I'm have a problem with links that I click being re-directed to other websites. Sometimes the correct website will open but another tab is opened with another site, and sometimes the correct link doesn't open at all and is re-directed to somewhere else. I have pasted some logs below:
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.11.03
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Chris :: EEE-PC [administrator]
8/11/2012 12:44:12 PM
mbam-log-2012-08-11 (12-44-12).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 191730
Time elapsed: 8 minute(s), 54 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\00000004.@ (Rootkit.Zaccess) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\80000000.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-11 13:04:30
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST916031 rev.0002
Running: ent2rgeu.exe; Driver: C:\Users\Chris\AppData\Local\Temp\uwldapow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/2/2010 1:43:20 PM
System Uptime: 8/11/2012 12:55:23 PM (1 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | 1005HA
Processor: Intel(R) Atom(TM) CPU N280 @ 1.66GHz | PBGA 437 | 1667/167mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 44 GiB total, 20.396 GiB free.
D: is FIXED (NTFS) - 100 GiB total, 79.274 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP386: 8/9/2012 12:20:33 PM - Windows Update
.
==== Installed Programs ======================
.
µTorrent
7-Zip 4.65
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.2 Lite
Adobe Shockwave Player 11.6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ASUSUpdate for Eee PC
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Bonjour
CCleaner
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
D3DX10
DivX Web Player
Driver Genius Professional Edition
EASEUS Partition Master 8.0.1 Home Edition
eReg
Google Chrome
Google Earth
Google Update Helper
Hotkey Service
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 33
Logitech SetPoint 6.30
Malwarebytes Anti-Malware version 1.62.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 14.0.1 (x86 en-US)
Mp3tag v2.45a
MSVCRT
OpenOffice.org 3.2
Qualcomm Atheros WiFi Driver Installation
QuickTime
Ralink RT2860 Wireless LAN Card
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
RunRev LiveCode Player Browser Plugin
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7
Skype Click to Call
Skype™ 5.10
SopCast 3.4.8
SRS Premium Sound Control Panel
Super Hybrid Engine
SUPERAntiSpyware
swMSM
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
VC80CRTRedist - 8.0.50727.6195
Veetle TV
VLC media player 1.1.11
Winamp
Winamp Application Detect
WinDjView 1.0.3
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Wolfram CDF Player (M-WIN-D 8.0.3 2427703)
.
==== Event Viewer Messages From Past Week ========
.
8/9/2012 6:41:36 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
8/9/2012 6:41:36 AM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
8/8/2012 11:36:08 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
8/7/2012 2:40:00 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
8/11/2012 12:55:42 PM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891
8/11/2012 12:55:42 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
8/11/2012 12:55:41 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
8/11/2012 12:55:41 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
.
==== End Of File ===========================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_33
Run by Chris at 13:06:08 on 2012-08-11
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2039.1162 [GMT -7:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\System32\AsusService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
"C:\Windows\System32\svchost.exe" -k LocalServiceDns
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [HotKeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [SuperHybridEngine] AsusSender.exe c:\program files\eeepc\she\SuperHybridEngine.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\iastoriconlaunch.exe "c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe" 60
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\14C657D60225F636B6 : DhcpNameServer = 10.255.255.33 10.255.255.32
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\16474777966696 : DhcpNameServer = 192.168.6.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\245627279756373716 : DhcpNameServer = 10.255.255.33 10.255.255.32
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\353434C4 : DhcpNameServer = 10.21.1.21 10.21.1.22
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\5467562776275656E6 : DhcpNameServer = 10.255.255.33 10.255.255.32
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\64F6F6478696C6C6027457563747 : DhcpNameServer = 153.18.144.8 153.18.96.30
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\75169707F62747F5143636563737 : DhcpNameServer = 192.168.5.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{D47D2BF9-3728-4A80-858F-B2C11E1DEF7B} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\chris\appdata\roaming\mozilla\firefox\profiles\ilgz0zir.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\millisecond software\inquisit 3.0 mozilla plugin\npInquisit_3060.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\chris\appdata\local\runrev\components\livecodeplayer\9\nplcplugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-1-2 11448]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608]
R2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2010-1-2 219136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2011-3-28 13632]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2011-8-11 88176]
R3 vjoy;vJoy Device;c:\windows\system32\drivers\vjoy.sys [2011-6-26 13184]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-3 135664]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-31 250056]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-5-1 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-5-1 8456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-3 135664]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]
S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [2004-1-23 13952]
S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [2004-1-23 28800]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2011-1-27 47176]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\drivers\silabser.sys [2011-1-27 58496]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-2-23 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-2-26 1343400]
.
=============== Created Last 30 ================
.
