Recently my computer had been infected with malware that attempted to extort money by posting all kinds of alarmist messages on the screen, telling me that my HD overheated, running too slow, sectors corrupted, etc. It removed registry entries, making it impossible to launch apps. It aslo hijacked the browser.
I managed to clear up most of its effects by restoring the original settings (system restore), then I ran: McAffee anti-virus (found a few infections), Trend Micro Homescan (found nothing), SUPERAntiSpyware (found many tracking cookies, but no viruses/trojans etc.). Finally, I ran Hijackthis, but did not see anything suspicious.
The bottom line: all tools at my disposal report a clean bill of health, but the Internet Explorer 9 starts up by itself (and restarts a short while after I kill it through the Task Manager), occasionally an audio plays from some unknown location, and once in a while McAffee tells me that it blocked an attempt to connect to an unsecure site (never happened before).
Windows Live Mail also complains that "Initialization of RSS support feed failed. RSS feeds could not be updated", although it proceeds to launch after the error panel is dismissed. I haven't seen this before either.
I have Windows 7, 64 bit installed on my Dell All-in-One machine. Any advice is greatly appreciated.
Thanks,
Alex
Logs
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 19:20:01 on 2011-11-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.8188.6234 [GMT -7:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Dell\OSD\DellOSDservice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files\Dell\OSD\DellOSD.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111012231759.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
mRun: [StickyNotesWidget] "c:\Program Files (x86)\Dell Touch Software Suite\StickyNotes\notes_startup_widgets.exe --renderer null"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [FAStartup]
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"
mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
StartupFolder: C:\Users\Alex\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{7817E592-0806-4B58-8743-B89365B31185} : DhcpNameServer = 192.168.0.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111012231759.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: FAIESSOHelper Class: {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO-X64: FAIESSO Helper Object - No File
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mRun-x64: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE
mRun-x64: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun-x64: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun-x64: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
mRun-x64: [StickyNotesWidget] "c:\Program Files (x86)\Dell Touch Software Suite\StickyNotes\notes_startup_widgets.exe --renderer null"
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [FAStartup]
mRun-x64: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [(Default)]
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce-x64: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce-x64: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"
mRunOnce-x64: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\8m8aa8g8.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://echo.msk.ru
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Virtual Earth 3D\npVE3D.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc -
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Users\Alex\AppData\Local\Temp\SAS_SelfExtract\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Users\Alex\AppData\Local\Temp\SAS_SelfExtract\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-9-5 64952]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-5-4 150920]
R2 DellOSDservice;DellOSDservice;C:\Program Files\Dell\OSD\DellOSDservice.exe [2010-11-25 7168]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-2-22 2409800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-9-28 199008]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-9-28 208272]
R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-6-15 689472]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AVerPola;AVerMedia USB Polaris Series Capture Service;C:\Windows\system32\DRIVERS\AVerPola.sys --> C:\Windows\system32\DRIVERS\AVerPola.sys [?]
R3 BcmVWL;Broadcom Virtual Wireless;C:\Windows\system32\DRIVERS\bcmvwl64.sys --> C:\Windows\system32\DRIVERS\bcmvwl64.sys [?]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
R3 nuviocir;Nuvoton W836x7HG CIR Device Driver;C:\Windows\system32\DRIVERS\nuviocir_win7_x64.sys --> C:\Windows\system32\DRIVERS\nuviocir_win7_x64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/06/15 06:32:40;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-10-26 236016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2011-10-5 25072]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-4-23 428384]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2010-4-3 59744]
