Last night I got a virus and MSE said the scan that I never started completed and then shut down. I wasn't able to start it again. I started it up into safe mode and ran malwarebytes as well as a few other things that people suggested for sirefef removal. After I ran these my computer started restarting 60 seconds after logging back on. I did a windows restore to a few days ago and now my computer starts fine but when I run a full MSE scan my computer freezes periodically. I'm concerned that I may not have gotten rid of the virus. I've ran MBAM, GMER and the dds script from the instructions.
GMER log: Nothing found so it's just a blank file
MBAM log:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.13.11
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Travis :: TRAVDESKTOPWIN7 [administrator]
7/13/2012 9:32:15 PM
mbam-log-2012-07-13 (21-32-15).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 264646
Time elapsed: 1 minute(s), 44 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.0.0
Run by Travis at 21:47:25 on 2012-07-13
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16345.13887 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
D:\Windows7\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
D:\Windows7\Program Files\Logitech\SolarApp\L4301_Solar.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
D:\Windows7\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
D:\Windows7\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
D:\Windows7\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
D:\Windows7\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
D:\Windows7\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
D:\Windows7\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
D:\Windows7\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
D:\Windows7\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
D:\Windows7\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
D:\Windows7\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Windows7\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Windows\system32\pnusbvirtualhubwssrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
D:\Windows7\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
D:\Windows7\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
D:\Windows7\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
D:\Windows7\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
D:\Windows7\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
d:\Windows7\Program Files\Microsoft Security Client\MsMpEng.exe
D:\Windows7\Program Files\Microsoft Security Client\msseces.exe
D:\Windows7\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - D:\Windows7\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: SteadyVideoBHO Class: {6c680bae-655c-4e3d-8fc4-e6a520c3d928} - D:\Windows7\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - D:\Windows7\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - D:\Windows7\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - D:\Windows7\PROGRA~3\MICROS~3\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - D:\Windows7\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [ISUSPM] "D:\Windows7\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
uRun: [Skype] "D:\Windows7\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Adobe ARM] "D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ASUS AiChargerPlus Execute] D:\Windows7\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
mRun: [BCSSync] "D:\Windows7\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [pnusbclitray] pnusbclitray.exe
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "d:\Windows7\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [LogMeIn Hamachi Ui] "D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun: [StartCCC] "D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRunOnce: [Malwarebytes Anti-Malware] D:\Windows7\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: D:\Windows7\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\VPNGUI~1.LNK - C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableInstallerDetection = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\Windows7\PROGRA~3\MICROS~3\Office14\EXCEL.EXE/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {D9397163-A2DB-4A4A-B2C9-34E876AF2DFC} - hxxps://voal.tamu.edu/windows/provision/web-it/clients/vasclient32t.cab
TCP: Interfaces\{DEF3E9AA-857A-4DA7-A910-1E88EE93EDB2} : DhcpNameServer = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - D:\Windows7\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Windows7\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Windows7\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Windows7\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Windows7\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - D:\Windows7\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
BHO-X64: AMD SteadyVideo BHO - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Windows7\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Windows7\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Windows7\PROGRA~3\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Windows7\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
mRun-x64: [Adobe ARM] "D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [ASUS AiChargerPlus Execute] D:\Windows7\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
mRun-x64: [BCSSync] "D:\Windows7\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [pnusbclitray] pnusbclitray.exe
mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "d:\Windows7\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun-x64: [LogMeIn Hamachi Ui] "D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun-x64: [StartCCC] "D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRunOnce-x64: [Malwarebytes Anti-Malware] D:\Windows7\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - D:\Windows7\Users\Travis\AppData\Roaming\Mozilla\Firefox\Profiles\72xe308k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
FF - plugin: D:\Windows7\PROGRA~3\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: D:\Windows7\PROGRA~3\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: D:\Windows7\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: D:\Windows7\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: D:\Windows7\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: d:\Windows7\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: D:\Windows7\Users\Travis\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: D:\Windows7\Users\Travis\AppData\Roaming\Mozilla\Firefox\Profiles\72xe308k.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AiChargerPlus;ASUS Charger Plus Driver;C:\Windows\system32\DRIVERS\AiChargerPlus.sys --> C:\Windows\system32\DRIVERS\AiChargerPlus.sys [?]
R0 amd_sata;amd_sata;C:\Windows\system32\drivers\amd_sata.sys --> C:\Windows\system32\drivers\amd_sata.sys [?]