2012-08-11 18:08:57 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-08-11 04:00:48 -------- d-----w- c:\users\chris\appdata\local\{632B55E7-1947-415C-A1F0-180244CABD24}
2012-08-11 04:00:36 -------- d-----w- c:\users\chris\appdata\local\{3D985EE6-25FE-4E97-8EC5-CD5FC1D6444D}
2012-08-10 16:00:03 -------- d-----w- c:\users\chris\appdata\local\{3AA71FA9-56FF-4A6A-B4FE-5D613AD4CE6A}
2012-08-10 15:59:48 -------- d-----w- c:\users\chris\appdata\local\{065C03EA-2213-45E0-83E4-8460FCE0E81A}
2012-08-10 03:59:18 -------- d-----w- c:\users\chris\appdata\local\{E9D560EA-D8B1-4805-9D8F-84E3684988EE}
2012-08-10 03:59:05 -------- d-----w- c:\users\chris\appdata\local\{FFA51CFD-D5B4-4C71-B21C-61653D44B0EF}
2012-08-09 15:58:35 -------- d-----w- c:\users\chris\appdata\local\{B9888C0B-7A0C-4216-8C13-2D63BCFE416A}
2012-08-09 15:58:22 -------- d-----w- c:\users\chris\appdata\local\{BC25A299-0327-4A24-BC4F-A2396D120333}
2012-08-08 23:42:58 -------- d-----w- c:\program files\CCleaner
2012-08-08 23:12:44 -------- d-----w- c:\users\chris\appdata\roaming\IrfanView
2012-08-08 23:12:41 -------- d-----w- c:\program files\IrfanView
2012-08-08 20:13:58 -------- d-----w- c:\programdata\Qualcomm Atheros
2012-08-08 20:02:15 1379760 ----a-w- c:\windows\system32\tosade.dll
2012-08-08 20:02:14 819648 ----a-w- c:\windows\system32\tadefxapo2.dll
2012-08-08 20:02:14 58264 ----a-w- c:\windows\system32\TepeqAPO.dll
2012-08-08 20:02:14 134584 ----a-w- c:\windows\system32\tadefxapo.dll
2012-08-08 20:02:03 1497704 ----a-w- c:\windows\system32\RTSndMgr.cpl
2012-08-08 20:02:01 3240400 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2012-08-08 20:02:01 2417808 ----a-w- c:\windows\system32\RtkPgExt.dll
2012-08-08 18:52:40 -------- d-----w- c:\users\chris\appdata\local\{C40F72D8-E66E-40EE-9240-EC7FD0BBF265}
2012-08-08 18:52:16 -------- d-----w- c:\users\chris\appdata\local\{2835313F-3C3F-4E51-A9A3-9EB19466F5E9}
2012-08-08 06:51:37 -------- d-----w- c:\users\chris\appdata\local\{A184D6C7-5E41-4E5C-B622-9CE4BED7F5F4}
2012-08-08 06:51:18 -------- d-----w- c:\users\chris\appdata\local\{50CCB122-4724-411A-8C23-F0DDA3467FCD}
2012-08-07 04:55:18 -------- d-----w- c:\users\chris\appdata\local\{A8DF6BB4-22B5-44F2-82CC-446121916175}
2012-08-07 04:55:05 -------- d-----w- c:\users\chris\appdata\local\{6AA3941B-D988-42B9-9D4A-D332B3DC530A}
2012-08-06 06:52:06 -------- d-----w- c:\users\chris\appdata\local\{3C738986-F70B-46F9-B334-AB24CB66D078}
2012-08-06 06:51:52 -------- d-----w- c:\users\chris\appdata\local\{F58B9F7A-A977-4DFC-A26C-DFA527982838}
2012-08-05 17:42:05 -------- d-----w- c:\users\chris\appdata\local\{69736EEC-C685-435F-A3F1-85177E01C58E}
2012-08-05 17:41:46 -------- d-----w- c:\users\chris\appdata\local\{A4D90CC7-0BE7-4AEA-9563-740D0E486057}
2012-08-05 05:13:15 -------- d-----w- c:\users\chris\appdata\local\{F8A2785C-A5DB-4CE8-9EE1-9E3C0E3F1926}
2012-08-05 05:12:58 -------- d-----w- c:\users\chris\appdata\local\{5C185527-0E48-4D97-B04B-2E88E8B77F15}
2012-08-04 17:12:37 -------- d-----w- c:\users\chris\appdata\local\{4A98F3ED-0F16-4ECA-B127-EA336189998F}
2012-08-04 17:12:21 -------- d-----w- c:\users\chris\appdata\local\{D4C2B4FE-BECF-4D29-BEB2-E2F8AC20AF23}
2012-08-04 04:46:16 -------- d-----w- c:\users\chris\appdata\local\{C0827F19-4FC3-4E6A-AE9C-89723247EB87}
2012-08-04 04:45:59 -------- d-----w- c:\users\chris\appdata\local\{699837E5-7A24-43F0-A5A2-530284DF4E20}
2012-08-03 15:33:45 -------- d-----w- c:\users\chris\appdata\local\{D8573E12-CADF-4E79-A2CA-C2A949FB0AE5}
2012-08-03 15:33:32 -------- d-----w- c:\users\chris\appdata\local\{EEF7FC5C-6972-4004-A2B6-0466EF3E1889}
2012-08-02 17:31:06 -------- d-----w- c:\users\chris\appdata\local\{4BD862A0-49C6-4F71-98A6-91DC47CC1735}
2012-08-02 17:30:53 -------- d-----w- c:\users\chris\appdata\local\{A9CD17B3-729E-4F8E-B58F-714F7D8E9739}
