. DDS (Ver_2011-06-23.01) - NTFSAMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_22 Run by [removed] at 9:54:20 on 2011-06-25 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3832.1475 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} AV: Immunet Protect *Enabled/Updated* {E26D838D-778A-C93D-0B41-46E786995C11} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe C:\Program Files\Immunet Protect\2.0.17\agent.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe C:\Program Files\Preton\PretonSaver\PretonClientService.exe C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperAgent.exe C:\Program Files\Immunet Protect\2.0.17\iptray.exe C:\Windows\SysWOW64\schtasks.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10q_ActiveX.exe C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe C:\Program Files (x86)\Windows Live\Mail\wlmail.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Users\Rob\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Rob\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Program Files (x86)\Common Files\XoftSpySE\6\xoftspyservice.exe C:\Windows\system32\msiexec.exe C:\Windows\SysWOW64\rundll32.exe C:\Users\Rob\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Rob\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.dailymail.co.uk/ushome/index.html uSearch Page = uSearch Bar = Preserve uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: &Crawler Toolbar Helper: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [cdloader] "C:\Users\Rob\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK uRun: [Google Update] "C:\Users\Rob\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe uRun: [Advanced SystemCare 4] "C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe" uRun: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe mRun: [Immunet Protect] "C:\Program Files\Immunet Protect\2.0.17\iptray.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRunOnce: [VirIT Uninst] cmd.exe /C rmdir /S /Q C:\VEXPLite uPolicies-explorer: DisallowRun = 1 (0x1) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{2D74C385-1955-48A7-AA22-E7832B650627}\2456C6B696E6F5E4F575962756C6563737F5636373233363 : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{DAD28796-0FC8-4778-8CE0-7F80A254299A} : DhcpNameServer = 192.168.2.1 Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: C:\ProgramData\iaspolcy32.dll mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: &Crawler Toolbar Helper: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: &Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~2\Crawler\Toolbar\ctbr.dll TB-X64: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File mRun-x64: [Immunet Protect] "C:\Program Files\Immunet Protect\2.0.17\iptray.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRunOnce-x64: [VirIT Uninst] cmd.exe /C rmdir /S /Q C:\VEXPLite AppInit_DLLs-X64: C:\ProgramData\iaspolcy32.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Rob\AppData\Roaming\Mozilla\Firefox\Profiles\7plvf7ve.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.huffingtonpost.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=380920&p= FF - component: C:\Program Files (x86)\Crawler\Toolbar\firefox\components\xcomm.dll FF - component: C:\Program Files (x86)\Crawler\Toolbar\firefox\components\xshared.dll FF - component: C:\Program Files (x86)\Crawler\Toolbar\firefox\components\xsupport.dll FF - component: C:\Program Files (x86)\Crawler\Toolbar\firefox\components\xwsg.dll FF - component: C:\Users\Rob\AppData\Roaming\Mozilla\Firefox\Profiles\7plvf7ve.default\extensions\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}\components\RadioWMPCoreGecko19.dll FF - component: C:\Users\Rob\AppData\Roaming\Mozilla\Firefox\Profiles\7plvf7ve.