William Clemens
Posts: 65 +0
The above infection is reported by Webroot SecureAnywhere (WSA). As soon as I remove it WSA rescans and it is there again.
I have completed scans with MalwareBytes, GMER, and DDS as requested in the Preliminary Removal Instructions. Logs are pasted below.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.19.02
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Owner :: OWNER-PC [administrator]
7/18/2012 11:05:47 PM
mbam-log-2012-07-18 (23-05-47).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 231395
Time elapsed: 13 minute(s), 40 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER found nothing and produced no log.
DDS Log follows
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Owner at 0:19:21 on 2012-07-19
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4061.2304 [GMT -7:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {9C0666FC-6C7D-3E97-3C40-0C6B33FC7401}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot SecureAnywhere *Enabled/Updated* {27678718-4A47-3119-06F0-3719487B3EBC}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uStart Page = hxxp://www.bing.com/?PC=BNHP
uInternet Settings,ProxyOverride = <local>
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [Uxtucue] C:\Users\Owner\AppData\Roaming\Teylge\ceysh.exe
mRun: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul
StartupFolder: C:\Users\Owner\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
uPolicies-explorer: DisableCurrentUserRun = 0 (0x0)
uPolicies-explorer: DisableCurrentUserRunOnce = 0 (0x0)
uPolicies-explorer: NoFile = 0 (0x0)
uPolicies-explorer: HideClock = 0 (0x0)
uPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
uPolicies-explorer: NoDFSTab = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-explorer: NoEncryptOnMove = 0 (0x0)
uPolicies-explorer: NoResolveTrack = 0 (0x0)
uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoViewOnDrive = 0 (0x0)
mPolicies-explorer: DisableCurrentUserRun = 0 (0x0)
mPolicies-explorer: DisableCurrentUserRunOnce = 0 (0x0)
mPolicies-explorer: NoFile = 0 (0x0)
mPolicies-explorer: HideClock = 0 (0x0)
mPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
mPolicies-explorer: NoDFSTab = 0 (0x0)
mPolicies-explorer: NoWindowsUpdate = 0 (0x0)
mPolicies-explorer: NoEncryptOnMove = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 0 (0x0)
mPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
dPolicies-explorer: NoViewOnDrive = 0 (0x0)
dPolicies-explorer: DisableLocalMachineRun = 0 (0x0)
dPolicies-explorer: DisableLocalMachineRunOnce = 0 (0x0)
dPolicies-explorer: DisableCurrentUserRun = 0 (0x0)
dPolicies-explorer: DisableCurrentUserRunOnce = 0 (0x0)
dPolicies-explorer: NoFile = 0 (0x0)
dPolicies-explorer: HideClock = 0 (0x0)
dPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
dPolicies-explorer: NoDFSTab = 0 (0x0)
dPolicies-explorer: NoWindowsUpdate = 0 (0x0)
dPolicies-explorer: NoEncryptOnMove = 0 (0x0)
dPolicies-explorer: NoResolveTrack = 0 (0x0)
dPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
dPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {03A89EFD-E023-B000-A22D-45F77558EB4C} - hxxp://content10.ilinc.com/download/AXCltInst11.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{35CEA933-7B30-44BF-B730-55376E69A12F} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3}\3757A796 : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3}\C4962627162797 : DhcpNameServer = 63.82.222.3 63.82.222.4
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3}\E4544574541425 : DhcpNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO-X64: NCO 2.0 IE BHO - No File
BHO-X64: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB-X64: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
mRun-x64: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul
.
============= SERVICES / DRIVERS ===============
.
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\system32\DRIVERS\tos_sps64.sys --> C:\Windows\system32\DRIVERS\tos_sps64.sys [?]
R0 WRkrn;WRkrn;C:\Windows\system32\drivers\WRkrn.sys --> C:\Windows\system32\drivers\WRkrn.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 OpenLibSys;OpenLibSys;C:\Program Files (x86)\NXP\FM Radio\OpenLibSysX64.sys [2008-12-18 14544]
R2 WRSVC;WRSVC;C:\Program Files (x86)\Webroot\WRSA.exe [2012-7-17 688360]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys --> C:\Windows\system32\DRIVERS\NETw5s64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 ssrangdr;ssrangdr;C:\Windows\system32\DRIVERS\ssrangdr.sys --> C:\Windows\system32\DRIVERS\ssrangdr.sys [?]
S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\System32\dllhost.exe [2009-7-13 7168]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe --> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]
S4 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-31 250056]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S4 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2012-3-13 168448]
S4 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2012-3-13 131072]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2011-6-9 555392]
S4 gupdate1ca0a76e89bc5f0;Google Update Service (gupdate1ca0a76e89bc5f0);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-7-21 133104]
S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-7-21 133104]
S4 KR10I64;KR10I64;C:\Windows\system32\drivers\kr10i64.sys --> C:\Windows\system32\drivers\kr10i64.sys [?]
S4 KR10N64;KR10N64;C:\Windows\system32\drivers\kr10n64.sys --> C:\Windows\system32\drivers\kr10n64.sys [?]
S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-5-30 3048136]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-3 160944]
S4 SmartFaceVWatchSrv;SmartFaceVWatchSrv;C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-8-25 89600]
S4 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2008-9-1 46392]
S4 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2008-7-17 139776]
.
