Johnny D
Posts: 14 +0
Built this new computer that runs Win 7 with a buddy who has done this numerous times on Friday, worked great all weekend.g
Today, Monday, all programs 3rd party or not, stop responding after ~20 seconds of uptime in Normal mode only.
Could not even be responsive long enough to do the preliminary steps as detailed in the pinned instruction threads all logs were done in safe mode.
Malware:
Malwarebytes Anti-Malware (Trial) 1.70.0.1100
www.malwarebytes.org
Database version: v2013.01.21.10
Windows 7 x64 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.7600.16385
John Daniel :: JOHNDANIEL-PC [administrator]
Protection: Disabled
1/21/2013 8:14:19 PM
mbam-log-2013-01-21 (20-14-19).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 225481
Time elapsed: 1 minute(s), 8 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 20
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\CLSID\{75A4D144-506D-4BE5-81DB-EC7DA1E7F840} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\TypeLib\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\esrv.funmoodsESrvc.1 (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\esrv.funmoodsESrvc (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\InstallCore\funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\InstallCore\funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 4
C:\Users\John Daniel\AppData\LocalLow\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\John Daniel\AppData\LocalLow\Funmoods\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\John Daniel\AppData\LocalLow\Funmoods\Funmoods\us (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\John Daniel\AppData\LocalLow\Funmoods\Funmoods\us\20101003 (PUP.FunMoods) -> Quarantined and deleted successfully.
Files Detected: 0
(No malicious items detected)
(end)
DDS:
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 8.0.7600.16385
Run by John Daniel at 20:25:26 on 2013-01-21
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8125.6809 [GMT -8:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\helppane.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=118564&tt=0313_6&babsrc=HP_ss&mntrId=b2bf64e6000000000000d43d7e357f9e
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10005&barid={942CD4B8-61FD-11E2-A437-D43D7E357F9E}
uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
mURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
mWinlogon: Userinit = userinit.exe,
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: smartdownloader Class: {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\Program Files (x86)\PutLockerDownloader\smarterdownloader.dll
TB: uTorrentControl_v2 Toolbar: {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [AdobeBridge] <no file>
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{8C3ECBB5-D9A9-47AD-95AA-B4D884D1D97C} : DHCPNameServer = 209.18.47.61 209.18.47.62
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://searchfunmoods.com/?f=1&a=nv1&ir=nv1&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0EtAyDyB0Fzy0EyCyE0EyCtN0D0Tzu0CtAzzyEtN1L2XzutBtFtBtFtCtFyEtDyB&cr=671711152
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2013-1-18 56208]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-1-18 676968]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-1-21 984144]
S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-1-21 370288]
S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-1-21 25232]
S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-1-21 71600]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-1-21 44808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-1-21 398184]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-1-21 682344]
S3 ElgatoGC658Y;Elgato Game Capture;C:\Windows\System32\drivers\ElgatoGC658.sys [2013-1-19 50288]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-1-21 24176]
S4 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-1-19 45056]
S4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-12-29 383416]
S4 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
.
=============== Created Last 30 ================
.
