dll
2012-07-28 01:08:3656832----a-w-C:\Windows\SysWow64\atimpc32.dll
2012-07-28 01:08:3656832----a-w-C:\Windows\SysWow64\amdpcom32.dll
2012-07-26 07:21:28291680----a-w-C:\Windows\System32\drivers\avgldx64.sys
2012-07-18 18:15:063148800----a-w-C:\Windows\System32\win32k.sys
.
============= FINISH: 14:19:14.26 ===============
Malwarebytes Anti-Malware (Trial) 1.65.0.1400
www.malwarebytes.org
Database version: v2012.10.14.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Babydoll :: BABYDOLL-PC [administrator]
Protection: Enabled
10/14/2012 1:05:57 PM
mbam-log-2012-10-14 (13-05-57).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206756
Time elapsed: 6 minute(s), 22 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 4
C:\Users\Babydoll\Downloads\coretemp_1236.exe (PUP.BundleOffers.IIQ) -> No action taken.
C:\Windows\Installer\{04cfe51a-6306-2045-1172-609246c62773}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{04cfe51a-6306-2045-1172-609246c62773}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{04cfe51a-6306-2045-1172-609246c62773}\U\80000000.@ (Rootkit.0Access.64) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-10-14 14:16:42
Windows 6.1.7601 Service Pack 1
Running: tdod0y70.exe
---- Registry - GMER 1.0.15 ----
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\Babydoll\AppData\Local\Logitech\xae Webcam Software\Logishrd\LU2.0\LogitechUpdate.exe 1
---- EOF - GMER 1.0.15 ----
DDS (Ver_2012-10-14.05) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by Babydoll at 14:18:45 on 2012-10-14
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8191.5717 [GMT -4:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\viakaraokesrv.exe
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Babydoll\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\ASUS\AI Suite\QFan4\FanHelp.exe
C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\Babydoll\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Users\Babydoll\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\AVG\AVG2012\avgcfgex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Babydoll\AppData\Local\Google\Chrome\Application\chrome.exe
"C:\Windows\SysWOW64\svchost.exe" -k LocalServiceDns
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\notepad.exe
C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2012\avgemca.exe
C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/?l=dis&o=APN10635&gct=hp
mWinlogon: Userinit = userinit.exe,
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.32\AVG Secure Search_toolbar.dll
uRun: [Google Update] "C:\Users\Babydoll\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [DW7] "C:\Program Files (x86)\The Weather Channel\The Weather Channel App\TWCApp.exe"
uRun: [Spotify Web Helper] "C:\Users\Babydoll\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
mRun: [QFan Help] "C:\Program Files (x86)\ASUS\AI Suite\QFan4\FanHelp.exe"
mRun: [Cpu Level Up help] "C:\Program Files (x86)\ASUS\AI Suite\CpuLevelUpHelp.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction
mRun: [ContentTransferWMDetector.exe] C:\Program Files (x86)\Sony\Content Transfer\ContentTransferWMDetector.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [ROC_ROC_JULY_P1] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_JULY_P1.exe" / /PROMPT /CMPID=ROC_JULY_P1
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Babydoll\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
LSP: mswsock.dll
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{46D2BCDE-7C84-4F6F-9848-39AF9E896812} : DHCPNameServer = 75.75.75.75 75.75.76.76
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg pku2u livessp
x64-BHO: AVG Do Not Track: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
x64-IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll
x64-Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Babydoll\AppData\Roaming\Mozilla\Firefox\Profiles\6qdbqp86.default\
FF - prefs.js: keyword.URL - hxxps://isearch.avg.com/search?cid=%7Bfeec4952-16d5-4827-9c1f-f9b426e47249%7D&mid=e4232c8089aa47d087916de78371ad09-b787440fbb17ee6c270c9e1b2f7e6e39c4a510ec&ds=AVG&v=12.2.5.32&lang=en&pr=fr&d=2012-05-06%2012%3A23%3A23&sap=ku&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\npsitesafety.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Babydoll\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2012-08-30 14:29; avg@toolbar; C:\ProgramData\AVG Secure Search\12.2.5.32
FF - ExtSQL: 2012-09-11 08:45; {1E73965B-8B48-48be-9C8D-68B920ABC1C4}; C:\Program Files (x86)\AVG\AVG2012\Firefox4
FF - ExtSQL: 2012-10-03 09:41; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Babydoll\AppData\Roaming\Mozilla\Firefox\Profiles\6qdbqp86.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-4-19 28480]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-1-31 36944]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-7-26 291680]
R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2011-12-23 47696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-8-24 384352]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-8-30 31080]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-7-27 239616]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-8-6 361984]
R2 AODDriver4.1;AODDriver4.1;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2012-5-8 96896]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [2012-8-13 5167736]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [2012-2-14 193288]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-14 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-14 676936]
R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\System32\ViakaraokeSrv.exe [2011-3-29 27760]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-8-30 722528]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2012-5-6 46136]
R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2012-7-28 10278912]
R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2012-7-27 368640]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-5-14 96896]
R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2011-12-23 124496]
R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\avgidsfiltera.sys [2011-12-23 29776]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2011-9-2 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2011-9-2 15128]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-14 25928]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2011-3-29 2157680]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-7-7 250808]
S3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-5-6 245760]
S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\System32\drivers\lvrs64.sys [2012-1-18 351136]
S3 LVUVC64;Logitech HD Webcam C270(UVC);C:\Windows\System32\drivers\lvuvc64.sys [2012-1-18 4865568]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-9-29 114144]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-5-5 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-5-7 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-5-6 1255736]
.