R0 amd_xata;amd_xata;C:\Windows\system32\drivers\amd_xata.sys --> C:\Windows\system32\drivers\amd_xata.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD FUEL Service;AMD FUEL Service;D:\Windows7\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-6-11 361984]
R2 AODDriver4.01;AODDriver4.01;D:\Windows7\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 asComSvc;ASUS Com Service;D:\Windows7\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2011-9-6 918144]
R2 asHmComSvc;ASUS HM Com Service;D:\Windows7\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2011-9-6 915584]
R2 AsSysCtrlService;ASUS System Control Service;D:\Windows7\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2011-9-6 586880]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-28 2343816]
R2 L4301_Solar;Logitech Solar Keyboard Service;D:\Windows7\Program Files\Logitech\SolarApp\L4301_Solar.exe [2010-10-26 403536]
R2 pnpnptool;Quest RDP PnP Driver;\??\C:\Windows\system32\Drivers\pnpnptool.sys --> C:\Windows\system32\Drivers\pnpnptool.sys [?]
R2 pnusbvirtualhubwssrv;Quest USB Hub Client Service;C:\Windows\system32\pnusbvirtualhubwssrv.exe --> C:\Windows\system32\pnusbvirtualhubwssrv.exe [?]
R2 TeamViewer6;TeamViewer 6;D:\Windows7\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-9-5 2358656]
R2 TeamViewer7;TeamViewer 7;D:\Windows7\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-18 2666880]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\system32\DRIVERS\asmthub3.sys --> C:\Windows\system32\DRIVERS\asmthub3.sys [?]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\system32\DRIVERS\asmtxhci.sys --> C:\Windows\system32\DRIVERS\asmtxhci.sys [?]
R3 athur;Wireless Network Adapter Service;C:\Windows\system32\DRIVERS\athurx.sys --> C:\Windows\system32\DRIVERS\athurx.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\system32\DRIVERS\LEqdUsb.Sys --> C:\Windows\system32\DRIVERS\LEqdUsb.Sys [?]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\system32\DRIVERS\LHidEqd.Sys --> C:\Windows\system32\DRIVERS\LHidEqd.Sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys --> C:\Windows\system32\DRIVERS\teamviewervpn.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
RUnknown SASKUTIL;SASKUTIL; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-15 250056]
S3 ahcix64s;ahcix64s;C:\Windows\system32\drivers\ahcix64s.sys --> C:\Windows\system32\drivers\ahcix64s.sys [?]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;D:\Windows7\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2011-1-8 87336]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;D:\Windows7\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-9-12 1431888]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\956C.tmp --> C:\Windows\system32\956C.tmp [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;D:\Windows7\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-26 113120]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;D:\Windows7\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 osppsvc;Office Software Protection Platform;D:\Windows7\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 pnusbd;Quest RDP USB Driver;\??\C:\Windows\system32\Drivers\pnusbd.sys --> C:\Windows\system32\Drivers\pnusbd.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 Remote Solver for Flow Simulation 2011;Remote Solver for Flow Simulation 2011;D:\Windows7\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2010-12-1 110344]
S3 SaiH8000;SaiH8000;C:\Windows\system32\DRIVERS\SaiH8000.sys --> C:\Windows\system32\DRIVERS\SaiH8000.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S3 WSDScan;WSD Scan Support via UMB;C:\Windows\system32\DRIVERS\WSDScan.sys --> C:\Windows\system32\DRIVERS\WSDScan.sys [?]
.
=============== Created Last 30 ================
.