2013-01-22 04:02:14--------d-----w-C:\Users\John Daniel\AppData\Roaming\Malwarebytes
2013-01-22 04:02:12--------d-----w-C:\ProgramData\Malwarebytes
2013-01-22 04:02:1124176----a-w-C:\Windows\System32\drivers\mbam.sys
2013-01-22 04:02:11--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-22 04:02:04--------d-----w-C:\Users\John Daniel\AppData\Local\Programs
2013-01-21 23:07:27984144----a-w-C:\Windows\System32\drivers\aswSnx.sys
2013-01-21 23:07:2754072----a-w-C:\Windows\System32\drivers\aswRdr2.sys
2013-01-21 23:07:2571600----a-w-C:\Windows\System32\drivers\aswMonFlt.sys
2013-01-21 23:07:1341224----a-w-C:\Windows\avastSS.scr
2013-01-21 23:07:05--------d-----w-C:\ProgramData\AVAST Software
2013-01-21 23:07:05--------d-----w-C:\Program Files\AVAST Software
2013-01-21 22:55:122622464----a-w-C:\Windows\System32\wucltux.dll
2013-01-21 22:54:5299840----a-w-C:\Windows\System32\wudriver.dll
2013-01-21 22:54:4336864----a-w-C:\Windows\System32\wuapp.exe
2013-01-21 22:54:43186752----a-w-C:\Windows\System32\wuwebv.dll
2013-01-20 05:11:42--------d-----w-C:\Users\John Daniel\AppData\Local\Ico Converter
2013-01-20 05:11:08--------d-----w-C:\Program Files (x86)\Search_Spin
2013-01-20 05:10:56--------d-----w-C:\Program Files (x86)\Tomatosoft
2013-01-20 05:09:50--------d-----w-C:\Users\John Daniel\AppData\Local\Coupon Companion Plugin
2013-01-20 05:09:47--------d-----w-C:\Users\John Daniel\AppData\Local\Wajam
2013-01-20 05:09:47--------d-----w-C:\Program Files (x86)\Wajam
2013-01-20 05:09:44--------d-----w-C:\Program Files (x86)\Coupon Companion Plugin
2013-01-20 04:24:26--------d--h--w-C:\ProgramData\Common Files
2013-01-20 04:24:09--------d-----w-C:\Program Files (x86)\Stardock
2013-01-19 23:34:52--------d-----w-C:\Program Files (x86)\Smith Micro
2013-01-19 23:27:26332288----a-w-C:\Windows\System32\uxtheme.dll.backup
2013-01-19 23:27:252851328----a-w-C:\Windows\System32\themeui.dll.backup
2013-01-19 23:27:2344544----a-w-C:\Windows\System32\themeservice.dll.backup
2013-01-19 22:48:5550288----a-w-C:\Windows\System32\drivers\ElgatoGC658.sys
2013-01-19 22:48:55--------d-----w-C:\Program Files\Elgato
2013-01-19 22:48:44--------d-----w-C:\Users\John Daniel\AppData\Roaming\Elgato
2013-01-19 22:48:43--------d-----w-C:\Program Files (x86)\Elgato
2013-01-19 11:48:33--------d-----w-C:\Windows\Panther
2013-01-19 08:42:04--------d-----w-C:\Program Files (x86)\Common Files\BattlEye
2013-01-19 08:02:39--------d-----w-C:\Users\John Daniel\AppData\Roaming\PACE Anti-Piracy
2013-01-19 08:02:39--------d-----w-C:\Users\John Daniel\AppData\Local\PACE Anti-Piracy
2013-01-19 08:02:39--------d-----w-C:\ProgramData\PACE Anti-Piracy
2013-01-19 08:02:36--------d-----w-C:\Users\John Daniel\AppData\Roaming\NVIDIA
2013-01-19 08:02:19--------d-----w-C:\ProgramData\regid.1986-12.com.adobe
2013-01-19 07:58:06--------d-----w-C:\Windows\System32\appmgmt
2013-01-19 07:55:4756208------w-C:\Windows\System32\drivers\PxHlpa64.sys
2013-01-19 07:55:4710224------w-C:\Windows\System32\drivers\cdralw2k.sys
2013-01-19 07:55:4710224------w-C:\Windows\System32\drivers\cdr4_xp.sys
2013-01-19 07:55:47--------d-----w-C:\Program Files (x86)\Common Files\Sonic Shared
2013-01-19 07:55:47--------d-----w-C:\Program Files (x86)\Common Files\PX Storage Engine
2013-01-19 07:55:41--------d-----w-C:\Program Files (x86)\My Company Name