S4 RsFx0150;RsFx0150 Driver;C:\Windows\system32\DRIVERS\RsFx0150.sys --> C:\Windows\system32\DRIVERS\RsFx0150.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-11-11 02:15:24 -------- d-----w- C:\Users\Alex\AppData\Local\{30237A4E-6EA2-48C0-86DA-61B8632FE7C8}
2011-11-11 02:14:57 -------- d-----w- C:\Users\Alex\AppData\Local\{703E7C38-E143-4D99-AD03-C547F9C45234}
2011-11-11 02:14:18 -------- d-----w- C:\Users\Alex\AppData\Local\{955449E0-AE14-4EEC-9152-245650BC196E}
2011-11-10 13:57:46 -------- d-----w- C:\Users\Alex\AppData\Local\{3B91E719-BF67-4D46-8C7E-8B2AD2FD3CA7}
2011-11-10 13:57:42 -------- d-----w- C:\Users\Alex\AppData\Local\{A0AFCC31-5E5D-4278-A227-AE350CDC3A9D}
2011-11-10 07:07:06 200976 ----a-w- C:\Windows\SysWow64\drivers\tmcomm.sys
2011-11-10 01:58:13 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-11-10 01:56:56 -------- d-----w- C:\Users\Alex\AppData\Local\{F7192B13-4E0D-4756-A62B-55555948D1AC}
2011-11-10 01:55:36 -------- d-----w- C:\Users\Alex\AppData\Local\{5AC48A65-F70E-4EE2-B7BF-8C4DB12145E5}
2011-11-09 05:25:10 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 05:25:09 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 05:25:07 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 05:25:05 3144704 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 02:33:16 -------- d-----w- C:\Users\Alex\AppData\Local\{9EDB4344-CB10-4A06-894B-DA5FFA90021E}
2011-11-09 02:31:47 -------- d-----w- C:\Users\Alex\AppData\Local\{FED61E1E-8A54-4EAE-B988-D225E281DB8D}
2011-11-09 02:01:17 -------- d-----w- C:\52d68c364344d967b33097
2011-11-09 01:48:21 -------- d-----w- C:\Users\Alex\AppData\Roaming\Sammsoft
2011-11-08 04:29:53 -------- d-----w- C:\Users\Alex\AppData\Local\{24190DD4-862A-4C51-89DF-7969FA9D2476}
2011-11-08 04:29:16 -------- d-----w- C:\Users\Alex\AppData\Local\{CFEE8127-6B7B-4D7D-A4CB-4019EA49A1C7}
2011-11-08 02:32:44 -------- d-----w- C:\Users\Alex\AppData\Local\{1B4F8561-2786-4862-BEDC-41C807F8DB20}
2011-11-08 02:31:39 -------- d-----w- C:\Users\Alex\AppData\Local\{5A244EF5-84AC-464A-8F28-E76C2FF82A42}
2011-11-07 03:53:42 -------- d-----w- C:\Users\Alex\AppData\Local\{7BEE95B6-6B0C-4900-B90F-D02FD9383DF1}
2011-11-07 03:52:56 -------- d-----w- C:\Users\Alex\AppData\Local\{25C09036-F8B7-491E-B371-0C1948FF6B7E}
2011-11-06 15:52:03 -------- d-----w- C:\Users\Alex\AppData\Local\{2B46CC7A-E80F-482F-82F1-71296D7516A0}
2011-11-06 15:50:59 -------- d-----w- C:\Users\Alex\AppData\Local\{D8EB5CBC-9C57-4D89-A83B-BA8171E8A060}
2011-11-06 03:02:51 -------- d-----w- C:\Users\Alex\AppData\Local\{7B779C31-A751-468C-B261-5BAD2028444F}
2011-11-06 03:02:01 -------- d-----w- C:\Users\Alex\AppData\Local\{30FBC544-8AE6-4054-8AFF-CC90BF66840B}
2011-11-05 15:01:36 -------- d-----w- C:\Users\Alex\AppData\Local\{1EF8E2CF-8CDC-4556-8B40-4D727DDD3EE9}
2011-11-05 15:01:30 -------- d-----w- C:\Users\Alex\AppData\Local\{7F761140-C939-4B24-8BF1-D479BCC749D8}
2011-11-05 02:35:16 -------- d-----w- C:\Program Files (x86)\StepForwardAdmin
2011-11-05 01:45:07 -------- d-----w- C:\Users\Alex\AppData\Local\{F469BE58-E46A-407D-AF06-ED842CBBC91C}
2011-11-05 01:44:03 -------- d-----w- C:\Users\Alex\AppData\Local\{CCA93615-2AD0-407E-B9BF-751CEA74416D}
2011-11-04 02:06:48 -------- d-----w- C:\Users\Alex\AppData\Local\{C38D37F7-ABC6-42E6-9754-761FF5B2E1C0}
2011-11-04 02:06:16 -------- d-----w- C:\Users\Alex\AppData\Local\{DD7DCFC1-965B-4766-B1C0-678C848E8C45}
2011-11-03 01:53:38 -------- d-----w- C:\Users\Alex\AppData\Local\{B94FC51C-2874-4422-8DCE-D096A30DD35C}
2011-11-03 01:52:42 -------- d-----w- C:\Users\Alex\AppData\Local\{FC88A71A-D1DD-4C85-A882-F811AC684764}
2011-11-02 01:14:03 -------- d-----w- C:\Users\Alex\AppData\Local\{AFAE05AE-A3C6-4A91-923F-7729568005B1}
2011-11-02 01:12:27 -------- d-----w- C:\Users\Alex\AppData\Local\{A2AA007D-6690-4C5F-9360-3D5E173C8E1A}
2011-11-01 01:31:14 -------- d-----w- C:\Users\Alex\AppData\Local\{263727D7-A107-4839-8189-F21B0C547E4A}
2011-11-01 01:30:02 -------- d-----w- C:\Users\Alex\AppData\Local\{CD487BF2-F7D4-460A-A2B4-CD5A502B6613}
2011-10-31 05:44:09 -------- d-----w- C:\Users\Alex\AppData\Local\{FB679E7D-300E-4155-8A5D-03D61914FC57}
2011-10-30 17:09:56 -------- d-----w- C:\Users\Alex\AppData\Local\{8F191CE8-8F39-4F68-8928-22E0632E93B5}
2011-10-30 17:08:35 -------- d-----w- C:\Users\Alex\AppData\Local\{D25A1EC6-7A4A-4376-B9E7-28D595BCA532}
2011-10-30 05:49:04 -------- d-----w- C:\Program Files (x86)\uTorrent
2011-10-30 05:46:16 -------- d-----w- C:\Users\Alex\AppData\Local\uTorrent
2011-10-30 03:30:47 -------- d-----w- C:\Users\Alex\AppData\Local\{E96CB59D-5E15-4E33-8E2F-909ED1482B9C}
2011-10-30 03:29:52 -------- d-----w- C:\Users\Alex\AppData\Local\{C1B881DB-004E-4EB3-B3BA-2CBF4B27BA61}
2011-10-29 15:29:08 -------- d-----w- C:\Users\Alex\AppData\Local\{234A3D1F-86AC-4487-80ED-70D8BDDBEEB5}
2011-10-29 15:28:36 -------- d-----w- C:\Users\Alex\AppData\Local\{01358DE2-6BB4-46CE-B477-74A410250C1A}
2011-10-29 03:27:50 -------- d-----w- C:\Users\Alex\AppData\Local\{7234F3F1-D852-4AB7-AD2D-B8363F3D5BA1}
2011-10-29 03:27:18 -------- d-----w- C:\Users\Alex\AppData\Local\{F3FF803B-5EB6-477D-B67B-B7B653B8EFFE}