2012-07-14 01:41:27 9013136 ----a-w- D:\Windows7\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{61A55AF3-7C28-44A2-AF24-A10356B59AA6}\mpengine.dll
2012-07-14 01:29:31 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-14 01:29:31 -------- d-----w- D:\Windows7\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-14 01:24:00 927800 ----a-w- D:\Windows7\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{21618E1C-196F-4C00-B3D9-7BB44D7DE2EA}\gapaengine.dll
2012-07-14 01:09:21 15728 ----a-w- C:\FixitRegBackup.reg
2012-07-13 23:33:55 -------- d-----w- D:\Windows7\Program Files\SUPERAntiSpyware
2012-07-13 05:14:42 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-13 04:42:44 -------- d-----w- C:\$RECYCLE.BIN
2012-07-13 04:34:00 98816 ----a-w- C:\Windows\sed.exe
2012-07-13 04:34:00 518144 ----a-w- C:\Windows\SWREG.exe
2012-07-13 04:34:00 256000 ----a-w- C:\Windows\PEV.exe
2012-07-13 04:34:00 208896 ----a-w- C:\Windows\MBR.exe
2012-07-13 04:03:31 6144 ------w- C:\Windows\System32\956C.tmp
2012-07-13 04:03:14 6144 ------w- C:\Windows\System32\51F6.tmp
2012-07-13 01:32:27 -------- d-----w- D:\Windows7\ProgramData\Spybot - Search & Destroy
2012-07-08 17:44:27 -------- d-----w- D:\Windows7\Program Files (x86)\ETS
2012-07-01 15:21:30 -------- d-----w- D:\Windows7\Users\Travis\AppData\Roaming\.Nitrous
2012-07-01 04:50:59 -------- d-----w- D:\Windows7\Program Files (x86)\AMD APP
2012-07-01 04:49:09 -------- d-----w- C:\AMD
2012-07-01 02:42:47 -------- d-----w- D:\Windows7\Program Files\GIMP 2
2012-07-01 02:37:34 955840 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-07-01 02:37:34 839096 ----a-w- C:\Windows\System32\deployJava1.dll
2012-07-01 02:32:40 -------- d-----w- D:\Windows7\Users\Travis\AppData\Roaming\.minecraft
2012-06-25 20:37:54 -------- d-----w- D:\Windows7\Program Files\Python 2.7.3 - 64 bit
2012-06-25 19:40:33 -------- d-----w- D:\Windows7\Program Files (x86)\Python 2.7.3
2012-06-25 19:39:02 -------- d-----w- D:\Windows7\Program Files (x86)\BOI_Gridzator
2012-06-25 03:04:19 7168 ----a-w- C:\Windows\SysWow64\shfoc580.rra
2012-06-25 03:04:19 21504 ----a-w- C:\Windows\SysWow64\versc580.rra
2012-06-25 03:04:19 15360 ----a-w- C:\Windows\SysWow64\wsocc58f.rra
2012-06-25 03:04:19 126464 ----a-w- C:\Windows\SysWow64\advpc551.rra
2012-06-25 02:56:10 7168 ----a-w- C:\Windows\SysWow64\shfoe678.rra
2012-06-25 02:56:10 21504 ----a-w- C:\Windows\SysWow64\verse687.rra
2012-06-25 02:56:10 15360 ----a-w- C:\Windows\SysWow64\wsoce697.rra
2012-06-25 02:56:10 126464 ----a-w- C:\Windows\SysWow64\advpe668.rra
2012-06-25 02:29:00 -------- d-----w- D:\Windows7\Users\Travis\AppData\Roaming\PowerUp Software
2012-06-25 02:29:00 -------- d-----w- D:\Windows7\ProgramData\PowerUp Software
2012-06-25 02:10:31 69715 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2012-06-25 02:10:31 5632 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2012-06-25 02:10:31 32768 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2012-06-25 02:10:31 266240 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2012-06-25 02:10:31 192512 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2012-06-25 02:10:30 724992 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2012-06-25 02:10:30 311428 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2012-06-25 02:10:30 184452 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2012-06-23 05:52:12 -------- d-----w- D:\Windows7\Users\Travis\AppData\Local\Macromedia
2012-06-21 23:10:34 224088 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys
2012-06-21 23:10:34 130904 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys
2012-06-21 23:10:31 -------- d-----w- D:\Windows7\Program Files\Oracle
2012-06-21 22:27:58 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-21 22:27:55 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-21 22:27:54 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-21 22:27:54 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-17 17:03:44 770384 ----a-w- D:\Windows7\Program Files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-17 17:03:44 421200 ----a-w- D:\Windows7\Program Files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-17 15:11:41 -------- d-----w- D:\Windows7\Users\Travis\AppData\Local\LogMeIn Hamachi
2012-06-17 15:11:31 -------- d-----w- D:\Windows7\Program Files (x86)\LogMeIn Hamachi
.
==================== Find3M ====================
.