2013-01-19 07:36:24--------d-----w-C:\Users\John Daniel\AppData\Roaming\Babylon
2013-01-19 07:36:24--------d-----w-C:\ProgramData\Babylon
2013-01-19 06:09:05--------d-----w-C:\Users\John Daniel\AppData\Local\ArmA 2
2013-01-19 06:09:03--------d-----w-C:\Program Files (x86)\Bohemia Interactive
2013-01-19 06:02:5968104----a-w-C:\Windows\System32\XAPOFX1_0.dll
2013-01-19 06:01:18--------d-----w-C:\Users\John Daniel\AppData\Local\SwvUpdater
2013-01-19 06:01:06--------d-----w-C:\Users\John Daniel\AppData\Local\DayZCommander
2013-01-19 06:00:52--------d-----w-C:\Program Files (x86)\SweetIM
2013-01-19 06:00:33--------d-----w-C:\ProgramData\CLSoft LTD
2013-01-19 06:00:26--------d-----w-C:\ProgramData\Zoomex
2013-01-19 06:00:21--------d-----w-C:\ProgramData\InstallMate
2013-01-19 05:58:59--------d-----w-C:\Program Files (x86)\Dotjosh Studios
2013-01-19 05:47:4199176----a-w-C:\Windows\SysWow64\PresentationHostProxy.dll
2013-01-19 05:47:4149472----a-w-C:\Windows\SysWow64\netfxperf.dll
2013-01-19 05:47:4148960----a-w-C:\Windows\System32\netfxperf.dll
2013-01-19 05:47:41444752----a-w-C:\Windows\System32\mscoree.dll
2013-01-19 05:47:41320352----a-w-C:\Windows\System32\PresentationHost.exe
2013-01-19 05:47:41297808----a-w-C:\Windows\SysWow64\mscoree.dll
2013-01-19 05:47:41295264----a-w-C:\Windows\SysWow64\PresentationHost.exe
2013-01-19 05:47:411942856----a-w-C:\Windows\System32\dfshim.dll
2013-01-19 05:47:411130824----a-w-C:\Windows\SysWow64\dfshim.dll
2013-01-19 05:47:41109912----a-w-C:\Windows\System32\PresentationHostProxy.dll
2013-01-19 05:27:56--------d-----w-C:\Users\John Daniel\AppData\Local\Adobe
2013-01-19 04:54:32--------d-----w-C:\Users\John Daniel\AppData\Roaming\Funmoods
2013-01-19 04:54:16--------d-----w-C:\Users\John Daniel\AppData\Local\PutLockerDownloader
2013-01-19 04:54:14--------d-----w-C:\ProgramData\Tarma Installer
2013-01-19 04:54:13--------d-----w-C:\Program Files (x86)\PutLockerDownloader
2013-01-19 04:47:33--------d-----w-C:\Users\John Daniel\AppData\Roaming\XBMC
2013-01-19 04:46:08--------d-----w-C:\Program Files (x86)\XBMC
2013-01-19 04:38:45--------d-----w-C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-01-19 04:36:16--------d-----w-C:\Users\John Daniel\AppData\Local\Apple Computer
2013-01-19 04:36:1133240----a-w-C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-01-19 04:35:48--------d-----w-C:\Program Files\iPod
2013-01-19 04:35:47--------d-----w-C:\Program Files\iTunes
2013-01-19 04:35:47--------d-----w-C:\Program Files (x86)\iTunes
2013-01-19 04:35:22--------d-----w-C:\Users\John Daniel\AppData\Local\Apple
2013-01-19 04:35:02--------d-----w-C:\Program Files\Bonjour
2013-01-19 04:35:02--------d-----w-C:\Program Files (x86)\Bonjour
2013-01-19 04:02:04884152----a-w-C:\Windows\System32\nvvsvc.exe
2013-01-19 04:02:0463928----a-w-C:\Windows\System32\nvshext.dll
2013-01-19 04:02:046382008----a-w-C:\Windows\System32\nvcpl.dll
2013-01-19 04:02:043455416----a-w-C:\Windows\System32\nvsvc64.dll
2013-01-19 04:02:042923201----a-w-C:\Windows\System32\nvcoproc.bin
2013-01-19 04:02:04118712----a-w-C:\Windows\System32\nvmctray.dll
2013-01-19 03:55:0777656----a-w-C:\Windows\System32\XAPOFX1_5.dll
2013-01-19 03:35:46--------d-----w-C:\Users\John Daniel\AppData\Roaming\Nico Mak Computing
2013-01-19 03:35:4318760----a-w-C:\Windows\System32\roboot64.exe
2013-01-19 03:35:42--------d-----w-C:\Program Files (x86)\WinZip Registry Optimizer
