Kellie Resetar
Posts: 11 +0
Before I saw this forum, I had run SuperAntiSpyware which allowed my PC to become useable again. I then uninstalled MSE which was no longer working and reinstalled it and ran a full scan which looked like it had cleaned everything. Was able to get services for Windows Update and Virus Update rerunning but now my Windows Firewall still won't turn on - haven't noticed any other issues.
Yesterday I started following the virus removal instructions here and the logs are posted below. My MSE reran in the meantime and found another issue so I've also included that at the end of this post.
Malwarebytes Log:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Database version: v2012.09.14.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Kellie :: KELLIE-PC [administrator]
9/14/2012 4:35:40 PM
mbam-log-2012-09-14 (16-35-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 247640
Time elapsed: 7 minute(s), 19 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\Kellie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum (Rogue.LiveSecurityPlatinum) -> Quarantined and deleted successfully.
Files Detected: 2
C:\Users\Kellie\AppData\Local\Temp\tsft.exe (Adware.Agent.K) -> Quarantined and deleted successfully.
C:\Users\Kellie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk (Rogue.LiveSecurityPlatinum) -> Quarantined and deleted successfully.
(end)
GMER Log: Nothing was found
DDS.Txt:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by Kellie at 7:31:21 on 2012-09-15
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3767.2092 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\ProgramData\ActivePath\ActiveMail\UpdateClient.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Kellie\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Video Web Camera\traybar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Users\Kellie\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW
mStart Page = hxxp://www.bing.com/?pc=MAGW
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = proxy_name:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: ActiveMail: {ef7aed5f-0c26-4820-a570-7da8b6d93f4a} - C:\ProgramData\ActivePath\ActiveMail\ActiveMailBHO.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [PCShowServer] C:\Users\Kellie\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
Trusted Zone: ameritrade.com\wwws
Trusted Zone: intuit.com\ttlc
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\0544D43402341464544554259414 : DhcpNameServer = 4.2.2.2 192.168.1.254 192.168.2.1
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\07164747562737F6E623 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\1447C616E6471602F457470716479656E647 : DhcpNameServer = 192.168.27.1
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\27F6F6D6C696E687 : DhcpNameServer = 64.89.70.2 64.89.74.2
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\34275616475727560234F6D666F6274737 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\34C61637379636F23557261627570234573747F6D656270275946494 : DhcpNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO-X64: ActiveMail: {EF7AED5F-0C26-4820-A570-7DA8B6D93F4A} - C:\ProgramData\ActivePath\ActiveMail\ActiveMailBHO.dll
BHO-X64: ActiveMail - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k
mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun-x64: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\48adz0vn.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Kellie\AppData\Local\DIRECTV Player\npPCShowPlugin.dll
FF - plugin: C:\Users\Kellie\AppData\Local\DIRECTV Player\npPlayerPlugin.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2012-3-30 151656]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-11-15 321104]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe [2011-3-14 868896]