2012-07-13 05:17:08 2519168 ----a-w- C:\Windows\PE_Rom.dll
2012-07-13 04:48:06 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-13 04:48:06 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-25 02:30:10 119296 ----a-w- C:\Windows\SysWow64\zlib.dll
2012-06-11 18:59:38 10248192 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2012-06-11 18:35:48 70144 ----a-w- C:\Windows\System32\coinst_8.98.dll
2012-06-11 18:29:34 24826368 ----a-w- C:\Windows\System32\atio6axx.dll
2012-06-11 18:00:32 20467712 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2012-06-11 17:50:46 187392 ----a-w- C:\Windows\System32\clinfo.exe
2012-06-11 17:50:30 75264 ----a-w- C:\Windows\System32\OpenVideo64.dll
2012-06-11 17:50:24 65024 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
2012-06-11 17:50:18 63488 ----a-w- C:\Windows\System32\OVDecode64.dll
2012-06-11 17:50:14 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2012-06-11 17:50:06 16457728 ----a-w- C:\Windows\System32\amdocl64.dll
2012-06-11 17:49:22 13008896 ----a-w- C:\Windows\SysWow64\amdocl.dll
2012-06-11 17:25:06 163840 ----a-w- C:\Windows\System32\atiapfxx.exe
2012-06-11 17:24:58 924160 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2012-06-11 17:23:12 1090560 ----a-w- C:\Windows\System32\aticfx64.dll
2012-06-11 17:20:02 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2012-06-11 17:19:58 532992 ----a-w- C:\Windows\System32\atieclxx.exe
2012-06-11 17:19:14 239616 ----a-w- C:\Windows\System32\atiesrxx.exe
2012-06-11 17:17:56 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2012-06-11 17:17:42 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2012-06-11 17:17:38 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2012-06-11 17:17:32 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2012-06-11 17:16:48 6301696 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2012-06-11 17:01:56 6914560 ----a-w- C:\Windows\System32\atidxx64.dll
2012-06-11 16:51:54 4246528 ----a-w- C:\Windows\System32\atiumd6a.dll
2012-06-11 16:45:48 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2012-06-11 16:45:46 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2012-06-11 16:45:44 5480448 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2012-06-11 16:45:40 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2012-06-11 16:45:38 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2012-06-11 16:45:26 15703040 ----a-w- C:\Windows\System32\aticaldd64.dll
2012-06-11 16:43:18 4729344 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2012-06-11 16:40:58 13277696 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2012-06-11 16:36:56 6605824 ----a-w- C:\Windows\System32\atiumd64.dll
2012-06-11 16:27:02 539136 ----a-w- C:\Windows\System32\atiadlxx.dll
2012-06-11 16:26:52 368640 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2012-06-11 16:26:40 17920 ----a-w- C:\Windows\System32\atig6pxx.dll
2012-06-11 16:26:36 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2012-06-11 16:26:36 14848 ----a-w- C:\Windows\System32\atiglpxx.dll
2012-06-11 16:26:30 41984 ----a-w- C:\Windows\System32\atig6txx.dll
2012-06-11 16:26:22 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2012-06-11 16:26:14 367616 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2012-06-11 16:25:20 54784 ----a-w- C:\Windows\System32\atiuxp64.dll
2012-06-11 16:25:12 42496 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2012-06-11 16:25:06 45056 ----a-w- C:\Windows\System32\atiu9p64.dll
2012-06-11 16:24:58 32768 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2012-06-11 16:24:24 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\atimpc64.dll
2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\amdpcom64.dll
2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-05 20:03:52 166232 ----a-w- C:\Windows\System32\drivers\VBoxNetFlt.sys
2012-06-05 20:03:52 147288 ----a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys
2012-06-05 20:02:22 320856 ----a-w- C:\Windows\System32\VBoxNetFltNobj.dll
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-31 16:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-05-12 06:32:04 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2012-05-07 00:53:12 1120768 ----a-w- C:\Windows\System32\atiumd6v.dll
2012-05-07 00:49:41 1831424 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2012-05-07 00:42:19 95760 ----a-w- C:\Windows\System32\drivers\AtihdW76.sys
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 05:32:05 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
.
============= FINISH: 21:47:50.20 ===============
GMER log: Nothing found so it's just a blank file
MBAM log:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.13.11
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Travis :: TRAVDESKTOPWIN7 [administrator]
7/13/2012 9:32:15 PM
mbam-log-2012-07-13 (21-32-15).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 264646
Time elapsed: 1 minute(s), 44 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.0.0
Run by Travis at 21:47:25 on 2012-07-13
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.16345.13887 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
D:\Windows7\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
D:\Windows7\Program Files\Logitech\SolarApp\L4301_Solar.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
D:\Windows7\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
D:\Windows7\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
D:\Windows7\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
D:\Windows7\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
D:\Windows7\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
D:\Windows7\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
D:\Windows7\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
D:\Windows7\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
D:\Windows7\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
D:\Windows7\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
D:\Windows7\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
C:\Windows\system32\pnusbvirtualhubwssrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
D:\Windows7\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
D:\Windows7\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
D:\Windows7\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
D:\Windows7\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
D:\Windows7\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