2011-10-28 01:24:30 -------- d-----w- C:\Users\Alex\AppData\Local\{893E98CB-3F41-4AB2-959A-A33A0D9A3E8D}
2011-10-28 01:24:09 -------- d-----w- C:\Users\Alex\AppData\Local\{CBC69AAA-294B-49B6-9532-430FBB04EC96}
2011-10-27 00:36:52 -------- d-----w- C:\Users\Alex\AppData\Local\{9ED28368-0386-4857-96A8-AC2ABEC4B90C}
2011-10-27 00:35:22 -------- d-----w- C:\Users\Alex\AppData\Local\{93BFB955-554A-4A96-9298-CE2E84A9EC53}
2011-10-26 01:05:46 -------- d-----w- C:\Users\Alex\AppData\Local\{82D89231-7A11-4796-AB17-4A032EE8DD28}
2011-10-26 01:04:34 -------- d-----w- C:\Users\Alex\AppData\Local\{C78B1856-EBD1-489A-A254-6ED3918459A9}
2011-10-25 01:49:14 -------- d-----w- C:\Users\Alex\AppData\Local\{740A888B-36FD-49C4-AE61-97120ABE23E5}
2011-10-25 01:48:01 -------- d-----w- C:\Users\Alex\AppData\Local\{501313BC-FDC3-4E3E-9A21-DBF4C9CF156D}
2011-10-24 04:22:21 -------- d-----w- C:\Users\Alex\AppData\Local\{0BFD9D20-9FDA-4C88-BA34-B8A712C08D8D}
2011-10-24 04:21:14 -------- d-----w- C:\Users\Alex\AppData\Local\{79A3C2FC-0BC9-4302-8EF3-D314604BB687}
2011-10-23 21:24:39 -------- d-----w- C:\Users\Alex\AppData\Local\Sonic_Solutions
2011-10-23 16:20:11 -------- d-----w- C:\Users\Alex\AppData\Local\{7F99C657-FDF3-4C46-BB79-E72523ED01E3}
2011-10-23 16:18:57 -------- d-----w- C:\Users\Alex\AppData\Local\{8DB07DC1-5D34-4931-A7FD-4D22A5EC26C0}
2011-10-23 04:18:07 -------- d-----w- C:\Users\Alex\AppData\Local\{C56125CE-E71E-4536-981D-92DB1FCD380C}
2011-10-23 04:17:00 -------- d-----w- C:\Users\Alex\AppData\Local\{9E34FA16-B2F1-4FCA-AD6C-B5E5C0ACB2DD}
2011-10-23 02:14:33 -------- d--h--w- C:\Program Files\eclipse3
2011-10-23 02:08:35 -------- d-----w- C:\Users\Alex\workspace
2011-10-23 02:02:50 -------- d-----w- C:\eclipse-SDK-3.5.1-win32
2011-10-23 00:49:57 -------- d-----w- C:\Program Files (x86)\StepForwardClient
2011-10-23 00:43:41 -------- d--h--w- C:\Program Files (x86)\Zero G Registry
2011-10-22 15:51:01 -------- d-----w- C:\Users\Alex\AppData\Local\{B27CEB9B-1FF1-4ED7-A7D6-973328F77EFD}
2011-10-22 15:49:45 -------- d-----w- C:\Users\Alex\AppData\Local\{A91C72A4-1382-491E-A763-CBDC055954CA}
2011-10-22 01:44:57 -------- d-----w- C:\Users\Alex\AppData\Local\{5A5D661F-AB72-4AAF-BD0E-A03678537884}
2011-10-22 01:43:59 -------- d-----w- C:\Users\Alex\AppData\Local\{7B494376-481C-4555-A7CB-36560123A754}
2011-10-21 01:45:26 -------- d-----w- C:\Users\Alex\AppData\Local\{F268828C-7678-45CF-8008-6A445D7568C6}
2011-10-21 01:44:11 -------- d-----w- C:\Users\Alex\AppData\Local\{0A9085E1-A89F-4C5D-8BC4-7F8ED8BB0116}
2011-10-20 00:29:54 -------- d-----w- C:\Users\Alex\AppData\Local\{AD2C6965-B913-4FDF-9E63-1E287263C124}
2011-10-20 00:28:57 -------- d-----w- C:\Users\Alex\AppData\Local\{A9BDE37B-7F5F-4200-A9B6-50647BCBE5B2}
2011-10-19 00:31:34 -------- d-----w- C:\Users\Alex\AppData\Local\{6B421DF5-16B8-4F0D-9038-094508856E8E}
2011-10-19 00:29:47 -------- d-----w- C:\Users\Alex\AppData\Local\{568C5453-37C0-41CD-ADA7-327EA3A6CCF7}
2011-10-18 00:29:59 -------- d-----w- C:\Users\Alex\AppData\Local\{C025218F-EE77-467B-916A-2F1509F38C6A}
2011-10-18 00:29:06 -------- d-----w- C:\Users\Alex\AppData\Local\{FE9F16C7-90E1-43D2-AB66-CFAF862786DC}
2011-10-16 21:24:08 -------- d-----w- C:\Users\Alex\AppData\Local\{B17CF388-64DC-4D4A-9437-2E2735914A70}
2011-10-16 21:23:27 -------- d-----w- C:\Users\Alex\AppData\Local\{113CEDD0-A60A-4697-8125-1AB52DF2B420}
2011-10-16 03:41:06 -------- d-----w- C:\Users\Alex\AppData\Local\{2CDE75EF-8183-464A-8AEE-1671AC04F965}
2011-10-16 03:40:37 -------- d-----w- C:\Users\Alex\AppData\Local\{1F7E8CD1-0EF8-4742-9998-5C278D4F53AD}
2011-10-15 15:40:24 -------- d-----w- C:\Users\Alex\AppData\Local\{43CC7FA2-4E51-4F97-B867-8BF9CD2BFB24}
2011-10-15 15:39:51 -------- d-----w- C:\Users\Alex\AppData\Local\{510E1721-4F0F-403A-9A80-4D78B11AF5A7}
2011-10-15 01:10:02 -------- d-----w- C:\Users\Alex\AppData\Local\{86391098-1503-48D3-A980-D7915EE87BB6}
2011-10-15 01:09:36 -------- d-----w- C:\Users\Alex\AppData\Local\{8B65DC12-F22F-4BDF-85B2-27D2F9DD1445}
2011-10-14 02:32:45 -------- d-----w- C:\Users\Alex\AppData\Local\{841BB974-ED9C-4CDA-A665-B1A0C95038FE}
2011-10-14 02:31:37 -------- d-----w- C:\Users\Alex\AppData\Local\{205E0237-15F5-4B9D-ABA4-A64F229AE94F}
2011-10-14 00:34:15 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-14 00:34:15 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-10-14 00:34:14 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-14 00:34:14 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-10-14 00:33:55 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-14 00:33:55 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-14 00:33:55 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-14 00:33:54 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-13 01:15:04 -------- d-----w- C:\Users\Alex\AppData\Local\{6FA3C4E8-F817-420B-9FF1-A1C08DA750DD}
2011-10-13 01:14:55 -------- d-----w- C:\Users\Alex\AppData\Local\{9B1E6C9B-3E59-4F0F-87D3-EAE4B4C77C65}
.
==================== Find3M ====================
.