R2 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2010-1-8 23584]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-15 13336]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2010-6-28 255744]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-11-15 2320920]
R2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2010-11-15 243232]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-10 136176]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-4 250568]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-10 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-30 113120]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-09-15 11:27:46 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D0B6E400-3A3A-4172-A3F6-C20B873E27C7}\mpengine.dll
2012-09-14 20:35:18 -------- d-----w- C:\Users\Kellie\AppData\Roaming\Malwarebytes
2012-09-14 20:35:05 -------- d-----w- C:\ProgramData\Malwarebytes
2012-09-14 20:35:04 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-09-14 20:35:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-09-14 12:41:57 -------- d-----w- C:\Users\Kellie\AppData\Local\{504475F9-DA32-42AA-A95C-2D18D2C64CE6}
2012-09-14 11:58:10 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-09-14 11:57:52 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-09-14 11:57:52 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-09-14 00:40:52 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-13 17:14:34 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{82831D0D-4E57-43F7-93A7-B82ECC7D7DF1}\gapaengine.dll
2012-09-13 17:13:10 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-09-13 17:13:08 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-09-13 13:15:02 -------- d-sh--w- C:\Windows\System32\%APPDATA%
2012-09-13 13:12:13 -------- d-----w- C:\ProgramData\7531CC9202C75886D6CFC216F875F002
2012-09-13 11:27:19 -------- d-----w- C:\Users\Kellie\AppData\Local\{712604E2-B68F-499C-8043-EDD39F515764}
2012-09-12 15:04:39 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2012-09-12 15:04:39 574464 ----a-w- C:\Windows\System32\d3d10level9.dll
2012-09-12 15:04:39 490496 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
2012-09-12 15:04:39 41472 ----a-w- C:\Windows\System32\drivers\RNDISMP.sys
2012-09-12 15:04:38 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2012-09-12 15:04:38 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-09-12 15:04:38 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-09-12 11:22:09 -------- d-----w- C:\Users\Kellie\AppData\Local\{27F2B198-BF96-4147-B113-E02D9A6439B8}
2012-09-11 12:39:39 -------- d-----w- C:\Users\Kellie\AppData\Local\{537208BB-3988-404B-8CEC-01F97950503A}
2012-09-11 00:39:04 -------- d-----w- C:\Users\Kellie\AppData\Local\{DABBD7CA-267E-49D4-BDE7-ADB5E719C990}
2012-09-10 11:18:29 -------- d-----w- C:\Users\Kellie\AppData\Local\{67FBBA47-15E8-4857-8700-E90636810ABE}
2012-09-08 11:54:21 -------- d-----w- C:\Users\Kellie\AppData\Local\{5F169BC9-B1DA-4467-B9AC-4B146F51AB03}
2012-09-07 10:41:51 -------- d-----w- C:\Users\Kellie\AppData\Local\{5D716406-0B9F-4783-9AD1-E646399B793A}
2012-09-06 10:54:32 -------- d-----w- C:\Users\Kellie\AppData\Local\{259111C6-9697-4158-B71B-EE48915AF83B}
2012-09-05 22:52:54 -------- d-----w- C:\Users\Kellie\AppData\Local\{7BCCBFB1-71E7-4B46-BA7F-D24D8666DFA3}
2012-09-05 10:52:18 -------- d-----w- C:\Users\Kellie\AppData\Local\{0B77C6BB-7992-4508-B59F-BE3BCE7E8AF6}
2012-09-04 11:24:03 -------- d-----w- C:\Users\Kellie\AppData\Local\{8B71B99B-FBF3-4D6E-A182-CEE0F88184AB}
2012-09-03 18:55:48 -------- d-----w- C:\Users\Kellie\AppData\Local\{FB5F4F25-AFE4-4C18-9E32-A987B2CEC40C}