=============== Created Last 30 ================
.
2012-10-14 17:18:0469000----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9624E30A-CAD6-495B-B230-65FA31120BD7}\offreg.dll
2012-10-14 17:01:56--------d-----w-C:\Users\Babydoll\AppData\Roaming\Malwarebytes
2012-10-14 17:01:4725928----a-w-C:\Windows\System32\drivers\mbam.sys
2012-10-14 17:01:47--------d-----w-C:\ProgramData\Malwarebytes
2012-10-14 17:01:47--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-10-14 16:43:308917360----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2012-10-14 16:43:279308616----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9624E30A-CAD6-495B-B230-65FA31120BD7}\mpengine.dll
2012-10-14 16:26:58--------d-----w-C:\TDSSKiller_Quarantine
2012-10-14 14:10:27--------d-----w-C:\Windows\SysWow64\QuickTime
2012-10-14 14:03:49--------d-sh--w-C:\Windows\SysWow64\%APPDATA%
2012-10-14 13:55:33--------d-----w-C:\Program Files (x86)\Mega Codec Pack
2012-10-10 17:42:14424448------w-C:\Windows\System32\KernelBase.dll
2012-10-10 17:42:13215040------w-C:\Windows\System32\winsrv.dll
2012-10-10 17:42:12274944------w-C:\Windows\SysWow64\KernelBase.dll
2012-10-10 17:42:11243200------w-C:\Windows\System32\wow64.dll
2012-10-10 17:42:10362496------w-C:\Windows\System32\wow64win.dll
2012-10-10 17:42:1013312------w-C:\Windows\System32\wow64cpu.dll
2012-10-10 17:41:56220160------w-C:\Windows\System32\wintrust.dll
2012-10-10 17:41:56172544------w-C:\Windows\SysWow64\wintrust.dll
2012-10-10 17:41:46715776------w-C:\Windows\System32\kerberos.dll
2012-10-10 17:41:431464320------w-C:\Windows\System32\crypt32.dll
2012-10-10 17:41:42140288------w-C:\Windows\System32\cryptnet.dll
2012-10-10 17:41:421159680------w-C:\Windows\SysWow64\crypt32.dll
2012-10-08 16:04:26--------d-----w-C:\Program Files (x86)\Coupons
2012-10-03 15:21:16359424----a-w-C:\Windows\System32\CmiInstallResAll64.dll
2012-10-03 15:21:151310720----a-w-C:\Windows\System32\drivers\CM10864.sys
2012-10-02 15:42:45--------d-----w-C:\Users\Babydoll\AppData\Local\MFAData
2012-10-02 15:42:45--------d-----w-C:\Users\Babydoll\AppData\Local\Avg2013
2012-10-01 16:30:18--------d-----w-C:\Users\Babydoll\AppData\Local\Macromedia
2012-09-30 16:04:12--------d-----r-C:\Users\Babydoll\AppData\Roaming\Brother
2012-09-30 02:22:34--------d-----w-C:\Users\Babydoll\AppData\Local\Mozilla
2012-09-30 02:22:29--------d-----w-C:\Program Files (x86)\Mozilla Maintenance Service
2012-09-27 13:47:01245760----a-w-C:\Windows\System32\OxpsConverter.exe
2012-09-21 17:51:37--------d-----w-C:\ProgramData\NVIDIA Corporation
2012-09-21 17:51:34--------d-----w-C:\Program Files\NVIDIA Corporation
2012-09-19 19:57:2733240----a-w-C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-09-19 19:56:02--------d-----w-C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-09-19 19:56:02--------d-----w-C:\Program Files\iTunes
2012-09-19 19:56:02--------d-----w-C:\Program Files\iPod
2012-09-19 19:56:02--------d-----w-C:\Program Files (x86)\iTunes
2012-09-19 17:55:51--------d-----w-C:\Program Files (x86)\Seagate
2012-09-19 17:35:07--------d-----w-C:\ProgramData\Hi-Rez Studios
2012-09-19 17:35:02--------d-----w-C:\Program Files (x86)\Hi-Rez Studios
2012-09-17 14:13:26--------d--h--r-C:\AHCache
.