2011-11-10 06:48:59 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-07 02:51:37 103784 ----a-w- C:\Users\Alex\GoToAssistDownloadHelper.exe
2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-19 21:59:28 158832 ----a-w- C:\Windows\System32\mfevtps.exe
2011-08-15 16:00:06 9984 ----a-w- C:\Windows\System32\drivers\mfeclnk.sys
2011-08-15 16:00:06 75672 ----a-w- C:\Windows\System32\drivers\mfenlfk.sys
2011-08-15 16:00:06 65128 ----a-w- C:\Windows\System32\drivers\cfwids.sys
2011-08-15 16:00:06 642824 ----a-w- C:\Windows\System32\drivers\mfehidk.sys
2011-08-15 16:00:06 481504 ----a-w- C:\Windows\System32\drivers\mfefirek.sys
2011-08-15 16:00:06 283744 ----a-w- C:\Windows\System32\drivers\mfewfpk.sys
2011-08-15 16:00:06 228752 ----a-w- C:\Windows\System32\drivers\mfeavfk.sys
2011-08-15 16:00:06 158584 ----a-w- C:\Windows\System32\drivers\mfeapfk.sys
2011-08-15 16:00:06 100904 ----a-w- C:\Windows\System32\drivers\mferkdet.sys
.
============= FINISH: 19:36:53.90 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 23/09/2011 7:59:27 PM
System Uptime: 10/11/2011 7:11:54 PM (0 hours ago)
.
Motherboard: Dell Inc. | | 0DPRF9
Processor: AMD Athlon(tm) II X4 610e Processor | CPU 1 | 2400/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 719.844 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
==== System Restore Points ===================
.
RP44: 22/10/2011 10:24:21 AM - Windows Modules Installer
RP45: 23/10/2011 1:35:48 AM - Windows Update
RP46: 26/10/2011 12:40:38 AM - Windows Update
RP47: 29/10/2011 9:17:41 AM - Windows Update
RP48: 05/11/2011 8:04:34 PM - Scheduled Checkpoint
RP49: 07/11/2011 9:02:27 PM - Restore Operation
RP50: 08/11/2011 6:47:37 PM - ARO 2011 - Before Installation
RP51: 08/11/2011 6:48:26 PM - ARO 2011 - FIRST RUN
RP52: 08/11/2011 7:21:13 PM - ARO 2011 Tue, Nov 08, 11 19:21
RP53: 09/11/2011 1:05:27 AM - Windows Update
.
==== Installed Programs ======================
.
Accidental Damage Services Agreement
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.1) MUI
Advanced Audio FX Engine
Apple Application Support
Apple Software Update
ATI Catalyst Control Center
µTorrent
Bejeweled 2 Deluxe
Blackhawk Striker 2
Bounce Symphony
Build-a-lot 2
Cake Mania
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Chuzzle Deluxe
CIR Tool Kit
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Cozi
CyberLink PowerDVD 9.5
CyberLink YouPaint
D3DX10
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Digital Delivery
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell Touch Software Suite Games
Dell VideoStage
Dell Webcam Central
Diner Dash 2 Restaurant Rescue
DirectX 9 Runtime
Dora's World Adventure
eBay
Escape Whisper Valley (TM)
Farm Frenzy
FATE
Final Drive Fury
Final Drive Nitro
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 24
Jewel Quest
Jewel Quest Solitaire 2
Junk Mail filter update
Luxor
McAfee SecurityCenter
Mesh Runtime
Microsoft Office 2010
Microsoft Report Viewer Redistributable 2008 (KB971119)
Microsoft Report Viewer Redistributable 2008 SP1
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2008 R2 Policies
Microsoft SQL Server Browser
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 Query Tools ENU
Microsoft Touch Pack for Windows 7
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft XNA Framework Redistributable 3.0
Mozilla Firefox 8.0 (x86 en-US)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Multimedia Card Reader
Namco All-Stars PAC-MAN
OpenOffice.org 3.3
OpenVPN 2.2.1
Penguins!
PhotoShowExpress
Plants vs. Zombies - Game of the Year
Poker Superstars III
Polar Bowler
Polar Golfer
QualxServ Service Agreement
QuickTime
Realtek High Definition Audio Driver
Remote Administrator v2.2
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
Samantha Swift
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Skins
Skype Click to Call
Skype™ 5.5
Sonic CinePlayer Decoder Pack
StepForward Client
StepForwardAdmin
StickyNotes
THX TruStudio PC
TrustedID
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update Installer for WildTangent Games App
Virtual Villagers 4 - The Tree of Life
Wedding Dash - Ready, Aim, Love!
WildTangent Games
WildTangent Games App (Dell Games)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Wisdom-soft Set up ScreenHunter 5.1 Free
Zuma Deluxe
.
==== Event Viewer Messages From Past Week ========
.
10/11/2011 7:32:56 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume .
08/11/2011 5:51:13 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
08/11/2011 3:18:37 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the McAfee McShield service to connect.
08/11/2011 3:18:37 AM, Error: Service Control Manager [7000] - The McAfee McShield service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
07/11/2011 8:24:42 PM, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
07/11/2011 8:22:53 PM, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
.
==== End Of File ===========================
I managed to clear up most of its effects by restoring the original settings (system restore), then I ran: McAffee anti-virus (found a few infections), Trend Micro Homescan (found nothing), SUPERAntiSpyware (found many tracking cookies, but no viruses/trojans etc.). Finally, I ran Hijackthis, but did not see anything suspicious.
The bottom line: all tools at my disposal report a clean bill of health, but the Internet Explorer 9 starts up by itself (and restarts a short while after I kill it through the Task Manager), occasionally an audio plays from some unknown location, and once in a while McAffee tells me that it blocked an attempt to connect to an unsecure site (never happened before).
Windows Live Mail also complains that "Initialization of RSS support feed failed. RSS feeds could not be updated", although it proceeds to launch after the error panel is dismissed. I haven't seen this before either.
I have Windows 7, 64 bit installed on my Dell All-in-One machine. Any advice is greatly appreciated.