2012-09-02 13:00:49 -------- d-----w- C:\Users\Kellie\AppData\Local\{60C1F5B6-0D52-4E83-A240-09576B98D50E}
2012-09-01 11:11:43 -------- d-----w- C:\Users\Kellie\AppData\Local\{5E38E7F8-0D40-4A95-BFCB-D7C47F03676C}
2012-08-31 10:25:27 -------- d-----w- C:\Users\Kellie\AppData\Local\{107E23D5-B451-4E02-8077-2DB780EBF8FB}
2012-08-30 14:20:58 -------- d-----w- C:\Users\Kellie\AppData\Local\{1782E3FE-6E91-46F0-95B3-47E4A141E187}
2012-08-29 23:47:13 -------- d-----w- C:\Users\Kellie\AppData\Local\{A71A3060-275B-4AA0-9AD5-B25546CC3056}
2012-08-29 11:01:43 -------- d-----w- C:\Users\Kellie\AppData\Local\{C1B4A26C-DCCF-4D5F-A368-6C0B5D506F83}
2012-08-28 12:04:32 -------- d-----w- C:\Users\Kellie\AppData\Local\{F2DA06DE-4DC3-476E-90DA-0F765EE315BB}
2012-08-27 13:27:12 -------- d-----w- C:\Users\Kellie\AppData\Local\{1ADF3078-DD36-417D-8186-49204C8EE135}
2012-08-27 01:26:37 -------- d-----w- C:\Users\Kellie\AppData\Local\{23441D3E-DEE3-4C83-9711-F6E334F9A38E}
2012-08-26 12:22:10 -------- d-----w- C:\Users\Kellie\AppData\Local\{D05004D1-DB12-439A-B683-0EBBFEC4E483}
2012-08-26 00:16:37 -------- d-----w- C:\Users\Kellie\AppData\Local\{AA64046D-23F3-4C13-B72A-76F6F6ADA301}
2012-08-25 10:45:37 -------- d-----w- C:\Users\Kellie\AppData\Local\{A36EAEC6-A51B-4C24-9EC6-32AEA5F5184C}
2012-08-24 11:07:07 -------- d-----w- C:\Users\Kellie\AppData\Local\{E7A0CA10-7308-45F2-9D93-73B5B8EEFF25}
2012-08-23 15:54:35 -------- d-----w- C:\Program Files\CCleaner
2012-08-23 12:42:39 -------- d-----w- C:\Users\Kellie\AppData\Local\{CA888684-9D18-44EB-9565-6D37F07A7787}
2012-08-23 00:42:02 -------- d-----w- C:\Users\Kellie\AppData\Local\{7050B1A7-2E28-4095-9883-804D4C9FE3CD}
2012-08-22 10:20:41 -------- d-----w- C:\Users\Kellie\AppData\Local\{8A612F32-D57C-428F-998E-6D91BE2B01C4}
2012-08-21 13:04:10 -------- d-----w- C:\Users\Kellie\AppData\Local\{196A0DF7-195C-4838-B06A-356A9322C27C}
2012-08-21 00:20:01 -------- d-----w- C:\Users\Kellie\AppData\Local\{95EACD01-5657-46A0-8423-AD32225CEA13}
2012-08-20 10:50:44 -------- d-----w- C:\Users\Kellie\AppData\Local\{9AE0C2B4-0F4C-4913-A959-05D89BA3A5FB}
2012-08-19 12:08:07 -------- d-----w- C:\Users\Kellie\AppData\Local\{333E96D9-C35E-4FE3-9CFE-A5B6B0E77994}
2012-08-18 11:24:15 -------- d-----w- C:\Users\Kellie\AppData\Local\{9D37CDF9-C62A-4DDF-8654-C05EC826F11F}
2012-08-17 12:36:45 -------- d-----w- C:\Users\Kellie\AppData\Local\ElevatedDiagnostics
2012-08-17 11:44:21 -------- d-----w- C:\Users\Kellie\AppData\Local\{68043674-7AA5-432D-877D-DE1434CB0A84}
2012-08-17 11:43:59 -------- d-----w- C:\Users\Kellie\AppData\Local\{DE1A0A84-14B3-46C4-9F6B-6EB7184C8D0C}
2012-08-16 23:43:33 -------- d-----w- C:\Users\Kellie\AppData\Local\{4D090A5A-FA28-4F75-97D3-6572A40E72A8}
2012-08-16 23:43:22 -------- d-----w- C:\Users\Kellie\AppData\Local\{77939F90-2A1C-44EF-BF54-033D94DB162E}
.
==================== Find3M ====================
.
2012-09-14 00:40:47 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-09-14 00:40:47 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-23 11:12:48 73416 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-23 11:12:48 696520 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-18 18:15:06 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-04 22:13:27 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-07-04 22:13:27 136704 ----a-w- C:\Windows\System32\browser.dll
2012-07-04 21:14:34 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 7:32:18.07 ===============
Yesterday I started following the virus removal instructions here and the logs are posted below. My MSE reran in the meantime and found another issue so I've also included that at the end of this post.