2012-08-02 05:30:35 -------- d-----w- c:\users\chris\appdata\local\{7101958E-41F1-45AC-BFED-98DFCF0E0764}
2012-08-02 05:30:21 -------- d-----w- c:\users\chris\appdata\local\{D2EAD98E-5DE5-4369-BF34-3D206341A6ED}
2012-08-01 06:28:35 -------- d-----w- c:\users\chris\appdata\local\{AC4FFEAD-184D-4AEB-AEF2-96E13118905D}
2012-08-01 06:28:18 -------- d-----w- c:\users\chris\appdata\local\{CB97313B-8C2C-4E09-926D-5614E423AB0D}
2012-07-31 06:04:18 -------- d-----w- c:\users\chris\appdata\local\{06E9089B-54A1-4712-8C5D-46511116CBF6}
2012-07-31 06:04:05 -------- d-----w- c:\users\chris\appdata\local\{60C56BB9-10F3-46E5-B295-E20AF6844B57}
2012-07-30 17:44:26 -------- d-----w- c:\users\chris\appdata\local\{4F5C962F-EA75-4989-AEA6-0172A57BE411}
2012-07-30 17:44:04 -------- d-----w- c:\users\chris\appdata\local\{C3C15045-1C84-47A1-81CE-5EA8691659B3}
2012-07-29 20:14:09 -------- d-----w- c:\users\chris\appdata\local\{DB6D64B9-BDF8-4397-9430-C8D8B93BA384}
2012-07-29 20:13:57 -------- d-----w- c:\users\chris\appdata\local\{5547DB44-1D70-4DB3-8702-507E42CBAB2B}
2012-07-29 08:13:43 -------- d-----w- c:\users\chris\appdata\local\{AF426123-352F-4D62-ACF0-9DD9AF9BDB5A}
2012-07-29 08:13:31 -------- d-----w- c:\users\chris\appdata\local\{B076B4E5-2EC9-439D-ABBE-90E9D40D3B20}
2012-07-28 20:13:13 -------- d-----w- c:\users\chris\appdata\local\{B3301479-89C6-4678-9682-5F3FAAEE965F}
2012-07-28 20:13:00 -------- d-----w- c:\users\chris\appdata\local\{EAF5B5CD-E67C-46B6-86E3-4894D38038BD}
2012-07-28 04:46:30 -------- d-----w- c:\users\chris\appdata\local\{5E2499DD-D251-47A6-A504-228178455DB1}
2012-07-28 04:46:18 -------- d-----w- c:\users\chris\appdata\local\{50754E6E-F137-46E2-8AFA-68388844421C}
2012-07-28 02:11:21 -------- d-----w- c:\users\chris\appdata\local\{D340074E-0FD2-4EE0-B502-5EAFB3C19835}
2012-07-26 05:27:42 -------- d-----w- c:\users\chris\appdata\local\{4D040D0E-F44C-4998-827C-AC22D030EDF9}
2012-07-26 05:27:30 -------- d-----w- c:\users\chris\appdata\local\{8EA90FEA-E9CE-4851-981F-AE98D9527C03}
2012-07-25 17:27:11 -------- d-----w- c:\users\chris\appdata\local\{B351623D-1F54-47FB-B5C0-29BDED67C5E1}
2012-07-25 17:26:52 -------- d-----w- c:\users\chris\appdata\local\{F26E069E-0243-4F73-9853-CE8D90A44707}
2012-07-25 05:26:37 -------- d-----w- c:\users\chris\appdata\local\{66829252-6897-4C5F-9C63-6E33C56E7917}
2012-07-25 05:26:23 -------- d-----w- c:\users\chris\appdata\local\{9FCC422F-6894-48E6-97F2-28730296F7D8}
2012-07-24 00:10:52 -------- d-----w- c:\users\chris\appdata\local\{FEEF416A-9198-4819-B428-22684AD26221}
2012-07-24 00:10:37 -------- d-----w- c:\users\chris\appdata\local\{EE7CA870-3D4E-4899-9555-DFBE3E8EDB89}
2012-07-22 04:09:13 -------- d-----w- c:\users\chris\appdata\local\{2665A19A-40C8-4412-9434-1FCCC9028CAC}
2012-07-22 04:08:58 -------- d-----w- c:\users\chris\appdata\local\{73C82EF8-6960-43AD-84A4-42AB416A9323}
2012-07-21 06:52:33 -------- d-----w- c:\users\chris\appdata\local\{D591B279-3348-40B8-9326-12DABBA1050C}
2012-07-21 06:52:19 -------- d-----w- c:\users\chris\appdata\local\{A6A61F19-334C-4FF7-908B-A743851A6A1A}
2012-07-19 18:07:06 -------- d-----w- c:\users\chris\appdata\local\{0B8E78D3-63BD-476A-B71E-74063052CC97}
2012-07-19 18:06:49 -------- d-----w- c:\users\chris\appdata\local\{E792308A-A205-45BE-A5AD-6B5C50E854DA}
2012-07-16 15:45:03 -------- d-----w- c:\users\chris\appdata\local\{132633EE-C1D1-4101-BEEA-773985515C7B}
2012-07-16 15:44:44 -------- d-----w- c:\users\chris\appdata\local\{396D40EB-70BE-4519-8036-9E6E13673C04}
2012-07-16 03:30:38 -------- d-----w- c:\users\chris\appdata\local\{C3AC779C-0201-4CA2-A2EA-A697336FDD14}
2012-07-16 03:30:24 -------- d-----w- c:\users\chris\appdata\local\{B5CC1347-760E-4113-987D-8B1668C63609}
2012-07-15 09:11:06 -------- d-----w- c:\users\chris\appdata\local\{342CC728-E22A-4A0B-BA57-EC00E8950E4C}