=============== File Associations ===============
.
inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
inifile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
txtfile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2012-07-19 06:48:00 -------- d-----w- C:\FRST
2012-07-18 01:47:52 -------- d-----w- C:\Users\Owner\AppData\Roaming\Malwarebytes
2012-07-18 01:47:39 -------- d-----w- C:\ProgramData\Malwarebytes
2012-07-18 01:47:38 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-18 01:47:38 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-18 01:19:09 -------- d-----w- C:\WSALog
2012-07-17 23:49:33 -------- d-----w- C:\Windows\pss
2012-07-17 16:44:08 -------- d-----w- C:\Users\Owner\AppData\Local\{E4829603-F9E7-42BB-A11C-B7FF147FF0B7}
2012-07-17 16:43:57 -------- d-----w- C:\Users\Owner\AppData\Local\{14CF98E6-318E-4A13-A534-29FA7DC78664}
2012-07-15 21:15:44 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yxhuo
2012-07-15 21:15:44 -------- d-----w- C:\Users\Owner\AppData\Roaming\Uqev
2012-07-15 21:15:44 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ahrabe
2012-07-14 19:39:12 -------- d-----w- C:\Users\Owner\AppData\Local\{F5295089-F0A9-4C9F-83C7-C808E15EB09F}
2012-07-14 19:38:50 -------- d-----w- C:\Users\Owner\AppData\Local\{5A93C0C1-127C-4C06-AC79-79BBAFBA86D0}
2012-07-14 18:50:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yrza
2012-07-14 18:50:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Hofe
2012-07-14 18:50:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Dysi
2012-07-13 18:53:12 -------- d-----w- C:\Users\Owner\AppData\Local\{5F3B96C4-574E-414C-B5B8-7819399388B6}
2012-07-13 18:53:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Luzosi
2012-07-13 18:53:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Iryh
2012-07-13 18:53:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Evetu
2012-07-13 18:53:02 -------- d-----w- C:\Users\Owner\AppData\Local\{509BBCAF-D554-447E-A1ED-C179424CACA9}
2012-07-12 13:24:50 -------- d-----w- C:\Users\Owner\AppData\Local\{49A2F336-10FD-426C-8443-D6165867225E}
2012-07-12 13:24:25 -------- d-----w- C:\Users\Owner\AppData\Local\{15FDE577-FF1B-48F4-8AC0-FC179AFD675E}
2012-07-12 13:20:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yqez
2012-07-12 13:20:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ehyk
2012-07-12 13:20:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Deygpe
2012-07-11 15:11:44 -------- d-----w- C:\Users\Owner\AppData\Local\{7476C7F6-6B33-4EF1-BABD-11213CE0136E}
2012-07-11 15:11:22 -------- d-----w- C:\Users\Owner\AppData\Local\{2B509738-2D10-49C3-9988-B85726205245}
2012-07-10 23:18:30 -------- d-----w- C:\Users\Owner\AppData\Local\{7679D9AA-E922-47AA-B38D-8B0930C545BC}
2012-07-10 23:18:06 -------- d-----w- C:\Users\Owner\AppData\Local\{A515DCDD-4051-4DD7-952F-DD99777DD3B4}
2012-07-09 17:55:53 -------- d-----w- C:\Users\Owner\AppData\Local\{90118A41-4C02-4A91-A78C-40DA33BE547D}
2012-07-09 17:55:31 -------- d-----w- C:\Users\Owner\AppData\Local\{419D9F31-8E5E-48A0-884A-7D038D375DCA}
2012-07-09 17:51:07 -------- d-----w- C:\Users\Owner\AppData\Roaming\Puyrak
2012-07-09 17:51:06 -------- d-----w- C:\Users\Owner\AppData\Roaming\Toovm
2012-07-09 17:51:06 -------- d-----w- C:\Users\Owner\AppData\Roaming\Odaxif
2012-07-09 00:58:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ydcei
2012-07-09 00:58:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Lyvyyr
2012-07-09 00:58:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Koxa
2012-07-08 22:20:51 -------- d-----w- C:\Users\Owner\AppData\Local\{1DE870FA-5F8B-4621-B8FE-2E423D9FB680}
2012-07-08 22:20:28 -------- d-----w- C:\Users\Owner\AppData\Local\{3C5EAC2E-7EE1-43BC-8288-A6FC3668AD1D}
2012-07-08 13:28:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ylybab
2012-07-08 13:28:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Guyv
2012-07-08 13:28:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Coco
2012-07-07 18:00:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ygsi
2012-07-07 18:00:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Qyxeoh
2012-07-07 18:00:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Bouxk
2012-07-07 00:55:17 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yxzawi
2012-07-07 00:55:17 -------- d-----w- C:\Users\Owner\AppData\Roaming\Usmei
2012-07-07 00:55:17 -------- d-----w- C:\Users\Owner\AppData\Roaming\Itiwa