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Google Updater\2.4.2166.3772\npCIDetect14.dll FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\Default\AppData\Local\HuluDesktop\instances\0.9.11.1\nphdplg.dll FF - plugin: C:\Users\Rob\AppData\Local\Google\Update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R0 ahcix64s;ahcix64s;C:\Windows\system32\DRIVERS\ahcix64s.sys --> C:\Windows\system32\DRIVERS\ahcix64s.sys [?] R0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys --> C:\Windows\system32\DRIVERS\Lbd.sys [?] R0 RapportKE64;RapportKE64;C:\Windows\system32\Drivers\RapportKE64.sys --> C:\Windows\system32\Drivers\RapportKE64.sys [?] R1 ImmunetProtectDriver;ImmunetProtectDriver;C:\Windows\system32\DRIVERS\ImmunetProtect.sys --> C:\Windows\system32\DRIVERS\ImmunetProtect.sys [?] R1 ImmunetSelfProtectDriver;ImmunetSelfProtectDriver;C:\Windows\system32\DRIVERS\ImmunetSelfProtect.sys --> C:\Windows\system32\DRIVERS\ImmunetSelfProtect.sys [?] R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?] R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2011-4-28 52496] R1 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2011-4-28 61200] R1 SBRE;SBRE;\??\C:\Windows\system32\drivers\SBREdrv.sys --> C:\Windows\system32\drivers\SBREdrv.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2011-6-25 2978720] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952] R2 AdvancedSystemCareService;Advanced SystemCare Service;C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe [2011-6-21 353168] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?] R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216] R2 ImmunetProtect;Immunet Protect;C:\Program Files\Immunet Protect\2.0.17\agent.exe [2011-6-23 272080] R2 MotoHelper;MotoHelper Service;C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [2010-12-2 218432] R2 PfFilter;PfFilter;C:\Program Files (x86)\IObit\Protected Folder\pffilter.sys [2011-6-21 36792] R2 PretonClientService;PretonSaver;C:\Program Files\Preton\PretonSaver\PretonClientService.exe [2011-2-2 91136] R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-4-28 870200] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2011-6-23 1153368] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 motccgp;Motorola USB Composite Device Driver;C:\Windows\system32\DRIVERS\motccgp.sys --> C:\Windows\system32\DRIVERS\motccgp.sys [?] R3 motccgpfl;MotCcgpFlService;C:\Windows\system32\DRIVERS\motccgpfl.sys --> C:\Windows\system32\DRIVERS\motccgpfl.sys [?] R3 motport;Motorola USB Diagnostic Port;C:\Windows\system32\DRIVERS\motport.sys --> C:\Windows\system32\DRIVERS\motport.sys [?] R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys --> C:\Windows\system32\DRIVERS\netr28x.sys [?] R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 282616] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 usbfilter;AMD USB Filter Driver;C:\Windows\system32\DRIVERS\usbfilter.sys --> C:\Windows\system32\DRIVERS\usbfilter.sys [?] R3 XoftSpyService;XoftSpyService;C:\Program Files (x86)\Common Files\XoftSpySE\6\xoftspyservice.exe [2010-9-29 582424] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-5-26 136176] S3 atillk64;atillk64;C:\Program Files\PC-Doctor for Windows\atillk64.sys [2010-1-19 14608] S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-9-23 1493352] S3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?] S3 nosGetPlusHelper;getPlus(R) Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-13 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2011-06-25 13:32:05 -------- d-----w- C:\ProgramData\ParetoLogic 2011-06-25 13:32:03 -------- d-----w- C:\Program Files (x86)\Common Files\ParetoLogic 2011-06-25 13:31:59 -------- d-----w- C:\Program Files (x86)\Common Files\XoftSpySE 2011-06-25 13:31:58 -------- d-----w- C:\ProgramData\XoftSpySE 2011-06-25 13:19:27 -------- d-----w- C:\Users\Rob\AppData\Local\{C4D7226D-F140-47DA-B171-50D882CC2633} 2011-06-25 13:12:15 -------- d-----w- C:\Program Files (x86)\SpyZooka 2011-06-25 12:01:47 -------- d-----w- C:\rei 2011-06-25 12:01:38 -------- d-----w- C:\Program Files\Reimage 2011-06-25 10:58:26 -------- d-----w- C:\Program Files (x86)\Emsisoft Anti-Malware 2011-06-25 08:27:08 10240 ----a-w- C:\Windows\listcmd.bin 2011-06-25 08:22:30 81144 ----a-w- C:\Windows\SysWow64\drivers\viragtlt.sys 2011-06-25 08:18:51 -------- dc-h--w- C:\ProgramData\~0 2011-06-25 01:19:03 -------- d-----w- C:\Users\Rob\AppData\Local\{EEDDD675-4D88-4BE0-8B85-578671610928} 2011-06-25 00:03:25 12872 ----a-w- C:\Windows\System32\bootdelete.exe 2011-06-24 23:59:47 23112 ----a-w- C:\Windows\System32\drivers\hitmanpro35.sys 2011-06-24 23:59:42 -------- d-----w- C:\Program Files\Hitman Pro 3.5 2011-06-24 23:58:18 -------- d-----w- C:\ProgramData\Hitman Pro 2011-06-24 14:09:27 -------- d-----w- C:\Users\Rob\AppData\Roaming\FixIt 2011-06-24 13:57:47 8873296 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-06-24 13:57:36 8873296 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{53DB6AA6-5A88-41E7-A03E-3E9EFA4B6041}\mpengine.dll 2011-06-24 13:18:38 -------- d-----w- C:\Users\Rob\AppData\Local\{ACC9A7EA-5FF0-4AD8-8A22-AB88A37B8D51} 2011-06-24 00:49:58 -------- d-----w- C:\Program Files (x86)\Spybot - Search & Destroy 2011-06-23 21:03:26 -------- d-----w- C:\Users\Rob\AppData\Local\{D5B5A8CD-C56C-42F4-BDC6-A45D5121C0A2} 2011-06-23 15:15:09 1110528 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-23 15:15:08 759296 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll 2011-06-23 13:17:39 -------- d-----w- C:\Users\Rob\AppData\Roaming\QuickScan 2011-06-23 11:45:40 -------- d-----w- C:\Users\Rob\AppData\Roaming\IObit 2011-06-23 11:32:48 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{048D1300-CAF1-490E-A8AA-E78E44E5C698}\gapaengine.dll 2011-06-23 11:29:14 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client 2011-06-23 11:29:05 -------- d-----w- C:\Program Files\Microsoft Security Client 2011-06-23 11:16:28 -------- d-----w- C:\WINSSLog 2011-06-23 10:33:54 142296 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll 2011-06-23 10:33:53 781272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll 2011-06-23 10:33:53 1850328 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2011-06-23 10:33:52 89048 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libEGL.dll 2011-06-23 10:33:52 465880 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll 2011-06-23 10:33:52 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll 2011-06-23 10:33:52 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll 2011-06-23 10:33:52 15832 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll 2011-06-23 09:49:44 -------- d-----w- C:\Program Files (x86)\Crawler 2011-06-23 09:33:40 -------- d-----w- C:\Users\Rob\AppData\Local\Immunet 2011-06-23 09:33:40 -------- d-----w- C:\ProgramData\Immunet 2011-06-23 02:00:07 -------- d-----w- C:\Users\Rob\AppData\Local\{7CDB9C1F-EFE4-4A21-9E74-DEEC4E473B81} 2011-06-22 12:31:58 -------- d-----w- C:\Users\Rob\AppData\Local\{25E607D3-3AFB-4999-9196-87650F621EDB} 2011-06-21 16:10:29 -------- d-----w- C:\Program Files (x86)\Common Files\Spigot 2011-06-21 16:10:29 -------- d-----w- C:\Program Files (x86)\Application Updater 2011-06-21 16:10:00 -------- d-----w- C:\Program Files (x86)\IObit 2011-06-21 15:29:31 -------- d-----w- C:\Users\Rob\AppData\Local\{56008EDC-A9D9-4231-A2B7-4BD8B6F5B4FF} 2011-06-21 11:50:38 -------- d-----w- C:\Users\Rob\AppData\Roaming\PC Tools 2011-06-21 11:50:38 -------- d-----w- C:\ProgramData\PC Tools 2011-06-21 11:49:30 -------- d-----w- C:\Users\Rob\AppData\Roaming\GetRightToGo 2011-06-21 11:43:33 388096 ----a-r- C:\Users\Rob\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2011-06-21 11:43:33 -------- d-----w- C:\Program Files (x86)\Trend Micro 2011-06-21 10:10:20 -------- d-----w- C:\Program Files (x86)\PCPitstop 2011-06-21 08:05:38 8873296 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{F5A9ED11-9184-4399-B9E8-71FC3171E8B8}\mpengine.dll 