Thanks,
Alex
Logs
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by [removed] at 19:20:01 on 2011-11-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.8188.6234 [GMT -7:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
c:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\Dell\OSD\DellOSDservice.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Windows\system32\mfevtps.exe
C:\Program Files\Dell\OSD\DellOSD.exe
C:\Windows\system32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
c:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
C:\Windows\system32\Dwm.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Windows\Explorer.EXE
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files (x86)\Sensible Vision\Fast Access\FATrayAlert.exe
C:\Program Files (x86)\CyberLink\Shared files\brs.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111012231759.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mRun: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun: [UpdReg] C:\Windows\UpdReg.EXE
mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
mRun: [StickyNotesWidget] "c:\Program Files (x86)\Dell Touch Software Suite\StickyNotes\notes_startup_widgets.exe --renderer null"
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun: [FAStartup]
mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"
mRunOnce: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
StartupFolder: C:\Users\Alex\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{7817E592-0806-4B58-8743-B89365B31185} : DhcpNameServer = 192.168.0.1
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\McAfee\MSC\McSnIePl.dll
Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\McAfee\SITEAD~1\McIEPlg.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - c:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20111012231759.dll
BHO-X64: scriptproxy - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: FAIESSOHelper Class: {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - c:\Program Files (x86)\Sensible Vision\Fast Access\FAIESSO.dll
BHO-X64: FAIESSO Helper Object - No File
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
TB-X64: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
mRun-x64: [StartCCC] "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun-x64: [FATrayAlert] c:\Program Files (x86)\Sensible Vision\Fast Access\FATrayMon.exe
mRun-x64: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r
mRun-x64: [UpdReg] C:\Windows\UpdReg.EXE
mRun-x64: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"
mRun-x64: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"
mRun-x64: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe
mRun-x64: [StickyNotesWidget] "c:\Program Files (x86)\Dell Touch Software Suite\StickyNotes\notes_startup_widgets.exe --renderer null"
mRun-x64: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
mRun-x64: [FAStartup]
mRun-x64: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [(Default)]
mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
mRun-x64: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRunOnce-x64: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
mRunOnce-x64: [DSUpdateLauncher] "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\hstart.exe" /NOCONSOLE /D="C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate" /RUNAS "C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe"
mRunOnce-x64: [STToasterLauncher] C:\Program Files (x86)\Dell DataSafe Local Backup\toasterLauncher.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\8m8aa8g8.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://echo.msk.ru
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
FF - plugin: c:\progra~2\mcafee\msc\npMcSnFFPl.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Virtual Earth 3D\npVE3D.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc -
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
R0 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\system32\drivers\mfewfpk.sys --> C:\Windows\system32\drivers\mfewfpk.sys [?]
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\system32\DRIVERS\mfenlfk.sys --> C:\Windows\system32\DRIVERS\mfenlfk.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Users\Alex\AppData\Local\Temp\SAS_SelfExtract\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Users\Alex\AppData\Local\Temp\SAS_SelfExtract\saskutil64.sys [2011-7-12 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-9-5 64952]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
R2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2011-5-4 150920]
R2 DellOSDservice;DellOSDservice;C:\Program Files\Dell\OSD\DellOSDservice.exe [2010-11-25 7168]
R2 FAService;FAService;C:\Program Files (x86)\Sensible Vision\Fast Access\FAService.exe [2010-2-22 2409800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McMPFSvc;McAfee Personal Firewall Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McNaiAnn;McAfee VirusScan Announcer;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McProxy;McAfee Proxy Service;C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-9-28 249936]
R2 McShield;McAfee McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2011-9-28 199008]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2011-9-28 208272]
R2 mfevtp;McAfee Validation Trust Protection Service;"C:\Windows\system32\mfevtps.exe" --> C:\Windows\system32\mfevtps.exe [?]
R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-6-15 689472]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
R3 AVerPola;AVerMedia USB Polaris Series Capture Service;C:\Windows\system32\DRIVERS\AVerPola.sys --> C:\Windows\system32\DRIVERS\AVerPola.sys [?]