2012-07-06 14:54:56 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yzikuw
2012-07-06 14:54:56 -------- d-----w- C:\Users\Owner\AppData\Roaming\Woadyk
2012-07-06 14:54:56 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ikyryk
2012-07-06 14:54:52 -------- d-----w- C:\Users\Owner\AppData\Local\{5572D201-B689-443B-BF65-0E39B11AF190}
2012-07-06 14:54:41 -------- d-----w- C:\Users\Owner\AppData\Local\{3C108ABC-0D21-4A5B-BE54-32DFF0238A37}
2012-07-05 21:32:45 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yncou
2012-07-05 21:32:45 -------- d-----w- C:\Users\Owner\AppData\Roaming\Efqa
2012-07-05 21:32:45 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ceur
2012-07-05 21:32:27 -------- d-----w- C:\Users\Owner\AppData\Local\{301A8294-B820-49E8-A2A3-7B2AE2B003D4}
2012-07-05 21:32:17 -------- d-----w- C:\Users\Owner\AppData\Local\{B7718B34-B544-4131-AD95-FFFA8E986751}
2012-07-05 02:42:55 -------- d-----w- C:\Users\Owner\AppData\Roaming\Zoiqe
2012-07-05 02:42:55 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ucva
2012-07-05 02:42:55 -------- d-----w- C:\Users\Owner\AppData\Roaming\Keqeto
2012-07-04 15:41:54 -------- d-----w- C:\Users\Owner\AppData\Local\{1A0C520C-9886-4BE5-AE6B-00C1D4E4D4B5}
2012-07-04 15:41:43 -------- d-----w- C:\Users\Owner\AppData\Local\{BC4BB09D-558A-4CAE-93FD-74D2D8FE69AE}
2012-07-03 18:07:13 -------- d-----r- C:\Users\Owner\Dropbox
2012-07-03 18:02:18 -------- d-----w- C:\Users\Owner\AppData\Roaming\Dropbox
2012-07-03 17:24:05 -------- d-----w- C:\Users\Owner\AppData\Local\{D829F5F7-0891-4060-96DE-0205E468B5ED}
2012-07-03 17:23:37 -------- d-----w- C:\Users\Owner\AppData\Local\{A04E4BBC-F2FD-4A20-ADA4-90A47D05F639}
2012-07-02 15:10:47 -------- d-----w- C:\Users\Owner\AppData\Local\{6CAB19EF-C2FC-470B-8300-A6CCA9C5824A}
2012-07-02 15:10:24 -------- d-----w- C:\Users\Owner\AppData\Local\{C80A999D-25F3-4ED1-9663-C0475DB4815A}
2012-07-01 21:20:44 -------- d-----w- C:\Users\Owner\AppData\Local\{B9FDBC6F-0345-4F22-8097-A170A4CD5F90}
2012-07-01 21:20:22 -------- d-----w- C:\Users\Owner\AppData\Local\{1047A30B-9614-4953-B4F4-CD2DB1B43439}
2012-07-01 20:15:36 -------- d-----w- C:\Users\Owner\AppData\Local\{4402A6AA-CF93-489B-8208-A0BCDF657B87}
2012-07-01 19:15:54 -------- d-----w- C:\Users\Owner\AppData\Local\{C645C65A-7BB5-45F5-917E-ACBC4FD92529}
2012-06-30 17:58:58 -------- d-----w- C:\Users\Owner\AppData\Local\{17683A3F-F178-4E6F-886B-4D61D34A358B}
2012-06-30 17:58:36 -------- d-----w- C:\Users\Owner\AppData\Local\{84B053B5-A46B-455D-96EA-1FAE8885DB96}
2012-06-30 17:09:23 -------- d-----w- C:\Users\Owner\AppData\Local\{0E4816AA-6CA8-43A7-BC88-51C57B38DECB}
2012-06-30 00:13:40 -------- d-----w- C:\Users\Owner\AppData\Local\{AC286A84-4430-41F0-AED1-45D1B3F10902}
2012-06-30 00:13:18 -------- d-----w- C:\Users\Owner\AppData\Local\{FF31B1CE-908A-4FB6-9CEE-98AB0D39F850}
2012-06-30 00:07:17 -------- d-----w- C:\Users\Owner\AppData\Local\{0F163A71-2228-4E3B-B045-EF90697D909E}
2012-06-29 01:22:24 -------- d-----w- C:\Users\Owner\AppData\Local\{144BCF66-AEF3-44AA-885F-74C76189D022}
2012-06-29 01:22:13 -------- d-----w- C:\Users\Owner\AppData\Local\{27998CBA-A647-407B-9D99-BC511B66D9DD}
2012-06-29 01:19:08 -------- d-----w- C:\Users\Owner\AppData\Roaming\Kemyc
2012-06-29 01:19:08 -------- d-----w- C:\Users\Owner\AppData\Roaming\Izge
2012-06-29 01:19:08 -------- d-----w- C:\Users\Owner\AppData\Roaming\Efzu
2012-06-28 02:59:20 -------- d-----w- C:\Users\Owner\AppData\Roaming\Petoe
2012-06-28 02:59:20 -------- d-----w- C:\Users\Owner\AppData\Roaming\Nuyxe
2012-06-28 02:59:20 -------- d-----w- C:\Users\Owner\AppData\Roaming\Neoxy
2012-06-28 02:59:12 -------- d-----w- C:\Users\Owner\AppData\Local\{95BC6D21-70F7-4BFC-B463-27D6E8658E75}
2012-06-28 02:58:50 -------- d-----w- C:\Users\Owner\AppData\Local\{A6B03DAA-4958-434E-9AFD-FC4B7FE4D736}
2012-06-26 19:49:40 -------- d-----w- C:\Users\Owner\AppData\Local\{B1E8483D-A03D-4E1D-8AFE-C1D1936F4799}
2012-06-26 19:49:18 -------- d-----w- C:\Users\Owner\AppData\Local\{F14584A5-9CB6-4A38-9CED-3D7E2B2ACEA2}
2012-06-26 19:49:14 -------- d-----w- C:\Users\Owner\AppData\Roaming\Okwoif
2012-06-26 19:49:14 -------- d-----w- C:\Users\Owner\AppData\Roaming\Laxu
2012-06-26 19:49:14 -------- d-----w- C:\Users\Owner\AppData\Roaming\Gike
2012-06-25 01:32:02 -------- d-----w- C:\Users\Owner\AppData\Roaming\Pidi
2012-06-25 01:32:02 -------- d-----w- C:\Users\Owner\AppData\Roaming\Eduwa