2012-07-15 09:10:52 -------- d-----w- c:\users\chris\appdata\local\{896C2115-97F3-494F-852D-77C4DE9DE773}
2012-07-14 17:08:43 -------- d-----w- c:\users\chris\appdata\local\{11D5122E-4F2F-474D-A6C2-68507048BB31}
2012-07-14 17:08:31 -------- d-----w- c:\users\chris\appdata\local\{E792CC8F-0912-4036-9C65-12D9255EA12B}
2012-07-14 05:08:14 -------- d-----w- c:\users\chris\appdata\local\{1423DB16-26E3-444B-86EB-D146197435EA}
2012-07-14 05:07:59 -------- d-----w- c:\users\chris\appdata\local\{9E43B1F6-39F3-49D2-AAE2-C7E61CC4AFDA}
2012-07-13 15:44:45 470848 ----a-w- c:\windows\system32\drivers\iaStor.sys
2012-07-12 23:05:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-12 23:05:03 194560 ----a-w- c:\program files\internet explorer\ieproxy.dll
2012-07-12 23:05:03 140920 ----a-w- c:\program files\internet explorer\sqmapi.dll
2012-07-12 23:05:01 194048 ----a-w- c:\program files\internet explorer\IEShims.dll
2012-07-12 23:05:00 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-07-12 23:04:59 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-07-12 23:04:57 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-07-12 23:04:55 748664 ----a-w- c:\program files\internet explorer\iexplore.exe
2012-07-12 23:04:55 387584 ----a-w- c:\program files\internet explorer\jsdbgui.dll
2012-07-12 23:04:54 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll
2012-07-12 23:04:53 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-12 22:57:35 2345984 ----a-w- c:\windows\system32\win32k.sys
.
==================== Find3M ====================
.
2012-08-03 16:25:44 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-03 16:25:42 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-04 23:55:04 53248 ----a-w- c:\windows\system32\CSVer.dll
2012-07-03 20:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-21 06:02:38 476936 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-06-21 06:02:38 472840 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-08 23:18:46 3173008 ----a-w- c:\windows\system32\RtkAPO.dll
2012-06-06 17:44:20 645776 ----a-w- c:\windows\system32\RtkApoApi.dll
2012-06-06 05:05:52 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 04:45:04 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- c:\windows\system32\ncrypt.dll
2012-06-01 01:08:16 87696 ----a-w- c:\windows\system32\RtkCoInstII.dll
2012-05-26 01:06:00 1706640 ----a-w- c:\windows\RtlExUpd.dll
2012-05-22 08:01:02 2240512 ----a-w- c:\windows\system32\drivers\athr.sys
2012-05-22 08:01:02 2240512 ------w- c:\windows\system32\athr.sys
.
============= FINISH: 13:07:21.98 ===============
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.11.03
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Chris :: EEE-PC [administrator]
8/11/2012 12:44:12 PM
mbam-log-2012-08-11 (12-44-12).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 191730
Time elapsed: 8 minute(s), 54 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 6
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Delete on reboot.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\00000004.@ (Rootkit.Zaccess) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\00000008.@ (Trojan.Dropper.BCMiner) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\000000cb.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\80000000.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\Windows\Installer\{00ff34b5-916a-9703-4564-252221bbb3bc}\U\80000032.@ (Rootkit.0Access) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-08-11 13:04:30
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST916031 rev.0002
Running: ent2rgeu.exe; Driver: C:\Users\Chris\AppData\Local\Temp\uwldapow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/2/2010 1:43:20 PM
System Uptime: 8/11/2012 12:55:23 PM (1 hours ago)
.