2013-01-19 03:35:39--------d-----w-C:\Users\John Daniel\AppData\Local\CRE
2013-01-19 03:35:37--------d-----w-C:\Program Files (x86)\Conduit
2013-01-19 03:35:36--------d-----w-C:\Users\John Daniel\AppData\Local\Conduit
2013-01-19 03:35:35--------d-----w-C:\Program Files (x86)\uTorrentControl_v2
2013-01-19 03:34:43--------d-----w-C:\Users\John Daniel\AppData\Roaming\uTorrent
2013-01-19 03:11:559161176----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A9D6CB93-784F-4B01-BCA7-F2DCF283F804}\mpengine.dll
2013-01-19 03:11:54279656------w-C:\Windows\System32\MpSigStub.exe
2013-01-19 03:02:43--------d-----w-C:\Program Files (x86)\Steam
2013-01-19 03:02:43--------d-----w-C:\Program Files (x86)\Common Files\Steam
2013-01-19 03:00:42--------d-sh--w-C:\Windows\Installer
2013-01-19 02:57:48--------d-----w-C:\Users\John Daniel\AppData\Local\Google
2013-01-19 02:56:46--------d-----w-C:\Users\John Daniel\AppData\Local\Deployment
2013-01-19 02:56:46--------d-----w-C:\Users\John Daniel\AppData\Local\Apps
2013-01-18 20:04:59712296----a-w-C:\Windows\System32\DTSSymmetryDLL64.dll
2013-01-18 20:03:15--------d-----w-C:\Program Files (x86)\Realtek
2013-01-18 20:01:1553248----a-w-C:\Windows\SysWow64\CSVer.dll
2013-01-18 20:01:08--------d-----w-C:\Intel
2013-01-18 20:00:54--------d-----w-C:\MSI
2013-01-18 19:55:45--------d-sh--w-C:\Recovery
2012-12-29 10:54:24550328----a-w-C:\Windows\SysWow64\nvStreaming.exe
.
==================== Find3M ====================
.
2012-12-19 21:53:041275392----a-w-C:\Windows\SysWow64\msxml4.dll
2012-12-19 21:53:0282432----a-w-C:\Windows\SysWow64\msxml4r.dll
.
============= FINISH: 20:25:39.45 ===============
Today, Monday, all programs 3rd party or not, stop responding after ~20 seconds of uptime in Normal mode only.
Could not even be responsive long enough to do the preliminary steps as detailed in the pinned instruction threads all logs were done in safe mode.
Malware:
Malwarebytes Anti-Malware (Trial) 1.70.0.1100
www.malwarebytes.org
Database version: v2013.01.21.10
Windows 7 x64 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.7600.16385
John Daniel :: JOHNDANIEL-PC [administrator]
Protection: Disabled
1/21/2013 8:14:19 PM
mbam-log-2013-01-21 (20-14-19).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 225481
Time elapsed: 1 minute(s), 8 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 20
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\CLSID\{75A4D144-506D-4BE5-81DB-EC7DA1E7F840} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\TypeLib\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\esrv.funmoodsESrvc.1 (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCR\esrv.funmoodsESrvc (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A} (PUP.Funmoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\InstallCore\funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\InstallCore\funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 4
C:\Users\John Daniel\AppData\LocalLow\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\John Daniel\AppData\LocalLow\Funmoods\Funmoods (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\John Daniel\AppData\LocalLow\Funmoods\Funmoods\us (PUP.FunMoods) -> Quarantined and deleted successfully.
C:\Users\John Daniel\AppData\LocalLow\Funmoods\Funmoods\us\20101003 (PUP.FunMoods) -> Quarantined and deleted successfully.