d:\Windows7\Program Files\Microsoft Security Client\MsMpEng.exe
D:\Windows7\Program Files\Microsoft Security Client\msseces.exe
D:\Windows7\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - D:\Windows7\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: SteadyVideoBHO Class: {6c680bae-655c-4e3d-8fc4-e6a520c3d928} - D:\Windows7\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - D:\Windows7\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - D:\Windows7\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - D:\Windows7\PROGRA~3\MICROS~3\Office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - D:\Windows7\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [ISUSPM] "D:\Windows7\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
uRun: [Skype] "D:\Windows7\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Adobe ARM] "D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [ASUS AiChargerPlus Execute] D:\Windows7\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
mRun: [BCSSync] "D:\Windows7\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [pnusbclitray] pnusbclitray.exe
mRun: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "d:\Windows7\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun: [LogMeIn Hamachi Ui] "D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun: [StartCCC] "D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRunOnce: [Malwarebytes Anti-Malware] D:\Windows7\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: D:\Windows7\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\VPNGUI~1.LNK - C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableInstallerDetection = 0 (0x0)
IE: E&xport to Microsoft Excel - D:\Windows7\PROGRA~3\MICROS~3\Office14\EXCEL.EXE/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {D9397163-A2DB-4A4A-B2C9-34E876AF2DFC} - hxxps://voal.tamu.edu/windows/provision/web-it/clients/vasclient32t.cab
TCP: Interfaces\{DEF3E9AA-857A-4DA7-A910-1E88EE93EDB2} : DhcpNameServer = 192.168.2.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - D:\Windows7\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Windows7\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - D:\Windows7\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Windows7\PROGRA~3\COMMON~1\Skype\SKYPE4~1.DLL
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Windows7\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - D:\Windows7\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
BHO-X64: AMD SteadyVideo BHO - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Windows7\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Windows7\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Windows7\PROGRA~3\MICROS~3\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Windows7\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
mRun-x64: [Adobe ARM] "D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [ASUS AiChargerPlus Execute] D:\Windows7\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
mRun-x64: [BCSSync] "D:\Windows7\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun-x64: [pnusbclitray] pnusbclitray.exe
mRun-x64: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "d:\Windows7\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
mRun-x64: [LogMeIn Hamachi Ui] "D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
mRun-x64: [StartCCC] "D:\Windows7\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRunOnce-x64: [Malwarebytes Anti-Malware] D:\Windows7\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - D:\Windows7\Users\Travis\AppData\Roaming\Mozilla\Firefox\Profiles\72xe308k.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll
FF - plugin: D:\Windows7\PROGRA~3\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: D:\Windows7\PROGRA~3\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: D:\Windows7\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: D:\Windows7\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: D:\Windows7\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: d:\Windows7\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: D:\Windows7\Users\Travis\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: D:\Windows7\Users\Travis\AppData\Roaming\Mozilla\Firefox\Profiles\72xe308k.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AiChargerPlus;ASUS Charger Plus Driver;C:\Windows\system32\DRIVERS\AiChargerPlus.sys --> C:\Windows\system32\DRIVERS\AiChargerPlus.sys [?]
R0 amd_sata;amd_sata;C:\Windows\system32\drivers\amd_sata.sys --> C:\Windows\system32\drivers\amd_sata.sys [?]
R0 amd_xata;amd_xata;C:\Windows\system32\drivers\amd_xata.sys --> C:\Windows\system32\drivers\amd_xata.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;D:\Windows7\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 AMD FUEL Service;AMD FUEL Service;D:\Windows7\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-6-11 361984]
R2 AODDriver4.01;AODDriver4.01;D:\Windows7\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-3-5 53888]
R2 asComSvc;ASUS Com Service;D:\Windows7\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe [2011-9-6 918144]
R2 asHmComSvc;ASUS HM Com Service;D:\Windows7\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [2011-9-6 915584]
R2 AsSysCtrlService;ASUS System Control Service;D:\Windows7\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [2011-9-6 586880]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;D:\Windows7\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-28 2343816]
R2 L4301_Solar;Logitech Solar Keyboard Service;D:\Windows7\Program Files\Logitech\SolarApp\L4301_Solar.exe [2010-10-26 403536]
R2 pnpnptool;Quest RDP PnP Driver;\??\C:\Windows\system32\Drivers\pnpnptool.sys --> C:\Windows\system32\Drivers\pnpnptool.sys [?]
R2 pnusbvirtualhubwssrv;Quest USB Hub Client Service;C:\Windows\system32\pnusbvirtualhubwssrv.exe --> C:\Windows\system32\pnusbvirtualhubwssrv.exe [?]
R2 TeamViewer6;TeamViewer 6;D:\Windows7\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-9-5 2358656]
R2 TeamViewer7;TeamViewer 7;D:\Windows7\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-18 2666880]
R3 amdiox64;AMD IO Driver;C:\Windows\system32\DRIVERS\amdiox64.sys --> C:\Windows\system32\DRIVERS\amdiox64.sys [?]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\system32\DRIVERS\asmthub3.sys --> C:\Windows\system32\DRIVERS\asmthub3.sys [?]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\system32\DRIVERS\asmtxhci.sys --> C:\Windows\system32\DRIVERS\asmtxhci.sys [?]