2012-06-25 01:32:02 -------- d-----w- C:\Users\Owner\AppData\Roaming\Afcoyg
2012-06-24 15:31:32 -------- d-----w- C:\Users\Owner\AppData\Local\{7978A1EA-D7DF-4150-A9C1-2648AD6CB68C}
2012-06-24 15:31:21 -------- d-----w- C:\Users\Owner\AppData\Local\{D7DB68F2-2045-462E-8B30-40FF6E8335C9}
2012-06-24 15:31:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Xuon
2012-06-24 15:31:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Qiyrva
2012-06-24 15:31:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Igycr
2012-06-24 02:22:34 -------- d-----w- C:\Users\Owner\AppData\Local\{C55BFBA3-E536-4679-819C-CDFDD21A08EC}
2012-06-24 02:22:12 -------- d-----w- C:\Users\Owner\AppData\Local\{D923F6A9-25DB-40AE-9D41-BD9F3E5F7C7A}
2012-06-24 02:21:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Koygex
2012-06-24 02:21:31 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yzkee
2012-06-24 02:21:31 -------- d-----w- C:\Users\Owner\AppData\Roaming\Xiqucy
2012-06-22 18:34:01 -------- d-----w- C:\Users\Owner\AppData\Local\ElevatedDiagnostics
2012-06-22 16:32:02 -------- d-----w- C:\Users\Owner\AppData\Local\{C3FAE189-4032-405B-8197-9D044A43D8F2}
2012-06-22 16:31:40 -------- d-----w- C:\Users\Owner\AppData\Local\{4A696D21-1E8A-432C-A1BB-47137F1F8DEF}
2012-06-22 16:29:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Xepiik
2012-06-22 16:29:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Imalav
2012-06-22 16:29:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Apuqyf
2012-06-21 20:05:41 -------- d-----w- C:\Users\Owner\AppData\Local\{779D4748-9789-4BFC-922F-70356C7F2A42}
2012-06-21 20:05:30 -------- d-----w- C:\Users\Owner\AppData\Local\{B5D2CCF7-D3B7-4280-B78D-28D3539C429B}
2012-06-21 00:17:37 -------- d-----w- C:\Users\Owner\AppData\Local\{45A0AC51-8C94-4E14-9BA8-46D4AFE42DC8}
2012-06-21 00:17:15 -------- d-----w- C:\Users\Owner\AppData\Local\{00034FD9-A8F3-4864-B264-2D934B6DD0E5}
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Roaming\Veetv
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Roaming\Inicu
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Roaming\Dyka
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Local\{418164AA-0866-4432-B6EC-3F4E5CA176ED}
2012-06-20 12:16:31 -------- d-----w- C:\Users\Owner\AppData\Local\{73FAC2E2-ADF6-454E-A20D-0C3DC2AC876C}
2012-06-20 01:34:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Semaz
2012-06-20 01:34:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Huivol
2012-06-20 01:34:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Beif
2012-06-19 15:04:26 -------- d-----w- C:\Users\Owner\AppData\Local\{ED3D3F16-83CB-4310-A50A-A6B6CDFFD7E2}
2012-06-19 15:04:15 -------- d-----w- C:\Users\Owner\AppData\Local\{0777C8DA-DCFD-412E-B795-36EFE744D22C}
.
==================== Find3M ====================
.
2012-07-17 23:56:11 148664 ----a-w- C:\Windows\SysWow64\WRusr.dll
2012-07-17 23:56:11 113168 ----a-w- C:\Windows\System32\drivers\WRkrn.sys
2012-07-17 23:56:11 101808 ----a-w- C:\Windows\System32\WRusr.dll
2012-07-13 23:45:56 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-13 23:45:56 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-16 17:20:36 94720 ----a-w- C:\ProgramData\mtstrcfg64.dll
2012-06-02 22:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-05-18 02:06:48 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-05-18 01:59:14 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-05-18 01:58:39 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:30 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:37 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:47 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:39 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
.
============= FINISH: 0:19:47.24 ===============
I have completed scans with MalwareBytes, GMER, and DDS as requested in the Preliminary Removal Instructions. Logs are pasted below.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.19.02
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Owner :: OWNER-PC [administrator]
7/18/2012 11:05:47 PM
mbam-log-2012-07-18 (23-05-47).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 231395
Time elapsed: 13 minute(s), 40 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER found nothing and produced no log.
DDS Log follows
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Owner at 0:19:21 on 2012-07-19
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4061.2304 [GMT -7:00]
.