R3 BcmVWL;Broadcom Virtual Wireless;C:\Windows\system32\DRIVERS\bcmvwl64.sys --> C:\Windows\system32\DRIVERS\bcmvwl64.sys [?]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\system32\drivers\cfwids.sys --> C:\Windows\system32\drivers\cfwids.sys [?]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\system32\DRIVERS\CtClsFlt.sys --> C:\Windows\system32\DRIVERS\CtClsFlt.sys [?]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\system32\drivers\mfefirek.sys --> C:\Windows\system32\drivers\mfefirek.sys [?]
R3 nuviocir;Nuvoton W836x7HG CIR Device Driver;C:\Windows\system32\DRIVERS\nuviocir_win7_x64.sys --> C:\Windows\system32\DRIVERS\nuviocir_win7_x64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 CLKMSVC10_9EC60124;CyberLink Product - 2011/06/15 06:32:40;C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [2010-10-26 236016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\system32\DRIVERS\facap.sys --> C:\Windows\system32\DRIVERS\facap.sys [?]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\Dell Support Center\pcdsrvc_x64.pkms [2011-10-5 25072]
S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]
S3 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2011-4-23 428384]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2010-4-3 59744]
S4 RsFx0150;RsFx0150 Driver;C:\Windows\system32\DRIVERS\RsFx0150.sys --> C:\Windows\system32\DRIVERS\RsFx0150.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2011-11-11 02:15:24 -------- d-----w- C:\Users\Alex\AppData\Local\{30237A4E-6EA2-48C0-86DA-61B8632FE7C8}
2011-11-11 02:14:57 -------- d-----w- C:\Users\Alex\AppData\Local\{703E7C38-E143-4D99-AD03-C547F9C45234}
2011-11-11 02:14:18 -------- d-----w- C:\Users\Alex\AppData\Local\{955449E0-AE14-4EEC-9152-245650BC196E}
2011-11-10 13:57:46 -------- d-----w- C:\Users\Alex\AppData\Local\{3B91E719-BF67-4D46-8C7E-8B2AD2FD3CA7}
2011-11-10 13:57:42 -------- d-----w- C:\Users\Alex\AppData\Local\{A0AFCC31-5E5D-4278-A227-AE350CDC3A9D}
2011-11-10 07:07:06 200976 ----a-w- C:\Windows\SysWow64\drivers\tmcomm.sys
2011-11-10 01:58:13 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-11-10 01:56:56 -------- d-----w- C:\Users\Alex\AppData\Local\{F7192B13-4E0D-4756-A62B-55555948D1AC}
2011-11-10 01:55:36 -------- d-----w- C:\Users\Alex\AppData\Local\{5AC48A65-F70E-4EE2-B7BF-8C4DB12145E5}
2011-11-09 05:25:10 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 05:25:09 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 05:25:07 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-11-09 05:25:05 3144704 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 02:33:16 -------- d-----w- C:\Users\Alex\AppData\Local\{9EDB4344-CB10-4A06-894B-DA5FFA90021E}
2011-11-09 02:31:47 -------- d-----w- C:\Users\Alex\AppData\Local\{FED61E1E-8A54-4EAE-B988-D225E281DB8D}
2011-11-09 02:01:17 -------- d-----w- C:\52d68c364344d967b33097
2011-11-09 01:48:21 -------- d-----w- C:\Users\Alex\AppData\Roaming\Sammsoft
2011-11-08 04:29:53 -------- d-----w- C:\Users\Alex\AppData\Local\{24190DD4-862A-4C51-89DF-7969FA9D2476}
2011-11-08 04:29:16 -------- d-----w- C:\Users\Alex\AppData\Local\{CFEE8127-6B7B-4D7D-A4CB-4019EA49A1C7}
2011-11-08 02:32:44 -------- d-----w- C:\Users\Alex\AppData\Local\{1B4F8561-2786-4862-BEDC-41C807F8DB20}
2011-11-08 02:31:39 -------- d-----w- C:\Users\Alex\AppData\Local\{5A244EF5-84AC-464A-8F28-E76C2FF82A42}
2011-11-07 03:53:42 -------- d-----w- C:\Users\Alex\AppData\Local\{7BEE95B6-6B0C-4900-B90F-D02FD9383DF1}
2011-11-07 03:52:56 -------- d-----w- C:\Users\Alex\AppData\Local\{25C09036-F8B7-491E-B371-0C1948FF6B7E}
2011-11-06 15:52:03 -------- d-----w- C:\Users\Alex\AppData\Local\{2B46CC7A-E80F-482F-82F1-71296D7516A0}
2011-11-06 15:50:59 -------- d-----w- C:\Users\Alex\AppData\Local\{D8EB5CBC-9C57-4D89-A83B-BA8171E8A060}
2011-11-06 03:02:51 -------- d-----w- C:\Users\Alex\AppData\Local\{7B779C31-A751-468C-B261-5BAD2028444F}
2011-11-06 03:02:01 -------- d-----w- C:\Users\Alex\AppData\Local\{30FBC544-8AE6-4054-8AFF-CC90BF66840B}
2011-11-05 15:01:36 -------- d-----w- C:\Users\Alex\AppData\Local\{1EF8E2CF-8CDC-4556-8B40-4D727DDD3EE9}
2011-11-05 15:01:30 -------- d-----w- C:\Users\Alex\AppData\Local\{7F761140-C939-4B24-8BF1-D479BCC749D8}
2011-11-05 02:35:16 -------- d-----w- C:\Program Files (x86)\StepForwardAdmin
2011-11-05 01:45:07 -------- d-----w- C:\Users\Alex\AppData\Local\{F469BE58-E46A-407D-AF06-ED842CBBC91C}
2011-11-05 01:44:03 -------- d-----w- C:\Users\Alex\AppData\Local\{CCA93615-2AD0-407E-B9BF-751CEA74416D}
2011-11-04 02:06:48 -------- d-----w- C:\Users\Alex\AppData\Local\{C38D37F7-ABC6-42E6-9754-761FF5B2E1C0}
2011-11-04 02:06:16 -------- d-----w- C:\Users\Alex\AppData\Local\{DD7DCFC1-965B-4766-B1C0-678C848E8C45}
2011-11-03 01:53:38 -------- d-----w- C:\Users\Alex\AppData\Local\{B94FC51C-2874-4422-8DCE-D096A30DD35C}
2011-11-03 01:52:42 -------- d-----w- C:\Users\Alex\AppData\Local\{FC88A71A-D1DD-4C85-A882-F811AC684764}
2011-11-02 01:14:03 -------- d-----w- C:\Users\Alex\AppData\Local\{AFAE05AE-A3C6-4A91-923F-7729568005B1}
2011-11-02 01:12:27 -------- d-----w- C:\Users\Alex\AppData\Local\{A2AA007D-6690-4C5F-9360-3D5E173C8E1A}
2011-11-01 01:31:14 -------- d-----w- C:\Users\Alex\AppData\Local\{263727D7-A107-4839-8189-F21B0C547E4A}
2011-11-01 01:30:02 -------- d-----w- C:\Users\Alex\AppData\Local\{CD487BF2-F7D4-460A-A2B4-CD5A502B6613}
2011-10-31 05:44:09 -------- d-----w- C:\Users\Alex\AppData\Local\{FB679E7D-300E-4155-8A5D-03D61914FC57}
2011-10-30 17:09:56 -------- d-----w- C:\Users\Alex\AppData\Local\{8F191CE8-8F39-4F68-8928-22E0632E93B5}
2011-10-30 17:08:35 -------- d-----w- C:\Users\Alex\AppData\Local\{D25A1EC6-7A4A-4376-B9E7-28D595BCA532}
2011-10-30 05:49:04 -------- d-----w- C:\Program Files (x86)\uTorrent