Motherboard: ASUSTeK Computer INC. | | 1005HA
Processor: Intel(R) Atom(TM) CPU N280 @ 1.66GHz | PBGA 437 | 1667/167mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 44 GiB total, 20.396 GiB free.
D: is FIXED (NTFS) - 100 GiB total, 79.274 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP386: 8/9/2012 12:20:33 PM - Windows Update
.
==== Installed Programs ======================
.
µTorrent
7-Zip 4.65
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.2 Lite
Adobe Shockwave Player 11.6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ASUSUpdate for Eee PC
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Bonjour
CCleaner
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
D3DX10
DivX Web Player
Driver Genius Professional Edition
EASEUS Partition Master 8.0.1 Home Edition
eReg
Google Chrome
Google Earth
Google Update Helper
Hotkey Service
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 33
Logitech SetPoint 6.30
Malwarebytes Anti-Malware version 1.62.0.1300
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 14.0.1 (x86 en-US)
Mp3tag v2.45a
MSVCRT
OpenOffice.org 3.2
Qualcomm Atheros WiFi Driver Installation
QuickTime
Ralink RT2860 Wireless LAN Card
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
RunRev LiveCode Player Browser Plugin
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
Silicon Laboratories CP210x VCP Drivers for Windows XP/2003 Server/Vista/7
Skype Click to Call
Skype™ 5.10
SopCast 3.4.8
SRS Premium Sound Control Panel
Super Hybrid Engine
SUPERAntiSpyware
swMSM
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
VC80CRTRedist - 8.0.50727.6195
Veetle TV
VLC media player 1.1.11
Winamp
Winamp Application Detect
WinDjView 1.0.3
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Wolfram CDF Player (M-WIN-D 8.0.3 2427703)
.
==== Event Viewer Messages From Past Week ========
.
8/9/2012 6:41:36 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
8/9/2012 6:41:36 AM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
8/8/2012 11:36:08 AM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
8/7/2012 2:40:00 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
8/11/2012 12:55:42 PM, Error: Service Control Manager [7023] - The Function Discovery Resource Publication service terminated with the following error: %%-2147024891
8/11/2012 12:55:42 PM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
8/11/2012 12:55:41 PM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
8/11/2012 12:55:41 PM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
.
==== End Of File ===========================
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_33
Run by Chris at 13:06:08 on 2012-08-11
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.2039.1162 [GMT -7:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\System32\AsusService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
"C:\Windows\System32\svchost.exe" -k LocalServiceDns
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [HotkeyService] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotkeyService.exe
mRun: [HotKeyMon] AsusSender.exe c:\program files\eeepc\hotkeyservice\HotKeyMon.exe
mRun: [SuperHybridEngine] AsusSender.exe c:\program files\eeepc\she\SuperHybridEngine.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IAStorIcon] c:\program files\intel\intel(r) rapid storage technology\iastoriconlaunch.exe "c:\program files\intel\intel(r) rapid storage technology\IAStorIcon.exe" 60
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\14C657D60225F636B6 : DhcpNameServer = 10.255.255.33 10.255.255.32
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\16474777966696 : DhcpNameServer = 192.168.6.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\245627279756373716 : DhcpNameServer = 10.255.255.33 10.255.255.32
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\353434C4 : DhcpNameServer = 10.21.1.21 10.21.1.22
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\5467562776275656E6 : DhcpNameServer = 10.255.255.33 10.255.255.32
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\64F6F6478696C6C6027457563747 : DhcpNameServer = 153.18.144.8 153.18.96.30
TCP: Interfaces\{27E504D0-AC2D-4A1C-90E1-58F659C4F934}\75169707F62747F5143636563737 : DhcpNameServer = 192.168.5.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{D47D2BF9-3728-4A80-858F-B2C11E1DEF7B} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\chris\appdata\roaming\mozilla\firefox\profiles\ilgz0zir.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\millisecond software\inquisit 3.0 mozilla plugin\npInquisit_3060.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\chris\appdata\local\runrev\components\livecodeplayer\9\nplcplugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-1-2 11448]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608]
R2 AsusService;Asus Launcher Service;c:\windows\system32\AsusService.exe [2010-1-2 219136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\intel\intel(r) rapid storage technology\IAStorDataMgrSvc.exe [2011-3-28 13632]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2011-8-11 88176]
R3 vjoy;vJoy Device;c:\windows\system32\drivers\vjoy.sys [2011-6-26 13184]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-3 135664]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-31 250056]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-5-1 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-5-1 8456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-3 135664]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]
S3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [2004-1-23 13952]
S3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [2004-1-23 28800]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2011-1-27 47176]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\system32\drivers\silabser.sys [2011-1-27 58496]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-2-23 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-2-26 1343400]
.