AV: Webroot SecureAnywhere *Enabled/Updated* {9C0666FC-6C7D-3E97-3C40-0C6B33FC7401}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Webroot SecureAnywhere *Enabled/Updated* {27678718-4A47-3119-06F0-3719487B3EBC}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Program Files (x86)\Webroot\WRSA.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
uStart Page = hxxp://www.bing.com/?PC=BNHP
uInternet Settings,ProxyOverride = <local>
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [Uxtucue] C:\Users\Owner\AppData\Roaming\Teylge\ceysh.exe
mRun: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul
StartupFolder: C:\Users\Owner\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Owner\AppData\Roaming\Dropbox\bin\Dropbox.exe
uPolicies-explorer: NoViewOnDrive = 0 (0x0)
uPolicies-explorer: DisableCurrentUserRun = 0 (0x0)
uPolicies-explorer: DisableCurrentUserRunOnce = 0 (0x0)
uPolicies-explorer: NoFile = 0 (0x0)
uPolicies-explorer: HideClock = 0 (0x0)
uPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
uPolicies-explorer: NoDFSTab = 0 (0x0)
uPolicies-explorer: NoWindowsUpdate = 0 (0x0)
uPolicies-explorer: NoEncryptOnMove = 0 (0x0)
uPolicies-explorer: NoResolveTrack = 0 (0x0)
uPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
uPolicies-system: NoDispSettingsPage = 0 (0x0)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoViewOnDrive = 0 (0x0)
mPolicies-explorer: DisableCurrentUserRun = 0 (0x0)
mPolicies-explorer: DisableCurrentUserRunOnce = 0 (0x0)
mPolicies-explorer: NoFile = 0 (0x0)
mPolicies-explorer: HideClock = 0 (0x0)
mPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
mPolicies-explorer: NoDFSTab = 0 (0x0)
mPolicies-explorer: NoWindowsUpdate = 0 (0x0)
mPolicies-explorer: NoEncryptOnMove = 0 (0x0)
mPolicies-explorer: NoResolveTrack = 0 (0x0)
mPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: NoDispAppearancePage = 0 (0x0)
mPolicies-system: NoDispSettingsPage = 0 (0x0)
dPolicies-explorer: NoViewOnDrive = 0 (0x0)
dPolicies-explorer: DisableLocalMachineRun = 0 (0x0)
dPolicies-explorer: DisableLocalMachineRunOnce = 0 (0x0)
dPolicies-explorer: DisableCurrentUserRun = 0 (0x0)
dPolicies-explorer: DisableCurrentUserRunOnce = 0 (0x0)
dPolicies-explorer: NoFile = 0 (0x0)
dPolicies-explorer: HideClock = 0 (0x0)
dPolicies-explorer: NoDevMgrUpdate = 0 (0x0)
dPolicies-explorer: NoDFSTab = 0 (0x0)
dPolicies-explorer: NoWindowsUpdate = 0 (0x0)
dPolicies-explorer: NoEncryptOnMove = 0 (0x0)
dPolicies-explorer: NoResolveTrack = 0 (0x0)
dPolicies-explorer: NoStartMenuSubFolders = 0 (0x0)
dPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-system: NoDispSettingsPage = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {03A89EFD-E023-B000-A22D-45F77558EB4C} - hxxp://content10.ilinc.com/download/AXCltInst11.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{35CEA933-7B30-44BF-B730-55376E69A12F} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3}\3757A796 : DhcpNameServer = 10.0.0.1
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3}\C4962627162797 : DhcpNameServer = 63.82.222.3 63.82.222.4
TCP: Interfaces\{F5D74FD8-3EC4-42E5-8471-D3AE0D16AFE3}\E4544574541425 : DhcpNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO-X64: NCO 2.0 IE BHO - No File
BHO-X64: SSVHelper Class: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
TB-X64: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
mRun-x64: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul
.
============= SERVICES / DRIVERS ===============
.
R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\system32\DRIVERS\tos_sps64.sys --> C:\Windows\system32\DRIVERS\tos_sps64.sys [?]
R0 WRkrn;WRkrn;C:\Windows\system32\drivers\WRkrn.sys --> C:\Windows\system32\drivers\WRkrn.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 OpenLibSys;OpenLibSys;C:\Program Files (x86)\NXP\FM Radio\OpenLibSysX64.sys [2008-12-18 14544]
R2 WRSVC;WRSVC;C:\Program Files (x86)\Webroot\WRSA.exe [2012-7-17 688360]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETw5s64.sys --> C:\Windows\system32\DRIVERS\NETw5s64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\netw5v64.sys --> C:\Windows\system32\DRIVERS\netw5v64.sys [?]
S3 ssrangdr;ssrangdr;C:\Windows\system32\DRIVERS\ssrangdr.sys --> C:\Windows\system32\DRIVERS\ssrangdr.sys [?]
S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;C:\Windows\System32\dllhost.exe [2009-7-13 7168]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe --> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]
S4 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
S4 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-3-31 250056]
S4 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
S4 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2012-3-13 168448]
S4 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2012-3-13 131072]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [2011-6-9 555392]
S4 gupdate1ca0a76e89bc5f0;Google Update Service (gupdate1ca0a76e89bc5f0);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-7-21 133104]
S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-7-21 133104]
S4 KR10I64;KR10I64;C:\Windows\system32\drivers\kr10i64.sys --> C:\Windows\system32\drivers\kr10i64.sys [?]
S4 KR10N64;KR10N64;C:\Windows\system32\drivers\kr10n64.sys --> C:\Windows\system32\drivers\kr10n64.sys [?]
S4 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-5-30 3048136]
S4 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-3 160944]
S4 SmartFaceVWatchSrv;SmartFaceVWatchSrv;C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-8-25 89600]
S4 TMachInfo;TMachInfo;C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe [2008-9-1 46392]
S4 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2008-7-17 139776]
.