Files Detected: 0
(No malicious items detected)
(end)
DDS:
DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 8.0.7600.16385
Run by John Daniel at 20:25:26 on 2013-01-21
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8125.6809 [GMT -8:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\helppane.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=118564&tt=0313_6&babsrc=HP_ss&mntrId=b2bf64e6000000000000d43d7e357f9e
mStart Page = hxxp://home.sweetim.com/?crg=3.1010000.10005&barid={942CD4B8-61FD-11E2-A437-D43D7E357F9E}
uURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
mURLSearchHooks: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
mWinlogon: Userinit = userinit.exe,
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: smartdownloader Class: {F1AF26F8-1828-4279-ABCE-074EF3235BD7} - C:\Program Files (x86)\PutLockerDownloader\smarterdownloader.dll
TB: uTorrentControl_v2 Toolbar: {7473B6BD-4691-4744-A82B-7854EB3D70B6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - C:\Program Files (x86)\uTorrentControl_v2\prxtbuTor.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [AdobeBridge] <no file>
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{8C3ECBB5-D9A9-47AD-95AA-B4D884D1D97C} : DHCPNameServer = 209.18.47.61 209.18.47.62
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\Installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://searchfunmoods.com/?f=1&a=nv1&ir=nv1&cd=2XzuyEtN2Y1L1Qzu0DyEtA0DyB0EtAyDyB0Fzy0EyCyE0EyCtN0D0Tzu0CtAzzyEtN1L2XzutBtFtBtFtCtFyEtDyB&cr=671711152
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2013-1-18 56208]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-1-18 676968]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-1-21 984144]
S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-1-21 370288]
S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-1-21 25232]
S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-1-21 71600]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-1-21 44808]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-1-21 398184]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-1-21 682344]
S3 ElgatoGC658Y;Elgato Game Capture;C:\Windows\System32\drivers\ElgatoGC658.sys [2013-1-19 50288]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-1-21 24176]
S4 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-1-19 45056]
S4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-12-29 383416]
S4 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
.
=============== Created Last 30 ================
.
2013-01-22 04:02:14--------d-----w-C:\Users\John Daniel\AppData\Roaming\Malwarebytes
2013-01-22 04:02:12--------d-----w-C:\ProgramData\Malwarebytes
2013-01-22 04:02:1124176----a-w-C:\Windows\System32\drivers\mbam.sys
2013-01-22 04:02:11--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-01-22 04:02:04--------d-----w-C:\Users\John Daniel\AppData\Local\Programs
2013-01-21 23:07:27984144----a-w-C:\Windows\System32\drivers\aswSnx.sys
2013-01-21 23:07:2754072----a-w-C:\Windows\System32\drivers\aswRdr2.sys
2013-01-21 23:07:2571600----a-w-C:\Windows\System32\drivers\aswMonFlt.sys
2013-01-21 23:07:1341224----a-w-C:\Windows\avastSS.scr
2013-01-21 23:07:05--------d-----w-C:\ProgramData\AVAST Software
2013-01-21 23:07:05--------d-----w-C:\Program Files\AVAST Software
2013-01-21 22:55:122622464----a-w-C:\Windows\System32\wucltux.dll
2013-01-21 22:54:5299840----a-w-C:\Windows\System32\wudriver.dll
2013-01-21 22:54:4336864----a-w-C:\Windows\System32\wuapp.exe
2013-01-21 22:54:43186752----a-w-C:\Windows\System32\wuwebv.dll
2013-01-20 05:11:42--------d-----w-C:\Users\John Daniel\AppData\Local\Ico Converter