R3 athur;Wireless Network Adapter Service;C:\Windows\system32\DRIVERS\athurx.sys --> C:\Windows\system32\DRIVERS\athurx.sys [?]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\system32\DRIVERS\LEqdUsb.Sys --> C:\Windows\system32\DRIVERS\LEqdUsb.Sys [?]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\system32\DRIVERS\LHidEqd.Sys --> C:\Windows\system32\DRIVERS\LHidEqd.Sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys --> C:\Windows\system32\DRIVERS\teamviewervpn.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
RUnknown SASKUTIL;SASKUTIL; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-15 250056]
S3 ahcix64s;ahcix64s;C:\Windows\system32\drivers\ahcix64s.sys --> C:\Windows\system32\drivers\ahcix64s.sys [?]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;D:\Windows7\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2011-1-8 87336]
S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;D:\Windows7\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2011-9-12 1431888]
S3 MEMSWEEP2;MEMSWEEP2;\??\C:\Windows\system32\956C.tmp --> C:\Windows\system32\956C.tmp [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;D:\Windows7\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-26 113120]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;D:\Windows7\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 osppsvc;Office Software Protection Platform;D:\Windows7\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 pnusbd;Quest RDP USB Driver;\??\C:\Windows\system32\Drivers\pnusbd.sys --> C:\Windows\system32\Drivers\pnusbd.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 Remote Solver for Flow Simulation 2011;Remote Solver for Flow Simulation 2011;D:\Windows7\Program Files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [2010-12-1 110344]
S3 SaiH8000;SaiH8000;C:\Windows\system32\DRIVERS\SaiH8000.sys --> C:\Windows\system32\DRIVERS\SaiH8000.sys [?]
S3 Synth3dVsc;Synth3dVsc;C:\Windows\system32\drivers\synth3dvsc.sys --> C:\Windows\system32\drivers\synth3dvsc.sys [?]
S3 terminpt;Microsoft Remote Desktop Input Driver;C:\Windows\system32\drivers\terminpt.sys --> C:\Windows\system32\drivers\terminpt.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 tsusbhub;tsusbhub;C:\Windows\system32\drivers\tsusbhub.sys --> C:\Windows\system32\drivers\tsusbhub.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S3 WSDScan;WSD Scan Support via UMB;C:\Windows\system32\DRIVERS\WSDScan.sys --> C:\Windows\system32\DRIVERS\WSDScan.sys [?]
.
=============== Created Last 30 ================
.
2012-07-14 01:41:27 9013136 ----a-w- D:\Windows7\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{61A55AF3-7C28-44A2-AF24-A10356B59AA6}\mpengine.dll
2012-07-14 01:29:31 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-14 01:29:31 -------- d-----w- D:\Windows7\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-14 01:24:00 927800 ----a-w- D:\Windows7\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{21618E1C-196F-4C00-B3D9-7BB44D7DE2EA}\gapaengine.dll
2012-07-14 01:09:21 15728 ----a-w- C:\FixitRegBackup.reg
2012-07-13 23:33:55 -------- d-----w- D:\Windows7\Program Files\SUPERAntiSpyware
2012-07-13 05:14:42 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-13 04:42:44 -------- d-----w- C:\$RECYCLE.BIN
2012-07-13 04:34:00 98816 ----a-w- C:\Windows\sed.exe
2012-07-13 04:34:00 518144 ----a-w- C:\Windows\SWREG.exe
2012-07-13 04:34:00 256000 ----a-w- C:\Windows\PEV.exe
2012-07-13 04:34:00 208896 ----a-w- C:\Windows\MBR.exe