==================== Find3M ====================
.
2012-10-14 17:07:1373656----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-14 17:07:13696760----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2012-09-22 17:48:1018960----a-w-C:\Windows\System32\drivers\LNonPnP.sys
2012-09-09 16:27:21255352----a-w-C:\Windows\SysWow64\awrdscdc.ax
2012-09-02 19:43:5595208----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-02 19:43:54821736----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2012-09-02 19:43:54746984----a-w-C:\Windows\SysWow64\deployJava1.dll
2012-08-30 18:29:1731080----a-w-C:\Windows\System32\drivers\avgtpx64.sys
2012-08-24 19:43:16384352----a-w-C:\Windows\System32\drivers\avgtdia.sys
2012-08-24 10:31:322312704----a-w-C:\Windows\System32\jscript9.dll
2012-08-24 10:21:181392128----a-w-C:\Windows\System32\wininet.dll
2012-08-24 10:20:111494528----a-w-C:\Windows\System32\inetcpl.cpl
2012-08-24 10:14:45173056----a-w-C:\Windows\System32\ieUnatt.exe
2012-08-24 10:13:29599040----a-w-C:\Windows\System32\vbscript.dll
2012-08-24 10:09:422382848----a-w-C:\Windows\System32\mshtml.tlb
2012-08-24 06:59:171800704----a-w-C:\Windows\SysWow64\jscript9.dll
2012-08-24 06:51:271129472----a-w-C:\Windows\SysWow64\wininet.dll
2012-08-24 06:51:021427968----a-w-C:\Windows\SysWow64\inetcpl.cpl
2012-08-24 06:47:26142848----a-w-C:\Windows\SysWow64\ieUnatt.exe
2012-08-24 06:47:12420864----a-w-C:\Windows\SysWow64\vbscript.dll
2012-08-24 06:43:582382848----a-w-C:\Windows\SysWow64\mshtml.tlb
2012-08-22 18:12:501913200----a-w-C:\Windows\System32\drivers\tcpip.sys
2012-08-22 18:12:40950128----a-w-C:\Windows\System32\drivers\ndis.sys
2012-08-22 18:12:40376688----a-w-C:\Windows\System32\drivers\netio.sys
2012-08-22 18:12:33288624----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-08-21 17:01:20125872----a-w-C:\Windows\System32\GEARAspi64.dll
2012-08-21 17:01:20106928----a-w-C:\Windows\SysWow64\GEARAspi.dll
2012-08-10 15:23:11152576----a-w-C:\Windows\SysWow64\msclmd.dll
2012-08-10 15:23:10175616----a-w-C:\Windows\System32\msclmd.dll
2012-08-02 17:58:52574464----a-w-C:\Windows\System32\d3d10level9.dll
2012-08-02 16:57:20490496----a-w-C:\Windows\SysWow64\d3d10level9.dll
2012-07-28 04:09:205538984----a-w-C:\Windows\SysWow64\atiumdag.dll
2012-07-28 04:07:4410278912----a-w-C:\Windows\System32\drivers\atikmdag.sys
2012-07-28 03:43:1270144----a-w-C:\Windows\System32\coinst_8.982.dll
2012-07-28 03:19:3424935424----a-w-C:\Windows\System32\atio6axx.dll
2012-07-28 02:50:1020546560----a-w-C:\Windows\SysWow64\atioglxx.dll
2012-07-28 02:47:40187392----a-w-C:\Windows\System32\clinfo.exe
2012-07-28 02:47:2475776----a-w-C:\Windows\System32\OpenVideo64.dll
2012-07-28 02:47:1665024----a-w-C:\Windows\SysWow64\OpenVideo.dll
2012-07-28 02:47:1063488----a-w-C:\Windows\System32\OVDecode64.dll
2012-07-28 02:47:0656320----a-w-C:\Windows\SysWow64\OVDecode.dll