Malwarebytes Log:
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Database version: v2012.09.14.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Kellie :: KELLIE-PC [administrator]
9/14/2012 4:35:40 PM
mbam-log-2012-09-14 (16-35-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 247640
Time elapsed: 7 minute(s), 19 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\Kellie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum (Rogue.LiveSecurityPlatinum) -> Quarantined and deleted successfully.
Files Detected: 2
C:\Users\Kellie\AppData\Local\Temp\tsft.exe (Adware.Agent.K) -> Quarantined and deleted successfully.
C:\Users\Kellie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk (Rogue.LiveSecurityPlatinum) -> Quarantined and deleted successfully.
(end)
GMER Log: Nothing was found
DDS.Txt:
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
Run by Kellie at 7:31:21 on 2012-09-15
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3767.2092 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\ProgramData\ActivePath\ActiveMail\UpdateClient.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Launch Manager\dsiwmis.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Kellie\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\StikyNot.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Video Web Camera\traybar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Users\Kellie\AppData\Local\DIRECTV Player\NDSPCShowServer.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
mDefault_Page_URL = hxxp://www.bing.com/?pc=MAGW
mStart Page = hxxp://www.bing.com/?pc=MAGW
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = proxy_name:8080
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: ActiveMail: {ef7aed5f-0c26-4820-a570-7da8b6d93f4a} - C:\ProgramData\ActivePath\ActiveMail\ActiveMailBHO.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [PCShowServer] C:\Users\Kellie\AppData\Local\DIRECTV Player\PCShowServerPMWrapper.exe
uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k
mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
Trusted Zone: ameritrade.com\wwws
Trusted Zone: intuit.com\ttlc
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\0544D43402341464544554259414 : DhcpNameServer = 4.2.2.2 192.168.1.254 192.168.2.1
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\07164747562737F6E623 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\1447C616E6471602F457470716479656E647 : DhcpNameServer = 192.168.27.1
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\27F6F6D6C696E687 : DhcpNameServer = 64.89.70.2 64.89.74.2
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\34275616475727560234F6D666F6274737 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{DA17269D-5C3D-45C6-B0A4-B7FC9C9BA0DF}\34C61637379636F23557261627570234573747F6D656270275946494 : DhcpNameServer = 192.168.0.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO-X64: ActiveMail: {EF7AED5F-0C26-4820-A570-7DA8B6D93F4A} - C:\ProgramData\ActivePath\ActiveMail\ActiveMailBHO.dll
BHO-X64: ActiveMail - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun-x64: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k
mRun-x64: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
mRun-x64: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [BingDesktop] C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\48adz0vn.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Kellie\AppData\Local\DIRECTV Player\npPCShowPlugin.dll
FF - plugin: C:\Users\Kellie\AppData\Local\DIRECTV Player\npPlayerPlugin.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [2011-8-11 140672]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2012-3-30 151656]
R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-11-15 321104]