=============== File Associations ===============
.
inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
inifile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
txtfile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2012-07-19 06:48:00 -------- d-----w- C:\FRST
2012-07-18 01:47:52 -------- d-----w- C:\Users\Owner\AppData\Roaming\Malwarebytes
2012-07-18 01:47:39 -------- d-----w- C:\ProgramData\Malwarebytes
2012-07-18 01:47:38 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-18 01:47:38 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-18 01:19:09 -------- d-----w- C:\WSALog
2012-07-17 23:49:33 -------- d-----w- C:\Windows\pss
2012-07-17 16:44:08 -------- d-----w- C:\Users\Owner\AppData\Local\{E4829603-F9E7-42BB-A11C-B7FF147FF0B7}
2012-07-17 16:43:57 -------- d-----w- C:\Users\Owner\AppData\Local\{14CF98E6-318E-4A13-A534-29FA7DC78664}
2012-07-15 21:15:44 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yxhuo
2012-07-15 21:15:44 -------- d-----w- C:\Users\Owner\AppData\Roaming\Uqev
2012-07-15 21:15:44 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ahrabe
2012-07-14 19:39:12 -------- d-----w- C:\Users\Owner\AppData\Local\{F5295089-F0A9-4C9F-83C7-C808E15EB09F}
2012-07-14 19:38:50 -------- d-----w- C:\Users\Owner\AppData\Local\{5A93C0C1-127C-4C06-AC79-79BBAFBA86D0}
2012-07-14 18:50:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yrza
2012-07-14 18:50:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Hofe
2012-07-14 18:50:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Dysi
2012-07-13 18:53:12 -------- d-----w- C:\Users\Owner\AppData\Local\{5F3B96C4-574E-414C-B5B8-7819399388B6}
2012-07-13 18:53:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Luzosi
2012-07-13 18:53:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Iryh
2012-07-13 18:53:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Evetu
2012-07-13 18:53:02 -------- d-----w- C:\Users\Owner\AppData\Local\{509BBCAF-D554-447E-A1ED-C179424CACA9}
2012-07-12 13:24:50 -------- d-----w- C:\Users\Owner\AppData\Local\{49A2F336-10FD-426C-8443-D6165867225E}
2012-07-12 13:24:25 -------- d-----w- C:\Users\Owner\AppData\Local\{15FDE577-FF1B-48F4-8AC0-FC179AFD675E}
2012-07-12 13:20:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yqez
2012-07-12 13:20:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ehyk
2012-07-12 13:20:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Deygpe
2012-07-11 15:11:44 -------- d-----w- C:\Users\Owner\AppData\Local\{7476C7F6-6B33-4EF1-BABD-11213CE0136E}
2012-07-11 15:11:22 -------- d-----w- C:\Users\Owner\AppData\Local\{2B509738-2D10-49C3-9988-B85726205245}
2012-07-10 23:18:30 -------- d-----w- C:\Users\Owner\AppData\Local\{7679D9AA-E922-47AA-B38D-8B0930C545BC}
2012-07-10 23:18:06 -------- d-----w- C:\Users\Owner\AppData\Local\{A515DCDD-4051-4DD7-952F-DD99777DD3B4}
2012-07-09 17:55:53 -------- d-----w- C:\Users\Owner\AppData\Local\{90118A41-4C02-4A91-A78C-40DA33BE547D}
2012-07-09 17:55:31 -------- d-----w- C:\Users\Owner\AppData\Local\{419D9F31-8E5E-48A0-884A-7D038D375DCA}
2012-07-09 17:51:07 -------- d-----w- C:\Users\Owner\AppData\Roaming\Puyrak
2012-07-09 17:51:06 -------- d-----w- C:\Users\Owner\AppData\Roaming\Toovm
2012-07-09 17:51:06 -------- d-----w- C:\Users\Owner\AppData\Roaming\Odaxif
2012-07-09 00:58:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ydcei
2012-07-09 00:58:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Lyvyyr
2012-07-09 00:58:53 -------- d-----w- C:\Users\Owner\AppData\Roaming\Koxa
2012-07-08 22:20:51 -------- d-----w- C:\Users\Owner\AppData\Local\{1DE870FA-5F8B-4621-B8FE-2E423D9FB680}
2012-07-08 22:20:28 -------- d-----w- C:\Users\Owner\AppData\Local\{3C5EAC2E-7EE1-43BC-8288-A6FC3668AD1D}
2012-07-08 13:28:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ylybab
2012-07-08 13:28:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Guyv
2012-07-08 13:28:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Coco
2012-07-07 18:00:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ygsi
2012-07-07 18:00:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Qyxeoh
2012-07-07 18:00:04 -------- d-----w- C:\Users\Owner\AppData\Roaming\Bouxk
2012-07-07 00:55:17 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yxzawi
2012-07-07 00:55:17 -------- d-----w- C:\Users\Owner\AppData\Roaming\Usmei