2011-10-30 05:46:16 -------- d-----w- C:\Users\Alex\AppData\Local\uTorrent
2011-10-30 03:30:47 -------- d-----w- C:\Users\Alex\AppData\Local\{E96CB59D-5E15-4E33-8E2F-909ED1482B9C}
2011-10-30 03:29:52 -------- d-----w- C:\Users\Alex\AppData\Local\{C1B881DB-004E-4EB3-B3BA-2CBF4B27BA61}
2011-10-29 15:29:08 -------- d-----w- C:\Users\Alex\AppData\Local\{234A3D1F-86AC-4487-80ED-70D8BDDBEEB5}
2011-10-29 15:28:36 -------- d-----w- C:\Users\Alex\AppData\Local\{01358DE2-6BB4-46CE-B477-74A410250C1A}
2011-10-29 03:27:50 -------- d-----w- C:\Users\Alex\AppData\Local\{7234F3F1-D852-4AB7-AD2D-B8363F3D5BA1}
2011-10-29 03:27:18 -------- d-----w- C:\Users\Alex\AppData\Local\{F3FF803B-5EB6-477D-B67B-B7B653B8EFFE}
2011-10-28 01:24:30 -------- d-----w- C:\Users\Alex\AppData\Local\{893E98CB-3F41-4AB2-959A-A33A0D9A3E8D}
2011-10-28 01:24:09 -------- d-----w- C:\Users\Alex\AppData\Local\{CBC69AAA-294B-49B6-9532-430FBB04EC96}
2011-10-27 00:36:52 -------- d-----w- C:\Users\Alex\AppData\Local\{9ED28368-0386-4857-96A8-AC2ABEC4B90C}
2011-10-27 00:35:22 -------- d-----w- C:\Users\Alex\AppData\Local\{93BFB955-554A-4A96-9298-CE2E84A9EC53}
2011-10-26 01:05:46 -------- d-----w- C:\Users\Alex\AppData\Local\{82D89231-7A11-4796-AB17-4A032EE8DD28}
2011-10-26 01:04:34 -------- d-----w- C:\Users\Alex\AppData\Local\{C78B1856-EBD1-489A-A254-6ED3918459A9}
2011-10-25 01:49:14 -------- d-----w- C:\Users\Alex\AppData\Local\{740A888B-36FD-49C4-AE61-97120ABE23E5}
2011-10-25 01:48:01 -------- d-----w- C:\Users\Alex\AppData\Local\{501313BC-FDC3-4E3E-9A21-DBF4C9CF156D}
2011-10-24 04:22:21 -------- d-----w- C:\Users\Alex\AppData\Local\{0BFD9D20-9FDA-4C88-BA34-B8A712C08D8D}
2011-10-24 04:21:14 -------- d-----w- C:\Users\Alex\AppData\Local\{79A3C2FC-0BC9-4302-8EF3-D314604BB687}
2011-10-23 21:24:39 -------- d-----w- C:\Users\Alex\AppData\Local\Sonic_Solutions
2011-10-23 16:20:11 -------- d-----w- C:\Users\Alex\AppData\Local\{7F99C657-FDF3-4C46-BB79-E72523ED01E3}
2011-10-23 16:18:57 -------- d-----w- C:\Users\Alex\AppData\Local\{8DB07DC1-5D34-4931-A7FD-4D22A5EC26C0}
2011-10-23 04:18:07 -------- d-----w- C:\Users\Alex\AppData\Local\{C56125CE-E71E-4536-981D-92DB1FCD380C}
2011-10-23 04:17:00 -------- d-----w- C:\Users\Alex\AppData\Local\{9E34FA16-B2F1-4FCA-AD6C-B5E5C0ACB2DD}
2011-10-23 02:14:33 -------- d--h--w- C:\Program Files\eclipse3
2011-10-23 02:08:35 -------- d-----w- C:\Users\Alex\workspace
2011-10-23 02:02:50 -------- d-----w- C:\eclipse-SDK-3.5.1-win32
2011-10-23 00:49:57 -------- d-----w- C:\Program Files (x86)\StepForwardClient
2011-10-23 00:43:41 -------- d--h--w- C:\Program Files (x86)\Zero G Registry
2011-10-22 15:51:01 -------- d-----w- C:\Users\Alex\AppData\Local\{B27CEB9B-1FF1-4ED7-A7D6-973328F77EFD}
2011-10-22 15:49:45 -------- d-----w- C:\Users\Alex\AppData\Local\{A91C72A4-1382-491E-A763-CBDC055954CA}
2011-10-22 01:44:57 -------- d-----w- C:\Users\Alex\AppData\Local\{5A5D661F-AB72-4AAF-BD0E-A03678537884}
2011-10-22 01:43:59 -------- d-----w- C:\Users\Alex\AppData\Local\{7B494376-481C-4555-A7CB-36560123A754}
2011-10-21 01:45:26 -------- d-----w- C:\Users\Alex\AppData\Local\{F268828C-7678-45CF-8008-6A445D7568C6}
2011-10-21 01:44:11 -------- d-----w- C:\Users\Alex\AppData\Local\{0A9085E1-A89F-4C5D-8BC4-7F8ED8BB0116}
2011-10-20 00:29:54 -------- d-----w- C:\Users\Alex\AppData\Local\{AD2C6965-B913-4FDF-9E63-1E287263C124}
2011-10-20 00:28:57 -------- d-----w- C:\Users\Alex\AppData\Local\{A9BDE37B-7F5F-4200-A9B6-50647BCBE5B2}
2011-10-19 00:31:34 -------- d-----w- C:\Users\Alex\AppData\Local\{6B421DF5-16B8-4F0D-9038-094508856E8E}
2011-10-19 00:29:47 -------- d-----w- C:\Users\Alex\AppData\Local\{568C5453-37C0-41CD-ADA7-327EA3A6CCF7}
2011-10-18 00:29:59 -------- d-----w- C:\Users\Alex\AppData\Local\{C025218F-EE77-467B-916A-2F1509F38C6A}
2011-10-18 00:29:06 -------- d-----w- C:\Users\Alex\AppData\Local\{FE9F16C7-90E1-43D2-AB66-CFAF862786DC}
2011-10-16 21:24:08 -------- d-----w- C:\Users\Alex\AppData\Local\{B17CF388-64DC-4D4A-9437-2E2735914A70}
2011-10-16 21:23:27 -------- d-----w- C:\Users\Alex\AppData\Local\{113CEDD0-A60A-4697-8125-1AB52DF2B420}
2011-10-16 03:41:06 -------- d-----w- C:\Users\Alex\AppData\Local\{2CDE75EF-8183-464A-8AEE-1671AC04F965}
2011-10-16 03:40:37 -------- d-----w- C:\Users\Alex\AppData\Local\{1F7E8CD1-0EF8-4742-9998-5C278D4F53AD}
2011-10-15 15:40:24 -------- d-----w- C:\Users\Alex\AppData\Local\{43CC7FA2-4E51-4F97-B867-8BF9CD2BFB24}
2011-10-15 15:39:51 -------- d-----w- C:\Users\Alex\AppData\Local\{510E1721-4F0F-403A-9A80-4D78B11AF5A7}
2011-10-15 01:10:02 -------- d-----w- C:\Users\Alex\AppData\Local\{86391098-1503-48D3-A980-D7915EE87BB6}
2011-10-15 01:09:36 -------- d-----w- C:\Users\Alex\AppData\Local\{8B65DC12-F22F-4BDF-85B2-27D2F9DD1445}
2011-10-14 02:32:45 -------- d-----w- C:\Users\Alex\AppData\Local\{841BB974-ED9C-4CDA-A665-B1A0C95038FE}
2011-10-14 02:31:37 -------- d-----w- C:\Users\Alex\AppData\Local\{205E0237-15F5-4B9D-ABA4-A64F229AE94F}
2011-10-14 00:34:15 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-14 00:34:15 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-10-14 00:34:14 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-14 00:34:14 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-10-14 00:33:55 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-14 00:33:55 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-14 00:33:55 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-14 00:33:54 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-13 01:15:04 -------- d-----w- C:\Users\Alex\AppData\Local\{6FA3C4E8-F817-420B-9FF1-A1C08DA750DD}
2011-10-13 01:14:55 -------- d-----w- C:\Users\Alex\AppData\Local\{9B1E6C9B-3E59-4F0F-87D3-EAE4B4C77C65}
.