2011-06-21 04:25:54 -------- d-----w- C:\Program Files (x86)\ESET 2011-06-20 17:56:30 -------- d-----w- C:\Users\Rob\AppData\Local\{34FA15AE-F992-431D-AED0-D3459C24F550} 2011-06-20 05:14:11 -------- d-----w- C:\Users\Rob\AppData\Local\{09ADF9F1-22F7-4D52-B4ED-05B840F1443D} 2011-06-19 12:43:57 -------- d-----w- C:\Users\Rob\AppData\Local\{DF1DA17F-15F6-4E6B-8D3B-8948FD2DE602} 2011-06-18 22:12:02 -------- d-----w- C:\Users\Rob\AppData\Local\{1E72350B-B695-466C-A71C-F5C33F8297BB} 2011-06-18 12:26:21 -------- d-----w- C:\Users\Rob\AppData\Roaming\SuperUtils.com 2011-06-18 12:26:20 -------- d-----w- C:\Program Files (x86)\SuperUtils.com 2011-06-18 05:32:24 -------- d-----w- C:\Users\Rob\AppData\Local\{3B843EB8-82D7-4765-A464-587DFF42B6F4} 2011-06-17 15:46:10 -------- d-----w- C:\Users\Rob\AppData\Local\{8C7565A2-7B25-4C4E-87C1-80FC9D5A6E90} 2011-06-16 23:58:55 -------- d-----w- C:\Users\Rob\AppData\Local\{2DBEDE87-52AA-4C68-A516-E2BF6EFCF724} 2011-06-16 05:10:10 -------- d-----w- C:\Users\Rob\AppData\Local\{A4DE7215-C06E-4922-91FE-FD801FFFF873} 2011-06-15 13:09:27 -------- d-----w- C:\Users\Rob\AppData\Local\{28F1EBBB-186E-4A19-B8B2-E02CCF82AD1E} 2011-06-14 16:25:24 -------- d-----w- C:\Users\Rob\AppData\Local\{79306C2E-4D05-4DA6-B8C8-F775EBD12E01} 2011-06-14 14:36:01 -------- d-----w- C:\ProgramData\ZA_PreservedFiles 2011-06-14 03:55:43 -------- d-----w- C:\Users\Rob\AppData\Local\{617B4F33-A7AF-4FD0-B4FD-1C3CFB893ED2} 2011-06-13 13:54:57 -------- d-----w- C:\Users\Rob\AppData\Local\{4B26F1C6-6878-4FA2-917E-A3A8CF40B684} 2011-06-12 14:30:48 -------- d-----w- C:\Users\Rob\AppData\Local\{3F051E22-ED9E-4CDA-8638-87EEC93E8815} 2011-06-11 15:58:41 -------- d-----w- C:\ProgramData\Drivers For Free 2011-06-11 15:58:17 -------- d-----w- C:\Users\Rob\AppData\Local\Drivers_For_Free 2011-06-11 15:58:08 -------- d-----w- C:\ProgramData\UAB 2011-06-11 15:58:03 -------- d-----w- C:\Users\Rob\AppData\Roaming\Drivers For Free 2011-06-11 15:36:41 -------- d-----w- C:\ProgramData\Uniblue 2011-06-11 13:28:00 -------- d-----w- C:\Users\Rob\AppData\Local\{6B4A4B35-644B-4472-8A16-093D806CD884} 2011-06-10 13:53:46 -------- d-----w- C:\Users\Rob\AppData\Local\{9D0D7E0F-AFCC-4CB0-9F32-91A2999B24FF} 2011-06-09 20:52:09 -------- d-----w- C:\Users\Rob\AppData\Local\{6FA2DBF5-2813-4955-9B32-6E865AF651E0} 2011-06-09 06:47:07 -------- d-----w- C:\Users\Rob\AppData\Local\{29AD2085-FA2A-40E7-A7A5-775DFB30BD05} 2011-06-08 15:32:26 -------- d-----w- C:\Users\Rob\AppData\Local\{A8787725-83D6-40FB-B8D8-5095B6096241} 2011-06-08 00:38:36 -------- d-----w- C:\Users\Rob\AppData\Local\{824784F3-8182-4978-B3C6-F7E212CEB3F9} 2011-06-07 12:17:41 -------- d-----w- C:\Users\Rob\AppData\Roaming\Smarty Uninstaller 2011-06-07 12:17:02 4603616 ----a-w- C:\Windows\SysWow64\DevComponents.DotNetBar2.dll 2011-06-07 12:17:02 -------- d-----w- C:\Program Files (x86)\Smarty Uninstaller 2011-06-07 12:12:39 -------- d-----w- C:\Users\Rob\AppData\Local\{4D4DF58B-E5C5-4AC5-914A-C9B8F3A5C7FC} 2011-06-07 00:04:20 -------- d-----w- C:\Users\Rob\AppData\Local\{837C700F-B582-4BB7-B05B-1B2AB52C62FA} 2011-06-06 16:55:30 183696 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2011-06-06 16:55:30 183696 ----a-w- C:\Program Files (x86)\Internet Explorer\Plugins\nppdf32.dll 2011-06-06 11:33:39 -------- d-----w- C:\Users\Rob\AppData\Local\{6E6201D5-BB43-471F-9364-C996BB98E7D6} 2011-06-05 17:12:50 -------- d-----w- C:\Users\Rob\AppData\Local\{AA6B5B91-6BAD-4321-AD5E-9C495E3BBCF3} 2011-06-05 02:41:55 -------- d-----w- C:\Users\Rob\AppData\Local\{39ED6CBF-995F-414A-8D24-9DD121230134} 2011-06-04 13:44:57 -------- d-----w- C:\Users\Rob\AppData\Local\{A6CDE405-DB88-498D-A0CB-DC4C16ADB415} 2011-06-03 23:44:43 -------- d-----w- C:\Users\Rob\AppData\Local\{7CBC8BA1-1594-4267-A64F-378C89569B58} 2011-06-03 01:01:21 -------- d-----w- C:\Users\Rob\AppData\Local\{AAA6B11B-E1E0-44D5-B850-D9ABFC30DD11} 2011-06-02 