2012-07-07 00:55:17 -------- d-----w- C:\Users\Owner\AppData\Roaming\Itiwa
2012-07-06 14:54:56 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yzikuw
2012-07-06 14:54:56 -------- d-----w- C:\Users\Owner\AppData\Roaming\Woadyk
2012-07-06 14:54:56 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ikyryk
2012-07-06 14:54:52 -------- d-----w- C:\Users\Owner\AppData\Local\{5572D201-B689-443B-BF65-0E39B11AF190}
2012-07-06 14:54:41 -------- d-----w- C:\Users\Owner\AppData\Local\{3C108ABC-0D21-4A5B-BE54-32DFF0238A37}
2012-07-05 21:32:45 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yncou
2012-07-05 21:32:45 -------- d-----w- C:\Users\Owner\AppData\Roaming\Efqa
2012-07-05 21:32:45 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ceur
2012-07-05 21:32:27 -------- d-----w- C:\Users\Owner\AppData\Local\{301A8294-B820-49E8-A2A3-7B2AE2B003D4}
2012-07-05 21:32:17 -------- d-----w- C:\Users\Owner\AppData\Local\{B7718B34-B544-4131-AD95-FFFA8E986751}
2012-07-05 02:42:55 -------- d-----w- C:\Users\Owner\AppData\Roaming\Zoiqe
2012-07-05 02:42:55 -------- d-----w- C:\Users\Owner\AppData\Roaming\Ucva
2012-07-05 02:42:55 -------- d-----w- C:\Users\Owner\AppData\Roaming\Keqeto
2012-07-04 15:41:54 -------- d-----w- C:\Users\Owner\AppData\Local\{1A0C520C-9886-4BE5-AE6B-00C1D4E4D4B5}
2012-07-04 15:41:43 -------- d-----w- C:\Users\Owner\AppData\Local\{BC4BB09D-558A-4CAE-93FD-74D2D8FE69AE}
2012-07-03 18:07:13 -------- d-----r- C:\Users\Owner\Dropbox
2012-07-03 18:02:18 -------- d-----w- C:\Users\Owner\AppData\Roaming\Dropbox
2012-07-03 17:24:05 -------- d-----w- C:\Users\Owner\AppData\Local\{D829F5F7-0891-4060-96DE-0205E468B5ED}
2012-07-03 17:23:37 -------- d-----w- C:\Users\Owner\AppData\Local\{A04E4BBC-F2FD-4A20-ADA4-90A47D05F639}
2012-07-02 15:10:47 -------- d-----w- C:\Users\Owner\AppData\Local\{6CAB19EF-C2FC-470B-8300-A6CCA9C5824A}
2012-07-02 15:10:24 -------- d-----w- C:\Users\Owner\AppData\Local\{C80A999D-25F3-4ED1-9663-C0475DB4815A}
2012-07-01 21:20:44 -------- d-----w- C:\Users\Owner\AppData\Local\{B9FDBC6F-0345-4F22-8097-A170A4CD5F90}
2012-07-01 21:20:22 -------- d-----w- C:\Users\Owner\AppData\Local\{1047A30B-9614-4953-B4F4-CD2DB1B43439}
2012-07-01 20:15:36 -------- d-----w- C:\Users\Owner\AppData\Local\{4402A6AA-CF93-489B-8208-A0BCDF657B87}
2012-07-01 19:15:54 -------- d-----w- C:\Users\Owner\AppData\Local\{C645C65A-7BB5-45F5-917E-ACBC4FD92529}
2012-06-30 17:58:58 -------- d-----w- C:\Users\Owner\AppData\Local\{17683A3F-F178-4E6F-886B-4D61D34A358B}
2012-06-30 17:58:36 -------- d-----w- C:\Users\Owner\AppData\Local\{84B053B5-A46B-455D-96EA-1FAE8885DB96}
2012-06-30 17:09:23 -------- d-----w- C:\Users\Owner\AppData\Local\{0E4816AA-6CA8-43A7-BC88-51C57B38DECB}
2012-06-30 00:13:40 -------- d-----w- C:\Users\Owner\AppData\Local\{AC286A84-4430-41F0-AED1-45D1B3F10902}
2012-06-30 00:13:18 -------- d-----w- C:\Users\Owner\AppData\Local\{FF31B1CE-908A-4FB6-9CEE-98AB0D39F850}
2012-06-30 00:07:17 -------- d-----w- C:\Users\Owner\AppData\Local\{0F163A71-2228-4E3B-B045-EF90697D909E}
2012-06-29 01:22:24 -------- d-----w- C:\Users\Owner\AppData\Local\{144BCF66-AEF3-44AA-885F-74C76189D022}
2012-06-29 01:22:13 -------- d-----w- C:\Users\Owner\AppData\Local\{27998CBA-A647-407B-9D99-BC511B66D9DD}
2012-06-29 01:19:08 -------- d-----w- C:\Users\Owner\AppData\Roaming\Kemyc
2012-06-29 01:19:08 -------- d-----w- C:\Users\Owner\AppData\Roaming\Izge
2012-06-29 01:19:08 -------- d-----w- C:\Users\Owner\AppData\Roaming\Efzu
2012-06-28 02:59:20 -------- d-----w- C:\Users\Owner\AppData\Roaming\Petoe
2012-06-28 02:59:20 -------- d-----w- C:\Users\Owner\AppData\Roaming\Nuyxe
2012-06-28 02:59:20 -------- d-----w- C:\Users\Owner\AppData\Roaming\Neoxy
2012-06-28 02:59:12 -------- d-----w- C:\Users\Owner\AppData\Local\{95BC6D21-70F7-4BFC-B463-27D6E8658E75}
2012-06-28 02:58:50 -------- d-----w- C:\Users\Owner\AppData\Local\{A6B03DAA-4958-434E-9AFD-FC4B7FE4D736}
2012-06-26 19:49:40 -------- d-----w- C:\Users\Owner\AppData\Local\{B1E8483D-A03D-4E1D-8AFE-C1D1936F4799}
2012-06-26 19:49:18 -------- d-----w- C:\Users\Owner\AppData\Local\{F14584A5-9CB6-4A38-9CED-3D7E2B2ACEA2}
2012-06-26 19:49:14 -------- d-----w- C:\Users\Owner\AppData\Roaming\Okwoif
2012-06-26 19:49:14 -------- d-----w- C:\Users\Owner\AppData\Roaming\Laxu
2012-06-26 19:49:14 -------- d-----w- C:\Users\Owner\AppData\Roaming\Gike