2013-01-20 05:11:08--------d-----w-C:\Program Files (x86)\Search_Spin
2013-01-20 05:10:56--------d-----w-C:\Program Files (x86)\Tomatosoft
2013-01-20 05:09:50--------d-----w-C:\Users\John Daniel\AppData\Local\Coupon Companion Plugin
2013-01-20 05:09:47--------d-----w-C:\Users\John Daniel\AppData\Local\Wajam
2013-01-20 05:09:47--------d-----w-C:\Program Files (x86)\Wajam
2013-01-20 05:09:44--------d-----w-C:\Program Files (x86)\Coupon Companion Plugin
2013-01-20 04:24:26--------d--h--w-C:\ProgramData\Common Files
2013-01-20 04:24:09--------d-----w-C:\Program Files (x86)\Stardock
2013-01-19 23:34:52--------d-----w-C:\Program Files (x86)\Smith Micro
2013-01-19 23:27:26332288----a-w-C:\Windows\System32\uxtheme.dll.backup
2013-01-19 23:27:252851328----a-w-C:\Windows\System32\themeui.dll.backup
2013-01-19 23:27:2344544----a-w-C:\Windows\System32\themeservice.dll.backup
2013-01-19 22:48:5550288----a-w-C:\Windows\System32\drivers\ElgatoGC658.sys
2013-01-19 22:48:55--------d-----w-C:\Program Files\Elgato
2013-01-19 22:48:44--------d-----w-C:\Users\John Daniel\AppData\Roaming\Elgato
2013-01-19 22:48:43--------d-----w-C:\Program Files (x86)\Elgato
2013-01-19 11:48:33--------d-----w-C:\Windows\Panther
2013-01-19 08:42:04--------d-----w-C:\Program Files (x86)\Common Files\BattlEye
2013-01-19 08:02:39--------d-----w-C:\Users\John Daniel\AppData\Roaming\PACE Anti-Piracy
2013-01-19 08:02:39--------d-----w-C:\Users\John Daniel\AppData\Local\PACE Anti-Piracy
2013-01-19 08:02:39--------d-----w-C:\ProgramData\PACE Anti-Piracy
2013-01-19 08:02:36--------d-----w-C:\Users\John Daniel\AppData\Roaming\NVIDIA
2013-01-19 08:02:19--------d-----w-C:\ProgramData\regid.1986-12.com.adobe
2013-01-19 07:58:06--------d-----w-C:\Windows\System32\appmgmt
2013-01-19 07:55:4756208------w-C:\Windows\System32\drivers\PxHlpa64.sys
2013-01-19 07:55:4710224------w-C:\Windows\System32\drivers\cdralw2k.sys
2013-01-19 07:55:4710224------w-C:\Windows\System32\drivers\cdr4_xp.sys
2013-01-19 07:55:47--------d-----w-C:\Program Files (x86)\Common Files\Sonic Shared
2013-01-19 07:55:47--------d-----w-C:\Program Files (x86)\Common Files\PX Storage Engine
2013-01-19 07:55:41--------d-----w-C:\Program Files (x86)\My Company Name
2013-01-19 07:36:24--------d-----w-C:\Users\John Daniel\AppData\Roaming\Babylon
2013-01-19 07:36:24--------d-----w-C:\ProgramData\Babylon
2013-01-19 06:09:05--------d-----w-C:\Users\John Daniel\AppData\Local\ArmA 2
2013-01-19 06:09:03--------d-----w-C:\Program Files (x86)\Bohemia Interactive
2013-01-19 06:02:5968104----a-w-C:\Windows\System32\XAPOFX1_0.dll
2013-01-19 06:01:18--------d-----w-C:\Users\John Daniel\AppData\Local\SwvUpdater
2013-01-19 06:01:06--------d-----w-C:\Users\John Daniel\AppData\Local\DayZCommander
2013-01-19 06:00:52--------d-----w-C:\Program Files (x86)\SweetIM
2013-01-19 06:00:33--------d-----w-C:\ProgramData\CLSoft LTD
2013-01-19 06:00:26--------d-----w-C:\ProgramData\Zoomex
2013-01-19 06:00:21--------d-----w-C:\ProgramData\InstallMate
2013-01-19 05:58:59--------d-----w-C:\Program Files (x86)\Dotjosh Studios
2013-01-19 05:47:4199176----a-w-C:\Windows\SysWow64\PresentationHostProxy.dll
2013-01-19 05:47:4149472----a-w-C:\Windows\SysWow64\netfxperf.dll
2013-01-19 05:47:4148960----a-w-C:\Windows\System32\netfxperf.dll
2013-01-19 05:47:41444752----a-w-C:\Windows\System32\mscoree.dll
2013-01-19 05:47:41320352----a-w-C:\Windows\System32\PresentationHost.exe
2013-01-19 05:47:41297808----a-w-C:\Windows\SysWow64\mscoree.dll
2013-01-19 05:47:41295264----a-w-C:\Windows\SysWow64\PresentationHost.exe
2013-01-19 05:47:411942856----a-w-C:\Windows\System32\dfshim.dll