2012-07-13 04:03:31 6144 ------w- C:\Windows\System32\956C.tmp
2012-07-13 04:03:14 6144 ------w- C:\Windows\System32\51F6.tmp
2012-07-13 01:32:27 -------- d-----w- D:\Windows7\ProgramData\Spybot - Search & Destroy
2012-07-08 17:44:27 -------- d-----w- D:\Windows7\Program Files (x86)\ETS
2012-07-01 15:21:30 -------- d-----w- D:\Windows7\Users\Travis\AppData\Roaming\.Nitrous
2012-07-01 04:50:59 -------- d-----w- D:\Windows7\Program Files (x86)\AMD APP
2012-07-01 04:49:09 -------- d-----w- C:\AMD
2012-07-01 02:42:47 -------- d-----w- D:\Windows7\Program Files\GIMP 2
2012-07-01 02:37:34 955840 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-07-01 02:37:34 839096 ----a-w- C:\Windows\System32\deployJava1.dll
2012-07-01 02:32:40 -------- d-----w- D:\Windows7\Users\Travis\AppData\Roaming\.minecraft
2012-06-25 20:37:54 -------- d-----w- D:\Windows7\Program Files\Python 2.7.3 - 64 bit
2012-06-25 19:40:33 -------- d-----w- D:\Windows7\Program Files (x86)\Python 2.7.3
2012-06-25 19:39:02 -------- d-----w- D:\Windows7\Program Files (x86)\BOI_Gridzator
2012-06-25 03:04:19 7168 ----a-w- C:\Windows\SysWow64\shfoc580.rra
2012-06-25 03:04:19 21504 ----a-w- C:\Windows\SysWow64\versc580.rra
2012-06-25 03:04:19 15360 ----a-w- C:\Windows\SysWow64\wsocc58f.rra
2012-06-25 03:04:19 126464 ----a-w- C:\Windows\SysWow64\advpc551.rra
2012-06-25 02:56:10 7168 ----a-w- C:\Windows\SysWow64\shfoe678.rra
2012-06-25 02:56:10 21504 ----a-w- C:\Windows\SysWow64\verse687.rra
2012-06-25 02:56:10 15360 ----a-w- C:\Windows\SysWow64\wsoce697.rra
2012-06-25 02:56:10 126464 ----a-w- C:\Windows\SysWow64\advpe668.rra
2012-06-25 02:29:00 -------- d-----w- D:\Windows7\Users\Travis\AppData\Roaming\PowerUp Software
2012-06-25 02:29:00 -------- d-----w- D:\Windows7\ProgramData\PowerUp Software
2012-06-25 02:10:31 69715 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll
2012-06-25 02:10:31 5632 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe
2012-06-25 02:10:31 32768 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll
2012-06-25 02:10:31 266240 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll
2012-06-25 02:10:31 192512 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll
2012-06-25 02:10:30 724992 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll
2012-06-25 02:10:30 311428 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll
2012-06-25 02:10:30 184452 ----a-w- D:\Windows7\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll
2012-06-23 05:52:12 -------- d-----w- D:\Windows7\Users\Travis\AppData\Local\Macromedia
2012-06-21 23:10:34 224088 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys
2012-06-21 23:10:34 130904 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys
2012-06-21 23:10:31 -------- d-----w- D:\Windows7\Program Files\Oracle
2012-06-21 22:27:58 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-21 22:27:55 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-21 22:27:54 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-21 22:27:54 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-17 17:03:44 770384 ----a-w- D:\Windows7\Program Files (x86)\Mozilla Firefox\msvcr100.dll
2012-06-17 17:03:44 421200 ----a-w- D:\Windows7\Program Files (x86)\Mozilla Firefox\msvcp100.dll
2012-06-17 15:11:41 -------- d-----w- D:\Windows7\Users\Travis\AppData\Local\LogMeIn Hamachi
2012-06-17 15:11:31 -------- d-----w- D:\Windows7\Program Files (x86)\LogMeIn Hamachi
.
==================== Find3M ====================
.