2012-06-25 01:32:02 -------- d-----w- C:\Users\Owner\AppData\Roaming\Pidi
2012-06-25 01:32:02 -------- d-----w- C:\Users\Owner\AppData\Roaming\Eduwa
2012-06-25 01:32:02 -------- d-----w- C:\Users\Owner\AppData\Roaming\Afcoyg
2012-06-24 15:31:32 -------- d-----w- C:\Users\Owner\AppData\Local\{7978A1EA-D7DF-4150-A9C1-2648AD6CB68C}
2012-06-24 15:31:21 -------- d-----w- C:\Users\Owner\AppData\Local\{D7DB68F2-2045-462E-8B30-40FF6E8335C9}
2012-06-24 15:31:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Xuon
2012-06-24 15:31:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Qiyrva
2012-06-24 15:31:09 -------- d-----w- C:\Users\Owner\AppData\Roaming\Igycr
2012-06-24 02:22:34 -------- d-----w- C:\Users\Owner\AppData\Local\{C55BFBA3-E536-4679-819C-CDFDD21A08EC}
2012-06-24 02:22:12 -------- d-----w- C:\Users\Owner\AppData\Local\{D923F6A9-25DB-40AE-9D41-BD9F3E5F7C7A}
2012-06-24 02:21:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Koygex
2012-06-24 02:21:31 -------- d-----w- C:\Users\Owner\AppData\Roaming\Yzkee
2012-06-24 02:21:31 -------- d-----w- C:\Users\Owner\AppData\Roaming\Xiqucy
2012-06-22 18:34:01 -------- d-----w- C:\Users\Owner\AppData\Local\ElevatedDiagnostics
2012-06-22 16:32:02 -------- d-----w- C:\Users\Owner\AppData\Local\{C3FAE189-4032-405B-8197-9D044A43D8F2}
2012-06-22 16:31:40 -------- d-----w- C:\Users\Owner\AppData\Local\{4A696D21-1E8A-432C-A1BB-47137F1F8DEF}
2012-06-22 16:29:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Xepiik
2012-06-22 16:29:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Imalav
2012-06-22 16:29:25 -------- d-----w- C:\Users\Owner\AppData\Roaming\Apuqyf
2012-06-21 20:05:41 -------- d-----w- C:\Users\Owner\AppData\Local\{779D4748-9789-4BFC-922F-70356C7F2A42}
2012-06-21 20:05:30 -------- d-----w- C:\Users\Owner\AppData\Local\{B5D2CCF7-D3B7-4280-B78D-28D3539C429B}
2012-06-21 00:17:37 -------- d-----w- C:\Users\Owner\AppData\Local\{45A0AC51-8C94-4E14-9BA8-46D4AFE42DC8}
2012-06-21 00:17:15 -------- d-----w- C:\Users\Owner\AppData\Local\{00034FD9-A8F3-4864-B264-2D934B6DD0E5}
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Roaming\Veetv
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Roaming\Inicu
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Roaming\Dyka
2012-06-20 12:16:50 -------- d-----w- C:\Users\Owner\AppData\Local\{418164AA-0866-4432-B6EC-3F4E5CA176ED}
2012-06-20 12:16:31 -------- d-----w- C:\Users\Owner\AppData\Local\{73FAC2E2-ADF6-454E-A20D-0C3DC2AC876C}
2012-06-20 01:34:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Semaz
2012-06-20 01:34:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Huivol
2012-06-20 01:34:32 -------- d-----w- C:\Users\Owner\AppData\Roaming\Beif
2012-06-19 15:04:26 -------- d-----w- C:\Users\Owner\AppData\Local\{ED3D3F16-83CB-4310-A50A-A6B6CDFFD7E2}
2012-06-19 15:04:15 -------- d-----w- C:\Users\Owner\AppData\Local\{0777C8DA-DCFD-412E-B795-36EFE744D22C}
.
==================== Find3M ====================
.
2012-07-17 23:56:11 148664 ----a-w- C:\Windows\SysWow64\WRusr.dll
2012-07-17 23:56:11 113168 ----a-w- C:\Windows\System32\drivers\WRkrn.sys
2012-07-17 23:56:11 101808 ----a-w- C:\Windows\System32\WRusr.dll
2012-07-13 23:45:56 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-13 23:45:56 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-06-16 17:20:36 94720 ----a-w- C:\ProgramData\mtstrcfg64.dll
2012-06-02 22:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-02 22:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-05-18 02:06:48 2311680 ----a-w- C:\Windows\System32\jscript9.dll
2012-05-18 01:59:14 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-05-18 01:58:39 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-05-18 01:55:22 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-05-18 01:51:30 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-05-17 22:45:37 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-05-17 22:35:47 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-05-17 22:35:39 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-05-17 22:29:45 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-05-17 22:24:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-05-15 01:32:33 3146752 ----a-w- C:\Windows\System32\win32k.sys
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
.
============= FINISH: 0:19:47.24 ===============