=============== Created Last 30 ================
.
2012-08-11 18:08:57 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-08-11 04:00:48 -------- d-----w- c:\users\chris\appdata\local\{632B55E7-1947-415C-A1F0-180244CABD24}
2012-08-11 04:00:36 -------- d-----w- c:\users\chris\appdata\local\{3D985EE6-25FE-4E97-8EC5-CD5FC1D6444D}
2012-08-10 16:00:03 -------- d-----w- c:\users\chris\appdata\local\{3AA71FA9-56FF-4A6A-B4FE-5D613AD4CE6A}
2012-08-10 15:59:48 -------- d-----w- c:\users\chris\appdata\local\{065C03EA-2213-45E0-83E4-8460FCE0E81A}
2012-08-10 03:59:18 -------- d-----w- c:\users\chris\appdata\local\{E9D560EA-D8B1-4805-9D8F-84E3684988EE}
2012-08-10 03:59:05 -------- d-----w- c:\users\chris\appdata\local\{FFA51CFD-D5B4-4C71-B21C-61653D44B0EF}
2012-08-09 15:58:35 -------- d-----w- c:\users\chris\appdata\local\{B9888C0B-7A0C-4216-8C13-2D63BCFE416A}
2012-08-09 15:58:22 -------- d-----w- c:\users\chris\appdata\local\{BC25A299-0327-4A24-BC4F-A2396D120333}
2012-08-08 23:42:58 -------- d-----w- c:\program files\CCleaner
2012-08-08 23:12:44 -------- d-----w- c:\users\chris\appdata\roaming\IrfanView
2012-08-08 23:12:41 -------- d-----w- c:\program files\IrfanView
2012-08-08 20:13:58 -------- d-----w- c:\programdata\Qualcomm Atheros
2012-08-08 20:02:15 1379760 ----a-w- c:\windows\system32\tosade.dll
2012-08-08 20:02:14 819648 ----a-w- c:\windows\system32\tadefxapo2.dll
2012-08-08 20:02:14 58264 ----a-w- c:\windows\system32\TepeqAPO.dll
2012-08-08 20:02:14 134584 ----a-w- c:\windows\system32\tadefxapo.dll
2012-08-08 20:02:03 1497704 ----a-w- c:\windows\system32\RTSndMgr.cpl
2012-08-08 20:02:01 3240400 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2012-08-08 20:02:01 2417808 ----a-w- c:\windows\system32\RtkPgExt.dll
2012-08-08 18:52:40 -------- d-----w- c:\users\chris\appdata\local\{C40F72D8-E66E-40EE-9240-EC7FD0BBF265}
2012-08-08 18:52:16 -------- d-----w- c:\users\chris\appdata\local\{2835313F-3C3F-4E51-A9A3-9EB19466F5E9}
2012-08-08 06:51:37 -------- d-----w- c:\users\chris\appdata\local\{A184D6C7-5E41-4E5C-B622-9CE4BED7F5F4}
2012-08-08 06:51:18 -------- d-----w- c:\users\chris\appdata\local\{50CCB122-4724-411A-8C23-F0DDA3467FCD}
2012-08-07 04:55:18 -------- d-----w- c:\users\chris\appdata\local\{A8DF6BB4-22B5-44F2-82CC-446121916175}
2012-08-07 04:55:05 -------- d-----w- c:\users\chris\appdata\local\{6AA3941B-D988-42B9-9D4A-D332B3DC530A}
2012-08-06 06:52:06 -------- d-----w- c:\users\chris\appdata\local\{3C738986-F70B-46F9-B334-AB24CB66D078}
2012-08-06 06:51:52 -------- d-----w- c:\users\chris\appdata\local\{F58B9F7A-A977-4DFC-A26C-DFA527982838}
2012-08-05 17:42:05 -------- d-----w- c:\users\chris\appdata\local\{69736EEC-C685-435F-A3F1-85177E01C58E}
2012-08-05 17:41:46 -------- d-----w- c:\users\chris\appdata\local\{A4D90CC7-0BE7-4AEA-9563-740D0E486057}
2012-08-05 05:13:15 -------- d-----w- c:\users\chris\appdata\local\{F8A2785C-A5DB-4CE8-9EE1-9E3C0E3F1926}
2012-08-05 05:12:58 -------- d-----w- c:\users\chris\appdata\local\{5C185527-0E48-4D97-B04B-2E88E8B77F15}
2012-08-04 17:12:37 -------- d-----w- c:\users\chris\appdata\local\{4A98F3ED-0F16-4ECA-B127-EA336189998F}
2012-08-04 17:12:21 -------- d-----w- c:\users\chris\appdata\local\{D4C2B4FE-BECF-4D29-BEB2-E2F8AC20AF23}
2012-08-04 04:46:16 -------- d-----w- c:\users\chris\appdata\local\{C0827F19-4FC3-4E6A-AE9C-89723247EB87}
2012-08-04 04:45:59 -------- d-----w- c:\users\chris\appdata\local\{699837E5-7A24-43F0-A5A2-530284DF4E20}
2012-08-03 15:33:45 -------- d-----w- c:\users\chris\appdata\local\{D8573E12-CADF-4E79-A2CA-C2A949FB0AE5}