2012-07-28 02:46:5616464896----a-w-C:\Windows\System32\amdocl64.dll
2012-07-28 02:46:0613013504----a-w-C:\Windows\SysWow64\amdocl.dll
2012-07-28 02:15:50163840----a-w-C:\Windows\System32\atiapfxx.exe
2012-07-28 02:15:42931328----a-w-C:\Windows\SysWow64\aticfx32.dll
2012-07-28 02:13:561100288----a-w-C:\Windows\System32\aticfx64.dll
2012-07-28 02:10:40442368----a-w-C:\Windows\System32\ATIDEMGX.dll
2012-07-28 02:10:34534528----a-w-C:\Windows\System32\atieclxx.exe
2012-07-28 02:09:44239616----a-w-C:\Windows\System32\atiesrxx.exe
2012-07-28 02:08:20120320----a-w-C:\Windows\System32\atitmm64.dll
2012-07-28 02:08:0421504----a-w-C:\Windows\System32\atimuixx.dll
2012-07-28 02:07:5859392----a-w-C:\Windows\System32\atiedu64.dll
2012-07-28 02:07:5243520----a-w-C:\Windows\SysWow64\ati2edxx.dll
2012-07-28 02:07:106430208----a-w-C:\Windows\SysWow64\atidxx32.dll
2012-07-28 01:51:127052288----a-w-C:\Windows\System32\atidxx64.dll
2012-07-28 01:41:324266496----a-w-C:\Windows\System32\atiumd6a.dll
2012-07-28 01:35:1051200----a-w-C:\Windows\System32\aticalrt64.dll
2012-07-28 01:35:0846080----a-w-C:\Windows\SysWow64\aticalrt.dll
2012-07-28 01:35:0244544----a-w-C:\Windows\System32\aticalcl64.dll
2012-07-28 01:35:0044032----a-w-C:\Windows\SysWow64\aticalcl.dll
2012-07-28 01:34:4816034304----a-w-C:\Windows\System32\aticaldd64.dll
2012-07-28 01:32:324751872----a-w-C:\Windows\SysWow64\atiumdva.dll
2012-07-28 01:30:1013605888----a-w-C:\Windows\SysWow64\aticaldd.dll
2012-07-28 01:25:526676480----a-w-C:\Windows\System32\atiumd64.dll
2012-07-28 01:15:32540160----a-w-C:\Windows\System32\atiadlxx.dll
2012-07-28 01:15:22368640----a-w-C:\Windows\SysWow64\atiadlxy.dll
2012-07-28 01:15:1217920----a-w-C:\Windows\System32\atig6pxx.dll
2012-07-28 01:15:0814848----a-w-C:\Windows\SysWow64\atiglpxx.dll
2012-07-28 01:15:0814848----a-w-C:\Windows\System32\atiglpxx.dll
2012-07-28 01:15:0441984----a-w-C:\Windows\System32\atig6txx.dll
2012-07-28 01:14:5633280----a-w-C:\Windows\SysWow64\atigktxx.dll
2012-07-28 01:14:46368640----a-w-C:\Windows\System32\drivers\atikmpag.sys
2012-07-28 01:13:54129536----a-w-C:\Windows\System32\atiuxp64.dll
2012-07-28 01:13:48109568----a-w-C:\Windows\SysWow64\atiuxpag.dll
2012-07-28 01:13:40103936----a-w-C:\Windows\System32\atiu9p64.dll
2012-07-28 01:13:3283456----a-w-C:\Windows\SysWow64\atiu9pag.dll
2012-07-28 01:12:5453248----a-w-C:\Windows\System32\drivers\ati2erec.dll
2012-07-28 01:08:4256320----a-w-C:\Windows\System32\atimpc64.dll
2012-07-28 01:08:4256320----a-w-C:\Windows\System32\amdpcom64.dll
2012-07-28 01:08:3656832----a-w-C:\Windows\SysWow64\atimpc32.dll
2012-07-28 01:08:3656832----a-w-C:\Windows\SysWow64\amdpcom32.dll
2012-07-26 07:21:28291680----a-w-C:\Windows\System32\drivers\avgldx64.sys
2012-07-18 18:15:063148800----a-w-C:\Windows\System32\win32k.sys
.
============= FINISH: 14:19:14.26 ===============