2013-01-19 05:47:411130824----a-w-C:\Windows\SysWow64\dfshim.dll
2013-01-19 05:47:41109912----a-w-C:\Windows\System32\PresentationHostProxy.dll
2013-01-19 05:27:56--------d-----w-C:\Users\John Daniel\AppData\Local\Adobe
2013-01-19 04:54:32--------d-----w-C:\Users\John Daniel\AppData\Roaming\Funmoods
2013-01-19 04:54:16--------d-----w-C:\Users\John Daniel\AppData\Local\PutLockerDownloader
2013-01-19 04:54:14--------d-----w-C:\ProgramData\Tarma Installer
2013-01-19 04:54:13--------d-----w-C:\Program Files (x86)\PutLockerDownloader
2013-01-19 04:47:33--------d-----w-C:\Users\John Daniel\AppData\Roaming\XBMC
2013-01-19 04:46:08--------d-----w-C:\Program Files (x86)\XBMC
2013-01-19 04:38:45--------d-----w-C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-01-19 04:36:16--------d-----w-C:\Users\John Daniel\AppData\Local\Apple Computer
2013-01-19 04:36:1133240----a-w-C:\Windows\System32\drivers\GEARAspiWDM.sys
2013-01-19 04:35:48--------d-----w-C:\Program Files\iPod
2013-01-19 04:35:47--------d-----w-C:\Program Files\iTunes
2013-01-19 04:35:47--------d-----w-C:\Program Files (x86)\iTunes
2013-01-19 04:35:22--------d-----w-C:\Users\John Daniel\AppData\Local\Apple
2013-01-19 04:35:02--------d-----w-C:\Program Files\Bonjour
2013-01-19 04:35:02--------d-----w-C:\Program Files (x86)\Bonjour
2013-01-19 04:02:04884152----a-w-C:\Windows\System32\nvvsvc.exe
2013-01-19 04:02:0463928----a-w-C:\Windows\System32\nvshext.dll
2013-01-19 04:02:046382008----a-w-C:\Windows\System32\nvcpl.dll
2013-01-19 04:02:043455416----a-w-C:\Windows\System32\nvsvc64.dll
2013-01-19 04:02:042923201----a-w-C:\Windows\System32\nvcoproc.bin
2013-01-19 04:02:04118712----a-w-C:\Windows\System32\nvmctray.dll
2013-01-19 03:55:0777656----a-w-C:\Windows\System32\XAPOFX1_5.dll
2013-01-19 03:35:46--------d-----w-C:\Users\John Daniel\AppData\Roaming\Nico Mak Computing
2013-01-19 03:35:4318760----a-w-C:\Windows\System32\roboot64.exe
2013-01-19 03:35:42--------d-----w-C:\Program Files (x86)\WinZip Registry Optimizer
2013-01-19 03:35:39--------d-----w-C:\Users\John Daniel\AppData\Local\CRE
2013-01-19 03:35:37--------d-----w-C:\Program Files (x86)\Conduit
2013-01-19 03:35:36--------d-----w-C:\Users\John Daniel\AppData\Local\Conduit
2013-01-19 03:35:35--------d-----w-C:\Program Files (x86)\uTorrentControl_v2
2013-01-19 03:34:43--------d-----w-C:\Users\John Daniel\AppData\Roaming\uTorrent
2013-01-19 03:11:559161176----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A9D6CB93-784F-4B01-BCA7-F2DCF283F804}\mpengine.dll
2013-01-19 03:11:54279656------w-C:\Windows\System32\MpSigStub.exe
2013-01-19 03:02:43--------d-----w-C:\Program Files (x86)\Steam
2013-01-19 03:02:43--------d-----w-C:\Program Files (x86)\Common Files\Steam
2013-01-19 03:00:42--------d-sh--w-C:\Windows\Installer
2013-01-19 02:57:48--------d-----w-C:\Users\John Daniel\AppData\Local\Google
2013-01-19 02:56:46--------d-----w-C:\Users\John Daniel\AppData\Local\Deployment
2013-01-19 02:56:46--------d-----w-C:\Users\John Daniel\AppData\Local\Apps
2013-01-18 20:04:59712296----a-w-C:\Windows\System32\DTSSymmetryDLL64.dll
2013-01-18 20:03:15--------d-----w-C:\Program Files (x86)\Realtek
2013-01-18 20:01:1553248----a-w-C:\Windows\SysWow64\CSVer.dll
2013-01-18 20:01:08--------d-----w-C:\Intel
2013-01-18 20:00:54--------d-----w-C:\MSI
2013-01-18 19:55:45--------d-sh--w-C:\Recovery
2012-12-29 10:54:24550328----a-w-C:\Windows\SysWow64\nvStreaming.exe
.
==================== Find3M ====================
.
2012-12-19 21:53:041275392----a-w-C:\Windows\SysWow64\msxml4.dll
2012-12-19 21:53:0282432----a-w-C:\Windows\SysWow64\msxml4r.dll
.
============= FINISH: 20:25:39.45 ===============