2012-08-03 15:33:32 -------- d-----w- c:\users\chris\appdata\local\{EEF7FC5C-6972-4004-A2B6-0466EF3E1889}
2012-08-02 17:31:06 -------- d-----w- c:\users\chris\appdata\local\{4BD862A0-49C6-4F71-98A6-91DC47CC1735}
2012-08-02 17:30:53 -------- d-----w- c:\users\chris\appdata\local\{A9CD17B3-729E-4F8E-B58F-714F7D8E9739}
2012-08-02 05:30:35 -------- d-----w- c:\users\chris\appdata\local\{7101958E-41F1-45AC-BFED-98DFCF0E0764}
2012-08-02 05:30:21 -------- d-----w- c:\users\chris\appdata\local\{D2EAD98E-5DE5-4369-BF34-3D206341A6ED}
2012-08-01 06:28:35 -------- d-----w- c:\users\chris\appdata\local\{AC4FFEAD-184D-4AEB-AEF2-96E13118905D}
2012-08-01 06:28:18 -------- d-----w- c:\users\chris\appdata\local\{CB97313B-8C2C-4E09-926D-5614E423AB0D}
2012-07-31 06:04:18 -------- d-----w- c:\users\chris\appdata\local\{06E9089B-54A1-4712-8C5D-46511116CBF6}
2012-07-31 06:04:05 -------- d-----w- c:\users\chris\appdata\local\{60C56BB9-10F3-46E5-B295-E20AF6844B57}
2012-07-30 17:44:26 -------- d-----w- c:\users\chris\appdata\local\{4F5C962F-EA75-4989-AEA6-0172A57BE411}
2012-07-30 17:44:04 -------- d-----w- c:\users\chris\appdata\local\{C3C15045-1C84-47A1-81CE-5EA8691659B3}
2012-07-29 20:14:09 -------- d-----w- c:\users\chris\appdata\local\{DB6D64B9-BDF8-4397-9430-C8D8B93BA384}
2012-07-29 20:13:57 -------- d-----w- c:\users\chris\appdata\local\{5547DB44-1D70-4DB3-8702-507E42CBAB2B}
2012-07-29 08:13:43 -------- d-----w- c:\users\chris\appdata\local\{AF426123-352F-4D62-ACF0-9DD9AF9BDB5A}
2012-07-29 08:13:31 -------- d-----w- c:\users\chris\appdata\local\{B076B4E5-2EC9-439D-ABBE-90E9D40D3B20}
2012-07-28 20:13:13 -------- d-----w- c:\users\chris\appdata\local\{B3301479-89C6-4678-9682-5F3FAAEE965F}
2012-07-28 20:13:00 -------- d-----w- c:\users\chris\appdata\local\{EAF5B5CD-E67C-46B6-86E3-4894D38038BD}
2012-07-28 04:46:30 -------- d-----w- c:\users\chris\appdata\local\{5E2499DD-D251-47A6-A504-228178455DB1}
2012-07-28 04:46:18 -------- d-----w- c:\users\chris\appdata\local\{50754E6E-F137-46E2-8AFA-68388844421C}
2012-07-28 02:11:21 -------- d-----w- c:\users\chris\appdata\local\{D340074E-0FD2-4EE0-B502-5EAFB3C19835}
2012-07-26 05:27:42 -------- d-----w- c:\users\chris\appdata\local\{4D040D0E-F44C-4998-827C-AC22D030EDF9}
2012-07-26 05:27:30 -------- d-----w- c:\users\chris\appdata\local\{8EA90FEA-E9CE-4851-981F-AE98D9527C03}
2012-07-25 17:27:11 -------- d-----w- c:\users\chris\appdata\local\{B351623D-1F54-47FB-B5C0-29BDED67C5E1}
2012-07-25 17:26:52 -------- d-----w- c:\users\chris\appdata\local\{F26E069E-0243-4F73-9853-CE8D90A44707}
2012-07-25 05:26:37 -------- d-----w- c:\users\chris\appdata\local\{66829252-6897-4C5F-9C63-6E33C56E7917}
2012-07-25 05:26:23 -------- d-----w- c:\users\chris\appdata\local\{9FCC422F-6894-48E6-97F2-28730296F7D8}
2012-07-24 00:10:52 -------- d-----w- c:\users\chris\appdata\local\{FEEF416A-9198-4819-B428-22684AD26221}
2012-07-24 00:10:37 -------- d-----w- c:\users\chris\appdata\local\{EE7CA870-3D4E-4899-9555-DFBE3E8EDB89}
2012-07-22 04:09:13 -------- d-----w- c:\users\chris\appdata\local\{2665A19A-40C8-4412-9434-1FCCC9028CAC}
2012-07-22 04:08:58 -------- d-----w- c:\users\chris\appdata\local\{73C82EF8-6960-43AD-84A4-42AB416A9323}
2012-07-21 06:52:33 -------- d-----w- c:\users\chris\appdata\local\{D591B279-3348-40B8-9326-12DABBA1050C}
2012-07-21 06:52:19 -------- d-----w- c:\users\chris\appdata\local\{A6A61F19-334C-4FF7-908B-A743851A6A1A}
2012-07-19 18:07:06 -------- d-----w- c:\users\chris\appdata\local\{0B8E78D3-63BD-476A-B71E-74063052CC97}