R2 ePowerSvc;Acer ePower Service;C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe [2011-3-14 868896]
R2 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2010-1-8 23584]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-15 13336]
R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe [2010-6-28 255744]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-11-15 2320920]
R2 Updater Service;Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2010-11-15 243232]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 Impcd;Impcd;C:\Windows\system32\DRIVERS\Impcd.sys --> C:\Windows\system32\DRIVERS\Impcd.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys --> C:\Windows\system32\DRIVERS\k57nd60a.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-10 136176]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-4 250568]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-12-10 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-7-30 113120]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\system32\Drivers\RtsUStor.sys --> C:\Windows\system32\Drivers\RtsUStor.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2012-09-15 11:27:46 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D0B6E400-3A3A-4172-A3F6-C20B873E27C7}\mpengine.dll
2012-09-14 20:35:18 -------- d-----w- C:\Users\Kellie\AppData\Roaming\Malwarebytes
2012-09-14 20:35:05 -------- d-----w- C:\ProgramData\Malwarebytes
2012-09-14 20:35:04 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-09-14 20:35:04 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-09-14 12:41:57 -------- d-----w- C:\Users\Kellie\AppData\Local\{504475F9-DA32-42AA-A95C-2D18D2C64CE6}
2012-09-14 11:58:10 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-09-14 11:57:52 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-09-14 11:57:52 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-09-14 00:40:52 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-09-13 17:14:34 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{82831D0D-4E57-43F7-93A7-B82ECC7D7DF1}\gapaengine.dll
2012-09-13 17:13:10 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-09-13 17:13:08 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-09-13 13:15:02 -------- d-sh--w- C:\Windows\System32\%APPDATA%
2012-09-13 13:12:13 -------- d-----w- C:\ProgramData\7531CC9202C75886D6CFC216F875F002
2012-09-13 11:27:19 -------- d-----w- C:\Users\Kellie\AppData\Local\{712604E2-B68F-499C-8043-EDD39F515764}
2012-09-12 15:04:39 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
2012-09-12 15:04:39 574464 ----a-w- C:\Windows\System32\d3d10level9.dll
2012-09-12 15:04:39 490496 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
2012-09-12 15:04:39 41472 ----a-w- C:\Windows\System32\drivers\RNDISMP.sys
2012-09-12 15:04:38 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
2012-09-12 15:04:38 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2012-09-12 15:04:38 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-09-12 11:22:09 -------- d-----w- C:\Users\Kellie\AppData\Local\{27F2B198-BF96-4147-B113-E02D9A6439B8}
2012-09-11 12:39:39 -------- d-----w- C:\Users\Kellie\AppData\Local\{537208BB-3988-404B-8CEC-01F97950503A}
2012-09-11 00:39:04 -------- d-----w- C:\Users\Kellie\AppData\Local\{DABBD7CA-267E-49D4-BDE7-ADB5E719C990}
2012-09-10 11:18:29 -------- d-----w- C:\Users\Kellie\AppData\Local\{67FBBA47-15E8-4857-8700-E90636810ABE}
2012-09-08 11:54:21 -------- d-----w- C:\Users\Kellie\AppData\Local\{5F169BC9-B1DA-4467-B9AC-4B146F51AB03}
2012-09-07 10:41:51 -------- d-----w- C:\Users\Kellie\AppData\Local\{5D716406-0B9F-4783-9AD1-E646399B793A}
2012-09-06 10:54:32 -------- d-----w- C:\Users\Kellie\AppData\Local\{259111C6-9697-4158-B71B-EE48915AF83B}
2012-09-05 22:52:54 -------- d-----w- C:\Users\Kellie\AppData\Local\{7BCCBFB1-71E7-4B46-BA7F-D24D8666DFA3}