11:31:25 -------- d-----w- C:\Users\Rob\AppData\Local\{2F4401A0-E74C-42DA-B5FB-386F0F0806D3} 2011-06-01 13:42:41 -------- d-----w- C:\Users\Rob\AppData\Local\{4B285E89-3824-4610-AE6F-6DE53BE6B7F2} 2011-05-31 14:48:20 -------- d-----w- C:\Users\Rob\AppData\Local\{00CB839A-31C5-41EA-995B-1F0411B4FBAA} 2011-05-30 22:26:10 -------- d-----w- C:\Users\Rob\AppData\Local\{2AD558D6-95C2-4FDE-B8DD-D25C1D249802} 2011-05-29 21:56:38 -------- d-----w- C:\Users\Rob\AppData\Local\{70176E97-6502-4115-92A1-EAF88A8B376E} 2011-05-29 15:57:47 -------- d-----w- C:\Program Files (x86)\WebEnhancements 2011-05-29 15:57:47 -------- d-----w- C:\Program Files (x86)\Viasheep Games 2011-05-29 15:57:47 -------- d-----w- C:\Program Files (x86)\Search Dock 2011-05-29 15:57:47 -------- d-----w- C:\Program Files (x86)\Click Coupon 2011-05-29 15:51:42 -------- d-----w- C:\Program Files (x86)\Real Alternative 2011-05-29 06:01:03 -------- d-----w- C:\Users\Rob\AppData\Local\{EB874F50-837C-4ED5-8F1F-4270063FA937} 2011-05-28 14:29:37 -------- d-----w- C:\Users\Rob\AppData\Local\{72647BC4-32E5-4AB0-94BF-96F769A733E6} 2011-05-27 11:46:11 -------- d-----w- C:\Users\Rob\AppData\Local\{2DE1B0F5-7267-4A54-9D37-0C421D4DACB8} 2011-05-27 11:45:01 -------- d-----w- C:\Users\Rob\AppData\Local\CrashDumps 2011-05-26 15:36:50 -------- d-----w- C:\Program Files (x86)\WizMouse 2011-05-26 15:15:49 -------- d-----w- C:\ProgramData\Soluto 2011-05-26 14:19:41 -------- d-----w- C:\Users\Rob\AppData\Local\{EF7FCE8B-A422-459C-A36D-3D239BCAF395} . ==================== Find3M ==================== . 2011-06-23 09:27:11 46160 ----a-w- C:\Windows\System32\drivers\ImmunetProtect.sys 2011-06-23 09:27:11 29776 ----a-w- C:\Windows\System32\drivers\ImmunetSelfProtect.sys 2011-06-14 14:32:27 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-05-29 13:11:30 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-05-29 13:11:20 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys 2011-05-28 03:30:09 1638912 ----a-w- C:\Windows\System32\mshtml.tlb 2011-05-28 03:06:58 3135488 ----a-w- C:\Windows\System32\win32k.sys 2011-05-28 02:53:58 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2011-05-24 23:14:10 270720 ------w- C:\Windows\System32\MpSigStub.exe 2011-05-08 16:54:56 175616 ----a-w- C:\Windows\System32\msclmd.dll 2011-05-08 16:54:56 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll 2011-05-03 05:29:29 976896 ----a-w- C:\Windows\System32\inetcomm.dll 2011-05-03 04:30:02 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll 2011-04-29 03:06:10 467456 ----a-w- C:\Windows\System32\drivers\srv.sys 2011-04-29 03:05:49 410112 ----a-w- C:\Windows\System32\drivers\srv2.sys 2011-04-29 03:05:37 168448 ----a-w- C:\Windows\System32\drivers\srvnet.sys 2011-04-27 02:40:40 158208 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys 2011-04-27 02:39:40 289280 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys 2011-04-27 02:39:37 128000 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys 2011-04-25 05:33:51 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys 2011-04-25 02:34:03 499200 ----a-w- C:\Windows\System32\drivers\afd.sys 2011-04-22 22:15:29 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys 2011-04-22 22:08:29 1188864 ----a-w- C:\Windows\System32\wininet.dll 2011-04-22 19:10:01 981504 ----a-w- C:\Windows\SysWow64\wininet.dll 2011-04-13 22:40:10 4284416 ----a-w- C:\Windows\SysWow64\GPhotos.scr 2011-04-09 07:02:55 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe 2011-04-09 06:58:56 142336 ----a-w- C:\Windows\System32\poqexec.exe 2011-04-09 06:02:25 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2011-04-09 06:02:25 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2011-04-09 05:56:38 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe 2011-04-08 14:17:46 64272 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys . ============= FINISH: 9:55:07.59 ===============