==================== Find3M ====================
.
2011-11-10 06:48:59 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-07 02:51:37 103784 ----a-w- C:\Users\Alex\GoToAssistDownloadHelper.exe
2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll
2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-08-19 21:59:28 158832 ----a-w- C:\Windows\System32\mfevtps.exe
2011-08-15 16:00:06 9984 ----a-w- C:\Windows\System32\drivers\mfeclnk.sys
2011-08-15 16:00:06 75672 ----a-w- C:\Windows\System32\drivers\mfenlfk.sys
2011-08-15 16:00:06 65128 ----a-w- C:\Windows\System32\drivers\cfwids.sys
2011-08-15 16:00:06 642824 ----a-w- C:\Windows\System32\drivers\mfehidk.sys
2011-08-15 16:00:06 481504 ----a-w- C:\Windows\System32\drivers\mfefirek.sys
2011-08-15 16:00:06 283744 ----a-w- C:\Windows\System32\drivers\mfewfpk.sys
2011-08-15 16:00:06 228752 ----a-w- C:\Windows\System32\drivers\mfeavfk.sys
2011-08-15 16:00:06 158584 ----a-w- C:\Windows\System32\drivers\mfeapfk.sys
2011-08-15 16:00:06 100904 ----a-w- C:\Windows\System32\drivers\mferkdet.sys
.
============= FINISH: 19:36:53.90 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 23/09/2011 7:59:27 PM
System Uptime: 10/11/2011 7:11:54 PM (0 hours ago)
.
Motherboard: Dell Inc. | | 0DPRF9
Processor: AMD Athlon(tm) II X4 610e Processor | CPU 1 | 2400/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 719.844 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: facap, FastAccess Video Capture
Device ID: ROOT\IMAGE\0000
Manufacturer: Sensible Vision
Name: facap, FastAccess Video Capture
PNP Device ID: ROOT\IMAGE\0000
Service: FACAP
.
==== System Restore Points ===================
.
RP44: 22/10/2011 10:24:21 AM - Windows Modules Installer
RP45: 23/10/2011 1:35:48 AM - Windows Update
RP46: 26/10/2011 12:40:38 AM - Windows Update
RP47: 29/10/2011 9:17:41 AM - Windows Update
RP48: 05/11/2011 8:04:34 PM - Scheduled Checkpoint
RP49: 07/11/2011 9:02:27 PM - Restore Operation
RP50: 08/11/2011 6:47:37 PM - ARO 2011 - Before Installation
RP51: 08/11/2011 6:48:26 PM - ARO 2011 - FIRST RUN
RP52: 08/11/2011 7:21:13 PM - ARO 2011 Tue, Nov 08, 11 19:21
RP53: 09/11/2011 1:05:27 AM - Windows Update
.
==== Installed Programs ======================
.
Accidental Damage Services Agreement
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.1) MUI
Advanced Audio FX Engine
Apple Application Support
Apple Software Update
ATI Catalyst Control Center
µTorrent
Bejeweled 2 Deluxe
Blackhawk Striker 2
Bounce Symphony
Build-a-lot 2
Cake Mania
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Chuzzle Deluxe
CIR Tool Kit
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Cozi
CyberLink PowerDVD 9.5
CyberLink YouPaint
D3DX10
Dell DataSafe Local Backup
Dell DataSafe Local Backup - Support Software
Dell DataSafe Online
Dell Digital Delivery
Dell Getting Started Guide
Dell MusicStage
Dell PhotoStage
Dell Stage
Dell Touch Software Suite Games
Dell VideoStage
Dell Webcam Central
Diner Dash 2 Restaurant Rescue
DirectX 9 Runtime
Dora's World Adventure
eBay
Escape Whisper Valley (TM)
Farm Frenzy
FATE
Final Drive Fury
Final Drive Nitro
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946040)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946308)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB946344)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947540)
Hotfix for Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789)
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 24
Jewel Quest
Jewel Quest Solitaire 2
Junk Mail filter update
Luxor
McAfee SecurityCenter
Mesh Runtime
Microsoft Office 2010
Microsoft Report Viewer Redistributable 2008 (KB971119)
Microsoft Report Viewer Redistributable 2008 SP1
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2008 R2 Policies
Microsoft SQL Server Browser
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 Query Tools ENU
Microsoft Touch Pack for Windows 7
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Visual Studio Tools for Applications 2.0 - ENU
Microsoft XNA Framework Redistributable 3.0
Mozilla Firefox 8.0 (x86 en-US)
MSVCRT
MSVCRT_amd64
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Multimedia Card Reader
Namco All-Stars PAC-MAN
OpenOffice.org 3.3
OpenVPN 2.2.1
Penguins!
PhotoShowExpress
Plants vs. Zombies - Game of the Year
Poker Superstars III
Polar Bowler
Polar Golfer
QualxServ Service Agreement
QuickTime
Realtek High Definition Audio Driver
Remote Administrator v2.2
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Creator Starter
Roxio Express Labeler 3
Samantha Swift
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Skins
Skype Click to Call
Skype™ 5.5
Sonic CinePlayer Decoder Pack
StepForward Client
StepForwardAdmin
StickyNotes
THX TruStudio PC
TrustedID
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update Installer for WildTangent Games App
Virtual Villagers 4 - The Tree of Life
Wedding Dash - Ready, Aim, Love!
WildTangent Games
WildTangent Games App (Dell Games)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Wisdom-soft Set up ScreenHunter 5.1 Free
Zuma Deluxe
.
==== Event Viewer Messages From Past Week ========
.
10/11/2011 7:32:56 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume .
08/11/2011 5:51:13 PM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
08/11/2011 3:18:37 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the McAfee McShield service to connect.
08/11/2011 3:18:37 AM, Error: Service Control Manager [7000] - The McAfee McShield service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
07/11/2011 8:24:42 PM, Error: Service Control Manager [7024] - The HomeGroup Listener service terminated with service-specific error %%-2147023143.
07/11/2011 8:22:53 PM, Error: Service Control Manager [7024] - The Windows Firewall service terminated with service-specific error Access is denied..
.
==== End Of File ===========================



(Selecting Uninstall application on close if you so wish)