2012-09-05 10:52:18 -------- d-----w- C:\Users\Kellie\AppData\Local\{0B77C6BB-7992-4508-B59F-BE3BCE7E8AF6}
2012-09-04 11:24:03 -------- d-----w- C:\Users\Kellie\AppData\Local\{8B71B99B-FBF3-4D6E-A182-CEE0F88184AB}
2012-09-03 18:55:48 -------- d-----w- C:\Users\Kellie\AppData\Local\{FB5F4F25-AFE4-4C18-9E32-A987B2CEC40C}
2012-09-02 13:00:49 -------- d-----w- C:\Users\Kellie\AppData\Local\{60C1F5B6-0D52-4E83-A240-09576B98D50E}
2012-09-01 11:11:43 -------- d-----w- C:\Users\Kellie\AppData\Local\{5E38E7F8-0D40-4A95-BFCB-D7C47F03676C}
2012-08-31 10:25:27 -------- d-----w- C:\Users\Kellie\AppData\Local\{107E23D5-B451-4E02-8077-2DB780EBF8FB}
2012-08-30 14:20:58 -------- d-----w- C:\Users\Kellie\AppData\Local\{1782E3FE-6E91-46F0-95B3-47E4A141E187}
2012-08-29 23:47:13 -------- d-----w- C:\Users\Kellie\AppData\Local\{A71A3060-275B-4AA0-9AD5-B25546CC3056}
2012-08-29 11:01:43 -------- d-----w- C:\Users\Kellie\AppData\Local\{C1B4A26C-DCCF-4D5F-A368-6C0B5D506F83}
2012-08-28 12:04:32 -------- d-----w- C:\Users\Kellie\AppData\Local\{F2DA06DE-4DC3-476E-90DA-0F765EE315BB}
2012-08-27 13:27:12 -------- d-----w- C:\Users\Kellie\AppData\Local\{1ADF3078-DD36-417D-8186-49204C8EE135}
2012-08-27 01:26:37 -------- d-----w- C:\Users\Kellie\AppData\Local\{23441D3E-DEE3-4C83-9711-F6E334F9A38E}
2012-08-26 12:22:10 -------- d-----w- C:\Users\Kellie\AppData\Local\{D05004D1-DB12-439A-B683-0EBBFEC4E483}
2012-08-26 00:16:37 -------- d-----w- C:\Users\Kellie\AppData\Local\{AA64046D-23F3-4C13-B72A-76F6F6ADA301}
2012-08-25 10:45:37 -------- d-----w- C:\Users\Kellie\AppData\Local\{A36EAEC6-A51B-4C24-9EC6-32AEA5F5184C}
2012-08-24 11:07:07 -------- d-----w- C:\Users\Kellie\AppData\Local\{E7A0CA10-7308-45F2-9D93-73B5B8EEFF25}
2012-08-23 15:54:35 -------- d-----w- C:\Program Files\CCleaner
2012-08-23 12:42:39 -------- d-----w- C:\Users\Kellie\AppData\Local\{CA888684-9D18-44EB-9565-6D37F07A7787}
2012-08-23 00:42:02 -------- d-----w- C:\Users\Kellie\AppData\Local\{7050B1A7-2E28-4095-9883-804D4C9FE3CD}
2012-08-22 10:20:41 -------- d-----w- C:\Users\Kellie\AppData\Local\{8A612F32-D57C-428F-998E-6D91BE2B01C4}
2012-08-21 13:04:10 -------- d-----w- C:\Users\Kellie\AppData\Local\{196A0DF7-195C-4838-B06A-356A9322C27C}
2012-08-21 00:20:01 -------- d-----w- C:\Users\Kellie\AppData\Local\{95EACD01-5657-46A0-8423-AD32225CEA13}
2012-08-20 10:50:44 -------- d-----w- C:\Users\Kellie\AppData\Local\{9AE0C2B4-0F4C-4913-A959-05D89BA3A5FB}
2012-08-19 12:08:07 -------- d-----w- C:\Users\Kellie\AppData\Local\{333E96D9-C35E-4FE3-9CFE-A5B6B0E77994}
2012-08-18 11:24:15 -------- d-----w- C:\Users\Kellie\AppData\Local\{9D37CDF9-C62A-4DDF-8654-C05EC826F11F}
2012-08-17 12:36:45 -------- d-----w- C:\Users\Kellie\AppData\Local\ElevatedDiagnostics
2012-08-17 11:44:21 -------- d-----w- C:\Users\Kellie\AppData\Local\{68043674-7AA5-432D-877D-DE1434CB0A84}
2012-08-17 11:43:59 -------- d-----w- C:\Users\Kellie\AppData\Local\{DE1A0A84-14B3-46C4-9F6B-6EB7184C8D0C}
2012-08-16 23:43:33 -------- d-----w- C:\Users\Kellie\AppData\Local\{4D090A5A-FA28-4F75-97D3-6572A40E72A8}
2012-08-16 23:43:22 -------- d-----w- C:\Users\Kellie\AppData\Local\{77939F90-2A1C-44EF-BF54-033D94DB162E}
.
==================== Find3M ====================
.
2012-09-14 00:40:47 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-09-14 00:40:47 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-08-23 11:12:48 73416 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-23 11:12:48 696520 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-18 18:15:06 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-04 22:13:27 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-07-04 22:13:27 136704 ----a-w- C:\Windows\System32\browser.dll
2012-07-04 21:14:34 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 7:32:18.07 ===============