2012-07-13 05:17:08 2519168 ----a-w- C:\Windows\PE_Rom.dll
2012-07-13 04:48:06 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-13 04:48:06 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-25 02:30:10 119296 ----a-w- C:\Windows\SysWow64\zlib.dll
2012-06-11 18:59:38 10248192 ----a-w- C:\Windows\System32\drivers\atikmdag.sys
2012-06-11 18:35:48 70144 ----a-w- C:\Windows\System32\coinst_8.98.dll
2012-06-11 18:29:34 24826368 ----a-w- C:\Windows\System32\atio6axx.dll
2012-06-11 18:00:32 20467712 ----a-w- C:\Windows\SysWow64\atioglxx.dll
2012-06-11 17:50:46 187392 ----a-w- C:\Windows\System32\clinfo.exe
2012-06-11 17:50:30 75264 ----a-w- C:\Windows\System32\OpenVideo64.dll
2012-06-11 17:50:24 65024 ----a-w- C:\Windows\SysWow64\OpenVideo.dll
2012-06-11 17:50:18 63488 ----a-w- C:\Windows\System32\OVDecode64.dll
2012-06-11 17:50:14 56320 ----a-w- C:\Windows\SysWow64\OVDecode.dll
2012-06-11 17:50:06 16457728 ----a-w- C:\Windows\System32\amdocl64.dll
2012-06-11 17:49:22 13008896 ----a-w- C:\Windows\SysWow64\amdocl.dll
2012-06-11 17:25:06 163840 ----a-w- C:\Windows\System32\atiapfxx.exe
2012-06-11 17:24:58 924160 ----a-w- C:\Windows\SysWow64\aticfx32.dll
2012-06-11 17:23:12 1090560 ----a-w- C:\Windows\System32\aticfx64.dll
2012-06-11 17:20:02 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll
2012-06-11 17:19:58 532992 ----a-w- C:\Windows\System32\atieclxx.exe
2012-06-11 17:19:14 239616 ----a-w- C:\Windows\System32\atiesrxx.exe
2012-06-11 17:17:56 120320 ----a-w- C:\Windows\System32\atitmm64.dll
2012-06-11 17:17:42 21504 ----a-w- C:\Windows\System32\atimuixx.dll
2012-06-11 17:17:38 59392 ----a-w- C:\Windows\System32\atiedu64.dll
2012-06-11 17:17:32 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll
2012-06-11 17:16:48 6301696 ----a-w- C:\Windows\SysWow64\atidxx32.dll
2012-06-11 17:01:56 6914560 ----a-w- C:\Windows\System32\atidxx64.dll
2012-06-11 16:51:54 4246528 ----a-w- C:\Windows\System32\atiumd6a.dll
2012-06-11 16:45:48 51200 ----a-w- C:\Windows\System32\aticalrt64.dll
2012-06-11 16:45:46 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll
2012-06-11 16:45:44 5480448 ----a-w- C:\Windows\SysWow64\atiumdag.dll
2012-06-11 16:45:40 44544 ----a-w- C:\Windows\System32\aticalcl64.dll
2012-06-11 16:45:38 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll
2012-06-11 16:45:26 15703040 ----a-w- C:\Windows\System32\aticaldd64.dll
2012-06-11 16:43:18 4729344 ----a-w- C:\Windows\SysWow64\atiumdva.dll
2012-06-11 16:40:58 13277696 ----a-w- C:\Windows\SysWow64\aticaldd.dll
2012-06-11 16:36:56 6605824 ----a-w- C:\Windows\System32\atiumd64.dll
2012-06-11 16:27:02 539136 ----a-w- C:\Windows\System32\atiadlxx.dll
2012-06-11 16:26:52 368640 ----a-w- C:\Windows\SysWow64\atiadlxy.dll
2012-06-11 16:26:40 17920 ----a-w- C:\Windows\System32\atig6pxx.dll
2012-06-11 16:26:36 14848 ----a-w- C:\Windows\SysWow64\atiglpxx.dll
2012-06-11 16:26:36 14848 ----a-w- C:\Windows\System32\atiglpxx.dll
2012-06-11 16:26:30 41984 ----a-w- C:\Windows\System32\atig6txx.dll
2012-06-11 16:26:22 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll
2012-06-11 16:26:14 367616 ----a-w- C:\Windows\System32\drivers\atikmpag.sys
2012-06-11 16:25:20 54784 ----a-w- C:\Windows\System32\atiuxp64.dll
2012-06-11 16:25:12 42496 ----a-w- C:\Windows\SysWow64\atiuxpag.dll
2012-06-11 16:25:06 45056 ----a-w- C:\Windows\System32\atiu9p64.dll
2012-06-11 16:24:58 32768 ----a-w- C:\Windows\SysWow64\atiu9pag.dll
2012-06-11 16:24:24 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll
2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\atimpc64.dll
2012-06-11 16:23:18 56320 ----a-w- C:\Windows\System32\amdpcom64.dll
2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\atimpc32.dll
2012-06-11 16:23:10 56832 ----a-w- C:\Windows\SysWow64\amdpcom32.dll
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-05 20:03:52 166232 ----a-w- C:\Windows\System32\drivers\VBoxNetFlt.sys
2012-06-05 20:03:52 147288 ----a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys
2012-06-05 20:02:22 320856 ----a-w- C:\Windows\System32\VBoxNetFltNobj.dll
2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-31 16:25:12 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-05-12 06:32:04 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys
2012-05-07 00:53:12 1120768 ----a-w- C:\Windows\System32\atiumd6v.dll
2012-05-07 00:49:41 1831424 ----a-w- C:\Windows\SysWow64\atiumdmv.dll
2012-05-07 00:42:19 95760 ----a-w- C:\Windows\System32\drivers\AtihdW76.sys
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 05:32:05 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
.
============= FINISH: 21:47:50.20 ===============