2012-07-19 18:06:49 -------- d-----w- c:\users\chris\appdata\local\{E792308A-A205-45BE-A5AD-6B5C50E854DA}
2012-07-16 15:45:03 -------- d-----w- c:\users\chris\appdata\local\{132633EE-C1D1-4101-BEEA-773985515C7B}
2012-07-16 15:44:44 -------- d-----w- c:\users\chris\appdata\local\{396D40EB-70BE-4519-8036-9E6E13673C04}
2012-07-16 03:30:38 -------- d-----w- c:\users\chris\appdata\local\{C3AC779C-0201-4CA2-A2EA-A697336FDD14}
2012-07-16 03:30:24 -------- d-----w- c:\users\chris\appdata\local\{B5CC1347-760E-4113-987D-8B1668C63609}
2012-07-15 09:11:06 -------- d-----w- c:\users\chris\appdata\local\{342CC728-E22A-4A0B-BA57-EC00E8950E4C}
2012-07-15 09:10:52 -------- d-----w- c:\users\chris\appdata\local\{896C2115-97F3-494F-852D-77C4DE9DE773}
2012-07-14 17:08:43 -------- d-----w- c:\users\chris\appdata\local\{11D5122E-4F2F-474D-A6C2-68507048BB31}
2012-07-14 17:08:31 -------- d-----w- c:\users\chris\appdata\local\{E792CC8F-0912-4036-9C65-12D9255EA12B}
2012-07-14 05:08:14 -------- d-----w- c:\users\chris\appdata\local\{1423DB16-26E3-444B-86EB-D146197435EA}
2012-07-14 05:07:59 -------- d-----w- c:\users\chris\appdata\local\{9E43B1F6-39F3-49D2-AAE2-C7E61CC4AFDA}
2012-07-13 15:44:45 470848 ----a-w- c:\windows\system32\drivers\iaStor.sys
2012-07-12 23:05:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-12 23:05:03 194560 ----a-w- c:\program files\internet explorer\ieproxy.dll
2012-07-12 23:05:03 140920 ----a-w- c:\program files\internet explorer\sqmapi.dll
2012-07-12 23:05:01 194048 ----a-w- c:\program files\internet explorer\IEShims.dll
2012-07-12 23:05:00 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-07-12 23:04:59 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-07-12 23:04:57 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-07-12 23:04:55 748664 ----a-w- c:\program files\internet explorer\iexplore.exe
2012-07-12 23:04:55 387584 ----a-w- c:\program files\internet explorer\jsdbgui.dll
2012-07-12 23:04:54 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll
2012-07-12 23:04:53 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-07-12 22:57:35 2345984 ----a-w- c:\windows\system32\win32k.sys
.
==================== Find3M ====================
.
2012-08-03 16:25:44 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-03 16:25:42 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-04 23:55:04 53248 ----a-w- c:\windows\system32\CSVer.dll
2012-07-03 20:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-21 06:02:38 476936 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-06-21 06:02:38 472840 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-08 23:18:46 3173008 ----a-w- c:\windows\system32\RtkAPO.dll
2012-06-06 17:44:20 645776 ----a-w- c:\windows\system32\RtkApoApi.dll
2012-06-06 05:05:52 1390080 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- c:\windows\system32\cdosys.dll
2012-06-02 22:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 04:45:04 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59 369336 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39 225280 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- c:\windows\system32\ncrypt.dll
2012-06-01 01:08:16 87696 ----a-w- c:\windows\system32\RtkCoInstII.dll
2012-05-26 01:06:00 1706640 ----a-w- c:\windows\RtlExUpd.dll
2012-05-22 08:01:02 2240512 ----a-w- c:\windows\system32\drivers\athr.sys
2012-05-22 08:01:02 2240512 ------w- c:\windows\system32\athr.sys
.
============= FINISH: 13:07:21.98 ===============